Big companies have incident-response binders. Small businesses need one page — printed, because when ransomware hits, the beautiful digital copy of your plan is encrypted along with everything else. Here’s what belongs on that page.
The call list (fill in the numbers now)
- Security provider / IT support — the first call, day or night.
- Cyber-insurance hotline — most policies require early notification and provide approved responders.
- Bank fraud line — payment recalls sometimes work in the first hours, almost never after a day.
- Lawyer or adviser for Privacy Act notification decisions.
- ACSC ReportCyber: cyber.gov.au or 1300 CYBER1.
First moves (in order)
- Disconnect affected machines from the network — pull cable or Wi-Fi. Do not power them off; memory holds evidence.
- Move team communication off possibly-compromised email — phones or a messaging app.
- From a clean device, change the passwords that matter most: email admin, banking, remote access.
- Start a timeline note: what you saw, when, what you did. Insurers and responders will bless you for it.
- Touch nothing else until a responder advises — cleanup before investigation destroys the answers.
Decisions to make on a calm day
Who speaks for the business? What’s our stance on ransom payment (decide with advice now, not at 3am)? Which systems must come back first? Where are the backups and who holds the keys? Write the answers on the page, laminate it if you’re feeling fancy, and revisit it once a year. A one-page plan you have beats the fifty-page plan you meant to write.
Want help with this in your business?
Book a free security check with our Sydney team — plain-English advice, no obligation.
Get a Free Security Check