What To Do in the First Hour of a Cyberattack: A Step-by-Step Guide for WA Businesses

Published on Tuesday, 4 August 2026 at 10:55:11 AM

The first hour of a cyber incident decides how bad the rest of it gets. It's also the hour in which most of the avoidable damage happens - someone powers down the wrong machine, someone deletes the ransom note, someone emails the whole team from an inbox the attacker is already sitting in.

None of the steps below need technical knowledge. They need someone to work through them in order, without guessing.

At Integrated ICT, we support businesses, Not for Profits, local governments, Aboriginal health providers and Aboriginal corporations across Western Australia. 

What should you do first if you think you've been hacked?

Get the affected devices off the network, then ring your managed ICT provider by phone.

That's the order. Isolation first, because it stops the problem spreading to other computers, your servers and your backups. Phone second, because if an attacker is reading your email, an email to your IT provider tells them you've noticed.

Your MSP is your IT support. For Integrated ICT clients, that means calling us before anything else. We can revoke account access, disable compromised logins, lock down remote access, isolate the affected network segment and start containment while you're still working out what's happened. Every minute that access stays live is a minute the attacker can use.

What should you avoid doing?

Before you touch anything, avoid these four things:

  • Don't turn the affected computer off if you can avoid it. Disconnecting it from the network is better. Powering down can wipe evidence held in memory that helps work out how the attacker got in and what they took.
  • Don't delete anything. Leave the ransom note, the suspicious email and any security alerts exactly where they are. That's what your IT team, your insurer and investigators will need.
  • Don't pay a ransom on the spot.
  • Don't use the compromised email or accounts to discuss the attack. Switch to phone calls, or a different account on a device you know is clean.

What are the steps, in order?

Work through these from the moment you notice something is wrong.

  1. Disconnect the affected devices from the network. Unplug the network cable and switch off Wi-Fi on anything that looks affected. Isolate rather than power down, and only shut a device off if you have no other way to get it off the network.
  2. Ring Integrated ICT straight away, by phone. We'll begin containment, revoke access and start working out the scope. If you hold cyber insurance, ring your insurer next — many policies require their incident team to be involved early, and acting outside that process can affect your cover.
  3. Leave the evidence alone. Don't wipe, rebuild or tidy up the affected machines yet. Take screenshots of the ransom note or suspicious emails, but keep the originals in place.
  4. If money has been sent, ring your bank immediately. Ask them to recall the transfer and freeze it if they can. With business email compromise and invoice fraud, the first few hours make the biggest difference to whether the funds are recoverable.
  5. Reset passwords from a clean device and switch on multi-factor authentication. Start with email and administrator accounts, and use a device you're confident isn't affected.
  6. Report it. Reporting helps you recover, and in some circumstances it's legally required. Details are below.

Why does isolating systems matter so much?

Because containment is what limits the size of the incident.

In July 2026, the Australian Signals Directorate led the release of joint guidance with international partners called CI Fortify — Advice for isolating vital systems. It's written for critical infrastructure operators, but the logic underneath it applies to any business with systems it can't afford to lose.

ASD's central point is that isolating vital systems from all other networks disrupts an attacker's ability to reach their goal, contains an active incident, and lets you rebuild compromised systems safely. Isolation points between critical and non-critical networks are highly effective at limiting an attacker's ability to pivot into the systems that matter most. Inside a critical network, they contain attacks, limit the operational impact, and cut the time needed to evict the attacker and restore services.

The guidance also makes a point that's easy to miss: isolation only works if you've planned it in advance. ASD recommends building a graduated isolation plan, progressively cutting pathways as the threat escalates, with the trigger for each step defined ahead of time and linked to your incident response plan. For a critical infrastructure operator, that might run from disabling remote worker access, through disabling on-premises remote access, to fully isolating the operational network. For a mid-sized WA business, the same thinking scales down neatly: which connections do we cut first, who decides, and what still works afterwards?

Two more points from CI Fortify worth carrying across to any business:

  • Test it. ASD recommends testing isolation periodically, because testing one system on its own rarely surfaces every dependency. The same is true of backups. An untested backup is a hope, not a plan.
  • Keep an offline copy. ASD advises storing a secure offline hard copy of isolation plans. If your systems are encrypted, a plan that only exists on the network is no help at all.

What does this mean for regional WA sites?

If you operate across Geraldton, the Mid West, the Wheatbelt or further north, you're running a distributed network, and CI Fortify has direct advice for exactly that situation.

ASD's guidance is that where physical isolation isn't feasible across dispersed sites, effective isolation can be achieved through strong encryption over untrusted and shared links, and that any carrier-provided service should be treated as untrusted and potentially hostile. For a WA business, "carrier-provided" covers a lot of ground: satellite, fixed wireless, microwave point-to-point, mobile broadband and Wi-Fi at remote depots and shire offices.

The practical consequences for regional operators:

  • Map every connection into your critical systems, including vendor and contractor remote access, cloud services and any link to a peer organisation. ASD's guidance is specific about capturing routine and emergency contact details for connections to other entities.
  • Know what still works when the link drops. ASD warns that isolation triggers manual processes and interrupts system-to-system communication. If a site can't operate for a day without head office, that's worth knowing before the day arrives.
  • Plan for the distance. A Perth-based response team can't unplug a switch in Northam. Someone on site needs to know what to disconnect, and needs a phone number that works when email doesn't.

