What to do if your business is hacked: A Brisbane business recovery guide
Key Takeaways
A hacked business needs a calm, ordered response. The first priority is to contain the incident, protect evidence, understand what happened and restore essential work without reopening the same weakness.
- Isolate affected systems carefully and avoid destroying evidence.
- Secure accounts, sessions, email rules and administrator access.
- Assess whether personal information may have been accessed.
- Restore only from clean, verified backups and prioritise essential services.
- Strengthen security and practise your response plan across Brisbane and South East Queensland.
1. Contain the attack without making things worse
When a Brisbane business discovers suspicious activity, the first few decisions can limit or increase the damage. Do not allow staff to keep using a device that may be infected, but do not rush into actions that erase useful evidence. Nominate one person to coordinate decisions and keep a written record from the beginning. If you are unsure, get experienced help before making broad changes.
Disconnect affected devices and systems safely
Remove a suspected computer from wired and wireless networks, but leave it powered on if a specialist may need to examine it. If ransomware is spreading, disconnect shared drives and other visibly affected devices as quickly as you can. Avoid unplugging every system automatically, because that may interrupt essential services and make the incident harder to understand.
Start with the smallest safe boundary. Record the device name, user, time and visible symptoms, then tell staff not to reconnect it. A Brisbane IT provider can help separate affected equipment while keeping unaffected operations available.
Disable compromised accounts and active sessions
If an account is sending unusual messages or showing unfamiliar activity, suspend it and revoke active sessions. Change the password from a known-clean device, especially for email, Microsoft 365, remote access and administrator accounts. Do not reuse an old password or send new credentials through the compromised mailbox.
Check whether the attacker created a second method of access, such as an application consent, recovery address or registered device. Resetting one password alone may not remove an active session or hidden access path.
Avoid deleting files, wiping devices or negotiating with attackers
A ransom note can create pressure to act immediately, but payment does not guarantee recovery or deletion of stolen information. Do not wipe computers, delete suspicious emails or run cleanup tools until evidence has been preserved where possible. Take photographs of messages and keep copies of relevant alerts, logs and correspondence.
The safest response is usually controlled and documented. Preserve evidence first so your technical and legal advisers can assess the incident properly. Never contact an attacker from an account that may already be compromised.
Decide when to shut down critical services
Some services may need to be stopped to prevent further loss. Others, such as phones, point-of-sale systems, clinical tools or customer portals, may be safer when isolated and kept available. Base the decision on the likely spread, the sensitivity of the system and the effect on customers and staff.
Use a simple decision owner and escalation path. If the incident affects multiple sites, payment systems or safety-related operations, seek urgent assistance rather than making disconnected decisions across the business.
2. Identify what has been compromised
Containment gives you breathing space, but you still need to establish the scope. A suspicious login does not always mean every server was breached, while a single compromised mailbox can expose invoices, customer details and reset links. Work from evidence rather than assumptions. Keep the investigation focused on what was accessed, changed, copied or made unavailable.
![]()
Check email, Microsoft 365 and administrator accounts
Begin with the accounts that control other accounts. Review sign-in activity, mailbox access, administrator roles, audit events and recent password resets. Pay particular attention to unusual locations, unfamiliar devices and activity outside normal working hours.
For Microsoft 365 environments, review sharing settings and application permissions as well as user accounts. Staff should report unexpected password prompts, sent messages or files shared without their knowledge. Practical IT insights for Brisbane businesses can help shape routine checks, but an active incident needs a direct investigation.
Look for unusual logins, forwarding rules and new users
Attackers often try to maintain access quietly after the first compromise. Look for new users, changed permissions, mailbox forwarding, transport rules, unfamiliar recovery details and newly registered devices. Compare these changes with your staff and supplier records.
Ask department managers whether customers received unexpected invoices or whether files suddenly became unavailable. Small clues can connect an email compromise with a wider business intrusion.
Assess affected computers, servers, websites and cloud systems
Create an asset list covering laptops, desktops, servers, network equipment, websites, domains, cloud applications and backup platforms. Mark each item as confirmed affected, possibly affected or checked with no signs found. Include devices used remotely and systems managed by external providers.
Do not overlook the website or domain account. Changes to DNS, hosting, email settings or administrator access may redirect visitors or intercept messages even when office computers appear normal.
Record the timeline, alerts and evidence of the incident
Write down when the first warning appeared, who saw it, which actions were taken and what remains unavailable. Preserve security alerts, email headers, access logs, ransom notes, screenshots and relevant conversations. Keep the record factual and avoid guessing about the attacker or the amount of data involved.
A timeline helps technical advisers work faster and gives legal and insurance advisers a clearer basis for decisions. It also becomes valuable when you later update your incident response plan.
