If your Queensland business has been hit by ransomware, email compromise or a data breach, do four things in this order. Isolate the affected devices from the network without powering them off, call your IT provider, notify your cyber insurer and start a written log with timestamps. Reporting to ReportCyber and, where personal information is involved, the OAIC comes next. The first hour is containment and evidence.
The first hour, in order
- Unplug the ethernet and turn off Wi-Fi. Do not shut the machine down, because that destroys forensic evidence.
- Call your IT provider. If you don't have one, your insurer's hotline will usually supply an incident responder.
- Call the cyber insurance hotline. Most policies require notification within 24 to 72 hours, and late notice is a common reason claims get reduced.
- Stop money moving. Tell whoever pays invoices to hold all payments until account details are re-verified by phone.
- Start a log: time, who noticed, what they saw and every decision after that.
Who you have to report it to in Australia
- ReportCyber at cyber.gov.au, the national police-linked reporting channel for any cybercrime.
- The OAIC, with a mandatory Notifiable Data Breach report within 30 days if personal information was exposed and serious harm is likely.
- Queensland Police, where there is extortion, theft or an identified offender.
- Your bank, immediately, if payment details or banking credentials were involved.
- Affected customers and suppliers, plainly and early, in writing.
The mistakes that cost the most
Paying an invoice that arrives with updated bank details during the incident. Wiping and rebuilding a machine before the insurer's investigator has seen it. Letting five people talk to customers with five different stories. And discovering the backups you assumed were running have been failing quietly since March.
"In a cyber incident you fall to the level of the plan you already wrote."
Worked example: invoice redirection fraud at a Gold Coast trades supplier
A 16-person plumbing supplies business received what looked like a routine email from a long-standing steel supplier advising new bank details ahead of a $47,000 payment. The accounts clerk, working from a template that required a phone call to a known number before any bank detail change, called the supplier directly rather than replying to the email, and discovered the email account had been compromised and the request was fraudulent. The $47,000 payment never left the business. A comparable business in Toowoomba that lacked this simple verification step paid a similar fraudulent invoice the same month and recovered less than 15 per cent of the funds despite an immediate bank report, which is typical once money has moved offshore through several accounts.
What good looks like
A well-prepared business has multi-factor authentication on email and finance systems, a written rule that no bank detail change is actioned without a phone call to a known number, a backup that has actually been restored from in a test within the last twelve months, and a one-page playbook with the call order and hotline numbers already printed rather than searched for during the incident.
What to have ready before it happens
A one-page playbook with the call order, the policy number and insurer hotline, the IT provider's after-hours mobile, a holding statement for customers and a backup you have actually restored from. That is the whole preparation, and it takes an afternoon.
How long do I have to report a data breach in Australia?
If the breach involves personal information and is likely to result in serious harm, the Notifiable Data Breach scheme requires you to notify the OAIC and affected individuals as soon as practicable, and in any case within 30 days of becoming aware. Cyber insurance policies often set a shorter internal notification window, commonly 24 to 72 hours, so check your policy wording rather than relying on the regulatory deadline alone.
Will my cyber insurance be voided if I don't report immediately?
Late notification is one of the most common reasons cyber claims are reduced or declined, because insurers lose the chance to direct containment and forensic work early. Report to your insurer's hotline the same day you become aware of an incident, even before you know the full extent of it.
Should I pay a ransomware demand?
The Australian Cyber Security Centre and Queensland Police advise against paying, because payment does not guarantee data recovery, can mark you as a target for repeat attacks, and may in some circumstances raise sanctions or legal issues depending on who is behind the attack. Any decision on payment should be made with your insurer and an experienced incident responder involved, not alone under pressure.
Our first hour of a cyber incident guide covers the decision-making side in more detail, crisis leadership training is where we train the people who make those calls, and our scenario testing keeps your playbooks current between incidents.
The Disruption Playbooks module holds the cyber call order, contacts and holding statement on the phone of whoever is on shift.
See the playbooks →