Gridware Logo

What to Do in the First 24 Hours After a Cyber Attack

By Ahmed Khanji Updated 1 May 2026 7 min read

in 𝕏
What to Do in the First 24 Hours After a Cyber Attack

The First 30 Minutes: Don’t Panic, Don’t Wipe

The most common costly mistake in early-stage response: IT teams immediately reimage affected machines or reset all passwords without first taking forensic images. Once you wipe a machine, the forensic evidence on it is gone. Courts, insurers, and regulators require documented timelines. You can’t reconstruct them from reimaged systems.

In the first 30 minutes, focus on four things.

  • Activate your incident response plan. If you don’t have one, start a manual log of everything that happens from this point forward.
  • Confirm this is a security incident, not a system failure. Don’t trigger a full incident response for a failed hard drive. Equally, don’t assume unusual behaviour is a system failure when it might be an active attacker.
  • Identify the incident commander and notify them. Every decision from this point needs to go through one person with authority.
  • Do not wipe, reimage, or shut down affected systems before taking forensic images. Preserve the state of every affected system as it is right now.

Containment: Hours 1 to 6

Once you’ve confirmed it’s a security incident, the priority is stopping the spread. Containment before eradication.

Isolate affected systems from the broader network. This means network segmentation: taking affected devices off the network without shutting them down entirely, where possible. Shutting a system down can destroy volatile memory evidence.

Disable compromised accounts. Disable, not delete. Deleting accounts removes log data you’ll need later. Disabling stops the attacker using those credentials while preserving the audit trail.

Identify the initial access vector if you can. Was it a phishing email? An exposed RDP port? A compromised supplier credential? Understanding how the attacker got in tells you where else they might have gone, and whether they’ve established additional persistence.

Call your incident response provider or retainer. If you have a managed security provider with a defined incident response capability, this is when you activate it. The earlier they’re engaged, the more they can do.

Notify your cyber insurer. Most cyber insurance policies require notification within a defined window after discovery, often 24 to 72 hours. Missing that window can affect your ability to make a claim. Check your policy now, before an incident happens, so you know the requirement.

Who to Call and When

Australian businesses have specific notification obligations and reporting channels. These need to be in your plan before an incident, not figured out mid-crisis.

ASD/ACSC: Call 1300 CYBER1 (1300 292 371). Available 24/7. Reporting is voluntary for most businesses but strongly recommended. The ACSC provides free technical assistance during incidents. Reporting also contributes to the national threat picture. For critical infrastructure operators, reporting is mandatory.

OAIC: If personal information has been or is likely to have been accessed without authorisation, and serious harm is likely, you have 30 days to assess and notify under the Notifiable Data Breaches scheme. This is not 30 days before you start assessing. It’s 30 days to complete the assessment and notify. Start the assessment immediately.

Ransomware payment reporting: From 30 May 2025, businesses with annual turnover above $3 million must report ransomware payments to the ASD within 72 hours. If you’re considering paying or have paid, this obligation applies.

Legal counsel: Get them involved early. Communications about the incident may be subject to legal privilege, but only if counsel is involved in the right way from the start. Your lawyers will also guide decisions about customer and regulator notification.

Board or executive team: Prepare a one-page factual summary: what happened, what’s been confirmed, what’s being done. Don’t present speculation or assumptions. Executives need accurate information to make decisions, not a technical briefing.

Evidence Preservation

Courts, insurers, and regulators increasingly require documented timelines. An undocumented response is treated as an inadequate response.

Take forensic images of affected systems before any remediation. This creates a point-in-time record of the system state that can be analysed independently of the live environment.

Preserve system logs. Many attacks target logs as part of the intrusion, to remove evidence. Check your log retention settings immediately: are logs being stored centrally, away from the affected environment? How long are they retained? Gaps in logs will be scrutinised in any subsequent regulatory or legal process.

