What Is Cyber Incident Response?
Cyber incident response is the organised way you handle a cyber attack or data breach — from the moment you realise something's wrong, through containing the damage, kicking the attacker out, recovering, and learning from it. Done well, it's the difference between a contained problem and a business-ending catastrophe.
It isn't a single product or a one-off action. It's a combination of three things: a plan (who does what), a team (the people who execute it), and a tested process (the steps you follow) — so that when the pressure hits, you act fast and correctly instead of panicking.
Cyber incident response is how an organisation detects, contains, and recovers from a cyber attack or data breach in a structured way. It covers the immediate response (stopping the spread and limiting damage), the investigation (working out what happened), recovery (getting safely back to normal), and the legal duty to notify regulators and affected people. The goal is to minimise harm — financial, operational, and reputational — and to get back on your feet as quickly and cleanly as possible.
Australia's threat picture is sobering. In its 2024–25 report, the Australian Signals Directorate recorded a cybercrime report roughly every six minutes, responded to over 1,200 incidents, and noted the average cost of cybercrime to a business jumped 50% to around $80,850. Most tellingly, of the ransomware incidents ASD handled, 39% were discovered by ASD — not by the victim. Many organisations don't even know they've been breached until someone tells them.
What to Do in the First 72 Hours of a Breach
If you suspect you've been breached or hit by ransomware right now, the first moves matter enormously. Here's what to do — in order.
-
Don't panic — and don't start wiping or "fixing" thingsThe instinct to immediately rebuild or delete can destroy the evidence you'll need and tip off the attacker. Pause, and work the plan.
-
Isolate affected systems — but preserve themDisconnect compromised devices from the network to stop the spread, but where possible keep them powered and intact so they can be investigated. Containment first, clean-up later.
-
Activate your plan and get the right people in the roomA serious incident isn't just an IT issue. Bring in leadership, legal, and communications alongside your technical team — decisions need to be made across all of them, fast.
-
Preserve evidenceKeep logs, affected systems, and any ransom notes intact. You'll need them to understand the attack, support recovery, and meet your reporting obligations.
-
Bring in expert incident responders earlySpecialists contain incidents faster and avoid the costly mistakes that make things worse — especially with ransomware. The earlier they're engaged, the better the outcome.
-
Work out your reporting clocksIdentify early what you must report and by when — the OAIC, ASD, APRA, or under the SOCI Act may all apply, and the deadlines are short (see below).
-
Communicate carefully and deliberatelyPlan what you tell staff, customers, and regulators — and when. Getting communication wrong adds legal exposure and reputational damage on top of the incident itself.
Don't immediately wipe or rebuild systems (you'll lose evidence and may not fully remove the attacker). Don't pay a ransom on impulse. Don't go silent and hope it passes — the obligations and the damage don't wait. And don't let one person handle it alone under pressure. Most of the worst outcomes come from rushed first moves, not the attack itself.
The Incident Response Lifecycle
Behind a calm, effective response is a well-understood process. Most frameworks describe the same six stages
Ransomware: Special Considerations
Ransomware is the most disruptive threat Australian organisations face, and it doesn't behave like an ordinary breach. Modern ransomware crews don't just lock your files — they steal your data first, then threaten to publish it if you don't pay. This "multi-layered extortion" means that even flawless backups won't make the problem go away, because the criminals still hold a copy of your information.
If ransomware hits, the early principles are the same as any incident — isolate, preserve, get help — with a few specifics:
- Isolate fast, but don't wipe. Disconnect affected systems to stop encryption spreading, but preserve them for investigation.
- Don't assume backups are enough. Check they're intact, offline, and uninfected — and remember they restore your files, not your privacy if data was stolen.
- Identify the scope. Work out what was accessed and taken, not just what was encrypted — that determines your legal obligations.
- Don't engage the attackers alone. Any contact or payment decision should go through experienced responders and legal advisers.
Ransomware made up about 11% of the incidents ASD responded to in 2024–25, and 35% of ransomware victims had their data posted online. The healthcare sector was hit especially hard, with ransomware incidents doubling year on year. One Australian e-prescription provider that suffered a major ransomware breach — exposing the data of millions of Australians — ultimately ceased to exist. The stakes are existential, not just financial.
Should You Pay the Ransom?
It's the question every ransomware victim asks. The honest answer is that paying is fraught with risk, and the Australian Government strongly discourages it. Here's what you need to weigh — though you should never decide alone.
