Cyber Ethos

Cyber Incident Response & Ransomware Recovery in Australia (2026 Guide) | Cyber Ethos
Incident Response Guide · Australia 2026

Cyber Incident Response & Ransomware Recovery in Australia: What to Do When You're Hit

Everything you need to know about responding to a cyber attack in Australia. The 72-hour action plan, mandatory reporting deadlines, ransom guidance and how to build a response plan that actually works.

🚨 Dealing with an incident right now? Call Cyber Ethos on 1800 CETHOS — and report it nationally at cyber.gov.au/report or the ASD hotline 1300 CYBER1.
KK
Dr. Kiran Kewalramani · PhD · CISSP · CISA · GAICD
Founder, Cyber Ethos · 20+ years in cybersecurity · Queensland, Australia
6 min
A cybercrime is reported in Australia every six minutes (ASD)
$80,850
Average cost of cybercrime to a business — up 50% (ASD)
72 hours
To report a ransomware payment to ASD (Cyber Security Act 2024)
39%
Of ransomware incidents were spotted by ASD — not the victim

What Is Cyber Incident Response?

Cyber incident response is the organised way you handle a cyber attack or data breach — from the moment you realise something's wrong, through containing the damage, kicking the attacker out, recovering, and learning from it. Done well, it's the difference between a contained problem and a business-ending catastrophe.

It isn't a single product or a one-off action. It's a combination of three things: a plan (who does what), a team (the people who execute it), and a tested process (the steps you follow) — so that when the pressure hits, you act fast and correctly instead of panicking.

The one-paragraph answer

Cyber incident response is how an organisation detects, contains, and recovers from a cyber attack or data breach in a structured way. It covers the immediate response (stopping the spread and limiting damage), the investigation (working out what happened), recovery (getting safely back to normal), and the legal duty to notify regulators and affected people. The goal is to minimise harm — financial, operational, and reputational — and to get back on your feet as quickly and cleanly as possible.

Why speed and preparation matter so much

Australia's threat picture is sobering. In its 2024–25 report, the Australian Signals Directorate recorded a cybercrime report roughly every six minutes, responded to over 1,200 incidents, and noted the average cost of cybercrime to a business jumped 50% to around $80,850. Most tellingly, of the ransomware incidents ASD handled, 39% were discovered by ASD — not by the victim. Many organisations don't even know they've been breached until someone tells them.

What to Do in the First 72 Hours of a Breach

If you suspect you've been breached or hit by ransomware right now, the first moves matter enormously. Here's what to do — in order.

  1. Don't panic — and don't start wiping or "fixing" things
    The instinct to immediately rebuild or delete can destroy the evidence you'll need and tip off the attacker. Pause, and work the plan.
  2. Isolate affected systems — but preserve them
    Disconnect compromised devices from the network to stop the spread, but where possible keep them powered and intact so they can be investigated. Containment first, clean-up later.
  3. Activate your plan and get the right people in the room
    A serious incident isn't just an IT issue. Bring in leadership, legal, and communications alongside your technical team — decisions need to be made across all of them, fast.
  4. Preserve evidence
    Keep logs, affected systems, and any ransom notes intact. You'll need them to understand the attack, support recovery, and meet your reporting obligations.
  5. Bring in expert incident responders early
    Specialists contain incidents faster and avoid the costly mistakes that make things worse — especially with ransomware. The earlier they're engaged, the better the outcome.
  6. Work out your reporting clocks
    Identify early what you must report and by when — the OAIC, ASD, APRA, or under the SOCI Act may all apply, and the deadlines are short (see below).
  7. Communicate carefully and deliberately
    Plan what you tell staff, customers, and regulators — and when. Getting communication wrong adds legal exposure and reputational damage on top of the incident itself.
What NOT to do

Don't immediately wipe or rebuild systems (you'll lose evidence and may not fully remove the attacker). Don't pay a ransom on impulse. Don't go silent and hope it passes — the obligations and the damage don't wait. And don't let one person handle it alone under pressure. Most of the worst outcomes come from rushed first moves, not the attack itself.

