Cyber incident response
Cyber incident response, when it cannot wait
Think you have been hacked? Call us now. Our engineers contain the attack, protect what is still clean, recover your systems and help you with reporting. We respond for our managed clients and for businesses that are not clients yet.

- $56,600Average cost of a cyber attack reported by a small business, ASD 2024 to 25
- 34%Of business reports to ASD involved a compromised email account
- 24/7Security operations centre monitoring for SecureShield clients
- ISO27001 certified ourselves, audited every year
01The first hour
What to do right now
The first hour decides how much damage an attack does. Do these five things, in this order.
- 01Disconnect, do not switch off. Unplug affected computers from the network or turn off their wifi. Leave them powered on, because what is in memory helps show how the attacker got in.
- 02Do not pay or reply. Ransom notes and fake emails are written to rush you. Do not contact the attacker or pay anything yet.
- 03Call us on 1300 787 429. Say it is a security incident. If you have cyber insurance, call your insurer's incident line too.
- 04Keep the evidence. Do not delete emails, wipe devices or restore from backup until we have looked. Write down what you saw and when.
- 05Warn your people. Tell staff not to open anything suspicious, and if a mailbox has been taken over, warn clients who may have received fake invoices.
Clients and non clients. Tell us it is a security incident so we can start straight away.
02What we respond to
The incidents we see most often
Most attacks on small and medium businesses start with an email or a stolen password, not a movie style hack. These are the four we are called about most.
- 01
A mailbox has been taken over
Staff get strange replies, clients receive invoices you did not send or rules appear that hide or forward mail. This is business email compromise, and it is the most common incident businesses report to ASD.
What we doLock the account, remove the attacker's access, rules and forwarding, find out what they read and sent and help you warn the people affected.
- 02
Files are encrypted or a ransom note appears
Files will not open, extensions have changed or a message demands payment. Ransomware often copies your data before it locks it.
What we doStop it spreading, work out what was taken, check your backups are clean and rebuild from them, so paying is not your only option.
- 03
A payment went to the wrong account
A supplier's bank details changed by email and the money went to a criminal. Speed matters, because banks can sometimes recall a payment if they hear quickly.
What we doFind the compromised mailbox, yours or the supplier's, close it off and give you the evidence your bank and the police will ask for.
- 04
Something just looks wrong
Sign in alerts from overseas, security warnings, a device acting strangely or an account you do not recognise. Often it is nothing. Sometimes it is the start of something bigger.
What we doCheck it quickly and tell you plainly whether it is an incident. If it is not, you have lost nothing by asking.
03How we respond
Contain first, then recover
Every response follows the same stages, so nothing is missed when everyone is under pressure. You get a single point of contact and plain English updates throughout.
Triage
On the first call we work out what is affected, how far it may have spread and what to switch off. We also agree who needs to know.
Contain
We isolate devices, disable compromised accounts, end sign in sessions and block the attacker's access, keeping the evidence as we go.
Investigate
We find how they got in, what they touched and whether data was taken, which is what your insurer and any report will need.
Recover
We clean or rebuild affected systems, restore from backups we have checked are clean and bring your team back online in order of priority.
Report
You get a written summary for your insurer, board or regulator, plus the technical detail for any report you need to make.
Stop it happening again
We close the gap they used and show you the few changes that would have stopped it, in order of cost and effect.
04Who we help
Our clients, and everyone else
You do not need to be a client to call us. What changes is how much we already know about your systems, and how early we see the attack.
We are usually first to know
Our security operations centre watches devices and Microsoft 365 accounts 24/7 and isolates threats as they happen. We already know your systems, backups and contacts, so recovery starts straight away.
- 24/7 detection and response on devices and accounts
- Documented incident response plan, tested every year, on Gold and Platinum
- Backups we manage and test
- Response handled as part of looking after you
Call us anyway
We respond to incidents for businesses we do not look after, whether you have an internal IT person, another provider or nobody at all. We work with whoever you already have.
- Help from the first phone call
- Remote containment where we can, onsite across Perth when needed
- Time based cost, agreed before recovery work starts
- No obligation to become a client afterwards
Want us on call before anything happens? SecureShield Gold and Platinum include an incident response plan tested every year.
Compare SecureShield plans05Reporting
Who you may need to tell
Some reports have deadlines that start the moment you find out. These are the four that come up most for Australian businesses.
| Report | Who it applies to | What and when |
|---|---|---|
| Notifiable data breach | Businesses covered by the Privacy Act, which generally means turnover over $3 million, plus all health service providers | Assess a suspected breach within 30 days. Notify the OAIC and the people affected as soon as practicable if it is eligible |
| Ransomware payment | Businesses with annual turnover over $3 million | Report any ransom or extortion payment to the Australian Signals Directorate within 72 hours of paying |
| Cybercrime report | Any business, whatever its size | Report through ReportCyber so ASD and police can act and warn others |
| Cyber insurance claim | Businesses with a cyber policy | Tell your insurer as early as the policy requires, which is often straight away and before you appoint anyone else |
Swipe the table sideways to see every column.
We handle the technical facts and the evidence for each report. Legal interpretation of any obligation sits with your advisers.
