●  Melbourne-based · Local support you can actually reach
← All insights
Cyber security

The first hour after a breach decides how bad it gets

Someone notices something off. A mailbox is sending emails nobody wrote. A shared drive is full of files renamed to gibberish. A supplier rings to ask why you emailed them new bank details this morning.

That moment is the one that counts. Most businesses spend their security budget on stopping an attack and almost no thought on the hour after one lands. But the gap between “something’s wrong” and “we’ve contained it” is where a small problem turns into a closed-for-a-week problem. The Australian Signals Directorate now fields a cybercrime report about once every six minutes (ASD Annual Cyber Threat Report 2024 to 25). Plenty of those started as something small that nobody acted on quickly.

Here’s what a calm, fast first hour actually looks like.

Contain it, don’t destroy it

The instinct is to make the bad thing go away. Resist it.

  • Disconnect the affected device from the network. Unplug the network cable, turn off the Wi-Fi. This stops ransomware spreading and cuts an attacker’s live access.
  • Don’t power it off, wipe it, or factory reset it. A running machine holds evidence (in memory and in logs) that tells you how far this went and what was taken. Wiping it blinds you.
  • Don’t reply, and don’t pay. If there’s a ransom note or a “your account is locked” message, leave it. Replying tells the attacker someone’s home.

Isolating one machine in the first ten minutes is often the single highest-value thing you can do.

Work from a clean device

Whatever you do next, don’t do it on the compromised computer.

  • From a phone or a different machine, reset the passwords on the affected accounts, starting with email and anything with admin rights.
  • Turn on multi-factor authentication if it isn’t already, and sign out all active sessions. An attacker with a stolen password is locked out the moment you do both.
  • If it’s a business email compromise, check the mailbox rules. Attackers quietly add a rule that auto-deletes or forwards messages so you don’t see their replies to your clients. Delete anything you didn’t create.

Tell the right people, in the right order

  • Start your incident plan and call your IT partner. This is the moment a managed relationship earns its keep. Someone who already knows your setup can move while you’re still finding the password to the firewall.
  • Write down what you see. Screenshots, the time you noticed it, the message on screen. Five minutes of notes now saves a forensic headache later.
  • Warn anyone in the payment chain. If there’s any sign of redirected invoices or fake bank details, ring your clients and suppliers before they pay. A phone call beats an email here, because the email channel may be the thing that’s compromised.
  • Know your reporting duties. If personal information has likely been exposed and serious harm is likely, the Notifiable Data Breaches scheme can require you to notify the people affected and the OAIC. For a law firm there may be obligations to clients and the regulator on top of that. This isn’t legal advice, but it’s a clock you want to start on purpose, not discover late.

The work that makes the hour easy

None of the above works if you improvise it. The firms that recover in a day, not a fortnight, did three boring things beforehand:

  • A one-page plan. Who to call, in what order, where the backups are, who can authorise what. Printed, because your systems might be the thing that’s down.
  • Backups that are tested and offline. A backup an attacker can reach and encrypt is not a backup. The only one that counts is the one you’ve actually restored from in a drill.
  • A current list of what you have. Accounts, devices, who has access to what. You can’t isolate or lock down what you can’t see.

The takeaway

You can’t promise you’ll never be hit. Nobody can. What you can decide, in advance, is how the first hour goes. A rehearsed response turns a breach from a business-ending event into a bad day you talk about later.

If you’ve never sat down and written what your first hour looks like, that’s the gap worth closing this month.

Want a plan before you need one?

Book a free, no-obligation security assessment. In about 30 minutes you'll know where you stand and exactly what to do in the first hour if something goes wrong.

Actively managed IT

Want your protection this clear?

Every article here comes from how we look after Melbourne businesses every day. See where your business stands, and what “actively managed” really feels like.

Book a free assessment

Or explore cyber security in Melbourne.