Before anything else: stop, do not panic
The single most expensive mistake in cyber incidents is a rushed reaction. Wiping a machine destroys evidence. Paying a ransom without legal review may breach Australian sanctions law. Notifying customers prematurely can create legal exposure. Take a breath.
If you have a cyber insurance policy, your insurer almost certainly requires you to call their incident response hotline before taking action. Doing so does not slow you down, it gets you a panel response team and protects your cover. Have that number visible before an incident, not after.
Minutes 0 to 15: contain, do not destroy
The first 15 minutes are about containment and evidence preservation. Establish scope before action. Isolate affected machines from the network without powering them off. Disable suspect accounts in your identity provider. Snapshot virtual machines.
Identify what is affected
One user reporting a strange email is a different incident to multiple file servers being encrypted. Establish scope before action.
Isolate, do not power off
Disconnect affected machines from the network by unplugging the cable or disabling Wi-Fi. Do not shut them down. Volatile memory contains evidence.
Disable suspect accounts
In Microsoft 365, block sign-in and revoke sessions for any account showing suspicious activity. Do not delete the account.
Snapshot, do not wipe
For virtual machines, take a snapshot before any remediation. For cloud workloads, enable retention locks if available.
If you power off a machine, you lose volatile memory that may contain the only evidence of how the attacker got in. Isolate from the network, leave it running, and let IR handle the forensic capture.
Minutes 15 to 30: notify the right people in the right order
The next 15 minutes are about notification in the right order. Your insurer comes first, then your IT or MSP partner, then senior leadership, then legal counsel, then your bank if money has moved.
1. Your cyber insurer
Most policies have a 24 to 72 hour notification clause. Call the panel hotline. They will engage IR, legal and PR if covered.
2. Your IT or MSP partner
If they are not already engaged, get them on the line. They have the audit logs and tenant access you need.
3. Your senior leadership
CEO, CFO and General Counsel need to know. Especially if customer or financial data may be involved.
4. Legal counsel
Privilege protections often start when legal is engaged. Your insurer's panel lawyers usually move fastest.
5. Your bank, if money has moved
For business email compromise or invoice fraud, call the bank fraud line immediately. Recall windows are short.
Notification order matters. If you notify customers before legal reviews the position, you may create legal exposure. If you notify your bank before your insurer, you may miss the panel response that covers the loss.
Minutes 30 to 60: preserve evidence, document everything
The next 30 minutes are about evidence preservation and documentation. Open an incident timeline, preserve audit logs, capture screenshots, identify affected data and verify backups are intact.
Start a timestamped incident log
Open a document and timestamp every action from the first suspicion. This log is evidence for your insurer and regulator.
Preserve audit and sign-in logs
Preserve mailbox audit logs and sign-in logs for at least 12 months. These show how the attacker got in and what they accessed.
Capture screenshots
Screenshot ransom notes, suspicious emails and unusual sign-ins. Visual evidence is harder to dispute than log exports.
Verify backups are intact
Confirm backups are intact, immutable, and not connected to the affected network. If the attacker reached the backups, you need to know now.
Identify the data that may be affected early: customer PII, finance records, intellectual property. This drives your notification obligations under the Privacy Act and sector regulators.
What NOT to do in the first hour
These mistakes are expensive and common. Each one either destroys evidence, creates legal exposure, or tips off the attacker that you know they are there.
Do not pay the ransom yet
Australian sanctions law prohibits payments to certain ransomware groups. Always get legal advice first. Many demands are negotiable or avoidable.
Do not wipe or rebuild
You destroy evidence, persistence indicators and the ability to confirm the attacker is fully evicted.
Do not communicate externally yet
No customer emails, no LinkedIn posts, no press release. All external messaging goes through legal and PR review.
Do not use the compromised email
Move to a separate, known-clean channel. Phone, Signal or a fresh tenant. Attackers are watching the inbox.
Do not delete suspicious emails
They are evidence. Even if it looks like a phishing test, preserve everything until IR has reviewed.
Who to call in Australia
These are the official Australian contacts for a cyber incident. Save them before you need them.
ACSC Hotline: 1300 CYBER1 (1300 292 371)
24/7 cyber security hotline operated by the Australian Cyber Security Centre. Free, confidential and a sensible first call for SMBs without a retained IR provider.
ReportCyber: cyber.gov.au/report
The official Australian portal for reporting cybercrime. Reports are routed to the AFP and joint cybercrime units. Often required by your insurer.
OAIC: Notifiable Data Breaches scheme
If personal information is likely to be involved, you have obligations under the Privacy Act 1988. Assessment must be made within 30 days.
Sector regulators: APRA, ASIC, TGA
Regulated entities have additional notification obligations. APRA-supervised entities under CPS 234, listed companies under ASIC continuous disclosure, healthcare and critical infrastructure under SOCI.
General information only. This guide is not legal advice. Speak with your privacy lawyer and your insurer for specific obligations. Notification timelines differ by regulator and sector.
How we help before, during and after
We provide retained incident response for Australian businesses. We help you pre-agree the runbook, the contacts and the legal hold process before something goes wrong, so the first hour is execution, not improvisation.
- Step 1
Pre-agree the runbook
We build your incident response runbook before an incident. You know who to call, in what order, and what each party does.
- Step 2
Be on speed dial
When something happens, you call us first or we call you. We join the call within minutes and start containment.
- Step 3
Contain and preserve
We isolate affected systems, preserve evidence and work with your insurer's panel. You focus on your business, we handle the technical response.
- Step 4
Review after the dust settles
We review what happened, what worked and what did not. You receive a lessons-learned report and an updated runbook.
Common questions
What is the first thing to do in a cyber incident?
Stop and do not panic. Call your cyber insurer first if you have a policy, as most require notification before taking action. Then isolate affected machines from the network without powering them off, disable suspect accounts in your identity provider, and start a timestamped incident log. The ACSC hotline is 1300 CYBER1 (1300 292 371).
Should I power off a computer I suspect is compromised?
No. Powering off destroys volatile memory that may contain the only evidence of how the attacker got in. Disconnect the machine from the network by unplugging the cable or disabling Wi-Fi, but leave it running. Let the incident response team handle forensic capture.
Can I pay the ransom immediately to get back up faster?
No. Australian sanctions law prohibits payments to certain ransomware groups, and paying without legal review can create criminal liability. Many demands are negotiable or avoidable. Always get legal advice first, and check whether your insurer covers the payment decision.
Who do I have to notify after a cyber incident in Australia?
Your cyber insurer first, then your IT or MSP partner, then senior leadership and legal counsel. If personal information is likely to be involved, you must assess notifiability under the OAIC Notifiable Data Breaches scheme within 30 days. Regulated entities may have additional obligations to APRA, ASIC or sector regulators. ReportCyber is the official portal for reporting cybercrime.
What evidence should I preserve in a cyber incident?
Preserve mailbox audit logs and sign-in logs for at least 12 months, capture screenshots of ransom notes and suspicious emails, take a snapshot of virtual machines before any remediation, and start a timestamped incident log documenting every action. Do not delete suspicious emails or wipe affected machines, as these are evidence.
What is the ACSC hotline number?
The Australian Cyber Security Centre operates a 24/7 hotline at 1300 CYBER1, which is 1300 292 371. It is free, confidential and a sensible first call for Australian businesses without a retained incident response provider. You can also report cybercrime at cyber.gov.au/report.
Need an incident response partner on speed dial?
Real Bytes provides retained incident response for Australian businesses. We help you pre-agree the runbook, the contacts and the legal hold process before something goes wrong. Tell us your environment and we will scope a retainer that fits.

Remote Support