Skip to content
Operations HubIT & Cybersecurity

Incident Response Plan: What to Do in the First 24 Hours of a Breach

Most Australian business owners have a working understanding of technology and security. You know the basics.

By Andrew Northcott·29 April 2026·5 min read·Last reviewed 8 July 2026

The short answer

In the first 24 hours of a breach, contain the incident, preserve evidence, and assess what data was exposed. Isolate affected systems without wiping them, reset compromised credentials, and record a timeline of what you know. Then work out your notification obligations: eligible data breaches must be reported to the OAIC and affected individuals under the Notifiable Data Breaches scheme, and serious cyber incidents can be reported to the ACSC. Decide early who leads response across IT, people, and operations.

When a breach hits — ransomware on the file server, a business-email-compromise wire fraud, a laptop stolen with client data on it — the first day sets the trajectory of everything that follows. The businesses that come through well aren't the ones with the fanciest tools; they're the ones who decided what to do before it happened. Here's how to spend those first 24 hours.

The first hour: contain, don't investigate

The instinct to work out exactly what happened is strong, but containment comes first. Every minute an attacker or malware has access, the damage grows.

  • Isolate, don't power off. Disconnect affected machines from the network — pull the cable, disable Wi-Fi — but resist shutting them down. Powering off can destroy volatile evidence in memory that later helps you understand the attack. Isolation stops the spread; shutdown can cost you the forensic trail.
  • Cut off the pathway. If it's an account compromise, reset that account's credentials and revoke its active sessions immediately. If it's a stolen device, trigger a remote wipe if you can.
  • Preserve, don't fix. Don't start deleting files, reimaging, or "cleaning up" yet. If this becomes a matter for insurers, police or the regulator, you'll want the scene intact.

Stand up the response team and start a log

Decide in advance who's in the room, because you won't want to be assembling it under pressure. At minimum: someone who owns the decisions (usually the owner or a senior manager), your IT provider or internal tech person, and a note-taker. From the very first phone call, keep a timeline log — timestamped, factual, one line per event: when it was detected, who was told, what was done. This single document does more work than anything else. It anchors your regulator notification, your insurance claim and your post-incident review, and it stops the story drifting as adrenaline distorts memory.

Assess scope: what was actually accessed

Once the bleeding has stopped, work out the blast radius. The critical question for your legal obligations isn't "were we attacked" but "was personal information likely accessed or exposed, and could it cause serious harm." Establish:

  • Which systems and accounts were touched.
  • What data lived there — client records, employee files, payment details, health information, credentials.
  • Whether data was exfiltrated (copied out) as opposed to merely encrypted or viewed.
  • How the attacker got in, so you can be sure you've closed it and not just swept them into another corner of the network.

Meet your notification obligations

Australia's Notifiable Data Breaches scheme requires organisations it covers to notify both the affected individuals and the Office of the Australian Information Commissioner where an eligible data breach is likely to result in serious harm. There are specific timeframes for assessing and notifying, and they matter — check the OAIC's current requirements rather than guessing. Notification isn't an admission of failure; failing to notify when you should is the bigger problem. Separately consider:

  • Your cyber insurer — most policies require prompt notification and many provide an incident-response hotline and pre-approved forensic and legal help. Read the policy's notification clause now, not during the incident.
  • Report to authorities. Report cybercrime through the ASD's ReportCyber service; it feeds the national picture and can support any insurance or law-enforcement follow-up.
  • If money moved in a payment-redirection fraud, contact your bank immediately — fast reporting is the only realistic chance of recovering funds.

Communicate deliberately

Say what you know, to the people who need to know, and no more. Staff need clear instructions (change your passwords, don't touch that server, direct media questions to one person). Affected clients deserve a straight, calm account of what happened and what you're doing about it — often the reputational damage comes less from the breach than from a defensive or drip-fed response. Prepare a holding statement early so you're not drafting one under pressure.

The 24-hour mindset, and preventing the next one

The through-line of a good first day is calm, sequence and record: contain, assemble the team, log everything, scope the damage, notify the right parties, communicate cleanly. What you can't do well at 2am is invent the plan — so write it down while things are quiet. A one-page incident-response plan with names, phone numbers, your insurer's hotline and this sequence, tested once a year, is the single highest-value cyber document a small business can own. Pair it with the preventive controls in the ASD's Essential Eight — patching, multi-factor authentication, backups you've actually tested restoring from — and most incidents either don't happen or don't hurt.

This kind of preparedness is core to a resilient operations function. This article is general information, not legal or security advice; for a breach affecting personal information, consult the OAIC's current guidance and your own advisers.

About the author

Andrew Northcott

Founder & Chairman, Valont

Andrew is the founder and chairman of Valont and the parent group Wattlestone. He has spent two decades building and running Australian SMEs, and writes about the realities of ownership — cash, people, systems, and the decisions that compound.

LinkedIn →

Want to know where your business stands?

Take our free Business Health Check — it takes 5 minutes and gives you a clear picture across finance, people, operations, and growth.