At a Glance
If your business has experienced or suspects a cyber incident, the immediate priorities are: isolate affected devices from your network, contact your IT provider straight away, do not pay any ransom without expert advice, preserve forensic evidence by not turning off affected devices unless instructed, and notify your cyber insurer. If personal information may have been accessed or disclosed without authorisation, you may have a legal obligation to notify the Office of the Australian Information Commissioner and affected individuals under the Notifiable Data Breaches scheme. A professional IT provider will guide you through each stage — from initial containment through to recovery and post incident hardening. You do not need to manage this alone. Call your IT provider first.
First — Stay Calm. Cyber Incidents Are Manageable.
Stress and urgency are natural responses to discovering that your business may have been compromised. But decisions made in panic are rarely the right ones. Some of the most common instinctive responses — such as turning off devices or attempting to delete affected files — can actively make the situation worse. Cyber incidents are manageable when the response is structured and guided by professionals who handle these situations regularly.
The Immediate Steps to Take Right Now
- Do not turn off affected devices: Powering down a device can destroy forensic evidence needed to understand what happened.
- Isolate affected devices from the network: Disconnect the affected device from Wi-Fi and unplug network cables to prevent spreading.
- Contact your IT provider immediately: This is the most important call you will make.
- Do not pay a ransom without expert advice: Paying does not guarantee restoration and may expose you to additional legal risk.
- Notify your cyber insurer: Most policies require prompt notification to trigger potential claim support.
What Types of Incidents Require Different Responses?
The appropriate response varies by incident type, but always starts with containment:
- Ransomware: Files or systems are encrypted. Immediate priority: isolate devices, do not pay, engage your IT provider and insurer.
- Compromised Account: Credentials captured. Immediate priority: revoke credentials, enable MFA, review access logs.
- Data Breach: Unauthorized data exfiltration. Immediate priority: contain the entry point and assess notification obligations.
Your Obligations — The Notifiable Data Breaches Scheme
If your business holds personal information, you may have obligations under the Australian Privacy Act 1988 and the Notifiable Data Breaches (NDB) scheme. You are generally required to notify the OAIC and affected individuals if personal information has been accessed or disclosed without authorisation and the breach is likely to result in serious harm. Always seek legal advice specific to your circumstances.
What Recovery Actually Looks Like
Once the incident is contained, recovery follows a structured path:
- Verify your backups: Confirm the backup is clean and predates the incident.
- Restore from a clean state: Do not restore from a compromised capture.
- Patch the vulnerability: Close the entry point exploited before reconnecting.
- Test before going live: Ensure systems are functioning correctly in a clean environment.
BitLOGIC's security services are built to prevent incidents from occurring and to respond effectively when they do. Our managed security layer includes continuous monitoring, vulnerability management, and incident response, designed to identify threats before they escalate.
Frequently Asked Questions
What should I do first if my business has been hacked?
The first steps are: do not turn off affected devices (this preserves forensic evidence), isolate the affected device from your network by disconnecting Wi-Fi and network cables, and contact your IT provider immediately. Do not pay any ransom without expert advice, and notify your cyber insurer as early as possible.
Do I have to report a data breach in Australia?
Under the Australian Notifiable Data Breaches scheme, businesses covered by the Privacy Act 1988 are generally required to notify the Office of the Australian Information Commissioner and affected individuals if personal information has been accessed or disclosed without authorisation and the breach is likely to result in serious harm.
Should I pay a ransom if my business is hit by ransomware?
Paying a ransom does not guarantee restoration of access or data, and in some cases may expose your business to additional legal risk. The recommended approach is to isolate affected systems, engage your IT provider immediately, and seek advice from both your IT provider and legal counsel before making any payment decision.
How do businesses recover from a cyber attack?
Recovery typically involves: verifying that backups are clean and predate the incident, restoring affected systems from the verified clean backup, patching the vulnerability that was exploited, testing restored systems before returning them to production, and documenting the full incident timeline.
What security controls should I put in place after a cyber incident?
Common hardening steps include: deploying multi factor authentication across all accounts, implementing a structured patching schedule, reviewing and testing backup integrity, reducing user privilege levels, and enabling continuous security monitoring.