The Incident Response Lifecycle

Behind a calm, effective response is a well-understood process. Most frameworks describe the same six stages

🧰
1. Prepare
Before anything happens: have a plan, a trained team, secure offline backups, and practised drills. Preparation is the stage that makes every other stage work.
🔍
2. Detect & analyse
Spot that something is wrong and work out what it is, how it got in, and how far it has spread. You can't respond to what you can't see — which is why detection matters so much.
🧱
3. Contain
Stop the spread and limit the damage — isolating systems, cutting off the attacker's access, protecting what's not yet affected.
🧹
4. Eradicate
Remove the attacker and their tools from your environment completely — closing the gaps they used so they can't simply walk back in.
🔧
5. Recover
Restore systems and data safely from clean backups, confirm everything is genuinely clean, and return to normal operations carefully and in the right order.
📘
6. Learn
Review what happened honestly, fix the weaknesses that allowed it, and update your plan — so the next attempt is stopped earlier, or stopped altogether.

Ransomware: Special Considerations

Ransomware is the most disruptive threat Australian organisations face, and it doesn't behave like an ordinary breach. Modern ransomware crews don't just lock your files — they steal your data first, then threaten to publish it if you don't pay. This "multi-layered extortion" means that even flawless backups won't make the problem go away, because the criminals still hold a copy of your information.

If ransomware hits, the early principles are the same as any incident — isolate, preserve, get help — with a few specifics:

  • Isolate fast, but don't wipe. Disconnect affected systems to stop encryption spreading, but preserve them for investigation.
  • Don't assume backups are enough. Check they're intact, offline, and uninfected — and remember they restore your files, not your privacy if data was stolen.
  • Identify the scope. Work out what was accessed and taken, not just what was encrypted — that determines your legal obligations.
  • Don't engage the attackers alone. Any contact or payment decision should go through experienced responders and legal advisers.
The Australian reality

Ransomware made up about 11% of the incidents ASD responded to in 2024–25, and 35% of ransomware victims had their data posted online. The healthcare sector was hit especially hard, with ransomware incidents doubling year on year. One Australian e-prescription provider that suffered a major ransomware breach — exposing the data of millions of Australians — ultimately ceased to exist. The stakes are existential, not just financial.

Should You Pay the Ransom?

It's the question every ransomware victim asks. The honest answer is that paying is fraught with risk, and the Australian Government strongly discourages it. Here's what you need to weigh — though you should never decide alone.

  • There's no guarantee. Paying doesn't ensure you get a working decryption key, or that the criminals actually delete the data they stole. You're trusting extortionists to keep their word.
  • It often invites more attacks. Evidence suggests a large share of organisations that pay — around two-thirds — are targeted again. Paying marks you as willing.
  • It may be unlawful. Paying a group subject to sanctions can breach Australian law, regardless of the circumstances.
  • It's now a reportable event. Since May 2025, larger businesses and critical infrastructure that pay must report it to ASD within 72 hours (more below). Payment is no longer a quiet, private choice.
The bottom line

Paying a ransom is a serious legal, financial, and strategic decision — not a technical one, and never one to make under pressure or alone. If you're facing it, get specialist incident response and legal advice immediately. The best protection against ever being in this position is preparation: secure, tested, offline backups and a rehearsed response plan.

Your Australian Reporting Obligations

This is where many organisations get caught out: a single incident can trigger several reporting duties at once, each with its own tight deadline. Here are the main obligations Australian organisations need to know.

Obligation Who it applies to The deadline
Notifiable Data Breaches (NDB) scheme
Privacy Act · OAIC
Most organisations covered by the Privacy Act, after an eligible data breach likely to cause serious harm Notify the OAIC and affected individuals as soon as practicable (assess a suspected breach within ~30 days)
Ransomware payment report
Cyber Security Act 2024 · ASD
Businesses with turnover over A$3M, and critical infrastructure entities, that make a ransom or extortion payment Within 72 hours of making the payment
APRA CPS 234
Prudential standard
APRA-regulated entities — banks, insurers, super funds Within 72 hours of a material information security incident
SOCI Act
Critical infrastructure
Responsible entities for critical infrastructure assets Within 12 hours (critical impact) or 72 hours (significant impact) to ASD

The newest of these is the most important to understand: under Part 3 of the Cyber Security Act 2024, in effect since May 2025, a ransomware payment is now a mandatory disclosure — and from January 2026, the Department of Home Affairs moved to actively enforce it. A regulated breach can easily mean reporting to the OAIC and ASD and your industry regulator simultaneously, so knowing your obligations in advance — and building them into your response plan — is essential.

