Cyberattack contingency plan: the minimum required for an ISO 27001/NIS2 audit

By Carles Latorre on Sep 8, 2026, 9:00:00 AM

<span id="hs_cos_wrapper_name" class="hs_cos_wrapper hs_cos_wrapper_meta_field hs_cos_wrapper_type_text" style="" data-hs-cos-general-type="meta_field" data-hs-cos-type="text" >Cyberattack contingency plan: the minimum required for an ISO 27001/NIS2 audit</span>

In Spain, cyberattacks increased by 66% during the first quarter of 2025 compared to the same period of the previous year. In addition, a business interruption can cost between €4,000 and €7,500 per minute, while companies take 25% longer than expected to recover after an incident.

In this context, having a contingency plan is not just a compliance requirement. It helps define who should act, which systems should be prioritized, and how to restore operations without improvising when a cyberattack occurs.

Nueva llamada a la acción

What is a cyberattack contingency plan?

It is a set of procedures that establishes how a company should respond when an incident affects its systems, data, or services. Its goal is to limit the impact, maintain business continuity, and restore operations in a controlled manner.

For organizations subject to NIS2 or operating under ISO 27001, incident management, continuity, and recovery are part of a security strategy that must be documented and regularly reviewed.

When should a contingency plan be activated?

The plan should define which situations could compromise business continuity and when it is necessary to activate the established procedures.

It may be necessary in the event of an infection affecting multiple devices, unauthorized access, loss or exposure of information, the failure of critical systems, or any incident that prevents the company from carrying out an essential business activity.

Early detection makes it possible to identify these situations before their impact increases and activate the appropriate response.

What should a cybersecurity contingency plan include?

A useful plan should be adapted to each company's infrastructure and business activities. At a minimum, it should include the following elements:

  • Critical systems and processes: identify which services must be restored first to maintain operations.
  • Roles and responsibilities: establish who makes decisions, who carries out technical actions, and who coordinates communications.
  • Incident response procedure: define how to detect, contain, investigate, and manage an incident.
  • Recovery plan: establish how systems, applications, and data will be restored after an interruption.
  • Backups: determine what information is backed up, where it is stored, and how recovery is tested.
  • Communication and notification: establish how employees, customers, suppliers, and authorities should be informed when applicable.
  • Testing and review: regularly verify that procedures remain valid and can be effectively executed.

The goal is to ensure that, when an incident occurs, critical decisions do not have to be made from scratch.

What do ISO 27001 and NIS2 require in the event of an incident?

Neither ISO 27001 nor NIS2 is based solely on having a document in place. The focus is on ensuring that the organization manages its risks, has appropriate security measures, and can respond to and recover from incidents.

This involves establishing procedures, responsibilities, and continuity mechanisms, as well as keeping them up to date and regularly verifying that they work as intended.

In the case of NIS2, organizations must also consider requirements related to incident management and notification when applicable.

Nueva llamada a la acción

What should you do during the first few hours of a cyberattack?

When an incident is confirmed, the priority is to contain it and determine its scope before beginning recovery.

  1. Isolate affected systems to limit the spread.
  2. Assess the scope and determine which devices, accounts, and data may be compromised.
  3. Secure credentials and revoke access that may have been used.
  4. Preserve evidence to investigate the origin and evolution of the incident.
  5. Activate recovery procedures according to the priorities established in the plan.

A predefined response allows the company to act more quickly and reduces the need to make improvised decisions during a crisis.

How can you verify that your contingency plan works?

Having a written procedure does not guarantee that it can be properly executed when needed. Companies should regularly conduct incident simulations and recovery tests.

These tests make it possible to verify whether backups can be restored, whether those responsible understand their roles, and whether the established recovery times are actually achievable.

In addition, each exercise helps identify weaknesses and update the plan before it needs to be used during a real incident.

Measures to reduce the impact of a cyberattack

  • Continuous monitoring: enables early detection of abnormal behavior.
  • MFA and access control: limits the impact of compromised credentials.
  • Protected backups: enable affected systems to be restored.
  • Audits and security testing: help identify vulnerabilities before they are exploited.
  • Employee training: reduces risks associated with human error and social engineering attacks.

Why choose ESED as your technology partner?

A contingency plan establishes how to respond when an incident affects the company, but its effectiveness depends on having a security strategy that enables systems to be detected, contained, and recovered in a coordinated manner.

At ESED, we help companies strengthen their prevention and response capabilities through monitoring, security audits, system protection, and managed cybersecurity services tailored to the needs of each organization.

Our fixed monthly pricing model enables continuous infrastructure monitoring and helps organizations progress toward NIS2, ISO 27001, and ENS requirements, without relying solely on one-off actions after an incident has already occurred.