What to do in the first hour after a breach
Incident response sounds like something with a command centre and a wall of screens. For a small business it's simpler: knowing what to do in the first hour, decided before you need it.
// overview
The plan is the point.
Incident response is just having decided in advance what happens when something goes wrong, so that the decisions get made by a calm person on a Tuesday, rather than a panicking one at 6pm on a Friday.
In practice, most small businesses don't need a document. They need three things written on one page and stuck somewhere findable: who to ring, what to do first, and where the backups are. That's a genuinely useful incident response plan.
The reason it matters is that the first hour disproportionately decides how bad this gets. Ransomware spreads. Fraudulent payments become unrecoverable. Attackers with mailbox access set up forwarding rules and go quiet. Speed is worth more than cleverness.
// the first hour
Six things, in this order.
- 01
Disconnect, don't switch off
Unplug the network cable or turn off wi-fi. That stops ransomware spreading and cuts off remote access. Don't power the machine down, useful evidence lives in memory, and for ransomware some recovery options vanish on shutdown.
- 02
Ring the bank if money moved
Before anything else technical. Banks can occasionally recall a payment that hasn't been withdrawn, and that window is measured in hours. This one call has the highest expected value of anything on the list.
- 03
Change passwords from a different device
Email first, then anything sharing that password. Use a phone or another computer, not the one you think is compromised. Turn on MFA while you're in there.
- 04
Check for mailbox rules
A standard move after an email takeover is a hidden forwarding or delete rule, so the attacker keeps reading your mail and you never see the replies. Check this even if everything else looks fine.
- 05
Work out what was actually reachable
Not what was taken, what could have been. Customer data? Payment details? Staff records? This determines whether you have a reporting obligation.
- 06
Write down what you did and when
A rough timeline in a notepad. Insurers ask, and so will we. Memory gets unreliable fast when you're stressed.
// who to tell
Reporting, in Australia.
There's a reasonable amount of confusion about who you're obliged to tell. For most small businesses it comes down to this:
- Your bank, immediately, if any money or payment details are involved
- ReportCyber at cyber.gov.au, the national reporting portal, and it also creates a police record
- Scamwatch, for scams, even where nothing was lost. It feeds the warnings that protect other people
- The OAIC, if personal information was likely exposed and serious harm is likely, under the Notifiable Data Breaches scheme
- Affected customers, if their data was involved. Early and straightforward beats late and defensive, every time
- Your insurer, many cyber policies require notification within a set window, and late notice can void a claim
// afterwards
The part everyone skips.
Once things are working again there's a strong urge to never speak of it. Resist that for one short conversation: what let this happen, and what would have caught it?
It's almost never a mystery. It's usually a missing MFA, a password reused from home, a backup nobody had tested, or someone who felt they couldn't question a payment request. Each of those has a fix costing very little, but only if somebody names it out loud.
The businesses we've seen handle this best are the ones that treated it as a process problem rather than looking for someone to blame. The ones that went looking for a culprit generally had a second incident, because the actual gap never got closed.
// questions
Good questions, straight answers.
Should we pay a ransomware demand?
The official advice is no, and we'd agree. There's no guarantee of getting your files back, it funds the next attack, and it marks you as someone who pays. This is much easier advice to follow if you have a tested backup, which is the real argument for having one.
How long does recovery take?
With a working, tested backup: often a day or two. Without one: weeks, sometimes never for some data. The gap between those two outcomes is entirely determined by decisions made before the incident.
Do we have to tell customers?
If their personal information was likely exposed and serious harm is likely, yes, that's the Notifiable Data Breaches scheme. Beyond the legal test, telling people early tends to go far better than having them find out later.
Can you help if we're in the middle of one right now?
Yes. Ring (07) 4592 8091. If it's ransomware, disconnect the affected machines from the network first and leave them running. We'll work out what's contained and what needs rebuilding.
$ inspyred --book-a-callout
Got a question about this?
Ask a human.
Give us a call, text or email, we're available by appointment, 7 days a week. A rough idea on the phone is always free.