IT & Technology Solutions11 September 20266 min read

What to Do Immediately After a Data Breach: A Step-by-Step Incident Response Plan

You’ve just found out your business has been breached.

ARAlex RiveraCSPRO insights
Data Breach response plan on a laptop

You’ve just found out your business has been breached. Maybe it’s a phishing email that got a click, a laptop that went missing, or a call from a customer asking why their details are on the dark web. Whatever triggered it, the next hour matters more than almost any other decision you’ll make this year.

Contain the breach first, assess what was accessed, work out whether you’re legally required to notify the OAIC and affected individuals within 30 days, notify the right people in the right order, then fix the hole and review what went wrong. Below is the full plan, broken into the order you should do it in, not the order a textbook would list it.

What Counts as a Data Breach?

A data breach is any unauthorised access to, disclosure of, or loss of personal or business information your organisation holds. That covers a hacked email account, a stolen laptop, a misdirected email with a client list attached, a ransomware attack, or an employee accessing records they shouldn’t have. Under Australia’s Privacy Act 1988, some of these become an eligible data breach likely to cause serious harm, which triggers a legal duty to notify.

The First 24 Hours: Immediate Response Checklist

If you only read one section, read this one:

  1. Contain it. Disconnect affected systems from the network; don’t switch them off.
  2. Preserve evidence. Note the time you discovered it and who found it.
  3. Loop in your IT/security team or provider immediately.
  4. Restrict access to the affected systems and data.
  5. Start a written incident log of every action, every timestamp.
  6. Assess what data and how many people are affected.
  7. Determine if it’s notifiable under the NDB scheme (30-day assessment clock starts now).
  8. Notify the OAIC, affected individuals, and internal stakeholders as required.
  9. Remediate the vulnerability that caused it.
  10. Review the incident and update your response plan.

Step 1: Contain the Breach

Containment is about stopping the bleeding without destroying the evidence you’ll need later. Disconnect compromised devices from the network rather than powering them off shutting a machine down can wipe the memory-based evidence (RAM) that forensic investigators need to work out how the attacker got in. Reset passwords for any accounts that may have been compromised, and revoke active sessions and API keys where you can. If it’s a lost or stolen device, remote-wipe it if you have mobile device management in place.

Short-term containment is about buying time; long-term containment is patching the vulnerability and closing the access point- comes in Step 6.

Step 2: Assess the Scope and Severity

Once the immediate danger is contained, work out:

  • What type of data was involved (names, financial details, health information, credentials)?
  • How many individuals are affected?
  • Was the data actually accessed, or just exposed?
  • Is the data encrypted, and was the encryption switched on, not just written into a policy document?
  • How did the attacker get in, and is that access point still open?

This is where a lot of businesses without an incident response plan lose days deciding who’s allowed to make these calls. Having a named person (or an external partner) authorised to run this assessment before an incident happens saves precious hours during one.

Step 3: Work Out If It’s a Notifiable Data Breach

This is the step most Australian businesses get wrong under pressure, so it’s worth slowing down for.

Under Part IIIC of the Privacy Act 1988, the Notifiable Data Breaches (NDB) scheme requires most APP entities, Australian Government agencies, and organisations with an annual turnover over $3 million, plus certain smaller entities that handle particular data types like tax file numbers, to notify when an eligible data breach occurs: unauthorised access to or disclosure of personal information that a reasonable person would conclude is likely to result in serious harm.

NDB Scheme, At a Glance

Detail

Who it applies to

APP entities: agencies and businesses with turnover over $3M, plus certain carved-in entities (e.g. TFN recipients, health service providers)

Assessment deadline

30 calendar days from when you first suspect an eligible breach - treated as a hard maximum, not a target

Notification deadline

“As soon as practicable” once you know it’s an eligible breach - don’t wait out the 30 days if you already know

Who you notify

The OAIC, plus affected individuals (or a public statement if individual notice isn’t practicable)

Maximum penalty

Up to $50 million, three times the benefit obtained, or 30% of adjusted turnover - whichever is greater, for serious or repeated breaches

Step 4: Notify the OAIC and Affected Individuals

Once you’ve confirmed it’s an eligible data breach, you have three main options for notifying affected individuals:

  1. Notify each individual whose information was involved.
  2. Notify only those individuals at likely risk of serious harm.
  3. Where neither is practicable, publish a statement on your website and take reasonable steps to publicise it.

