Cyber Ethos

How Quickly Should You Respond to a Cyber Attack?

It’s 5:40 on a Friday afternoon. Someone in accounts mentions that a few files won’t open and the shared drive is behaving oddly. It’s probably nothing. It’s been a long week.

What happens in the next ten minutes will shape the next few months of your business.

The honest answer to “how quickly should you respond” is immediately. But that’s not much help on its own, because it doesn’t tell you what to do first. So here’s the practical version: what to do in the first hour, what to sort out in the first day, and the reporting deadlines most Australian businesses don’t know about until they’re already running.

In short: Contain it within minutes, get expert help within the hour, and work out who you need to notify within the first day. The clock on your legal obligations starts when you first become aware something’s wrong, not when you’ve worked out how bad it is.

Most businesses don’t notice at all

Before we talk about response speed, there’s an uncomfortable thing worth saying.

In its most recent threat report, the Australian Signals Directorate noted that of the ransomware incidents it dealt with, 39% were found by ASD, not by the victim. Nearly four in ten organisations learned they’d been breached because a government agency rang them.

That changes the question a bit. Asking how fast you should respond assumes you know something’s happening. For plenty of businesses, the real gap isn’t slow response. It’s never noticing, and you can’t act on an attack you haven’t seen.

The first hour

These all happen at once. Someone needs to be doing each of them.

Don’t start fixing things. I know. Every instinct says rebuild the machine and get everyone working again. Resist it. Wiping systems destroys the evidence you’ll need later, and it often leaves the attacker sitting there anyway while you clean up around them.

Disconnect affected systems, but leave them alone. Take them off the network to stop the spread. Don’t wipe them, and don’t start deleting things. Containment now, clean-up later.

Get the right people in the room. This gets skipped because it feels like an IT problem. It isn’t. You need someone from leadership, and access to legal advice, sitting alongside whoever handles your technology.

Call for expert help. Experienced responders contain things faster and stop you making expensive mistakes. If you’ve already got someone lined up, that’s one phone call. If you haven’t, expect to lose hours finding them while the attack continues.

Write things down. What was noticed, when, by whom, and every decision you make from here. It feels like paperwork in the middle of a crisis. Do it anyway. Your insurer will ask, and nobody’s memory is reliable under this much stress.

The first day

By the end of day one you want three things settled.

What did they actually get? Encrypted files are obvious. Stolen data isn’t, and it’s the stolen data that decides your legal obligations. The question isn’t only “what stopped working,” it’s “what did they get their hands on.”

Do your backups work? Plenty of businesses discover theirs were encrypted too, or that nobody has tested a restore in two years. Check before you rely on it.

Who do you have to tell? More on that next.

You’ll also need to decide what you’re saying to staff and customers, and who’s allowed to say it. Handled badly, that adds a second problem on top of the one you already have.

The deadlines you need to know

This is where “how quickly” stops being a judgement call and becomes a legal question. Two obligations apply to most Australian businesses.

Notifiable Data Breaches scheme. If personal information was involved and the breach is likely to cause serious harm, you generally need to notify the Office of the Australian Information Commissioner and the people affected. You have roughly 30 days to assess a suspected breach, and must notify as soon as practicable once you believe one has occurred.

Ransomware payments. Since 2025, businesses with turnover over $3 million, and critical infrastructure operators, must report any ransom payment to the Australian Signals Directorate within 72 hours of paying.

If you’re in a regulated industry, there will be more. Banks, insurers and super funds have obligations to APRA, and critical infrastructure operators have obligations under the SOCI Act, some as short as 12 hours. Worth knowing which ones apply to you before you need them.

One detail catches people out: these clocks generally start when you become aware of a problem, not when you’ve confirmed the damage. So during an incident, assume the clock is already running. Waiting until you’re certain is how businesses miss deadlines they were always going to owe.

Should you pay a ransom to make it go away?

Short answer: not without advice.