- There's no guarantee. Paying doesn't ensure you get a working decryption key, or that the criminals actually delete the data they stole. You're trusting extortionists to keep their word.
- It often invites more attacks. Evidence suggests a large share of organisations that pay — around two-thirds — are targeted again. Paying marks you as willing.
- It may be unlawful. Paying a group subject to sanctions can breach Australian law, regardless of the circumstances.
- It's now a reportable event. Since May 2025, larger businesses and critical infrastructure that pay must report it to ASD within 72 hours (more below). Payment is no longer a quiet, private choice.
Paying a ransom is a serious legal, financial, and strategic decision — not a technical one, and never one to make under pressure or alone. If you're facing it, get specialist incident response and legal advice immediately. The best protection against ever being in this position is preparation: secure, tested, offline backups and a rehearsed response plan.
Your Australian Reporting Obligations
This is where many organisations get caught out: a single incident can trigger several reporting duties at once, each with its own tight deadline. Here are the main obligations Australian organisations need to know.
| Obligation | Who it applies to | The deadline |
|---|---|---|
| Notifiable Data Breaches (NDB) scheme Privacy Act · OAIC |
Most organisations covered by the Privacy Act, after an eligible data breach likely to cause serious harm | Notify the OAIC and affected individuals as soon as practicable (assess a suspected breach within ~30 days) |
| Ransomware payment report Cyber Security Act 2024 · ASD |
Businesses with turnover over A$3M, and critical infrastructure entities, that make a ransom or extortion payment | Within 72 hours of making the payment |
| APRA CPS 234 Prudential standard |
APRA-regulated entities — banks, insurers, super funds | Within 72 hours of a material information security incident |
| SOCI Act Critical infrastructure |
Responsible entities for critical infrastructure assets | Within 12 hours (critical impact) or 72 hours (significant impact) to ASD |
The newest of these is the most important to understand: under Part 3 of the Cyber Security Act 2024, in effect since May 2025, a ransomware payment is now a mandatory disclosure — and from January 2026, the Department of Home Affairs moved to actively enforce it. A regulated breach can easily mean reporting to the OAIC and ASD and your industry regulator simultaneously, so knowing your obligations in advance — and building them into your response plan — is essential.
This section is general information, not legal advice. Your specific obligations depend on your circumstances — during a real incident, confirm them with your legal advisers.
Being Ready: An IR Retainer vs Scrambling Mid-Crisis
When an attack hits, the clock is already running. The single biggest factor in how badly it ends is whether you were ready — and that's the difference between scrambling to find help mid-crisis and having experts on call.
This is why an incident response retainer — pre-engaging experts so they're ready the moment you need them — and regular tabletop exercises (practice runs of your plan) are among the most valuable investments an organisation can make. The cheapest time to plan your response is long before you need it; the most expensive is at 2am during the attack.
5 Myths About Incident Response
How Cyber Ethos Helps With Incident Response
Cyber Ethos is led by Dr. Kiran Kewalramani — a PhD-qualified cybersecurity specialist with CISSP, CISA, and GAICD credentials and over 20 years of experience. We help Australian organisations prepare for, respond to, and recover from cyber incidents — calmly and clearly, when it matters most. That includes:
- Incident response planning. A clear, practical plan that defines who does what, so your team isn't improvising under pressure.
- Rapid response support. Experienced responders to help contain and manage a live incident, and limit the damage.
- Digital forensics. Working out exactly what happened and what was accessed, while preserving the evidence you need.
- Ransomware recovery. Guiding safe recovery and helping you navigate the difficult payment and legal questions.
- Regulatory notification support. Helping you meet the OAIC, ASD, APRA, and SOCI reporting clocks correctly and on time.
- Tabletop exercises. Practising your response so your people perform when it counts.
- Joined-up protection. Incident response works best alongside a managed SOC that detects threats early and a virtual CISO who leads through a crisis and reports to your board.
🚨 Dealing with an incident — or want to be ready before one?
If you're in the middle of an attack, call Cyber Ethos now. If you want to prepare, talk to Dr. Kiran Kewalramani about an incident response plan, a retainer, or a tabletop exercise — so the next bad day is a manageable one.
Talk to Cyber Ethos →📞 1800 CETHOS (1800-238-467) · cyberethos.com.au · National reporting: cyber.gov.au/report