Your statement to the OAIC and to individuals needs to explain what happened, what information was involved, and what steps you’re taking both to contain the breach and to help affected people protect themselves (for example, recommending a password reset or a credit alert).

Step 5: Notify Everyone Else Who Needs to Know

Beyond the OAIC, work through this list depending on the nature of the breach:

  • Your cyber insurer - many policies require notification within a specific window or coverage can be affected.
  • Your bank, if payment or banking details were exposed.
  • Law enforcement, particularly for ransomware, extortion, or suspected criminal activity - report to the Australian Cyber Security Centre (ACSC) via ReportCyber.
  • Your legal counsel, especially if the breach involves regulated data (health records, financial data) or you’re unsure about your notification obligations.
  • Staff and internal stakeholders, so everyone is given the same message to customers and media.
  • Key clients or partners, if their data or systems were connected to yours.

If the incident involves a ransomware payment and your business meets the turnover threshold under the Cyber Security Act 2024, there’s a separate obligation to report the payment within 72 hours; this runs alongside, not instead of your NDB obligations.

Step 6: Eradicate the Threat and Recover Your Systems

Containment stops the immediate spread; eradication removes the attacker’s foothold for good. This typically means patching the exploited vulnerability, rebuilding compromised systems from clean backups rather than simply cleaning infected ones, rotating every credential the attacker may have touched, and re-scanning your environment before bringing systems back online. Rushing this step is one of the most common causes of repeat breaches: businesses restore from backup, breathe a sigh of relief, and don’t realise the same gap is still open.

Step 7: Review, Report and Strengthen Your Defences

Once the dust settles, run a proper post-incident review: how did the attacker get in, how long did it take to detect, what worked in your response and what didn’t, and what needs to change. Update your incident response plan with what you learned, and consider whether ongoing monitoring, multi-factor authentication, staff phishing training, or a managed security service would have caught this earlier.

How CSPRO Can Help

If you’re reading this because it’s already happening, CSPRO’s incident response and managed cybersecurity teams can help you contain, assess, and notify correctly; and if you’re reading this to prepare, we can build an incident response plan, deploy monitoring and managed firewall protection, and run staff training so a breach is far less likely to happen in the first place. Either way, you shouldn’t be figuring this out alone at 11 pm with a spreadsheet.

Experiencing a breach right now? Contact CSPRO’s emergency IT support team immediately for urgent incident response assistance.

Conclusion

A data breach is a bad day, not necessarily a business-ending one, but only if you move through containment, assessment, notification, and recovery in the right order, and fast. Build the plan before you need it, know your NDB obligations cold, and have someone on call who’s done this before.

Need help right now, or want to get a response plan in place before you do? Get in touch with CSPro’s cybersecurity team today.

TaggedData BreachIT Support

Frequently asked questions

Contain it: disconnect affected systems from the network without powering them off, so you don’t destroy forensic evidence, then loop in your IT or security provider straight away.

Common signs include unusual login activity, staff or customers reporting phishing emails impersonating your business, ransomware messages, unexplained account lockouts, or a security tool flagging unauthorised access.

You have up to 30 calendar days to assess whether a suspected breach is an eligible data breach, and you must notify the OAIC and affected individuals as soon as practicable once you know it is; you shouldn’t wait for the full 30 days if you already know.

The Notifiable Data Breaches scheme, under Part IIIC of the Privacy Act 1988, requires most APP entities to notify the OAIC and affected individuals when an eligible data breach is likely to cause serious harm.

Generally, the NDB scheme applies to organisations with annual turnover over $3 million, plus certain smaller entities handling specific data types like tax file numbers or health records. Removing the small business exemption entirely has been proposed but is not yet law.

Keep reading

More practical guidance

All articles