06Questions
Incident response questions
What business owners ask us during and after an incident. Anything urgent, call 1300 787 429.
01What should we do first if we think we have been hacked?
Disconnect the affected devices from the network but leave them switched on, do not reply to or pay the attacker and call us on 1300 787 429. If you have cyber insurance, call your insurer's incident line as well. Then write down what you saw and when, before details are forgotten.
Do not wipe or rebuild anything yet. Logs and files on the affected devices show how the attacker got in and what they touched.
02Should we pay the ransom?
The Australian Signals Directorate advises against it. Paying does not guarantee your files come back or that your data is deleted, and it marks you as a business that pays. Good backups are what make recovery possible without paying.
If a business with an annual turnover over $3 million does pay, it must report the payment to ASD within 72 hours. See the 72 hour rule.
03Do you help businesses that are not clients?
Yes. Call 1300 787 429 and tell us it is a security incident. We work out what is happening on the call, start containing it remotely where we can and agree the cost with you before the larger recovery work begins. There is no obligation to become a client afterwards.
04How quickly can you start?
We start on the first call: working out what is affected and telling you what to disconnect or switch off while we connect. SecureShield clients already have 24/7 monitoring, so our security operations centre usually isolates an affected device or account before anyone has to call.
05Can you work with our cyber insurer?
Yes. Many cyber policies have an incident line and a panel of response firms, and some require you to use them. Call your insurer early. We work alongside their responders, give them the technical detail they ask for and handle the recovery of your systems.
06Do we have to report a cyber incident?
It depends on what happened and who you are. If personal information was involved and your business is covered by the Privacy Act, you must assess a suspected breach within 30 days and report eligible breaches to the OAIC. Ransomware payments by businesses over $3 million turnover must be reported to ASD within 72 hours. Anyone can report a cybercrime through ReportCyber.
We give you the technical facts each report needs. Your lawyer or your insurer's breach coach advises on the legal obligations.
07How much does incident response cost?
For businesses that are not clients, we charge for the time our engineers spend and agree the cost with you before recovery work starts, so there are no surprises. For managed clients, response and recovery are handled as part of looking after you, and anything outside your agreement is agreed first. Many cyber insurance policies cover response costs, so check your policy.
08How do we know the attacker is really gone?
We check every way back in, not only the one they used. That means resetting passwords and sign in sessions, removing mailbox rules and forwarding the attacker set up, reviewing admin accounts and app permissions and scanning every device before it goes back on the network. You get a written summary of what we found and what we changed.
What our clients say
800+ reviews from the people who call our Perth service desk every day.
700+
30+
70+
-
“Turns every IT problem into a non-issue”
Arthur turns every IT problem into a non-issue and does it with real patience and professionalism. He explains things in a way that makes the process easy and always leaves us feeling supported. We appreciate the way he handles every request.
Bronte J.Indian Ocean Hotel
-
“Patient, capable and a genuine listener”
The support was outstanding. Patient, capable and a genuine listener, which is rare in support calls. He took the time to understand the issue and work through it with care. You are fortunate to have him on your team and the level of service was impressive.
Peter MidgleyPowertech
-
“Steady, thoughtful and stress free”
Jamie put in a great deal of effort to resolve the problem and it showed in the result. His approach was steady and thoughtful and the support was appreciated. It made the whole experience smooth and stress free.
Jason CavallaroCallidus Process Solutions
-
“Resolved the issue within minutes”
The consultant knew exactly what to do and resolved the issue within minutes. He talked through each step so I understood what was happening and made the process simple. The clear communication and fast resolution made a real difference.
Kirk LentonPilbara Construction
-
“The extra guidance made it more valuable”
Brady tracked down an email I could not locate and took the time to show us how to search more effectively in the future. The extra guidance was helpful and made the experience more valuable. His support was straightforward and appreciated.
Tony YoungOptimus Real Estate
-
“Resolved quickly, with none of my work lost”
They resolved my issue quickly and efficiently, which meant I didn’t lose any of the work I had done today. The support was clear and straightforward, and the outcome made a real difference to my day. Thank you.
Warner PriestInterContinental Energy
-
“Calm, patient and always willing to help”
Dev Sandhu is outstanding in his knowledge and support. He has a calm and patient way of working through any IT issue and is always willing to help at short notice. His positive attitude makes the whole experience easier and more reassuring. Thank you to Dev and the team at Austin for the consistent support.
Peter AlexanderKoch Solutions
-
“A calm and methodical engineer”
Chris Wade is a great engineer and I have a lot of respect for his professionalism. He approaches every issue with a calm and methodical attitude and communicates clearly so I always understand what is happening. His steady approach and reliability make a real difference to our team, and his support is always appreciated.
Paul GreenGlobal Cardiology
-
“Refreshing after two unreliable IT providers”
After dealing with two unreliable IT providers in recent years, it has been refreshing to place my trust in Greg and the team at Austin. They have been professional and highly competent, even under pressure. Their support has made a real difference. Thank you, and keep it up.
Mark HutchisonLifewood
07Cyber incident response
Think you have been hacked?
Call us now.
Call 1300 787 429 and tell us it is a security incident. If it is not urgent, send us the details and an engineer will come back to you.