Security

Cyberattack Response: What to Do in the First Hour

cyber security incident

If a Cyberattack Hits Your Business, the First Hour Matters Most

A cyberattack is one of those situations where the instinct to act fast can actually make things worse. Turning off the wrong machine, deleting a suspicious email, or sending messages from a compromised inbox — these are common mistakes made in the first panicked minutes, and they cost businesses dearly.

This guide walks you through what to do, in order, so you’re not guessing when it counts.

Before You Touch Anything — Don’t Make It Worse

There are a few things to avoid immediately:

  • Don’t power off the affected device if you can help it. Shutting it down can wipe evidence stored in memory that helps identify what happened and how.
  • Don’t delete anything. Leave ransom notes, suspicious emails, and alerts exactly where they are. Your IT team and any investigators will need them.
  • Don’t pay a ransom on the spot. That’s a decision to make with your IT provider, insurer, and potentially law enforcement — not alone in the first hour.
  • Don’t use the compromised accounts to discuss the attack. If an attacker is inside your inbox, they can read everything. Switch to phone calls or a separate, unaffected device.

Step-by-Step: What to Do Right Now

1. Disconnect Affected Devices from the Network

Unplug the network cable and turn off Wi-Fi on anything that looks compromised. This stops the attack spreading to other systems and — critically — to your backups. The ACSC recommends isolating devices rather than powering them off where possible.

2. Call Your IT Provider — By Phone

Don’t email them. If the attacker has access to your inbox, that communication is exposed. Pick up the phone.

3. Contact Your Cyber Insurer

Many cyber insurance policies require early notification to activate their incident response support. Call them as soon as you’ve spoken to your IT provider.

4. If Money Was Transferred, Call Your Bank Immediately

Ask them to recall the transfer and freeze it if they can. With bank fraud, the first few hours are the window where recovery is most likely. Don’t wait.

5. Reset Passwords from a Clean Device

Start with email and admin accounts. Use a device you’re confident isn’t affected, and enable multi-factor authentication if it isn’t already on.

6. Report the Incident

In Australia, report through ReportCyber at cyber.gov.au or call the 24/7 hotline on 1300 CYBER1 (1300 292 371). Reporting helps national threat intelligence and may be required under the Notifiable Data Breaches (NDB) scheme if personal data was exposed.

If customer or staff data has been compromised, you may have a legal obligation under the Privacy Act to notify both the Office of the Australian Information Commissioner (OAIC) and the individuals affected. Get your IT provider or legal counsel involved early so you don’t miss the deadline.

Should You Pay the Ransom?

The short answer: not without expert input. Paying doesn’t guarantee you’ll get your data back, it marks your business as one that pays, and the funds support further attacks. Before making any payment, check whether a free decryption tool already exists for the ransomware variant that hit you — this does happen, and it’s worth knowing before you hand over money.

Make this decision with your IT or incident response team, your insurer, and if appropriate, the Australian Federal Police.

The Best Preparation Happens Before an Incident

A one-page incident response plan is worth more than you’d think. It should cover:

  • Who to call first — your IT provider and insurer, with their numbers stored somewhere accessible offline
  • Where your backups are, and confirmation they’ve been tested by actually restoring from them
  • Which accounts and systems are highest priority to protect and recover first

If you’re running on Microsoft 365, tools like Microsoft Defender, Entra ID, and Intune give your IT team real visibility and containment options when something goes wrong. Having those configured properly before an incident makes a significant difference to how quickly you can respond.

Ready to Build a Proper Incident Response Plan?

Most small and mid-sized businesses in Brisbane don’t have a tested plan in place — until something goes wrong. We can help you get ahead of it. Talk to the team at IT TechNinjas about building a response plan that fits your business, or explore our Safe to Scale programme if you want a broader look at your security posture.

Ready to scale safely?

Book a discovery call and we'll map out where you stand and what comes next.