This section is general information, not legal advice. Your specific obligations depend on your circumstances — during a real incident, confirm them with your legal advisers.

Being Ready: An IR Retainer vs Scrambling Mid-Crisis

When an attack hits, the clock is already running. The single biggest factor in how badly it ends is whether you were ready — and that's the difference between scrambling to find help mid-crisis and having experts on call.

😰 No plan — scrambling mid-crisis
Hours or days lost just finding and onboarding help
Panicked first moves that destroy evidence and worsen damage
Reporting deadlines missed in the chaos
Confused, damaging communications
Longer downtime and far higher total cost
🛡️ A prepared response (IR plan + retainer)
Experienced responders engaged within minutes
Faster containment and properly preserved evidence
Reporting clocks tracked and met
Clear, pre-planned communications
Much shorter downtime and lower overall cost

This is why an incident response retainer — pre-engaging experts so they're ready the moment you need them — and regular tabletop exercises (practice runs of your plan) are among the most valuable investments an organisation can make. The cheapest time to plan your response is long before you need it; the most expensive is at 2am during the attack.

KK
Practitioner's advice
"In a real incident, the organisations that come through well are almost never the ones with the most technology — they're the ones who practised. They've run the scenario, they know who makes the call to take systems offline, they know who speaks to customers, and they know their reporting clocks before the lawyers ask. A plan you've never rehearsed is just a document. The first time you test your response should never be during the actual attack."
— Dr. Kiran Kewalramani, PhD, CISSP · Founder, Cyber Ethos

5 Myths About Incident Response

Myth 1: "We have backups, so ransomware can't hurt us."
Reality: Modern ransomware steals your data before encrypting it, then threatens to publish it — so backups restore your files but don't stop the extortion or the data being leaked. And in practice, only around half of organisations successfully restore from backups when they try.
Myth 2: "We're too small to be a target."
Reality: Small and medium businesses are prime ransomware targets — attackers know they're often less defended and more likely to pay quickly to get running again. Size is no protection.
Myth 3: "If we pay, it all goes away."
Reality: Paying offers no guarantee of recovery or data deletion, a large share of organisations that pay are hit again, it may breach sanctions law, and it's now a reportable event. Payment rarely makes the problem cleanly disappear.
Myth 4: "Incident response is just IT's job."
Reality: A serious incident involves legal obligations, customer and media communications, executive decisions, and board oversight — not just technical work. Treating it as an IT-only problem is how organisations miss deadlines and make things worse.
Myth 5: "We'll deal with it if it happens."
Reality: The time to build and rehearse your response is before an attack. Organisations that plan and practise contain incidents faster, lose less, and recover sooner. Improvising mid-crisis is the most expensive option there is.

How Cyber Ethos Helps With Incident Response

Cyber Ethos is led by Dr. Kiran Kewalramani — a PhD-qualified cybersecurity specialist with CISSP, CISA, and GAICD credentials and over 20 years of experience. We help Australian organisations prepare for, respond to, and recover from cyber incidents — calmly and clearly, when it matters most. That includes:

  • Incident response planning. A clear, practical plan that defines who does what, so your team isn't improvising under pressure.
  • Rapid response support. Experienced responders to help contain and manage a live incident, and limit the damage.
  • Digital forensics. Working out exactly what happened and what was accessed, while preserving the evidence you need.
  • Ransomware recovery. Guiding safe recovery and helping you navigate the difficult payment and legal questions.
  • Regulatory notification support. Helping you meet the OAIC, ASD, APRA, and SOCI reporting clocks correctly and on time.
  • Tabletop exercises. Practising your response so your people perform when it counts.
  • Joined-up protection. Incident response works best alongside a managed SOC that detects threats early and a virtual CISO who leads through a crisis and reports to your board.

🚨 Dealing with an incident — or want to be ready before one?

