A customer reports that their account is not working. Staff cannot sign in, files have changed or email is behaving strangely. You may not know whether it is an attack, a fault or a stolen account.
Do not start making random changes. Record what you can see and contact the person responsible for incident response.
First steps
Contact your IT or security provider
Use a trusted phone number, not contact details shown in a suspicious message. Explain what happened, when it started and which people or systems are affected.
If the business has cyber insurance, check the policy's incident instructions and contact the insurer or approved response service early. Some policies require the insurer to approve providers or costs.
Follow advice on isolating affected devices
An incident responder may ask you to disconnect a computer from the network or disable an account. Follow their instructions.
If you cannot reach help and a device is clearly spreading damage, disconnecting its network cable or Wi-Fi may limit further harm. Do not switch off or reset equipment unless instructed, as that can remove information needed to understand the incident.
Record what happened
Write down the time, the people involved and the actions already taken. Photograph unusual messages or screens if it is safe to do so. Keep suspicious emails and do not forward them widely.
Use a safe way to communicate
If business email may be compromised, use a separate trusted channel to coordinate the response. Do not discuss sensitive incident details in a mailbox the attacker may be reading.
Avoid common mistakes
Do not install cleanup tools, delete files or use the affected system to change important passwords without professional advice. Speak with incident, legal and insurance advisers before contacting an attacker, making public statements or restoring backups.
Contain, assess and recover
The response team first needs to work out which accounts, devices and information are affected. They can then contain the attacker and preserve useful records.
Password resets should be planned and performed from a trusted device. Start with important accounts and administrator access, then remove unknown sessions, forwarding rules or recovery details as directed.
Recovery should use known clean systems and backups that have been checked. Restoring too early can bring the same problem back.
Communicate carefully
Tell staff what they need to know, including which systems to avoid and where to report new problems. Keep the message factual.
If personal information may have been exposed, get privacy or legal advice promptly. The business may need to assess its obligations under Australia's Notifiable Data Breaches scheme or other rules that apply to its industry. Do not assume every incident requires the same notification.
Prepare before an incident
Keep an incident plan with trusted phone numbers, insurer details, system owners and an offline copy of the first steps. Test backups and make sure more than one person knows how to reach the IT provider.
Download the JCPIT Cyber Incident First Hour Checklist and complete the contact fields before you need it. For an ink-light copy, download the complete two-page ink-light copy.
Current JCPIT clients should use their agreed incident contact during an active incident. The public phone number is not a promise of 24 x 7 response. To prepare before an incident, ask JCPIT about an incident-readiness review. We will confirm the required access and scope before reviewing accounts, devices, backups or response contacts.