Skip to main content

Part of Objective B - Protecting against cyber attacks and data breaches

Principle: B5 Resilient networks and systems

Current Chapter

Current chapter – Principle: B5 Resilient networks and systems


B5.a Resilience preparation

“You are prepared to restore the operation of your essential function(s) following adverse impact to network and information systems.”

Overview

To achieve this outcome, you need to be prepared to withstand an incident, maintain your essential functions, and restore the full operation of your essential functions in the event of an incident.

Restoring the operation of the essential function

You should understand the information, networks and systems that are necessary to restore the operation of the essential function in the event of an incident. 

The scoping exercise at the outset of your DSPT assessment which determines the information, networks and systems which support your essential functions provides such an overview.

You should understand:

  • business importance the systems which are most important to bring back online for the operation of the essential function from a time-bound perspective
  • dependencies the order in which systems can technically be brought back online given the interdependencies between them

Where your essential services and functions support the direct delivery of care to patients, your determination of ‘business importance’ should be supported by clinical input from people who understand the impact that unavailable systems would have on patient safety.  

With patient safety in mind, you should establish a hierarchy setting out the order in which key clinical and administrative systems should be brought back online if multiple systems become unavailable. 

"Achieved" level

Business continuity and disaster recovery plans

See ‘D1.a Response plan’ and ‘D1.c Testing and exercising’.

Identifying risk and enhancing security measures 

You should use threat intelligence sources to identify new or heightened risks that may affect your organisation. 

Where a credible threat is identified, you should assess whether it applies to your environment. Where necessary, you should apply immediate and potentially temporary security measures.  

These measures may include:  

  • restricting access to systems  

  • increasing monitoring 

  • applying emergency patches or mitigations 

  • blocking newly discovered indicators of compromise  

  • limiting supplier connectivity 

  • strengthening email filtering 

  • preparing specific business continuity arrangements

When you assess that there is no longer a heightened risk to your organisation, temporary measures should be reviewed and removed or replaced with permanent business as usual controls. 

Supporting evidence

To support your response, you can upload (or link to) evidence which best demonstrates your achievement of the contributing outcome. Examples include:

  • documentation identifying networks, information systems and technologies necessary for restoring the operation of essential functions
  • evidence of interdependencies between essential functions and networks, systems and technologies being identified
  • business continuity and disaster recovery plans 
  • evidence of testing exercises conducted related to business continuity and disaster recovery plans 
  • procedures for identifying heightened levels of risk and implementing mitigating actions 

This is not an exhaustive list. You're welcome to provide other types of evidence if you feel they are relevant to the contributing outcome.

Your supporting statement should cross-reference how each piece of evidence provides justification for your achievement of the contributing outcome, including relevant page numbers where appropriate. 

Interpreting indicators of good practice

Indicator(s) of good practice Term Interpretation

PA#1

You know all network and information systems, and underlying technologies, that are necessary to restore the operation of your essential function(s) and understand their interdependence

'essential function(s)'

Your essential functions should be identified in a scoping exercise which you carry out before beginning your DSPT submission. The same exercise should identify all the information, systems and networks which support your essential functions.

For more information, see guidance on scoping essential functions.

National services

The following national services may help you meet the requirements of B5.a Resilience preparation: 

NCSC services | Exercise in a box

Additional guidance

For additional guidance, see:

National Cyber Security Centre CAF guidance | B5 Resilient networks and systems


B5.b Design for resilience

“You design network and information systems supporting your essential function(s) to be resilient to cyber security incidents. Systems are appropriately segregated and resource limitations are mitigated.”


For this contributing outcome, there is no minimum expected level of achievement for ‘Standards met’. You are still required to assess your achievement level and provide a response, showing you have considered the implications of the contributing outcome for your organisation’s cyber security and information governance (IG) activities. The Data Security Protection Toolkit (DSPT) ‘Standards met’ expectation should be regarded as a minimum compliance level, not the end goal of your organisation’s cyber security and IG activities.  

Overview

To achieve this outcome, you should be able to demonstrate that your networks and systems are designed to be resilient to incidents.

Logical separation 

You should design your network with the segregation principle in mind, dividing your networks and systems into zones according to the security requirements of their assets.  

A risk analysis should determine the level of security required for each zone and guide the technical and physical solutions you put in place.  