If you're in the middle of an attack, call Cyber Ethos now. If you want to prepare, talk to Dr. Kiran Kewalramani about an incident response plan, a retainer, or a tabletop exercise — so the next bad day is a manageable one.

Talk to Cyber Ethos →
📞 1800 CETHOS (1800-238-467) · cyberethos.com.au · National reporting: cyber.gov.au/report

Common Questions About Incident Response

What is cyber incident response in simple terms? +
Cyber incident response is the organised way an organisation handles a cyber attack or data breach — detecting it, containing the damage, removing the attacker, recovering systems, and learning from it. It's a combination of a plan, a team, and a tested process, so that when something goes wrong you act quickly and correctly rather than panicking. Done well, it's the difference between a contained problem and a disaster.
What should I do first if we've been hacked or hit by ransomware? +
Don't panic, and don't rush to wipe or rebuild systems — that destroys evidence. Isolate affected systems from the network to stop the spread, but preserve them. Activate your incident response plan and get the right people involved: IT, leadership, legal, and communications. Bring in expert incident responders early, work out which reporting deadlines apply, and communicate carefully. The first moves matter enormously to how it ends.
Should we pay the ransom? +
The Australian Government strongly discourages paying. There's no guarantee you'll get your data back or that stolen copies are deleted, around two-thirds of organisations that pay are attacked again, and paying a sanctioned group may breach Australian law. Since May 2025, larger businesses and critical infrastructure that pay must also report it to ASD within 72 hours. It's a serious legal and strategic decision that should never be made alone — get specialist incident response and legal advice immediately.
Do we have to report a cyber incident in Australia? +
Often, yes — and there can be several obligations at once. Under the Notifiable Data Breaches scheme, most organisations must notify the OAIC and affected individuals of an eligible data breach likely to cause serious harm. APRA-regulated entities must notify APRA within 72 hours. Critical infrastructure operators report to ASD within 12 or 72 hours depending on severity. And since May 2025, ransomware payments must be reported to ASD within 72 hours by larger businesses and critical infrastructure.
Do we have to report a ransomware payment? +
Yes, if you're a larger business or critical infrastructure. Under Part 3 of the Cyber Security Act 2024, in effect since May 2025, businesses with annual turnover over A$3 million and entities responsible for critical infrastructure must report any ransomware or cyber-extortion payment to the Australian Signals Directorate within 72 hours of making it. From January 2026 this is being actively enforced — so paying a ransom is no longer a private decision.
What is the Notifiable Data Breaches (NDB) scheme? +
The NDB scheme, under the Privacy Act, requires the organisations it covers to notify the Office of the Australian Information Commissioner (OAIC) and affected individuals when an eligible data breach is likely to result in serious harm. You must assess a suspected breach promptly — generally within 30 days — and notify as soon as practicable once you believe an eligible breach has occurred.
What's the difference between incident response and a managed SOC? +
A managed SOC watches your environment day to day and detects and triages threats. Incident response is what happens when a serious incident is confirmed — the deeper investigation, containment, recovery, forensics, and regulatory navigation. The SOC is your ongoing detection; incident response is the specialist team that handles the crisis. They work together, and a good SOC often triggers the incident response process.
What is an incident response retainer, and do we need one? +
An incident response retainer pre-engages expert responders so they're ready to help the moment you're hit, rather than you scrambling to find and onboard help mid-crisis. It means faster containment, fewer costly mistakes, and far less downtime. For any organisation that would be seriously harmed by an attack, a retainer is one of the most valuable preparations you can make.
How long does it take to recover from a ransomware attack? +
It varies enormously — from days to many weeks — depending on how far the attack spread, whether you have clean, tested backups, how quickly it was detected, and how well-prepared your response was. Organisations with a rehearsed plan, offline backups, and responders on call recover dramatically faster than those improvising. Recovery also includes confirming systems are genuinely clean and meeting your reporting obligations, not just turning things back on.
How do we get help from Cyber Ethos in an incident? +
If you're dealing with an incident, contact Cyber Ethos on 1800 CETHOS (1800-238-467) or via cyberethos.com.au/contact — and report it nationally through cyber.gov.au/report. If you want to be ready before an incident, we can help you build an incident response plan, set up a retainer, and run tabletop exercises so your team is prepared. The best time to make that call is before you need it.