Call NowFree Quote
Cybersecurity

What to Do After a Cyber Attack: A Guide for Perth Businesses

Discovering your business has been attacked is one of the most stressful moments a business owner can face. The decisions you make in the first few hours significantly affect how bad the outcome will be. This guide walks through what to do - step by step.

Step 1: Don't Panic - But Act Immediately

The instinct to quickly delete files, reboot machines, or “fix it yourself” can destroy forensic evidence and make recovery harder. Stay calm, document what you're seeing (take photos of screens if needed), and move to the next steps.

Step 2: Isolate Affected Devices

If you suspect ransomware or an active breach, disconnect affected computers from the network immediately - unplug the ethernet cable or disable WiFi. Do not turn them off (this can destroy volatile memory evidence), just disconnect them from the network to stop the spread. This is the single most important action in the first few minutes.

If you're not sure which machines are affected, consider temporarily disconnecting your entire office network from the internet at the router level until your IT provider arrives.

Step 3: Call Your IT Provider

This is not the time for Google. Call your managed IT provider or an IT security specialist immediately. They will triage the situation, determine the scope of the attack, and begin containment. If you don't have an IT provider, Top Tier Computing provides emergency response for Perth businesses.

While you wait: don't use email systems that may be compromised to communicate about the incident. Use personal mobile phones or an out-of-band channel.

Step 4: Assess What Was Accessed

Once your IT provider is engaged, the next priority is understanding the scope:

  • Which systems and data were accessed or encrypted?
  • Were any credentials stolen?
  • How did the attacker get in - phishing email, compromised password, unpatched vulnerability?
  • How long had the attacker been in the system before being detected?

This assessment drives every subsequent decision, including whether you have a legal obligation to notify anyone.

Step 5: Check Your Reporting Obligations

If your business holds personal information about customers or employees and that data was accessed or exfiltrated, you may have mandatory reporting obligations under the Privacy Act 1988 (Cth) and the Notifiable Data Breaches scheme. You have 30 days from becoming aware of the breach to notify the Office of the Australian Information Commissioner (OAIC) and affected individuals.

Businesses with fewer than 250 employees are often exempt from the Privacy Act - but not always. If you handle health records, credit information, or government-related data, the exemptions don't apply. Get legal advice if you're unsure.

Step 6: Restore From Backups - Carefully

If ransomware has encrypted your files, the recovery path (assuming you have good backups) is to wipe affected machines and restore from a clean backup taken before the infection. This sounds straightforward but has important caveats:

  • Confirm your backups are clean - some ransomware sits dormant for weeks before triggering, meaning recent backups may also be infected
  • Close the entry point the attacker used before restoring - otherwise you'll be reinfected
  • Rebuild affected machines clean rather than restoring the OS image - restoring an OS can reintroduce malware

Step 7: Learn and Harden

Once the immediate crisis is resolved, conduct a post-incident review. How did the attacker get in? What controls would have prevented it? Common improvements after an incident include: enabling MFA everywhere, improving email filtering, deploying endpoint detection software, and tightening user access permissions. Treat the incident as a paid education on your security gaps.

Our cybersecurity services build in the MFA, email filtering, and endpoint detection that stop most cyber attacks before they start.

Cybersecurity Services →

Should You Pay the Ransom?

The Australian Cyber Security Centre (ACSC) advises against paying ransoms. Payment doesn't guarantee you'll get your data back, funds criminal organisations, and marks you as a target willing to pay. With good backups, paying is almost never necessary. Without backups, get specialist advice before making any payment decision.

Frequently Asked Questions

What's the first thing we should do if we think we've been hacked?

Disconnect affected devices from the network immediately, unplug the ethernet cable or turn off WiFi, but don't turn the machine off, since that can destroy evidence needed to understand what happened. Then call your IT provider straight away rather than trying to fix it yourself.

Do we have to report a cyber attack to anyone?

If personal information about customers or staff was accessed, there may be a notification obligation under the Privacy Act and the Notifiable Data Breaches scheme, though the exact rules depend on your business size and industry. It's worth getting legal advice to confirm what applies to your specific situation rather than assuming either way.

Should we pay a ransomware demand?

The Australian Cyber Security Centre generally advises against paying, since it doesn't guarantee you'll get your data back and marks you as a target willing to pay. With good, tested backups, paying is rarely necessary, if you don't have backups, get specialist advice before making any decision.

Is it safe to just restore from backup and move on after an attack?

Not straight away, you need to confirm the backup itself is clean, since some ransomware sits dormant for weeks before triggering. It's also important to close off however the attacker got in first, otherwise restoring from backup just gets you reinfected.

Dealing with a cyber incident right now?

Call 0433 087 091 immediately - we provide emergency IT response for Perth businesses.

Get Emergency IT Help

For related reading, see our guides to Running an Incident Response Drill: Stress-Test Your Team First and Cyber Insurance for Perth Businesses.

Share this article