At “Partially achieved” level, all systems may still be part of the same overall network, but grouped into isolated zones. 

Internet services  

You should not allow systems which support your delivery of health or care services to access internet services, such as web browsing and email, unless there is a clear business need and the access is subject to appropriate restrictions. 

A ‘clear business need’ means you must have a documented policy, process or procedure establishing: 

  • acceptable use of the internet  

  • which staff member groups have a legitimate business need to access the internet 

  • how legitimate internet access is managed  

‘Appropriate restrictions’ may include controls such as: 

  • monitoring and analysing incoming and outgoing internet traffic, such as by encrypted traffic analysis.  (You should not normally decrypt outbound encrypted traffic, and only with a careful assessment of the risks created by doing so.)  

  • blocking or filtering out harmful content 

  • blocking unauthorised or unsafe protocols 

  • managing internet access  

Resource limitations

You should conduct a review of your network and systems to identify single points of failure, which risk causing major disruption to your essential service if compromised. You should document, review and manage the associated risks, mitigating them where possible. 

At the “Partially achieved” level, you may not have fully mitigated the risks.

"Achieved" level

Segregation

Systems that are critical to your organisation and essential service delivery (informed by risk assessment) should be segregated from other business and external systems through dedicated infrastructure and administration arrangements. 

This means placing these systems within purpose-built environments that are managed separately from your business as usual environment. An attacker would need to compromise the segregated environment separately to disrupt services supported by those systems. 

Resource limitations 

All risks related to single points of failure on your network which you have identified should have been mitigated.

Geographical constraints and weaknesses 

When designing your networks and systems, you should consider geographical constraints and weaknesses.  

If all your servers, or all your suppliers’ servers, are in the same geographical area, one serious security event localised to that area could cause system-wide consequences with little chance of an efficient recovery.  

For this reason, your documentation should reflect the mitigations you have in place to prevent adverse impact. 

Supporting evidence

To support your response, you can review and upload (or link to) evidence which best demonstrates your achievement of the contributing outcome. Examples include:

  • network architecture documentation 
  • evidence of a clear business need and restrictions being applied to networks and systems with internet access
  • documentation identifying single points of failure, associated risks and proposed mitigations 
  • evidence of technical and physical segregation of networks supporting essential functions
  • evidence of single points of failure being remediated
  • evidence of geographical constraints and mitigations
  • evidence of scheduled review process for assessments relating to network resilience 

This is not an exhaustive list. You're welcome to provide other types of evidence if you feel they are relevant to the contributing outcome.

Your supporting statement should cross-reference how each piece of evidence provides justification for your achievement of the contributing outcome, including relevant page numbers where appropriate. 

Interpreting indicators of good practice

Indicator(s) of good practice Term Interpretation

NA#2

Internet services, such as browsing and email, are accessible without restriction or business need from network and information systems supporting your essential function(s).

'without restriction or business need'

'Without restriction' would mean that there are no solutions in place to:

  • monitor and analyse incoming and outgoing internet traffic, such as by encrypted traffic analysis. (You should not normally decrypt outbound encrypted traffic, and only with a careful assessment of the risks created by doing so.)  

  • block or filter out harmful content 

  • block and monitor connections to unsafe or malicious sites, such as by using the national Protective Domain Name Service (PDNS) 

  • block unauthorised or unsafe protocols 

  • manage internet access

'Without business need' would mean that there is no documented policy, process or procedure establishing:

  • acceptable use of the internet
  • which staff member groups have a legitimate business need to access the internet
  • how legitimate internet access is managed 

PA#1

Network and information systems supporting the operation of your essential function(s) are logically separated from your business systems (for example they reside on the same network as the rest of the organisation but within isolated zones)

'essential function(s)'

Your essential functions should be identified in a scoping exercise which you carry out before beginning your DSPT submission. The same exercise should identify all the information, systems and networks which support your essential functions.

For more information, see guidance on scoping essential functions.

National services

The following national services may help you meet the requirements of B5.b Design for resilience:

Additional guidance

For additional guidance, see:

National Cyber Security Centre CAF guidance | B5 Resilient networks and systems
National Cyber Security Centre | Secure design principles


B5.c Backups

“You hold accessible and secured current backups of data and information needed to recover operation of your essential function(s) following an adverse impact to network and information systems."

