Cyber Attack? What to Do in the First Hour: A Guide for Sydney Small Businesses
It usually starts with something small. A staff member clicks a link and then realises the login page looked wrong. A client calls to ask why you emailed them new bank details. Files on the shared drive suddenly have strange names and will not open. However it starts, what you do in the first hour has a big effect on how much damage is done.
This guide sets out the steps in order. Print it, keep a copy somewhere you can reach if your computers are down, and make sure your team knows where it is.
First: stay calm and do not cover it up
Attackers rely on people panicking, or staying quiet because they are embarrassed. Make it clear to your team that reporting a mistake quickly is the right thing to do. A link clicked and reported in five minutes is a small problem. The same link kept quiet for a week can become a very large one.
Step 1: Contain it (first 15 minutes)
- Disconnect affected devices from the network. Unplug the network cable or turn off Wi-Fi. Do not turn the computer off unless your IT provider tells you to, because useful evidence can be lost.
- If files are being encrypted (ransomware), disconnect every device you can, including laptops connected from home, and disconnect any backup drives that are plugged in.
- If an email account is compromised, change the password from a clean device, sign the account out of all sessions and check that multi-factor authentication (MFA) is on.
Step 2: Call for help (within 30 minutes)
- Your IT provider: tell them exactly what happened, when, and which devices or accounts are involved.
- Your bank, immediately, if money may be involved: if a payment has gone to fraudulent bank details, the sooner your bank contacts the receiving bank, the better the chance of recovering it.
- Your cyber insurer, if you have one. Most policies have an incident hotline and require you to notify them quickly.
- The Australian Cyber Security Centre: report the incident through ReportCyber at cyber.gov.au, or call 1300 CYBER1 (1300 292 371) for advice, 24 hours a day.
Step 3: Protect the evidence
Do not delete suspicious emails, wipe computers or “clean up” before your IT provider has looked. Take photos of any ransom messages or warnings, note the time you first noticed something wrong, and write down who did what. This helps your IT provider, your insurer and, if needed, the police.
Step 4: Warn the people who could be targeted next
- If your email was compromised, attackers often email your clients and suppliers next. Call your key contacts and tell them to ignore any request to change bank details or open unexpected attachments.
- Remind your own staff to report anything unusual and to verify any payment request by phone.
Step 5: Do not pay a ransom without advice
Paying does not guarantee you will get your data back, and it can mark your business as a target for future attacks. Talk to your IT provider, insurer and the ACSC first. Under the Cyber Security Act 2024, businesses with annual turnover over $3 million must also report any ransomware payment to the Australian Signals Directorate within 72 hours.
After the first hour: recovery and reporting
- Restore from clean backups once your IT provider confirms the threat has been removed. This is where tested, offsite backups make all the difference.
- Check your privacy obligations. If personal information may have been accessed and your business is covered by the Privacy Act, you may need to assess the breach and notify affected people and the Office of the Australian Information Commissioner (OAIC) under the Notifiable Data Breaches scheme.
- If personal identity information was stolen, IDCARE (1800 595 160) offers free support to help affected people protect themselves.
- Fix the cause. Most attacks exploit the same gaps: no MFA, unpatched systems, reused passwords or untested backups. Close them so it does not happen again.
How to make the first hour much easier
The businesses that recover fastest are the ones that prepared before anything went wrong. Three things matter most:
- Multi-factor authentication on email and every important system, which stops most account takeovers. See our small business guide to MFA.
- Tested, offsite backups, so you can recover without paying anyone. See our guide to backup and recovery plans.
- A one-page incident plan with phone numbers for your IT provider, bank and insurer, printed and kept somewhere safe.
Want to know where your business stands? Our free Essential Eight checklist takes about ten minutes, and our managed IT security services put these protections in place for you, with 24/7 monitoring.
Find your gaps before an attacker does
Our free IT Health Check reviews your security, backups and email protection, and gives you a plain-English list of what to fix first.
Or call 1300 133 770.




