CyberLegion ← Back to site

What to Do If Your Business Is Hacked: A Step by Step Guide

Short answer: stay calm, contain the incident, preserve the evidence, get expert help, and meet your reporting obligations. Acting in the right order in the first hours is the difference between a contained incident and a disaster.

Here is the practical sequence for an Australian business.

In the first hour

  1. Do not panic, and do not wipe anything. Reformatting or deleting destroys the evidence you need to understand what happened.
  2. Isolate, do not power off. Disconnect affected systems from the network (unplug the cable, turn off Wi-Fi) to stop the spread, but avoid shutting them down, which can lose volatile evidence.
  3. Preserve evidence. Keep logs, note times, and do not let well meaning staff "tidy up".
  4. Reset credentials. Change passwords for affected and privileged accounts, and turn on MFA if it is not already on, ideally from a known clean device.
  5. Get help. Engage your incident response support, IT provider, or a DFIR specialist early. Speed matters.

Assess the scope

Work out what was actually affected:

You cannot contain or report what you have not scoped.

Contain and remove the threat

Recover

Meet your reporting obligations (Australia)

When in doubt about obligations, get advice quickly. Getting notification right protects you legally and reputationally.

Learn and prevent the next one

Once you are stable, run a review:

The businesses that recover well treat an incident as a lesson, not just a fire to put out.

Common mistakes to avoid

Frequently asked questions

Should we pay the ransom? Treat it as a last resort, and never without expert and legal advice. Payment does not guarantee recovery and can carry legal risk.

Do we have to tell anyone? Possibly. If personal information was exposed and serious harm is likely, the NDB scheme requires notification. Reporting to ReportCyber is always recommended.

How fast do we need to act? Immediately. The first hours shape the outcome.

Hit by an incident, or want to be ready before one?

Cyber Legion provides incident response and digital forensics for Australian businesses, plus IR planning so you are ready before it happens. If you are dealing with an incident right now, get in touch.

Ready to talk?
Get a clear picture of your security and a plan to act on it.
Get in touch
© 2026 CyberLegion. Sydney, Australia. Contact