Cyber Incident: First Hour (Australia)
Guides an Australian small business through the first hour of a suspected scam payment, phishing account takeover or ransomware attack, using ASD, Scamwatch and IDCARE contact points. Use when something has just gone wrong and the owner needs calm, ordered steps and the right numbers to call.
Gives an Australian small business ordered first-hour steps for a scam payment, account takeover or ransomware attack, with verified ReportCyber, 1300 CYBER1, Scamwatch and IDCARE contacts.
Cyber incident: the first hour
What it does
This skill gives a business owner a short, ordered checklist for the first hour after they suspect a cyber incident. It works out which of three situations they are in, gives the steps for that situation in the order that limits damage, and lists who to call and where to report. It keeps a running log of what was done and when, because banks, insurers and police will ask for it.
When to use it
- Money has been paid to a bank account that now looks wrong.
- A staff member entered their password on a fake login page, or an email account is sending messages nobody wrote.
- Files have been locked or renamed and a ransom note has appeared.
If anyone is in danger, call 000 first.
What you need
- A phone that is not on the affected network.
- The business bank's official phone number, taken from a card or the bank's website, not from an email.
- The business's ABN, for the ReportCyber business report.
- Optional: access to the Microsoft 365 admin centre or Google Admin console to reset passwords and sign users out. No connector is required, and Claude should not be given access to affected systems during the incident.
Steps for Claude
Ask one question first: "Which is closest: money sent to a scammer, an account taken over, or files locked by ransomware?" Then give only the steps for that path. Keep each step to one or two sentences. Start a timestamped log and add to it as the user reports progress.
Path A: money sent to a scammer
- Call the bank now on its official number. Ask them to stop or recall the payment and to flag the receiving account. Scamwatch says to contact your bank immediately and ask them to stop any transactions.
- Stop sending money, including any "fee" to recover the loss.
- Change passwords on email, banking and accounting accounts, and turn on MFA.
- Keep every email, invoice and phone record. Do not delete the thread.
- Report a cybercrime to police through ReportCyber, and report the scam to Scamwatch.
- For help making a recovery plan, contact IDCARE on 1800 595 160.
Path B: an account has been taken over
- From a clean device, reset the password for the affected account and sign it out of all sessions. Turn on MFA if it was off.
- Check the mailbox for new forwarding rules, inbox rules or connected apps, and screenshot them before removing them.
- Warn staff, and warn customers and suppliers by phone that emails from that account may be fake.
- Check whether any payment details were changed or any invoices were sent. If money moved, switch to Path A.
- Report through ReportCyber as a business.
Path C: ransomware
- Photograph the screen, the ransom note and any new file extensions.
- Turn off the infected device, then turn off other devices on the same network, starting with servers and network storage.
- From a clean device, change passwords for email, cloud storage, bank and business accounts.
- Do not connect backups to anything until the infection is removed. Ask an IT professional before touching backups.
- Do not pay. ASD advises never paying a ransom.
- Report through ReportCyber and call the Australian Cyber Security Hotline, 1300 CYBER1 (1300 292 371), which ASD lists as a 24/7 hotline.
For every path, before the hour ends
- Tell the cyber insurer, if the business has one, and note the policy's notification rules.
- Note whether personal information may have been accessed. If the business is covered by the Privacy Act, it may need to notify under the Notifiable Data Breaches scheme. Flag this for follow-up; do not decide it in the first hour.
Output format
- The steps for the chosen path, numbered, with tick boxes.
- A contact card: bank (official number), ReportCyber link, 1300 CYBER1, Scamwatch link, IDCARE number.
- An incident log table: Time, What happened, What we did, Who did it.
- A short "next 24 hours" list for recovery and notification questions.
Australian rules and sources
- ReportCyber (report a cybercrime or incident): https://www.cyber.gov.au/report-and-recover/report
- Cybercrime, getting help (lists the 24/7 hotline 1300 CYBER1, 1300 292 371): https://www.cyber.gov.au/report-and-recover/where-get-help
- Report and recover from ransomware: https://www.cyber.gov.au/report-and-recover/recover-from/ransomware
- Scamwatch, what to do if you've been scammed: https://www.scamwatch.gov.au/stop-check-protect/what-to-do-if-youve-been-scammed
- Scamwatch, report a scam: https://www.scamwatch.gov.au/report-a-scam
- IDCARE (number 1800 595 160 as published by Scamwatch): https://www.idcare.org/
- OAIC, Notifiable Data Breaches: https://www.oaic.gov.au/privacy/notifiable-data-breaches
ASD's ransomware page also describes a mandatory reporting regime for ransomware or cyber extortion payments that applies to businesses with annual turnover above $3 million and some critical infrastructure entities, with reports due within 72 hours. Point the user to that page rather than advising on payment.
Limits
This is general guidance for the first hour, not legal, insurance or technical incident response advice. Get an IT professional involved as soon as possible. Check phone numbers against the official pages above if in any doubt.
Example requests
- "We just paid a supplier invoice and the supplier says they never sent new bank details. What do I do right now?"
- "My bookkeeper typed her Microsoft password into a fake page 20 minutes ago."
- "All the files on our shared drive have a weird extension and there's a ransom note. Help."
- →We just paid a supplier invoice and the supplier says they never sent new bank details. What do I do right now?
- →My bookkeeper typed her Microsoft password into a fake page 20 minutes ago.
- →All the files on our shared drive have a weird extension and there's a ransom note. Help.
Source
custom
Author
Tech Horizon Labs
Version
1.0
Complexity
Compatible With
Prerequisites
- A phone not on the affected network
- The bank's official phone number
- Business ABN
Tags
