How to Maintain Business Continuity After a Cyberattack
By Daniel Agyemang Prempeh, Founder, DefendVistaLast reviewed:
A step by step guide for UK transport and logistics operators: what to do in the first hours, how to keep loads moving without your systems, how to sequence recovery, and what to preserve for the insurer and the regulator.
This guide is about the days after the alarm goes off, not the planning that happens before it. If your transport management system, warehouse system or email has just been taken away from you, the questions that matter are immediate: what do we do in the next hour, how do we keep contracted loads moving, what must we not destroy, and in what order do we bring things back. The sequence below follows UK practice, including the National Cyber Security Centre incident management guidance and the Information Commissioner's Office rule that a notifiable personal data breach must be reported within 72 hours of you becoming aware of it.
The first hour: contain, log and tell the right people
Isolate affected machines from the network by unplugging them or disabling the switch port, and disable remote access at the perimeter. Do not power machines off, because memory contents help the investigation. Start a written timestamped log of every action and decision, kept off the affected systems. Notify your cyber insurer straight away, since most policies require early notification and some void cover for unauthorised remediation. The NCSC incident management guidance is the reference point for this stage, and it is worth having a printed copy in the depot.
Decide what must keep running
Before anyone touches recovery, agree the two or three operational outputs that cannot stop. For a haulier that is usually dispatch of contracted loads and driver communication. For a third party logistics operator it is goods in and goods out at agreed accuracy. For a warehouse it is picking rates for the largest accounts. Everything else is deferrable for now. Writing this down in the first hour stops the team spreading itself across twenty problems at once.
Operational workarounds that hold for 72 hours
Transport and logistics has an advantage over most sectors: the work is physical and can be run on paper. Printed run sheets and manifests, a whiteboard load board in the transport office, manual goods received notes, a paper KPI log, and mobile phones for driver contact will carry an operation through several days. Fuel cards, gate access and tachograph obligations continue regardless of the outage, so assign someone to each. If telematics is down, drivers report by phone at fixed times rather than continuously.
Prioritise systems by operational consequence, not by size
Rank the recovery queue by what it unblocks on the yard, not by which server is largest. In most operations the order is: identity and email, then the transport or warehouse management system, then telematics and routing, then customer portals and EDI links, then finance and reporting. Agree the order with operations rather than leaving it to IT, and record the reasoning so nobody relitigates it at midnight.
Talking to staff, customers and drivers
Assume email is unavailable or untrusted, and move coordination to an agreed alternative channel set up in advance. Brief staff first, because they will be asked questions by customers within the hour. Contact your largest customers proactively with a short factual holding statement: what is affected, what is still running, what they can expect and when you will next update them. Fixed update times, even when there is nothing new, are what preserve the relationship. Drivers need a single named contact and a fixed call-in schedule.
Preserve evidence while you recover
Do not wipe or rebuild machines before they have been triaged. Keep disk images and logs, keep the ransom note if there is one, and keep the written incident log. This material is what the insurer, the forensic investigator and, if personal data is involved, the ICO will ask for. If driver, employee or customer personal data may have been accessed or exfiltrated, the 72 hour ICO clock starts when you become aware, not when the investigation finishes. Report on what you know and follow up with detail later.
Sequence the recovery so it holds
Rebuild into a clean environment rather than back into the compromised one. In practice that means new credentials for every privileged account, endpoint detection deployed before a machine rejoins the network, patching validated, and backups checked for integrity before restoration. Bring systems back in the agreed operational order, verify each with a real transaction (one live load, one live pick) before declaring it available, and only then reconnect customer portals and supplier EDI links. Declaring recovery early and being reinfected is the most expensive mistake in this phase.
Returning to normal running
There is usually a backlog: proof of delivery documents to re-key, invoices to raise, stock counts to reconcile, tachograph and compliance records to reconstruct. Plan the catch-up explicitly with overtime or agency cover rather than assuming the team absorbs it. Tell customers when you are back to normal service, and confirm which of their jobs were affected.
The post-incident review that actually changes something
Within two weeks, hold a structured review with operations, IT and leadership. Use the incident log rather than memory. Identify the three changes that would have made the biggest difference, assign owners and dates, and fold them into the continuity plan and the incident response plan. Cyber Essentials controls, tested offline backups and multi-factor authentication on remote access are the usual outcomes, and they are also what insurers and customers will ask about at renewal.
Frequently asked questions
How quickly do we have to tell the ICO?+
If personal data is involved and the breach is likely to risk people's rights and freedoms, you have 72 hours from becoming aware to report it to the Information Commissioner's Office. Report with what you know and supply further detail as the investigation progresses.
Should we keep trading while systems are down?+
In most cases yes, on manual processes, provided you can still meet safety and compliance obligations such as tachograph and driver hours records. Stopping entirely usually costs more than running at reduced capacity on paper.
Can we start rebuilding straight away?+
Not before the affected systems have been triaged. Rebuilding early destroys the evidence your insurer and investigator need, and risks restoring the same access the attacker used.
Who should speak to customers?+
One named person, usually the managing director or commercial lead, working from an agreed holding statement. Multiple people improvising different versions is what turns an operational problem into a reputational one.
What is the most common gap operators discover?+
Communications. Most plans assume email or Teams is available to coordinate the response, and both are frequently unavailable or untrusted during an incident.
Next step
Want to talk this through?
Book an initial call. No sales pitch, just clear answers.
Book an initial call