June 2026
You've Been Hit. The First 24 Hours: A Small Business Response Guide
Something's wrong: files won't open, a ransom note appears, a customer says they paid an invoice you never sent. What you do in the next 24 hours will largely decide the cost. This is the checklist we walk clients through — save it before you need it.
Hour 0–1: Contain, don't destroy
- Disconnect, don't power off. Unplug affected machines from the network (pull the cable, kill the Wi-Fi) but leave them running — memory holds evidence that shutdown destroys.
- Don't log into things from an infected machine. You may be handing over more passwords in real time.
- Call for help now, not after "having a look". Well-meaning IT cleanup routinely wipes the evidence needed to know what was actually taken.
Hour 1–4: Establish command
- Pick one decision-maker and one communication channel that is NOT your possibly-compromised email (phone, Signal, a personal account).
- Change passwords and revoke sessions for key accounts — from a known-clean device — starting with email admin, banking and remote access.
- Call your bank immediately if any payment might be involved; rapid recalls sometimes succeed in the first hours and almost never after a day.
- Notify your cyber insurer's hotline if you have cover — most policies require early notification and provide an approved response panel.
Hour 4–12: Assess honestly
- What systems and data are affected? Client records? Payment details? Employee files?
- Are backups intact and offline? Verify before you touch anything — ransomware crews target backups first.
- How did they get in? (Your responder will work this out; don't reimage machines before they do, or you'll never know — and it will happen again.)
Hour 12–24: Report and notify
- Report to the ACSC via ReportCyber (cyber.gov.au) or the 1300 CYBER1 hotline — it helps you and it helps the next business.
- Assess your Notifiable Data Breaches obligations: if personal information was accessed and serious harm is likely, the Privacy Act requires notifying affected individuals and the OAIC. Get advice — the 30-day assessment clock starts when you become aware.
- Prepare honest, calm communications for staff and, where needed, customers. Businesses that notify promptly and plainly consistently keep more trust than those caught concealing.
The mistakes that make it worse
- Paying the ransom immediately — payment doesn't guarantee recovery, may be unlawful depending on the recipient (sanctions), and marks you as a payer. It's a last resort taken with professional and legal advice, not a first reflex.
- Wiping and reinstalling before investigation — you lose the evidence, the entry point stays open, and round two follows within weeks.
- Keeping it secret from your own staff — they're your sensors; they need to know what to watch for.
Before it happens: the one-page plan
Every SMB should have a single page answering: who do we call (IT, security provider, insurer hotline, bank, lawyer), where are the backups and their passwords, and who speaks for the company. Printed, because when the server's encrypted, so is the intranet copy of your incident response plan. Our managed clients get this plan as standard — and if you're reading this mid-incident, call us.
Want help with this in your business?
Book a free security check with our Sydney team — plain-English advice, no obligation.
Get a Free Security Check