Overview

This outcome relates to you having a robust system for backups which ensures you can efficiently restore your essential functions in the event of an incident.

Backups

You should maintain backups of the most important electronic information supporting your essential functions (see ‘B3.c Stored data’). These should be deployed following an incident or event to restore your essential service.

The frequency of backup operations should also be agreed, documented and adhered to. It is up to you to decide what intervals are appropriate. However, you should make and justify your decision based on:

  • the agreed length of time your organisation could be disrupted by loss of access to data before unacceptable consequences would arise
  • the frequency of backup operations which would enable you to restore your essential functions to an acceptable level within the timeframe  

Your recovery point objective (RPO) and recovery time objective (RTO) need to be formally agreed and tested to ensure they can be met. Where services cannot be returned within the timeframe, this should be documented and managed as a risk.

Appropriately securing backups

You should appropriately secure your backups to ensure they are accessible and the data within them is recoverable at critical times. 

Rules outlined by NCSC which serve as effective guidelines for backup protection are:

  • the offline rule – at any given time, one or more backups should be offline and therefore unaffected by incidents impacting the live environment
  • the 3-2-1 rule – keep at least 3 logically separated backup copies, on 2 devices, with 1 being offsite, to ensure that if one is compromised the other remains  

For more detail, and other rules see NCSC guidance on offline backups in an online world.

For cloud backup services, see NCSC cloud security principle 2 on asset protection and resilience for things you should consider when working with a cloud service provider.

Testing backups

It is important that you are confident you can recover the data which is required to maintain your essential service from your backups. To gain this confidence, you should test your backups on a scheduled basis, or after significant changes have been made to your networks and systems. 

Things to look out for include:

  • overused or old media
  • corrupt backup catalogue
  • bad backup image files
  • multiple complex restores required 
  • backup didn’t occur or backed up the wrong system
  • nowhere to store the restore
  • networked disk-based storage being unavailable due to the nature of the incident

The testing should be representative of the service or system in focus and not based on routine smaller scale requests or an old live incident. For example, a routine restore of single mailbox for a returning member of staff would not be considered as enough confidence to restore a whole email system.

You should decide whether to use live systems or test systems based on your judgment of the risk and whether the test system is sufficiently representative of the live system to make the testing valid.

You should also know the process for restoring the system, as well as documenting any issues found during the test and the plan to rectify them.

Documenting backup procedures 

Your backup activities should be supported by documentation which outlines:  

  • frequency of backups 

  • how you ensure the ongoing security and maintenance of your backups 

  • which business events trigger backups to be made or used

  • how you have automated your backups processes (in areas where it is appropriate to do so) 

  • how your testing regime ensures you are ready to efficiently recover the essential function in the event of an incident 

Supporting evidence

To support your response, you can upload (or link to) evidence which best demonstrates your achievement of the contributing outcome. Examples include:

  • procedures for accessing and deploying backups after extreme event scenarios. 
  • backup tests. 
  • documentation of comprehensive procedures for backups. 
  • evidence of secure sites being used for backups storage
  • evidence of results of backup tests being reviewed and acted upon

This is not an exhaustive list. You're welcome to provide other types of evidence if you feel they are relevant to the contributing outcome.

Your supporting statement should cross-reference how each piece of evidence provides justification for your achievement of the contributing outcome, including relevant page numbers where appropriate. 

Interpreting indicators of good practice

Indicator(s) of good practice Term Interpretation

PA#2

You routinely test backups to ensure that the backup process functions correctly and the backups are usable.

'routinely' On a scheduled basis, with enough frequency to give you confidence that your backups are usable.

A#2

Backups of all important data and information needed to recover the essential function(s) are made, tested, documented and routinely reviewed.

'essential function(s)'

Your essential functions should be identified in a scoping exercise which you carry out before beginning your DSPT submission. The same exercise should identify all the information, systems and networks which support your essential functions.

For more information, see guidance on scoping essential functions.

National services

The following national services may help you meet the requirements of B5.c Backups:

Additional guidance

For additional guidance, see:

National Cyber Security Centre CAF guidance | B5 Resilient networks and systems
National Cyber Security Centre | Cloud security guidance - Principle 2: Asset protection and resilience
NHS England | Backups and Office 365 guidance


Last edited: 26 August 2026 12:35 pm