Crisis Protocol

Security Incident Response Playbook

Contain the incident, preserve evidence and restore trustworthy operations. Choose the incident below for practical actions, responsibilities and reporting guidance. Adapt this playbook to your systems and obtain professional advice; the suggested timings are priorities, not guaranteed recovery times.

Reviewed by Real Bytes: . Based on ASD, OAIC and Home Affairs guidance.

RANSOMWARE ATTACK - Data Encrypted or Held for Ransom

If this is happening now, nominate an incident lead and use a clean phone or other trusted channel to coordinate. An attacker may be reading compromised email or Teams messages. Contact your IT response team and insurer, and call the ACSC on 1300 CYBER1 (1300 292 371). Prioritise human safety before changes to operational, clinical or industrial systems.

Select Incident Type

Who Do You Call First?

Minute 1

Incident Response Lead

Command and control

Orchestrate entire response. Must be immediately contactable 24/7. Make critical decisions on backup recovery vs forensics approach.

ACSC (1300 CYBER1)

Free expert guidance

Call immediately for professional support. ACSC advises on recovery strategy, forensics coordination, and reporting to AFP.

IT Security Team / SOC

Contain the incident

Begin immediate isolation and forensics. Stop ransomware from spreading across network. Preserve all evidence.

Hour 1

Legal Counsel

Regulatory compliance

Assess Privacy Act obligations, insurance requirements, and reporting deadlines. Advise on ransom policy and law enforcement involvement.

Cyber Insurance Broker

Preserve insurance claim

Check policy conditions, approved providers and consent requirements. Notify promptly and obtain coverage advice; payment of response costs is not automatic.

Hour 2

Finance/CFO

Cost and approval

Budget for forensics, recovery, and potential regulatory fines. Ransom payment requires board approval (not recommended by ACSC).

External Forensics Firm

Investigation and evidence

Investigate attack vector, preserve evidence, search for persistence mechanisms. Essential before any system rebuilds.

AFP Cyber Crime

Law enforcement

Report via cyber.gov.au/report-and-recover/report. Do NOT pay ransom. Reporting disrupts threat actor infrastructure.

Immediate Response (Steps 1-4)

Follow these steps in sequence

Progress

1/4

Use this guidance in your organisation's response plan

Keep an offline contact list, response authorities and critical-system priorities. Record observations, actions, approvals and next updates in a single incident log, and keep evidence separately with collection times and access records. Rehearse the plan with business, IT, legal and supplier representatives. ASD's ISM expects the incident management policy and response plan to be exercised at least annually.

Should we turn off a ransomware-affected computer? Isolate it from the network first and preserve power where safe. CISA recommends shutdown only when isolation is not possible and spread must be stopped. Critical and safety-related systems need specialist direction.

Does changing a password remove the attacker? Not necessarily. Revoke compromised sessions, review application consent and remove persistence as well as resetting credentials. Use a known-clean device and verify the result.

Do we have 30 days to notify the OAIC? No. The NDB scheme requires prompt assessment, with all reasonable steps to complete it within 30 calendar days. Once an eligible breach is established, notify the OAIC and affected people as soon as practicable.

Is reporting a ransomware payment a separate obligation? Yes. In-scope businesses must report within 72 hours of payment or awareness that a payment was made on their behalf. Legal should check the turnover threshold and critical infrastructure status; a general incident report does not replace this report.

When can we reconnect systems or supplier access? When agreed recovery criteria have been met: the entry path is closed, compromised access is removed, evidence is preserved, restored data and dependencies are tested, and the responsible owner approves reconnection with monitoring in place.

Sources checked 4 October 2026: ASD incident guidance; CISA ransomware response; OAIC NDB requirements; Home Affairs payment reporting.

In an active incident, every minute matters. Don't wait to learn this later.