Add Think Technology as a trusted source Cyber Incident Response: What to Do in Hour One | TTA

What businesses need to do in the first hour of a cyber attack

Business owner following a cyber incident response plan during an active cyber attack

A cyber attack is confirmed. Someone has clicked a phishing link, ransomware is encrypting files, or an account has been accessed by an unknown party. The first hour is the most consequential window in any cyber incident response. Decisions made in those 60 minutes shape how quickly the business recovers, what legal obligations are triggered, and how much damage is ultimately contained.

This article is for business owners, operations managers, and IT decision-makers at small and mid-sized Australian businesses. It covers what to do, in what order, when an incident is active. It is not a theoretical framework. It is a working sequence of actions that reduce harm.

Why the first hour determines the outcome

Cyber incident response is time-critical because attackers move fast. The Australian Signals Directorate (ASD) observed attackers exploiting publicly released vulnerabilities at increasing speed throughout FY2024-25, and ASD’s ACSC notified Australian entities more than 1,700 times of potentially malicious cyber activity during that period, an 83% increase on the prior year. The gap between detection and containment is where breaches expand from a single endpoint to an entire network.

The first hour is also when legal clocks start running. Under the Notifiable Data Breaches (NDB) scheme, organisations covered by the Australian Privacy Act must assess a suspected breach and notify the Office of the Australian Information Commissioner (OAIC) and affected individuals once they become aware a breach is likely to cause serious harm. That assessment process cannot begin until someone in the business recognises the incident and starts gathering facts.

Step 1: Confirm and declare the incident

Cyber incident response starts with a clear internal declaration. One person, typically the most senior person available, says out loud: “We are treating this as a cyber incident until proven otherwise.” This sounds obvious. In practice, many businesses spend the first 20 minutes in uncertainty, waiting for someone else to decide whether it is serious. Every minute spent in that waiting room is a minute the attacker uses.

Confirm what you are seeing. A single locked file may be ransomware spreading. Unusual login activity may be an account compromise that has already accessed payroll data. A slow system may be an exfiltration tool running in the background. You do not need a full picture to declare an incident. You need enough information to stop normal operations on affected systems immediately.

Step 2: Isolate affected systems without shutting them down

Isolation means cutting network access to affected systems while keeping them powered on. Disconnect the device from your network, either by unplugging the ethernet cable or disabling Wi-Fi. Do not shut the device down. Powering off a machine can destroy volatile memory evidence that a forensic investigation may later rely on. It can also, in some ransomware scenarios, accelerate encryption.

If the incident involves cloud accounts, such as Microsoft 365 or a line-of-business application, revoke active sessions and reset credentials for affected accounts before doing anything else. A compromised cloud account that stays active while the business investigates the initial device is a second, open front.

The goal at this stage is to stop lateral movement. Attackers in an SME network look to move from one device to others quickly. Isolating the known point of compromise slows that movement and buys time for the next steps. Our data security and backup services include network segmentation designed to limit how far an incident can travel before it is caught.

Step 3: Call your IT provider or managed security partner

If you have a managed IT provider, call them now. Not after you have investigated further. Not once you have a better sense of the scope. Now. A managed service provider or fully outsourced IT partner who knows your environment can start containment actions remotely, begin preserving evidence, and advise on the next sequence of steps far faster than an internal team working from first principles under pressure.

If you do not have a managed IT partner, call the ASD’s Australian Cyber Security Hotline on 1300 CYBER1 (1300 292 371). The hotline operates 24 hours a day, seven days a week, and can provide immediate guidance specific to your situation. This should be the number saved in every business’s incident contact list before an incident occurs.

Step 4: Preserve evidence and start a log

From the moment an incident is declared, someone must start writing things down. Date and time of discovery, who noticed it, what they saw, what actions have been taken, and in what order. This log becomes the foundation of any subsequent investigation, insurance claim, or regulatory notification. Memories degrade fast under pressure, and conflicting accounts of the sequence of events are a common problem in post-incident reviews.

Do not delete anything on affected systems. Do not attempt to clean up or restore from backup before a forensic assessment has begun. Restoring systems prematurely removes the evidence trail and may mean the underlying access method is never identified, leaving the same vulnerability open for a return visit.

Step 5: Notify your cyber insurer early

Most cyber insurance policies require the insured to notify the insurer as soon as practicable after becoming aware of an incident. Delaying that notification, even to gather more information, can affect the validity of a claim. Call your insurer or broker in the first hour if you have cover. They will confirm what steps are covered and may direct you to pre-approved forensic and legal specialists as part of the policy response.

