Cyber Incident Response Checklist

Print it, fill in the contacts, and keep a copy where you can find it if systems are down.
Organisation: [Name] · Last updated: [date]

Key contacts (fill in NOW, not during an incident)

RoleNamePhone
Incident lead  
IT support / MSP  
Bank (fraud line)  
Cyber insurer + policy #  
Australian Cyber Security Hotline1300 292 371 (24/7)

First hour

  1. Don't panic, don't pay. Ransom demands and scam "fees" are negotiable-by-ignoring; get advice first.
  2. Contain. Disconnect affected devices from the network/Wi-Fi. Don't turn them off (evidence lives in memory).
  3. Change passwords for affected accounts from a clean device — email first, then banking, then admin accounts.
  4. Call your bank immediately if money was sent or bank details were changed on an invoice.
  5. Write down what happened while it's fresh: what was clicked, when, on what device, what you saw.

First day

  1. Call your IT support/MSP and your cyber insurer (they often have their own response team — call before spending money).
  2. Report it: ReportCyber at cyber.gov.au (and Scamwatch for scams). If money is involved, this can help recovery.
  3. Check email rules. Attackers add hidden forwarding rules — check email settings for rules you didn't create.
  4. Brief your team. Tell staff what happened in plain terms and what to watch for (follow-up scams impersonating you are common).

First week

  1. Assess what data was exposed. Personal information involved? You may have obligations under the Notifiable Data Breaches scheme — see oaic.gov.au.
  2. Tell affected people honestly and early if their data was involved.
  3. Close the hole. Patch, enable MFA everywhere, remove unused accounts.
  4. Debrief without blame. What made this possible? What nearly stopped it? Fix the system, not the person.