Skip to content

What to do in the first hour of a cyber incident

When something goes wrong, the first hour shapes how bad it gets. A calm, non-technical playbook for business owners to act on before the experts arrive.
Published
Reading time
3 min
Topic
Incident Response
On this page

Nobody thinks clearly during an emergency, which is exactly why you decide what to do before one happens. If you suspect a cyber incident (ransomware on a screen, a strange login, money gone to the wrong account, a supplier saying they got a dodgy email “from you”), the first hour matters enormously. Panic and guesswork make things worse; a calm sequence limits the damage.

Here’s a plain-English playbook you can follow before any specialist is involved.

First: don’t make it worse

The instinct to “fix it fast” causes real harm. In particular:

  • Don’t pay a ransom on impulse. It funds crime, often doesn’t restore your data, and marks you as a payer. It’s a decision for later, with advice, not a reflex.
  • Don’t wipe or reboot machines if you can avoid it. That can destroy the evidence needed to understand what happened and how far it spread.
  • Don’t tip off the attacker by broadcasting to all-staff that you’re “onto them,” if the situation is still unclear.

The first-hour sequence

1. Contain, don’t destroy. Isolate affected devices, unplug the network cable or disconnect Wi-Fi, and leave the machine on. This stops the spread while preserving the scene. Isolating is different from turning off.

2. Protect the keys. Reset passwords for critical accounts (email, banking, admin) from a device you trust is clean, and make sure MFA is on. If credentials may be compromised, this slams the most important doors.

3. Preserve evidence. Take photos of ransom notes and error screens. Note the time you noticed, what you saw, and what you’ve done. This record is invaluable later, for experts, insurers, and any authorities.

4. Call for help early. Contact your IT/security provider (and your cyber insurer, if you have a policy, many require early notification and provide response help). Getting expertise involved quickly almost always improves the outcome.

5. Check your legal obligations. If personal information may have been accessed, the Notifiable Data Breaches scheme may require you to notify the OAIC and affected individuals. You don’t need to have this memorised, but you do need to raise it early so it’s handled correctly and on time.

6. Communicate carefully. Decide who needs to know and what to say. Measured, honest communication protects trust; silence or spin usually backfires.

Isolating is different from turning off.

Where to report in Australia

  • ReportCyber (cyber.gov.au) is the government’s channel for reporting cybercrime and incidents.
  • Scamwatch for scams and fraudulent payments.
  • Your bank immediately, if money or banking details are involved. Fast action sometimes recovers funds.

The best time to prepare is now

Everything above is far easier if it’s been thought through in advance: a written contact list (IT, insurer, bank), known-clean devices, tested backups, and a one-page plan of who does what. A little preparation turns a chaotic scramble into a calm, practised response, and that difference can be the difference between a bad week and a genuine crisis.


We help businesses prepare a simple incident response plan and respond calmly if the worst happens. If something’s going wrong right now, or you’d rather be ready before it does, get in touch.

Want help putting this into practice?

Tell us what you are trying to solve and we will tell you what it would take.

Get in touch