If you are unsure whether your current cyber insurance policy meets the minimum obligations your business faces, a cyber insurance compliance review can clarify the gaps before an incident forces the question.

Step 6: Understand your reporting obligations

Australian businesses now face layered reporting requirements that can be triggered within the first hour. Under the NDB scheme, organisations covered by the Privacy Act must complete an assessment once they have grounds to suspect a data breach involving personal information that could cause serious harm. The OAIC must be notified, and affected individuals must be contacted, once that assessment confirms serious harm is likely.

From 30 May 2025, businesses with an annual turnover of $3 million or more are required to report any ransomware payment to the Australian Signals Directorate within 72 hours of making the payment. From 1 January 2026, the Department of Home Affairs moved to active compliance and enforcement of this requirement. Paying a ransom is now a regulated event with a mandatory reporting obligation attached.

These obligations do not all need to be actioned in the first hour. But understanding that they exist, and that the clock starts running from the moment of awareness, means you need legal advice and your IT partner in the room early, not days later.

What we see at TTA: the two things Brisbane SMEs consistently get wrong

Across the Brisbane and South-East Queensland businesses we support, two patterns come up repeatedly in post-incident reviews. The first is delayed declaration. A staff member notices something unusual and spends an hour trying to resolve it quietly before telling anyone. By the time the incident is declared, the attacker has moved laterally across the network. The single endpoint incident has become a network-wide problem.

The second pattern is the instinct to restore quickly. The backup is there, the systems are down, the pressure to get back to normal is intense. Businesses restore without completing a forensic review, which means the entry point is never identified and closed. We have seen businesses cycle through the same ransomware attack twice in six months because the initial recovery skipped the root cause investigation. Fast recovery and thorough investigation are not opposites, but they require deliberate sequencing.

Having a written incident response plan, even a one-page version, changes both patterns. When people know what to do and who to call, the delay between detection and declaration collapses. That is the biggest single improvement most SMEs can make. Our IT security assessments include reviewing whether an incident response plan exists and whether staff understand their role in it.

What the first hour does not need to include

You do not need to identify the attacker. You do not need to know exactly what data was taken. You do not need to have written a public statement or notified customers. All of those things come later, and doing them too early, before the scope is understood, creates more problems than it solves.

The first hour is about three things: stop the spread, preserve the evidence, and get the right people involved. Everything else follows from those three actions being done well.

Frequently asked questions about cyber incident response

What is the first thing a business should do when a cyber attack is suspected?

Declare the incident immediately to whoever is responsible for IT decisions in the business. Do not wait until you are certain. Isolate the affected device from the network by disconnecting it without shutting it down. Call your IT provider or managed security partner, or the ASD’s Cyber Security Hotline on 1300 CYBER1. The earlier these steps begin, the less damage the attack can do.

Do Australian businesses have to report a cyber attack?

It depends on the type of attack and the business. Under the Notifiable Data Breaches scheme, organisations covered by the Privacy Act must notify the OAIC and affected individuals if a breach is likely to cause serious harm. From 30 May 2025, businesses with over $3 million in annual turnover must report ransomware payments to the ASD within 72 hours. Other sector-specific or contractual obligations may also apply.

Should a business pay a ransom during a ransomware attack?

Paying a ransom does not guarantee data recovery and may fund further criminal activity. The Australian Government discourages ransom payments. If a business does pay, it must report this to the Australian Signals Directorate within 72 hours if annual turnover exceeds $3 million. Before any ransom decision is considered, legal and IT security advice should be sought. Payment should never be the first response.

What evidence should a business preserve after a cyber attack?

Keep affected systems powered on but disconnected from the network. Do not delete files or attempt to clean up systems before a forensic review. Record a chronological log of everything noticed and every action taken, including timestamps. Do not restore from backup until the entry point has been identified. This evidence is essential for investigation, insurance claims, and regulatory notifications.

How can a small business prepare for a cyber incident before it happens?

Write a one-page incident response plan that names who is responsible, what the first five actions are, and which phone numbers to call. Save the ASD hotline (1300 CYBER1) and your IT provider’s emergency contact. Test your backups regularly and confirm they can be restored quickly. Run a basic IT security assessment to identify the most exposed areas of your environment before an attacker finds them first.

Where do we start with cyber incident response?

Talk to the team at TTA. We work with businesses across South-East Queensland to put written incident response plans in place, run security assessmentsand provide the kind of IT consulting that helps you know what to do before you are under pressure. Get in touch and we can start with a straightforward conversation about where your business stands today.

Get tech tips

Stay up-to-date with the latest in tech for small and medium business.
Subscribe to our newsletter and get tips and monthly updates.