3. Protect your data and meet Australian obligations
A hacked system becomes a privacy issue when personal or sensitive information may have been exposed. Customer records, health information, identification documents, employee files and financial details all require careful handling. Australian businesses should involve legal advice early rather than relying on an informal internal assessment. Keep communications accurate, limited to confirmed facts and consistent across channels.
Determine whether personal or sensitive information was accessed
List the information held by each affected system and consider whether it was viewed, copied, changed or made inaccessible. Check audit logs, unusual downloads, shared links and database activity where those records exist. If evidence is incomplete, document the uncertainty instead of claiming that no data was taken.
Consider contractual obligations as well as privacy responsibilities. Businesses in legal, healthcare, education and professional services often handle information that could cause serious harm if misused. OutTask supports businesses across these sectors through industry-focused IT services, while legal advice should guide notification decisions.
Understand when the Notifiable Data Breaches scheme may apply
The Australian Notifiable Data Breaches scheme may apply when an eligible data breach is likely to result in serious harm to affected individuals. Whether notification is required depends on the facts, the information involved and the steps taken to contain or remedy the breach.
Ask your privacy or legal adviser to assess the incident and keep a clear record of that assessment. The Office of the Australian Information Commissioner is the relevant Australian privacy regulator, but this article is general guidance, not legal advice.
Contact your cyber insurer, legal adviser and relevant authorities
Notify your insurer according to your policy and follow any conditions about approved investigators, communications or payment decisions. Contact legal counsel before sending detailed statements to customers or suppliers. Depending on the incident, you may also need to report criminal activity or seek guidance from relevant Australian authorities.
Do not delay simply because the investigation is incomplete. Early advice can protect your options and help coordinate technical, privacy, insurance and operational decisions.
Prepare clear communications for staff, customers and suppliers
Staff need short instructions about what to stop using, how to report suspicious messages and where legitimate updates will come from. Customers and suppliers may need to know whether invoices, contact details or shared files could be affected. Avoid speculation, blame or technical detail that could confuse people.
Nominate one communications lead and use a known, trusted channel. Consistent updates help prevent a second wave of phishing that exploits the original incident.
4. Restore your business operations securely
Recovery is more than turning systems back on. Every restored account, device and backup should be checked so the attacker is not quietly returned to the environment. Start with the processes that keep customers safe and staff productive. A staged recovery is often slower at first but reduces the chance of repeated disruption.
![]()
Reset passwords and enforce multi-factor authentication
Reset credentials in an order that protects administrator and recovery accounts first, followed by email, cloud applications, remote access and ordinary users. Enforce multi-factor authentication wherever it is available, especially for privileged access. Check that recovery phone numbers, alternate email addresses and authentication devices belong to the right people.
Use unique passwords and do not share administrator credentials between staff. Document each reset so an account is not accidentally missed.
Remove malware, backdoors and unauthorised access
A clean-up should identify how the attacker entered and whether they left scheduled tasks, new accounts, remote tools or altered security settings. Rebuild severely affected devices where appropriate instead of assuming that deleting one suspicious file makes them safe. Patch the weakness before reconnecting the system.
Have a qualified technician verify the environment. Testing a restored service from an isolated network can reveal problems before they affect the whole office.
Restore clean data from verified backups
Choose a backup created before the compromise and check that it is complete and usable. Restore into a controlled environment, scan systems and confirm that important files open correctly. Backups should be protected from ordinary administrator accounts, because attackers commonly target them during ransomware incidents.
A recovery service should include more than storage. Backup and disaster recovery planning helps Brisbane businesses consider restoration, continuity and local response before an emergency occurs.
Prioritise essential systems and minimise downtime
Agree on recovery order with business leaders, not just the IT team. A useful priority list might look like this:
- Identity, email and secure staff communication.
- Core files, practice systems and customer records.
- Phones, websites and customer-facing services.
- Finance, payment and supplier processes.
This list should reflect your business, including any safety or regulatory needs. Review dependencies before restoring each service so one unavailable system does not block the next step.
Work with a managed IT and cybersecurity provider in Brisbane
An experienced local team can coordinate containment, recovery and follow-up across a small business environment. OutTask provides managed IT, cybersecurity, cloud, network, phone and backup services for businesses in Brisbane and South East Queensland. The right provider should explain what is known, what remains uncertain and what must happen next in plain English.
5. Strengthen your systems after the incident
Once operations are stable, resist the temptation to close the ticket and move on. A breach often reveals gaps in access, patching, monitoring or staff processes. Review the root cause with the people who understand the business, then turn the findings into dated actions. Security improvements should be practical enough for staff to follow every day.
Patch exposed software, devices and network equipment
Identify the software, operating systems, firewalls, remote access tools and network equipment involved in the incident. Apply current security updates, replace unsupported products and remove services that are no longer needed. Confirm that internet-facing systems are included in the patching schedule.
