Print it, fill in the contacts, and keep a copy where you can find it if systems are down.
Organisation: [Name] · Last updated: [date]
Key contacts (fill in NOW, not during an incident)
First hour
- Don't panic, don't pay. Ransom demands and scam "fees" are negotiable-by-ignoring; get advice first.
- Contain. Disconnect affected devices from the network/Wi-Fi. Don't turn them off (evidence lives in memory).
- Change passwords for affected accounts from a clean device — email first, then banking, then admin accounts.
- Call your bank immediately if money was sent or bank details were changed on an invoice.
- Write down what happened while it's fresh: what was clicked, when, on what device, what you saw.
First day
- Call your IT support/MSP and your cyber insurer (they often have their own response team — call before spending money).
- Report it: ReportCyber at cyber.gov.au (and Scamwatch for scams). If money is involved, this can help recovery.
- Check email rules. Attackers add hidden forwarding rules — check email settings for rules you didn't create.
- Brief your team. Tell staff what happened in plain terms and what to watch for (follow-up scams impersonating you are common).
First week
- Assess what data was exposed. Personal information involved? You may have obligations under the Notifiable Data Breaches scheme — see oaic.gov.au.
- Tell affected people honestly and early if their data was involved.
- Close the hole. Patch, enable MFA everywhere, remove unused accounts.
- Debrief without blame. What made this possible? What nearly stopped it? Fix the system, not the person.