
Cyber Incident
Response Plan.
One of the key ingredients for elevating your scheme's cyber crisis response readiness is a robust CIRP designed specifically for your trustee board.

There are two types of CIRP: those that reduce the impact of a cyber crisis and those that amplify it. Which one have you got?

Introduction
The value of a robust Cyber Incident Response Plan (CIRP) is difficult to overstate, but especially when a major cyber attack or data breach rears its unwelcome head.
​
A robust CIRP won't just provide the contact details of key resources or define their roles and responsibilities, it will highlight the trustee's key priorities at each phase of the incident, it will tell you what information you must capture, it will draw your attention to common pitfalls that should be avoided, but most of all, it will tell you which questions you need to ask and when to ask them.
Cyserri can develop a CIRP that doesn't just align to your risk appetite, scheme structure, and available resources, we can develop a CIRP that will also minimise mistakes, reduce unnecessary actions, and materially enhance your scheme's cyber resilience.

A robust Cyber Incident Response Plan is crucial. However, its usefulness plummets if it isn't regularly tested and updated.
More than a plan
In addition to developing a Cyber Incident Response Plan (CIRP), a Cyserri consultant can work with you to develop a number of supporting documents.
One example of these is a Cyber Crisis Comms Plan (C3P), a key part of which are external comms templates. Not only will a C3P help you keep avoidable communication mistakes to a minimum and significantly reduce comms drafting time, they will also help you build confidence amongst members and other stakeholders that the right people are involved, the right decisions are being made and response efforts are proceeding without delay.
​
It's important to remember that a trustee board and their suppliers could respond to a cyber crisis in a genuinely robust manner, but if their comms plan or comms execution is clearly sub-optimal, their members and other stakeholders are much less likely to be confident that your actions -- both before and after the incident's discovery -- were adequate.
And where there is a lack of stakeholder confidence, there is usually an abundance of scrutiny.


Your cyber crisis comms templates must balance brevity, clarity, empathy, and urgency. Just don't scrimp on transparency.

Benefits of our CIRPs
Each of our Cyber Incident Response Plans:
​
-
are designed specifically for pension trustee boards
-
satisfy the TPR's requirements around response plans
-
are well structured, easy to understand, and prioritise the most pressing decisions and actions
-
provide high-value advice that can be utilised during plan walkthroughs, simulation exercises or a real incident
-
help lower cyber insurance premiums
-
help to reduce the operational, financial and reputational risks associated with cyber attacks and data breaches
-
are designed by consultants that understand the cyber risks UK pension schemes are exposed to
​
Please see our cyber crisis simulation exercise service for further ways of enhancing your scheme's cyber resilience.