Keep a record of exceptions and set a date to resolve them. A patch that is planned but never completed is not a control.
Review administrator privileges and application access
Reduce the number of people with elevated access and separate daily work from administration. Review access when staff join, change roles or leave. Remove old accounts, unused applications and supplier access that no longer has a business reason.
Use regular access reviews to check who can open sensitive files, approve payments or change security settings. This is especially important for growing businesses across South East Queensland.
Improve email filtering, endpoint protection and network security
Use layered controls rather than expecting one tool to catch everything. Review email filtering, endpoint protection, firewall rules, remote access and network separation. Confirm that alerts reach someone who can act on them, including outside normal office hours.
OutTask describes its local IT support team as Brisbane-based and accountable, with proactive monitoring and helpdesk support. Any provider you choose should be able to show how alerts are handled and how improvements are measured.
Align your controls with the Essential Eight
The Essential Eight provides a practical framework for reducing common attack paths. Consider application control, patching, restricted administrator privileges, multi-factor authentication, daily backups and other relevant controls as part of a staged programme. Do not claim compliance simply because a single product is installed.
Map each control to an owner, evidence and review date. This makes progress easier to explain to insurers, customers and management.
Use managed cybersecurity monitoring for ongoing protection
Monitoring can identify unusual behaviour after the immediate crisis has passed, when attention often drops. Establish who reviews alerts, how incidents are escalated and how long records are retained. Combine monitoring with testing, staff training and regular reviews rather than treating it as a replacement for those activities.
6. Prevent the next business hacking incident
Prevention is a continuing business process, not a one-off technology purchase. Brisbane businesses face staff turnover, remote work, extreme weather disruptions and changing online services. Build habits that make the secure action the easy action. Revisit them whenever your systems or team change.
Train staff to spot phishing and social engineering
Training should use ordinary examples such as invoice changes, urgent payment requests, fake shared documents and executive impersonation. Teach staff to verify unusual requests using a second channel and to report mistakes quickly without fear of blame. Fast reporting can limit damage.
Keep training short and repeat it during the year. Your phishing protection guidance can help identify practical controls alongside staff awareness.
Test backups and document a disaster recovery plan
Restore sample files and test a larger recovery, not just whether a backup job says it completed. Record recovery times, dependencies, contacts and alternate ways of working. A disaster recovery plan should cover cyber incidents as well as power loss, equipment failure and severe weather in South East Queensland.
Create and practise an incident response plan
Write down who leads the response, who contacts legal and insurance advisers, who manages communications and who approves service shutdowns. Run a short tabletop exercise using a realistic scenario. The aim is not a perfect performance, but a clear list of gaps to fix.
Schedule regular security assessments and access reviews
Arrange periodic reviews of internet-facing systems, accounts, devices, network settings and backup protections. Recheck access after staff changes, office moves, new applications or acquisitions. A planned review is easier to fund and complete than an emergency investigation.
Book a free IT assessment with OutTask in South East Queensland
If you are unsure whether your business could recover from a hack, arrange an honest review of your current setup. OutTask invites Brisbane and South East Queensland businesses to contact the team for a free IT assessment. Book an assessment or contact OutTask to discuss your risks, recovery priorities and next practical steps.
Conclusion
Knowing what to do if your business is hacked means acting carefully: contain the incident, protect evidence, assess privacy impacts, restore clean systems and improve the controls that failed. For businesses in Brisbane and South East Queensland, a tested plan and a responsive local IT partner can make recovery clearer and less disruptive. Contact OutTask or book a free IT assessment to start strengthening your business.
Frequently Asked Questions
Should I turn off every computer after a hack?
Not necessarily. Isolate systems that show signs of compromise, while seeking technical advice before shutting down unaffected services. A blanket shutdown may disrupt essential work and remove useful evidence.
Should I pay a ransom?
There is no guarantee that payment will restore access or prevent stolen information from being misused. Speak with legal, insurance and cybersecurity advisers before making any decision.
How do I know whether customer data was stolen?
Review access logs, downloads, mailbox activity, file sharing and the systems involved. If evidence is incomplete, record that uncertainty and obtain legal and technical advice.
When should I notify customers?
Notification depends on the facts, the type of information involved and applicable obligations. Coordinate with your legal or privacy adviser so communications are timely, accurate and consistent.
Are backups enough to recover from ransomware?
Backups help only when they are clean, available and tested. They should be protected from ordinary administrative access, and the business should know how to restore essential systems in the right order.
What should an incident response plan contain?
It should name decision-makers, technical contacts, legal and insurance contacts, communication channels, shutdown criteria, recovery priorities and evidence-handling steps. Practise it so people know their roles.
How can a small business prepare without a large IT team?
Start with multi-factor authentication, timely patching, restricted administrator access, tested backups, staff training and regular reviews. A managed local provider can help prioritise the work and keep it moving.