You’ve Been Compromised. Here’s Exactly What to Do Next.
The order matters more than the speed. Lock down whatever was accessed first, work out what was actually exposed, then report it and tell the people who need to know. Most of the damage in a breach happens in the confusion afterward, not the breach itself, which is exactly why having someone who has managed this before makes the difference. Technicalities handles incidents like this for clients regularly. If you’re dealing with one right now, contact us before you do anything else.
30 Days
the legal window to assess whether a breach must be reported under Australia’s Privacy Act
$56,600
the average cost small businesses reported per cybercrime incident last financial year
1300 292 371
the Australian Cyber Security Hotline, for reporting and immediate advice
First: Contain It, Don’t Just React
Before anything else, stop the access. If it’s a device, disconnect it from the internet and Wi-Fi rather than shutting it down, since powering off can sometimes destroy evidence that’s useful later. If it’s an account, an email inbox, a cloud login, a piece of software, change the password immediately and, wherever the service allows it, revoke all active sessions so anyone already logged in gets kicked out.
If ransomware is involved, don’t plug in a backup drive to the infected machine to try to save files. Backups have been wiped out this way within seconds of connecting. Isolate first, assess second.
If It Was an Email Account, Check for Hidden Forwarding Rules
A changed password doesn’t always end the problem. A common trick is to quietly set up a forwarding rule or an inbox filter that keeps copying your mail to the attacker even after you’ve locked them out. Check your mailbox rules and forwarding settings for anything you didn’t create, and check which third-party apps have access to your account under connected apps or app passwords, revoking anything unfamiliar.
It’s also worth scanning any device that accessed the account for malware. If an infostealer was involved, your new password can be captured the moment you type it.
Work Out What Was Actually Exposed
This decides everything that comes next, so it’s worth taking the time to get it right rather than guessing. Was it just a device, with no data actually accessed? Money, through a fraudulent transfer or invoice? Personal information belonging to staff or clients? Business data with no personal information in it at all? The scale of your response should match the scale of what actually got out, not how alarming the moment felt.
Low exposure
A device or account was accessed but no data appears to have been taken or viewed. Contain, reset, and monitor.
Higher exposure
Money moved, or personal information belonging to staff, clients, or customers was accessed. Reporting obligations likely apply.
Report It, Even If It Feels Small
Reporting isn’t just paperwork. It’s how you get help, and how the broader picture of who’s behind an attack gets built. A few calls are worth making straight away, depending on what happened.
- Call your IT or security partner first, if you have one, before working through the rest of this list. A partner who already knows your systems can contain the incident and coordinate the calls below at the same time, rather than you doing it alone while also trying to run your business.
- Report the incident through ReportCyber at cyber.gov.au, the ACSC’s official channel for reporting cybercrime.
- Call your bank immediately if any financial details, transactions, or transfers were involved, so they can freeze accounts or cards.
- Notify the ATO if your tax file number or business tax identity may have been compromised.
- Call the Australian Cyber Security Hotline on 1300 292 371 if you need immediate advice on what to do next.
Do You Have to Tell the Regulator? The 30-Day Clock
If personal information was involved, Australia’s Notifiable Data Breaches scheme may apply. An “eligible data breach” is one where personal information has been accessed, disclosed, or lost, it’s likely to cause serious harm, and you can’t prevent that harm through quick remedial action. Once you have reasonable grounds to suspect this might be the case, you have 30 days to assess it, and the OAIC expects that assessment to move as quickly as possible, not sit on the clock until day 30.
If it is an eligible breach, both the OAIC and the affected individuals need to be notified, with a statement covering what happened, what information was involved, and what people should do about it. Worth knowing too: the small business exemption from this scheme has been narrowing, so a business that assumed it was too small to be covered is worth double-checking against the current rules rather than the old ones.
Tell the People Who Need to Know
If an account sent messages while it was compromised, whether that’s a fake invoice, a phishing link, or just strange behaviour, the people who received those messages deserve a heads-up, even before you know the full picture. A short, plain message along the lines of “our email was compromised, please disregard anything unusual and don’t click links from us until we confirm it’s safe” does more good than staying quiet until everything is resolved.
Once It’s Contained, Close the Gap That Let This Happen
Every compromise has a way in, and it’s worth finding it rather than just cleaning up and moving on. Turning on multi-factor authentication and moving to a password manager closes off the two most common entry points we see. Patching the software or device involved, and reviewing who still has access they no longer need, rounds out the basics.
Why This Goes Faster With Someone Who’s Handled It Before
Every step above is manageable on your own, but most businesses are working through this list for the first time, under pressure, while trying to keep everything else running. We’re not. Technicalities manages incidents like this for clients on a regular basis, which means we already know the environment we’re walking into, can act on containment and reporting at the same time instead of one after the other, and have worked through the OAIC assessment process enough times to move through it properly rather than second-guessing every step.
That experience is what actually shortens a breach, not luck. If you’re a client, this is exactly what we’re here for. If you’re not and something’s happened, get in touch anyway, we’d rather help now than have you find us after the wrong decision has already been made.
- ReportCyber: cyber.gov.au, for reporting the incident itself.
- Australian Cyber Security Hotline: 1300 292 371, for immediate advice.
- Your bank: call directly if any financial details or transactions were involved.
- The 30-day clock: if personal information was exposed, start the eligible breach assessment straight away, don’t wait.
Sources
- Cyber.gov.au (ACSC), “Report and Recover From Hacking”
- ACSC, “Annual Cyber Threat Report 2024-2025”
- ACSC, “Small Business Cyber Security Guide”
- OAIC, “Part 4: Notifiable Data Breach (NDB) Scheme”
- Australian Taxation Office, “Help for Identity Theft”
- Guardian Digital, “Email Recovery: What to Do After Account Compromise”
Dealing with this right now?
Technicalities manages incident response for businesses like yours as a matter of course. Contact us straight away and we’ll help you contain it, work out what happened, and handle the reporting from there.
Contact Us Now