Skip to main content

It’s Not About If, It’s About What You Do Next

Most cybersecurity advice focuses on prevention. This article is about what happens after, because how you respond in the first hours and days determines whether a breach becomes a manageable incident or a business-ending event.

The numbers are clear. In Australia, ASD received over 84,700 cybercrime reports in FY2024–25, one every six minutes. The average cost of cybercrime for Australian small businesses rose 14% to $56,600. Globally, a breach costs businesses with fewer than 500 employees an average of $3.31 million.

Yet only 34% of SMBs have a formal incident response plan.

Here’s what to do if it happens to you.

Step 1: Identify What Happened

Before fixing anything, understand what you’re dealing with.

  • What systems are affected?
  • What type of attack, ransomware, phishing, data exposure?
  • Is it still active?
  • What data may have been accessed?

Critically, preserve evidence from the moment an incident is suspected. Do not wipe or restart systems before forensic data has been collected. Without proper logs and monitoring, you’re working blind.

Step 2: Contain the Threat

Stop the breach from spreading. Act fast, but don’t cause more damage.

  • Isolate affected devices from the network (disconnect, don’t power off)
  • Disable compromised accounts or reset credentials
  • Block suspicious external connections
  • Segment network access to protect unaffected systems

Short-term containment buys you time. Long-term containment, adjusting firewall rules or shutting down specific services, protects the rest of your environment while you investigate.

Step 3: Eradicate and Clean

Remove the threat completely before reconnecting anything.

  • Remove malicious code, backdoors, or unauthorised access
  • Patch the vulnerability that was exploited
  • Reset all potentially compromised credentials
  • Scan all systems to confirm they’re clean

Rushing this step is one of the most common mistakes. If the attacker’s access isn’t fully removed, they can re-enter through the same path.

Step 4: Recover and Restore

Getting systems back online safely, not just quickly.

  • Restore from verified, clean backups, not from compromised systems
  • Validate data integrity before resuming operations
  • Monitor closely for re-infection in the following weeks
  • Document everything, what was restored, when, and by whom

Here’s the painful reality: 19% of small businesses hit by cyber incidents had no backup or recovery plan in place. Average downtime after a breach is 21 days.

Businesses that recover fastest are those with tested backups and a documented process before the incident happens.

Step 5: Notify, Your Legal Obligation in Australia

If your business is covered by the Privacy Act 1988, you have legal obligations under the Notifiable Data Breaches (NDB) scheme.

When must you notify? If a breach involving personal information is likely to result in serious harm, you must notify the OAIC and affected individuals.

The 30-day clock starts from the moment your organisation suspects a breach may have occurred, not from when forensic analysis confirms it. If you can’t determine the breach status after 30 days, you must notify anyway.

Your notification must include: what happened, what data was involved, what you’ve done to contain it, and what steps affected individuals should take.

Penalties for serious breaches can reach up to $50 million AUD, three times the benefit obtained, or 30% of adjusted turnover.

Step 6: Learn and Improve

Every incident should make your business stronger.

Conduct a post-incident review:

  • How did the attacker get in?
  • How quickly was it detected?
  • Did the response plan work, or were there gaps?
  • What needs to change in tools, processes, or training?

The NIST framework treats incident response as a continuous cycle, prepare, respond, recover, improve, repeat. Update your plan. Train your team. Test your backups.

The Real Cost of Not Having a Plan

StatSource
$3.31M avg breach cost for businesses <500 employeesIBM
$1.49M saved withIBM
21 days avg downtime after a breachWorldmetrics
88% of SMB breaches involve ransomwareVerizon DBIR 2025
$56,600 avg cost per AU small businessASD

Organisations with a formal incident response plan save $1.49 million per breach compared to those without one.

What Every SMB Should Have Ready

At minimum, your plan should cover:

  1. Response team and roles, who leads, who communicates, who handles IT
  2. Contact list, IT provider, cyber insurer, legal counsel, OAIC
  3. Containment procedures, step-by-step for ransomware, phishing, data exposure
  4. Recovery process, backup restoration, validation, monitoring
  5. Communication plan, internal, client, and regulatory notifications
  6. Post-incident review, lessons learned and plan updates

A plan that hasn’t been tested is a plan that won’t work under pressure.


How Motionwave Helps

Most SMBs don’t have a dedicated security team, and they shouldn’t need one. Motionwave provides proactive monitoring, Microsoft 365 security configuration, tested backup and recovery, incident response support, and ongoing security assessments aligned with the Essential Eight.

The goal is simple: when something happens, your business can respond, recover, and keep operating.

Don’t wait for a breach to find out if you’re ready.

Chat us now
Before You Go, Is Your Business Protected?

Get a FREE IT Security & Microsoft 365 Health Check from Motionwave

Book Our Free Assessment