If you suspect your business is under cyber attack right now, whether that's ransomware encrypting files, a compromised email account, or unauthorised access to your systems, the order of your next actions matters more than their speed. Done in the right sequence, you contain the damage and preserve your options; done in panic, you can destroy evidence and let the attacker keep their foothold.
Step one: isolate, but do not power off
Disconnect affected devices from the network immediately. Pull ethernet cables, switch off Wi-Fi on the affected machines, and sever any remote access sessions. This stops the attack spreading to other devices and cuts the attacker's connection.
Critically, do not shut the devices down. Volatile memory holds forensic evidence about what the attacker did, what they accessed, and how they got in, and powering off erases it. If investigators or your insurer's incident response team later need to establish what data was taken, that evidence may be the difference between knowing and guessing. Disconnect, leave running, and don't "tidy up" by deleting suspicious files or emails.
Step two: lock the attacker out of your accounts
Using a clean device, one you have no reason to believe is compromised, such as a personal phone on mobile data, change the passwords on your most critical systems in this order of priority: email first (it's the master key to everything else via password resets), then banking, accounting software, payroll, and cloud storage.
Turn on multi-factor authentication everywhere it's offered. If MFA was already enabled and the attacker got in anyway, treat the MFA channel itself as suspect and switch methods, moving from SMS codes to an authenticator app, for instance. Also check email accounts for forwarding rules and mailbox delegations the attacker may have planted; these are the standard way intruders keep reading your mail after you change the password.
Step three: make the calls
- The Australian Cyber Security Centre. Report the incident through the ACSC's ReportCyber service or its hotline. Reporting creates an official record, and the ACSC can provide guidance during an active incident. If a crime is clearly in progress, contact your state police as well.
- Your bank. If financial systems are potentially compromised, or the attack involved business email compromise (fake invoices, altered payment details), call the bank's fraud team straight away. They can monitor accounts, attempt to recall recent suspicious payments, and restrict access. Speed genuinely matters here; recalling a fraudulent transfer gets harder with every passing hour.
- Your IT provider. They need to hunt for persistence: other compromised accounts, malware left behind, and the original entry point. Removing the attacker's access once is not enough if the door they came through is still open.
- Your insurer. If you hold cyber insurance, notify early. Many policies require prompt notification and give access to incident response specialists, and acting without the insurer's involvement can complicate a claim.
Preserve evidence and start a log
From the moment you discover the incident, keep a written timeline: what you observed, when, and every action you took. Preserve system logs, suspicious emails (as attachments, with headers, not forwarded inline), and screenshots of ransom notes or unusual behaviour. This record supports the police report, the insurance claim, and any regulatory notification, and it is far easier to keep as you go than to reconstruct afterwards.
Work out your notification obligations
If personal information may have been accessed or taken, employee records, client details, financial information, you may have obligations under the Notifiable Data Breaches scheme administered by the OAIC. The scheme turns on whether the breach is likely to result in serious harm to the individuals affected, and it sets expectations for how promptly assessment and notification must happen. Don't self-assess this under pressure: get advice from a privacy-literate lawyer or your insurer's response team, because both notifying unnecessarily and failing to notify carry costs.
After containment: recover deliberately
Restore from backups only after your IT provider confirms the environment is clean; restoring onto a still-compromised network just re-infects your data. Then treat the incident as the audit you never commissioned. How did they get in? Which controls, MFA coverage, patching, backup isolation, staff phishing awareness, would have stopped it? The Essential Eight framework is a sensible structure for that review. Incident response capability is part of the operational resilience we cover across the Operations hub, and the businesses that handle attacks best are invariably the ones that decided, in advance and in writing, who does what when it happens. If you haven't been attacked and you're reading this preparedness-first: write that one-page plan today, while it's cheap.
About the author
Andrew Northcott
Founder & Chairman, Valont
Andrew is the founder and chairman of Valont and the parent group Wattlestone. He has spent two decades building and running Australian SMEs, and writes about the realities of ownership — cash, people, systems, and the decisions that compound.
LinkedIn →