28 Jul 2026

This article provides a step-by-step plan of what to do if your business is hit with a cyber attack plus where to report an attack. What you do in the first hour after an attack matters. It's also the easiest time to make a costly mistake, such as turning off computers, accidentally deleting evidence or using an email account the attacker is already reading. The steps below show you what to do, in order, so you're not guessing in the moment. Completion of these steps does not require any technical knowledge.
Before you touch anything, avoid these:
• Don't turn the affected computer off, if you can avoid it. Disconnecting it from the network is better. Powering it down can wipe evidence which may help determine what happened.
• Don't delete anything. Leave the ransom note, the suspicious email and any alerts exactly where they are. They're what your IT team and investigators will need.
• Don't pay a ransom.
• Don't use the hacked email or accounts to talk about the attack. If an attacker is in your inbox, they can read those messages. Switch to phone calls or a different account.
Work through these in order, starting the moment you notice something is wrong.
Step 1. Disconnect the affected devices from the network.
Unplug the network cable and turn off Wi-Fi on any computers that are affected. This stops the problem spreading to other computers and to your backups. Cybersecurity and Infrastructure Security Agency (CISA) recommend isolating devices rather than powering them off where you can and to shut a device down only if you can't get it off the network any other way.
Step 2. Call your IT provider straight away, by phone.
Don't email, in case the attacker is watching your inbox. If you have cyber insurance, call your insurance company next. Many policies require you to involve the insurer's incident team early.
Step 3. Leave any evidence. Don't wipe, reinstall or tidy up the affected machines. Screenshots of the ransom note or suspicious emails are useful and keep the originals.
Step 4. If money was sent, call your bank immediately.
Ask your bank to recall the transfer if they can.
Step 5. Reset passwords from a clean device and turn on multi-factor authentication (MFA).
Start with email and any admin accounts and use a device you are confident is not affected.
Step 6. Report it.
This can help you recover and it can be a legal requirement.
Call the 24/7 hotline on 1300 CYBER1 for urgent assistance.
Report the incident to Australian Signals Directorate (ASD) through the ReportCyber Portal. Australian law mandates that a business entity must submit a formal report within 72 hours of making or becoming aware of a ransomware or cyber extortion payment.
If customer or staff personal data about was exposed you may be legally required to notify a regulator and the individuals affected, possibly within 72 hours. Ask your lawyer or IT provider so you don't miss a deadline.
If it's ransomware, the big question is whether to pay. It is not recommended and paying doesn't guarantee your files will be returned, it indicates your business is an organisation that will pay, possibly funding future attacks.
It's ultimately your decision, but it's one to make with legal assistance, your IT or incident-response team and your insurer, not alone in the first panicked hour.
Sometimes a free decryption tool already exists for the exact ransomware that hit you, which is another reason to get the experts involved before you pay anyone.
All of this is far easier if you have made some decisions in advance. A simple plan is all that's required including:
• Who to call first (your IT provider, your insurer) and their numbers, kept somewhere you can access without your main systems.
• Where are your backups located plus proof they've been tested by restoring from them.
• Which accounts and devices matter most, so you know what to protect first.
A single page with this information is enough for most small businesses and it will save a lot of scrambling if the day ever comes.
Disconnect the affected devices from the network by unplugging the network cable and turning off Wi-Fi, then call your IT provider by phone. Getting the device off the network stops the problem spreading while you ask for help.
If you can, disconnect it from the network instead of powering it off. Shutting it down can wipe evidence stored in memory that may help work determine what happened. Only power a device off if you can't get it off the network any other way.
It is not recommended. Paying doesn't guarantee you get your data back, and it funds more attacks. Make that decision with law enforcement, your IT or incident-response team, and your insurer, and check whether a free decryption tool already exists first.
Call your bank immediately and ask them to recall the transfer and report the incident to Australian Signals Directorate (ASD) through the ReportCyber Portal. Australian law mandates that a business entity must submit a formal report within 72 hours of making or becoming aware of a ransomware or cyber extortion payment.
Call the 24/7 hotline on 1300 CYBER1 for urgent assistance.
Report the incident to Australian Signals Directorate (ASD) through the ReportCyber Portal. Australian law mandates that a business entity must submit a formal report within 72 hours of making or becoming aware of a ransomware or cyber extortion payment.
When a cyber attack occurs, every minute matters. Knowing who to call and what steps to take can significantly reduce the impact on your business and improve the chances of a successful recovery.
Pact IT Solutions can help contain the threat, assess the extent of the incident, secure affected systems and guide you through the recovery process.
If your business has experienced a cyber attack, or you need assistance developing an incident response plan before one occurs, contact Pact IT Solutions today. Our team is here to help you respond quickly, minimise disruption and get your business back on track. 👉 Need urgent assistance? Contact Pact IT Solutions today.
Article used with permission from The Technology Press.