Haines & Company

NCSC guidance on long-term cyber resilience

Talk to an expert

The National Cyber Security Centre (NCSC) states that UK organisations should prepare for an extended period of heightened cyber security threat. It has guidance for organisations on the steps to take to improve security.


The guidance is designed to be applicable to any period of sustained heightened cyber threat, including the one arising from Russia in light of events in and around Ukraine.


The NCSC says that the cyber threat to the UK remains heightened and they expect it to stay that way for some time.


The NCSC guidance aims to help organisations avoid complacency and staff burnout. It advises that increased workloads for cyber security staff over an extended period can harm wellbeing and lead to lower productivity, with a potential rise in unsafe behaviours or errors.


The recommended actions in the guidance include:

  • following the NCSC's actions to take when the cyber threat is heightened guidance;
  • revisiting risk-based decisions taken during the initial phase of heightened threat;
  • empowering cyber staff to make day-to-day decisions about the threat response without requiring additional oversight;
  • ensuring workloads are spread evenly across individuals and teams;
  • ensuring frontline cyber staff can take breaks to recharge; and
  • accelerating planned action to harden networks and boost defence capabilities.
    See: [Maintaining a sustainable strengthened cyber security posture - NCSC.GOV.UK](https://www.ncsc.gov.uk/guidance/maintaining-a-sustainable-strengthened-cyber-security-posture)
November 13, 2025
Free Recruitment Support Available to UK Businesses Through Jobcentre Plus

The Department for Work and Pensions (DWP) has launched a national campaign to offer UK businesses access to no-fee specialist recruitment support through Jobcentre Plus. The service is available to all businesses, regardless of size or sector.

Read article
November 12, 2025
Reminder: Companies House Identity Verification Becomes Mandatory from 18 November 2025

From 18 November 2025, identity verification with Companies House will start to be required for company directors and People with Significant Control (PSCs). The measure is intended to improve the reliability of information on the UK’s company register and support efforts to reduce economic crime.

Read article