A plain-English emergency guide for Gold Coast business owners. No jargon — just the steps that protect your business in the first hour, in order.
Quick answer
Disconnect affected machines from the network (unplug the cable, kill the WiFi) — but do not switch them off or wipe them; they hold the evidence. Change critical passwords from a known-clean device, starting with email and banking. Call your IT provider and your bank, write down what you saw and when, and don’t communicate with the attacker before getting advice. The full hour, step by step, is below.
Panic wastes the hour; a sequence uses it. Work through these in order — every step assumes the previous one is done.
Disconnect affected machines from the network — pull the Ethernet cable, turn off WiFi, or if you can’t tell which machines are affected, unplug the office switch or router. Do not power machines off and do not start deleting things: memory and logs are the evidence an investigator needs, and a machine that is mid-encryption is a question for a professional, not a power button.
What made you notice — a ransom note, a strange email rule, money moved, files renamed? Which machines and which accounts? Is the file server involved? Two minutes of notes now (photos of screens are fine) shape the entire response. Check whether your backups are isolated from the network — if they’re on a connected drive, disconnect it immediately.
From a device you trust — a phone on mobile data qualifies — change passwords in this order: email first (it resets everything else), then banking, then Microsoft 365 / Google Workspace admin, then anything financial. Turn on multi-factor authentication anywhere it’s off. Sign out all sessions where the option exists.
Call your IT provider — ours is 07 3041 8993, answered 24/7 — and describe what you scoped. If money moved or banking details were exposed, call your bank’s fraud line now; recovery odds drop by the hour. If you hold cyber insurance, notify them early — many policies require it and some provide their own response team.
Write the timeline while it’s fresh: what happened, when, what you did. Report via ReportCyber at cyber.gov.au — it routes to the right agency and creates a reference your bank and insurer will ask for. If personal information may have been accessed, flag the Notifiable Data Breaches assessment with whoever advises you — it has legal deadlines. Do not email the attacker, and do not announce anything publicly yet.
Don’t wipe or reinstall anything yet — you’re destroying evidence and possibly your only map of what was taken. Don’t pay or negotiate before advice — see the FAQ below. Don’t log into accounts from affected machines — you may be handing over the new passwords too. Don’t assume it’s over when things look normal — attackers commonly leave a second way in. Don’t keep it secret from staff — they need to know not to click, not to use affected systems, and what to tell callers.
The first hour is containment; recovery is days. A proper response covers eradication, restoring from clean backups, a root-cause review, and any notifications your obligations require — AFS licensees have specific ASIC expectations. When the dust settles, the honest question is which basic controls were missing. Our cybersecurity risk assessment maps your setup against the Essential Eight, and our managed security services include the 24/7 monitoring that catches the next attempt at minute zero instead of day three.
Get professional advice before deciding anything. The Australian Cyber Security Centre advises against paying — payment funds further attacks, does not guarantee recovery, and may create legal exposure. Talk to your incident responder, your insurer and, where relevant, your lawyer before any contact with the attacker.
Often, yes. Report to the ACSC via ReportCyber (cyber.gov.au). If personal information was likely accessed, the Notifiable Data Breaches scheme may require notifying the OAIC and affected individuals. AFS licensees have ASIC obligations on top. Report obligations have deadlines — start the clock assessment early.
After recovery: a proper root-cause review, then the boring controls that actually work — MFA everywhere, patched systems, tested backups, staff phishing awareness and restricted admin rights. That set maps to the ASD Essential Eight, which is where our cybersecurity risk assessments start.
Phones are answered 24/7. For everything short of an emergency, book a callback and we’ll respond within 4 business hours.
Last updated: July 2026 · Reviewed by the bcom ICT team