This is the part regional businesses most often haven't done — not because they don't take security seriously, but because nobody has walked the site and written it down. Not sure about your set up? Speak to the Integrated ICT team

Who do you report a cyberattack to in Australia?

Report it through ReportCyber at cyber.gov.au, which is the joint reporting portal run by ASD and State and Territory police. If you need help urgently, the Australian Cyber Security Hotline is 1300 CYBER1 (1300 292 371) and operates 24/7.

Depending on what's happened, you may also need to contact:

  • Your bank or credit union — immediately, if financial details were stolen or money was transferred. They may be able to freeze accounts or stop a transaction.
  • IDCARE (1800 595 160) — Australia and New Zealand's national identity and cyber support service, for staff or customers whose personal information is at risk.
  • Scamwatch, run by the National Anti-Scam Centre — if the incident was a scam rather than an intrusion.
  • WA Police — if identity documents were physically stolen. Where the offence occurred online, you'll generally be directed to ReportCyber.
  • ASIC — for financial or corporate misconduct.
  • Your cyber insurer — early, as noted above.

If there's an immediate threat to life, ring 000.

Do you have to notify anyone if customer data was exposed?

Possibly, yes. Under the Notifiable Data Breaches scheme in the Privacy Act, if you suspect an eligible data breach you generally have 30 days to assess it, and if it's likely to result in serious harm you must notify the Office of the Australian Information Commissioner and the affected individuals as soon as practicable.

Don't sit on this. Get advice from your lawyer and your ICT provider early so you don't miss a deadline while you're focused on recovery.

Should you pay the ransom?

It isn't recommended, and it isn't a decision to make alone in the first panicked hour.

Paying doesn't guarantee you get your data back, it marks your business as one that pays, and it funds the next attack. In some cases a free decryption tool already exists for the specific ransomware involved — which is a good reason to get expert eyes on it before any money moves.

There are also Australian legal considerations. Under the Cyber Security Act 2024, businesses carrying on business in Australia with an annual turnover above $3 million, plus entities responsible for critical infrastructure assets regardless of turnover, must report a ransomware or cyber extortion payment to the Australian Government within 72 hours of the payment being made — including where it's made on their behalf by an insurer or incident response firm. The obligation commenced on 30 May 2025, with a civil penalty for failing to report. Paying also doesn't remove any separate data breach notification obligation.

Make that call with your incident response team, your insurer and legal advice — not on your own at 2am.

How do you prepare before it happens?

All of the above is far easier if some of it was decided in advance. You don't need a thick binder. You need one page covering:

  • Who to ring first, with numbers, stored somewhere you can reach without your main systems. Print it.
  • Where your backups are, and evidence they've been tested by actually restoring from them.
  • Which accounts, systems and sites matter most, so you know what to protect and isolate first.
  • Who can physically disconnect equipment at each regional site, and what they should do.

For context on why this is worth an afternoon: ASD's Annual Cyber Threat Report 2024–25 recorded more than 84,700 cybercrime reports — roughly one every six minutes — and the average self-reported cost of cybercrime for a small business rose 14% to around $56,600 per report. Across businesses of all sizes, the average was $80,850.

That's the number to plan around. Not the seven-figure ransoms that make the news.

Frequently asked questions

What's the first thing to do in a cyberattack?

Disconnect the affected devices from the network by unplugging the network cable and switching off Wi-Fi, then ring your managed ICT provider by phone. Getting the device off the network stops the problem spreading while help is on the way.

Should I turn the computer off if I get ransomware?

If you can, disconnect it from the network instead of powering it off. Shutting it down can wipe evidence held in memory that helps establish how the attack happened. Only power a device off if you have no other way to get it off the network.

Who do I report a cyberattack to in Australia?

Report it through ReportCyber at cyber.gov.au, or call the Australian Cyber Security Hotline on 1300 CYBER1 (1300 292 371), available 24/7. Also notify your bank if money or financial details are involved, IDCARE if personal information is at risk, and your cyber insurer.

We transferred money to a scammer. What do we do?

Ring your bank immediately and ask them to recall the transfer and freeze the account. Then report it through ReportCyber and contact IDCARE if identity information was also exposed. Acting within the first few hours makes the biggest difference to recovering funds.

Do I have to report a ransomware payment in Australia?

If your business has an annual turnover above $3 million, or you're responsible for a critical infrastructure asset, yes. Under the Cyber Security Act 2024 you must report a ransomware or cyber extortion payment within 72 hours of it being made, including where it's paid on your behalf.

Should I ring my IT provider or the police first?

Ring your managed ICT provider first. They can revoke access, isolate systems and stop the attack spreading while you're still gathering facts. Reporting to ReportCyber is important, but it doesn't contain the incident. If there's an immediate threat to life, ring 000.

What if the affected site is in regional WA and no one technical is on site?

That's exactly why the plan matters. Someone at each site should know which cable to unplug and which number to ring. Integrated ICT supports clients across Perth, Geraldton, the Mid West and the Wheatbelt, and much of the containment work — revoking access, disabling accounts, isolating network segments — can be done remotely the moment you call.

Let's Talk

If a cyber incident hit your business tomorrow, would your team know who to ring and what to unplug? Integrated ICT can help you build the plan before you need it, and we're the first call when you do.

Call us on 08 6374 8200 email hello@integratedict.com.au or get in touch, and let's talk about what your first hour looks like.

Back to All News