Paying doesn’t guarantee you get a working key, or that your stolen data actually gets deleted. Businesses that pay are often targeted again. Paying a sanctioned group may breach Australian law. And as above, larger businesses now have to report the payment anyway.

It’s a legal and commercial decision, not a technical one, and not one to make at 9pm on a Friday with everyone panicking. Get specialist advice first.

What actually separates the fast from the slow

It’s almost never the technology.

The businesses that come through well have a simple written plan that says who decides what, including who can take systems offline without ringing the owner first. They’ve talked it through at least once. They can spot problems reasonably quickly. And they’d already worked out who to call.

The ones that struggle lose their first day to avoidable things. Hunting for a provider. Arguing about who’s allowed to make the call. Finding out the backups don’t restore. Reading up on their obligations for the first time while a deadline runs down.

Six things worth doing before anything happens

  1. Write down who decides what in an incident, and what they’re allowed to do.
  2. Talk through a scenario with your team once a year.
  3. Find out which reporting obligations apply to you, while nobody is panicking.
  4. Know who you’d call, before you need to call them.
  5. Actually test a restore from your backups.
  6. Keep a copy of that plan and those phone numbers offline, because you may not be able to get into your systems.

None of that costs much. All of it buys you hours when hours are worth the most.

Working towards the Essential Eight helps too, both in keeping attackers out and in noticing sooner when something’s wrong.

If you’d rather not find out the hard way

Cyber Ethos is a Queensland-based cyber security firm led by Dr Kiran Kewalramani, a PhD-qualified specialist with CISSP, CISA and GAICD credentials and more than 20 years in the field. We help Australian businesses get ready for incidents, respond when they happen, and get the reporting right.

That includes incident response planning, ransomware recovery, digital forensics, help with notifications, and vCISO and cyber advisory if you need senior leadership through a crisis without hiring full-time.

Frequently asked questions

How quickly should you respond to a cyber attack?

Start containing it within minutes and get expert help within the first hour. By the end of the first day you should know what was accessed, whether your backups work, and who you’re legally required to notify. Speed matters more than getting everything perfect.

What should I do first if we’ve been attacked?

Don’t wipe or rebuild anything, because that destroys evidence and often leaves the attacker in place. Disconnect affected systems from the network but leave them intact. Get leadership and legal advice involved alongside your technical people. Call for expert help. And start writing down what happened and what you decide.

How long do I have to report a cyber incident in Australia?

It depends on your business. Under the Notifiable Data Breaches scheme, most organisations have around 30 days to assess a suspected breach and must notify as soon as practicable after that. If you pay a ransom and your turnover is over $3 million, you must report it to ASD within 72 hours. Regulated industries such as banking, insurance and critical infrastructure have additional obligations, some as short as 12 hours.

When does the reporting clock start?

Generally when you first become aware of the problem, not when you’ve confirmed how bad it is. During an incident it’s safest to assume the clock is already running rather than waiting until you’re certain.

How do most businesses find out they’ve been breached?

Often from someone else. Of the ransomware incidents the Australian Signals Directorate handled in its most recent reporting year, 39% were discovered by ASD rather than the victim. That’s why noticing matters as much as responding.

Should we pay the ransom?

Not without specialist legal and incident response advice. There’s no guarantee you’ll get your data back or that stolen copies get deleted, businesses that pay are often targeted again, and paying a sanctioned group may breach Australian law. Larger businesses also have to report the payment to ASD within 72 hours.

Kiran Kewalramani

Kiran Kewalramani

Kiran Kewalramani stands as an acclaimed technologist with over two decades of robust executive experience in technology, cybersecurity, data privacy and cloud solution enablement. His illustrious career has been marked by transformative roles in esteemed organizations, including Cyber Ethos, Queensland Department of Education, Gladstone Area Water Board, NSW Rural Fire Service, NSW Police Force, Telstra, American Express, and more.