Hacked? What to Do in the First 24 Hours
Stay Calm — But Act Fast
Discovering that your business has been hacked is one of the most stressful moments a business owner can face. Your instinct might be to panic, shut everything down or quietly hope the problem goes away. None of those responses will help.
The ASD’s Annual Cyber Threat Report 2023–2024 recorded over 87,400 cybercrime reports in the financial year — one every six minutes. Small businesses reported average losses of $46,000 per incident, but businesses that responded quickly and methodically consistently experienced lower total losses and faster recovery. What you do in the first 24 hours makes an enormous difference.
This guide gives you a structured, hour-by-hour plan for responding to a cyber incident. Print it, save it somewhere accessible offline, and share it with your team before you need it.
First Hour: Contain and Isolate
The priority in the first hour is to stop the attack from spreading while preserving evidence for investigation.
- Disconnect affected systems from the network. Unplug Ethernet cables and disable Wi-Fi on compromised devices. Do not turn them off — powering down can destroy evidence stored in memory.
- Change credentials for critical accounts. Immediately reset passwords on email, banking, cloud services and admin accounts. Do this from a device you trust (one not connected to the compromised network).
- Identify the type of incident. Is it ransomware (files encrypted, ransom note displayed)? Unauthorised access (suspicious logins)? Business email compromise (fraudulent emails sent from your account)? Data exfiltration (unusual data transfers)? The response differs depending on the type.
- Designate an incident lead. One person should coordinate the response. In a small business, this is usually the owner or most senior person available.
Hours 2–4: Assess the Scope
Once immediate containment is in place, assess how far the compromise extends.
- Determine which systems and accounts are affected. Check login logs, email forwarding rules, recent file changes and cloud service activity.
- Engage your IT support. Whether that is an internal IT person, a managed service provider (MSP) or an external incident response firm, get professional help involved as early as possible. The ACSC can help you find accredited incident response providers.
- Preserve evidence. Take screenshots of ransom notes, suspicious emails or unusual system behaviour. Do not delete anything. If possible, create forensic images of affected hard drives. This evidence may be critical for law enforcement, insurance claims and legal proceedings.
- Check your backups. Confirm that your backups exist, are intact and are not connected to the compromised network. If you follow the 3-2-1 backup rule, your offline or offsite copy should be safe.
Hours 4–12: Notify and Communicate
Australian law imposes specific obligations on businesses that experience data breaches. Failing to meet them can result in significant penalties.
Legal Obligations
- Notifiable Data Breaches (NDB) scheme: If your business has an annual turnover of $3 million or more (or is in healthcare, finance or other prescribed sectors), you must notify the Office of the Australian Information Commissioner (OAIC) and affected individuals if a breach is likely to result in serious harm. You have 72 hours to assess and 30 days to notify.
- Ransomware reporting: Under the Cyber Security Act 2024, certain businesses are required to report ransomware payments to the Australian Signals Directorate. See our guide on mandatory ransomware reporting requirements.
- Report to ReportCyber: Lodge a report at cyber.gov.au. This helps law enforcement track threats and may assist in recovery.
Stakeholder Communication
- Employees: Brief your team on what happened, what they should and should not do (e.g., do not use work email from personal devices), and how to report anything suspicious.
- Customers and partners: If their data may have been accessed, notify them promptly and honestly. Transparency builds trust; cover-ups destroy it.
- Cyber insurer: If you have cyber insurance, notify your insurer immediately. Many policies have strict notification timeframes and provide access to incident response specialists, legal counsel and PR support.
- Legal counsel: If personal data has been compromised, engage a lawyer experienced in Australian privacy law to guide your notification obligations.
Hours 12–24: Begin Recovery
With containment confirmed and notifications underway, shift focus to getting your business operational again.
- Restore from clean backups. Rebuild affected systems from backups that pre-date the compromise. Verify backups are clean before restoring.
- Patch the vulnerability. Before reconnecting restored systems, ensure the entry point the attacker used has been closed. This might mean applying a software update, closing an open port or revoking compromised credentials.
- Monitor for re-entry. Attackers often leave backdoors. Implement enhanced monitoring on restored systems for at least 30 days.
- Document everything. Create a timeline of the incident: when it was discovered, what actions were taken, who was notified and what evidence was collected. This documentation is essential for insurance claims, regulatory responses and improving your defences.
Critical Mistakes to Avoid
In the chaos of an incident, it is easy to make decisions that make things worse. Avoid these common mistakes:
- Do not pay a ransom immediately. There is no guarantee you will get your data back, and payment funds criminal activity. Consult with law enforcement and your insurer first. The ACSC strongly advises against paying ransoms.
- Do not wipe systems before forensics. Reformatting a hard drive destroys evidence that investigators need to understand the breach and prevent recurrence.
- Do not communicate on compromised channels. If your email has been compromised, do not use it to coordinate your response. Use personal phones, an alternative email provider or a secure messaging app.
- Do not ignore the incident. Hoping it will go away is not a strategy. Unaddressed breaches tend to escalate, and delayed notification can result in regulatory penalties.
- Do not blame employees publicly. Even if a phishing click caused the breach, public blame damages morale and discourages future reporting. Focus on systemic improvements.
After the Crisis: Build Resilience
Once the immediate crisis is over, conduct a post-incident review. What worked? What did not? What needs to change? Use the lessons learned to build or update your incident response plan so you are better prepared if it happens again.
In the IDIA framework, incident response planning and post-incident review sit within the Assurance pillar — the governance layer that ensures your security controls are not just implemented but continuously tested, measured and improved. Businesses that treat assurance as an ongoing discipline, rather than a one-off exercise, recover faster and suffer fewer repeat incidents.
The ASD reports that businesses with a documented, tested incident response plan recover up to 50% faster than those without one. An hour of planning now can save days of chaos later.
Understanding the potential financial impact can also help you make the case for investment. Our analysis of the cost of a cyber attack on Australian small business breaks down the direct and indirect costs you should be aware of.
“The question is not whether your business will face a cyber incident — it is whether you will be prepared when it happens.”
Know Your Readiness Before an Incident
The best time to prepare for a cyber incident is before one occurs. Platforms like How’s My Cyber use the IDIA framework (Identity, Data, Infrastructure, Assurance) to organise every control — including incident response readiness — into a clear operating model that works alongside any standard. Start with the free CYBER9 assessment to benchmark your business across nine critical security domains in under 10 minutes. You will receive a maturity score and a prioritised action plan that highlights gaps in your incident preparedness before a crisis forces you to find them the hard way.
How secure is your business?
Take the free CYBER9 assessment and get your security score in under 10 minutes. No credit card required.
Try CYBER9 Free