Create and maintain a documented incident timeline from the moment of discovery. Record every decision made, who made it, and when. This record becomes your primary evidence in insurance claims, regulatory responses, and any litigation.

Hours 6 to 24: Eradication and Communication

Once contained, shift focus to eradication and stakeholder communication.

Remove the threat from affected systems. A full reimage is often appropriate, but don’t assume it’s sufficient without first understanding the initial access vector. If the attacker has established persistence elsewhere in the network, reimaging the initial victim machine doesn’t remove them.

Prepare external communications carefully. Be honest and factual. Don’t speculate about what happened or what data was affected until you have confirmed information. Incorrect statements in early communications create problems later, particularly with regulators.

Update the incident log continuously through this phase. Everything that happens needs to be documented.

Start recovery planning, but don’t restore from backups until you’ve confirmed the backups are clean and the initial attack vector has been closed. Restoring from a backup that’s also infected returns you to the same problem.

Conclusion

The decisions made in the first few hours of an incident determine how bad the outcome is. Having a defined escalation path, a qualified response team to call, and documented procedures makes a measurable difference. Gridware offers incident response retainers so businesses have that capability in place before they need it.

Frequently asked questions

What should I do immediately after discovering a cyber attack?

Activate your incident response plan and confirm who the incident commander is. Verify it’s a genuine security incident rather than a system failure. Document everything from the moment of discovery. Do not wipe or reimage affected systems before preserving forensic images. Start your incident log and keep it running throughout.

Should I shut down my systems if I’ve been hacked?

Not immediately, and not before preserving forensic images first. Shutting down too quickly destroys volatile memory evidence that may be the only record of what the attacker did. Isolate affected systems from the network to stop the spread, but try to preserve system state before powering anything off. If you’re unsure, call your incident response provider before taking action.

Do I have to report a cyber attack to the government in Australia?

Reporting to the ACSC (1300 CYBER1) is voluntary for most businesses but strongly recommended. If personal information was accessed and serious harm is likely, you have NDB reporting obligations to the OAIC. Critical infrastructure operators have mandatory obligations under the SOCI Act. Businesses with $3M+ turnover must report ransomware payments to the ASD within 72 hours from May 2025.

When do I need to notify the OAIC after a data breach?

Under the Notifiable Data Breaches scheme, if a breach is likely to result in serious harm to affected individuals, you must notify the OAIC and those individuals. You have 30 days from becoming aware of a suspected breach to complete your assessment. Start the assessment immediately rather than treating the 30 days as a waiting period. Check oaic.gov.au for current requirements.

What is the ACSC hotline number?

1300 CYBER1, which is 1300 292 371. Available 24 hours a day, 7 days a week. The ACSC provides free technical assistance during cyber incidents and guidance on response and recovery. Reporting to them also helps build the national picture of the threat environment.

How long does it take to recover from a cyber attack?

It varies widely depending on the type of attack, the scope of the compromise, and the quality of your preparation. A contained ransomware incident in a well-prepared organisation with clean, tested backups might take days. A full network compromise that spread undetected for weeks can take months. Preparation, particularly having current backups and a tested incident response plan, is the biggest factor in recovery time.

Should I pay a ransom?

The Australian Government and the ACSC advise against paying ransoms. Payment doesn’t guarantee recovery of your data, funds further criminal activity, and may not result in a working decryption key. From May 2025, ransomware payments above the reporting threshold must be reported to the ASD within 72 hours regardless of whether you pay. Before making any decision, contact the ACSC and your legal counsel.

Ahmed Khanji

Ahmed Khanji

CEO, Gridware

Ahmed Khanji is the CEO of Gridware, a leading cybersecurity consultancy based in Sydney, Australia. He is recognised for his insights into offensive security and emerging technologies such as blockchain, and often contributes to broader cybersecurity conversations across the country. With an extensive background as a security advisor to major Australian enterprises, Ahmed helps organisations navigate the evolving threat landscape with clarity and confidence.