Cyber incident response for Sydney businesses. If you think you’ve been hacked, act fast and follow these steps.

Think you’ve been hacked? Call (02) 8212 4722 now.

While you wait for us, do these things first:

  1. Disconnect affected devices from the network (unplug the cable and turn off Wi-Fi). If you suspect ransomware, turn the device off, as the Australian Cyber Security Centre advises.
  2. Don’t delete anything, and don’t pay a ransom.
  3. Don’t use a compromised email account to discuss the incident. Use the phone or a different, clean device.
  4. Write down what you saw: take a photo of any ransom message or strange screen, and note the time.
  5. If it’s serious and you have cyber insurance (ransomware, a data breach, business email compromise or money lost), contact your insurer’s incident line early, as many policies require prompt notification. For smaller issues, talk to us first and we’ll help you work out whether your insurer needs to know.

A cyber incident is stressful, and the first hours matter. Sydney Technology Solutions helps Sydney businesses respond quickly and calmly: we contain the threat, investigate what happened, remediate the damage and help restore your operations, then help you work out what needs to be reported.
Cyber incident response in Sydney – Sydney Technology Solutions

Cyber incident response: incidents we help with

  • Compromised Microsoft 365 or email account: someone else has logged in, emails are being sent from your account, or strange inbox rules have appeared
  • Business email compromise and invoice fraud: fake invoices or changed bank details sent to your clients or suppliers, often from a real but hijacked mailbox
  • Ransomware: files suddenly encrypted, renamed or replaced with a ransom note
  • Phishing attack: a staff member clicked a link, entered their password on a fake page, or opened a suspicious attachment
  • Malware infection: unusual pop-ups, slow or misbehaving computers, or security alerts you don’t recognise
  • Lost or stolen device: a laptop or phone with access to company email, files or systems has gone missing
  • Data breach: personal or confidential information may have been accessed, copied or exposed
  • Suspicious activity: something just doesn’t look right: unexpected logins, password reset emails or changed settings

If you’re not sure whether it’s an incident, call us anyway. It’s far better to check early.

How our cyber incident response works

1. Contain

Stop the spread: isolate devices, lock compromised accounts, cut off attacker sessions and block malicious senders.

2. Investigate

Work out what happened, how they got in, which accounts, devices and data were affected, and whether the attacker is still present.

3. Remediate

Remove malware, close the gap they used, reset credentials, and fix the settings or software that let them in.

4. Restore

Recover systems and data from clean backups and get your team working again, safely.

5. Report and learn

Help you work through reporting obligations and insurance, then strengthen your defences so it doesn’t happen again.

Reporting obligations

Depending on your business and what happened, you may have to report an incident:

  • Notifiable Data Breaches scheme: businesses covered by the Privacy Act must notify the OAIC and affected individuals of an eligible data breach that is likely to cause serious harm.
  • Ransomware payments: since 30 May 2025, businesses with annual turnover over $3 million (and critical infrastructure entities) must report any ransomware payment to the Australian Signals Directorate within 72 hours.
  • Reporting cybercrime: any business can report cybercrime through ReportCyber or the Australian Cyber Security Hotline on 1300 CYBER1 (1300 292 371).

We’ll help you gather the facts you need to make these decisions. For more detail, read what Australian businesses have to report after a cyber incident. This page is general information, not legal advice.

Working with your insurer

Not every incident needs to go to your insurer. A blocked phishing email or a quickly contained infection usually doesn’t, while ransomware, a data breach, business email compromise or financial loss usually should, and early. We’ll help you work out which applies, but your policy wording decides, so check it. For serious incidents, your insurer may have its own incident hotline and approved responders, and may need to be told before you engage anyone. We’re happy to work alongside your insurer and their team, and to provide the technical information they need for a claim.

Be ready before you need it: keep your policy number and your insurer’s incident hotline somewhere you can find them even if your computers and email are down, such as printed or saved on your phone.

After cyber incident response: preventing the next one

Once things are back to normal, we’ll look at how the attacker got in and close the gaps so it’s much harder to happen again. That might include managed EDR, identity threat detection for Microsoft 365, email security, staff training or working towards the Essential Eight. See our full cybersecurity services.

Why choose STS for cyber incident response

Cyber incident response is about speed, calm and clear steps. Our team helps contain the threat, recover your systems and work through reporting, including the Notifiable Data Breaches scheme where personal information is involved and reports to the Australian Cyber Security Centre. Good cyber incident response starts before anything happens, with backups, monitoring and a plan. Our cyber incident response approach is the same calm, step-by-step process every time, and cyber incident response planning is part of every managed security service we provide.

What our clients say

“They have saved my office from so many email attacks and recovered my data on numerous occasions. Without the professional service and immediate attention they provide to my office life would be a lot more difficult.”

Robert Nap, Google review

STS is rated 4.8★ on Google. Read more client reviews.

Frequently asked questions

Should I turn the computer off?

Disconnect it from the network first. If you suspect ransomware, the Australian Cyber Security Centre advises turning the device off to stop it spreading. If you’re unsure, call us and we’ll talk you through it.

Should we pay the ransom?

The Australian Government advises against paying. Payment doesn’t guarantee you’ll get your data back or that it won’t be leaked, and it can make you a target again. If a payment is made, larger businesses must report it within 72 hours.

Our email has been hacked. What should we tell our clients?

If fake emails or invoices may have been sent, let affected clients and suppliers know by phone as soon as possible, and tell them not to act on any request to change bank details. We can help you work out who was contacted.

How do we stop it happening again?

After every incident we identify the root cause and recommend practical fixes, from MFA and email security to EDR, identity protection and staff training.

Should we have a cyber incident response plan?

Yes. A cyber incident response plan sets out who does what, who to call and how to recover. We help clients write and test a cyber incident response plan, so everyone knows the steps before anything happens.

What does cyber incident response cost?

It depends on the incident and the work involved. For our managed security clients, cyber incident response is planned in advance as part of their security services.

Get cyber incident response help now

Call (02) 8212 4722. If it’s not urgent, send us a message and we’ll be in touch.