Security Incident Response Playbook
Contain the incident, preserve evidence and restore trustworthy operations. Choose the incident below for practical actions, responsibilities and reporting guidance. Adapt this playbook to your systems and obtain professional advice; the suggested timings are priorities, not guaranteed recovery times.
Reviewed by Real Bytes: . Based on ASD, OAIC and Home Affairs guidance.
RANSOMWARE ATTACK - Data Encrypted or Held for Ransom
If this is happening now, nominate an incident lead and use a clean phone or other trusted channel to coordinate. An attacker may be reading compromised email or Teams messages. Contact your IT response team and insurer, and call the ACSC on 1300 CYBER1 (1300 292 371). Prioritise human safety before changes to operational, clinical or industrial systems.
Select Incident Type
Who Do You Call First?
Minute 1
Incident Response Lead
Command and control
Orchestrate entire response. Must be immediately contactable 24/7. Make critical decisions on backup recovery vs forensics approach.
ACSC (1300 CYBER1)
Free expert guidance
Call immediately for professional support. ACSC advises on recovery strategy, forensics coordination, and reporting to AFP.
IT Security Team / SOC
Contain the incident
Begin immediate isolation and forensics. Stop ransomware from spreading across network. Preserve all evidence.
Hour 1
Legal Counsel
Regulatory compliance
Assess Privacy Act obligations, insurance requirements, and reporting deadlines. Advise on ransom policy and law enforcement involvement.
Cyber Insurance Broker
Preserve insurance claim
Check policy conditions, approved providers and consent requirements. Notify promptly and obtain coverage advice; payment of response costs is not automatic.
Hour 2
Finance/CFO
Cost and approval
Budget for forensics, recovery, and potential regulatory fines. Ransom payment requires board approval (not recommended by ACSC).
External Forensics Firm
Investigation and evidence
Investigate attack vector, preserve evidence, search for persistence mechanisms. Essential before any system rebuilds.
AFP Cyber Crime
Law enforcement
Report via cyber.gov.au/report-and-recover/report. Do NOT pay ransom. Reporting disrupts threat actor infrastructure.
Immediate Response (Steps 1-4)
Follow these steps in sequence
Progress
1/4
Use this guidance in your organisation's response plan
Keep an offline contact list, response authorities and critical-system priorities. Record observations, actions, approvals and next updates in a single incident log, and keep evidence separately with collection times and access records. Rehearse the plan with business, IT, legal and supplier representatives. ASD's ISM expects the incident management policy and response plan to be exercised at least annually.
Should we turn off a ransomware-affected computer? Isolate it from the network first and preserve power where safe. CISA recommends shutdown only when isolation is not possible and spread must be stopped. Critical and safety-related systems need specialist direction.
Does changing a password remove the attacker? Not necessarily. Revoke compromised sessions, review application consent and remove persistence as well as resetting credentials. Use a known-clean device and verify the result.
Do we have 30 days to notify the OAIC? No. The NDB scheme requires prompt assessment, with all reasonable steps to complete it within 30 calendar days. Once an eligible breach is established, notify the OAIC and affected people as soon as practicable.
Is reporting a ransomware payment a separate obligation? Yes. In-scope businesses must report within 72 hours of payment or awareness that a payment was made on their behalf. Legal should check the turnover threshold and critical infrastructure status; a general incident report does not replace this report.
When can we reconnect systems or supplier access? When agreed recovery criteria have been met: the entry path is closed, compromised access is removed, evidence is preserved, restored data and dependencies are tested, and the responsible owner approves reconnection with monitoring in place.
Sources checked 4 October 2026: ASD incident guidance; CISA ransomware response; OAIC NDB requirements; Home Affairs payment reporting.

Remote Support