
A ransomware attack does not feel like a slow-burning problem. One moment your team is working, the next a screen full of scrambled files and a ransom note is staring back at you. What you do in the first day shapes how much you lose, how quickly you recover, and whether the attack turns into a reportable breach. The good news is that the immediate response follows a clear order, and none of it requires you to be a security expert. This is a plain-English, hour-by-hour plan for the critical first 24 hours after you discover ransomware in an Australian small or medium business.
Print this, save it somewhere your team can reach it offline, and read it now rather than in the middle of a crisis. If you want the wider picture of how these attacks work and how to stop them, our guide on how ransomware works and how to prevent and recover is the companion piece to this one.
The first hour: contain the spread
Ransomware wants to move sideways. It looks for shared drives, connected backups, servers and other machines on the same network, and it encrypts everything it can reach. Your first job is to stop that movement, so containment comes before everything else, including reporting.
The Australian Signals Directorate advises turning off the infected device by holding down the power button or unplugging it from the wall, then disconnecting other important devices on the same network. Work through it in this order:
- Disconnect the affected machine from the network. Unplug the ethernet cable and turn off its Wi-Fi. If you cannot do that quickly, power the device down.
- Isolate the rest of the network. Turn off or disconnect other computers, servers, network storage (NAS) devices, phones and tablets, starting with the ones that hold your most important data.
- Unplug external drives and USB backups. Anything still connected can be encrypted next, so physically remove it.
- Pause cloud sync where you can. Services that sync folders automatically can push encrypted files up to the cloud, so sign out or pause syncing on affected accounts.
Do not log back into the infected machine to poke around, and do not reconnect it to test whether things are working. Every extra minute it spends on the network is a minute the attack can keep spreading.
Record what you see before it disappears
In the rush to fix things, it is easy to wipe away the very details that help you recover and report. Take two minutes to capture evidence first. Use your phone to photograph the ransom note and the screen, and write down a few simple facts while they are fresh.
- The date and time you first noticed something wrong, and who noticed it.
- The exact wording of the ransom note, the name it gives the ransomware, and any payment demand or deadline.
- The new file extension on the encrypted files, and which folders or drives are affected.
- Any unusual emails, links or attachments opened in the hours before, which can point to how the attackers got in.
This record helps a professional identify the strain, tells the authorities what they are dealing with, and gives you a clear timeline if you later need to notify customers or your insurer. Keep it somewhere separate from the affected systems, such as on your phone or a clean device.
Report the attack and get help
You do not have to face this alone, and reporting is quick. In Australia you report cybercrime, including ransomware, through ReportCyber, the online reporting tool run by the Australian Signals Directorate’s Australian Cyber Security Centre. If you need advice while the incident is unfolding, call the 24/7 Australian Cyber Security Hotline on 1300 CYBER1 (1300 292 371). It is a free service and the people answering deal with this every day.
If you have cyber insurance, call your insurer or broker early too. Many policies require you to notify them promptly and may give you access to an incident response team, legal advice and forensic specialists as part of the cover. If money has already moved, for example through a fraudulent payment, contact your bank straight away and report it to Scamwatch. Where customers’ personal data may be caught up in the attack, IDCARE can help affected individuals at no cost.
Should you pay the ransom?
The pressure to pay is real, especially when your business is at a standstill. The Australian Government’s advice is unambiguous: never pay a ransom. Paying does not guarantee you will get your files back, it does not stop stolen data from being leaked, and it marks you as a business willing to pay, which invites a second attack. The Australian Signals Directorate also warns that a payment could breach sanctions laws, which can itself be a serious criminal offence.
Paying also does nothing to fix the hole the attackers came through. If you restore your data but leave the original weakness open, you are simply waiting for it to happen again. Put the energy you would spend negotiating into recovery from your own backups, which is where a well-prepared business gets back on its feet.
Check your legal and notification obligations
Ransomware is not only an IT problem, it can be a privacy one. Modern ransomware crews often copy your data before they encrypt it, then threaten to publish it. If personal information your business holds has been accessed or stolen and it is likely to cause serious harm, the Privacy Act’s Notifiable Data Breaches scheme may require you to assess the incident and notify both the affected people and the Office of the Australian Information Commissioner.
This is a judgement you should not leave to guesswork in the heat of the moment. Our guide to your obligations under the Notifiable Data Breaches scheme walks through when notification is required and how the 30-day assessment window works. Flagging the possibility early, and looping in legal advice if you have it, keeps you on the right side of the rules and protects your reputation.
Start your recovery the right way
Once the spread is contained and the incident is reported, recovery becomes a careful process rather than a scramble. The temptation is to plug a backup drive straight into an infected machine, but that is how clean backups get encrypted too. Work through it in order.
- Confirm your backups are clean and untouched before you rely on them. If they were connected during the attack, treat them as suspect.
- Remove the ransomware fully. This usually means wiping the affected drives and reinstalling the operating system rather than trying to clean around it.
- Rebuild, then restore. Only once a machine is clean should you connect a known-good backup and restore your files.
- Reset passwords and turn on multi-factor authentication for critical accounts, including email, banking, cloud storage and any admin logins, in case credentials were captured.
This is the moment where good preparation pays off. A business that follows the 3-2-1 backup rule, with at least one copy kept offline or immutable, can wipe and restore without ever considering the ransom. If you do not have secure backups, or the recovery is beyond your team, this is the point to bring in a professional rather than experiment on live systems. When the dust settles, run a short review to work out how the attackers got in, and close that gap so the same attack cannot land twice.
Related reading: the best time to prepare is before an attack. See our guide to backups and ransomware recovery to build the plan and the backups that make this checklist easier, and the complete guide to cyber security for small business in Australia.
Find out where you stand
The businesses that survive ransomware with the least pain are almost always the ones that prepared before it happened: clean offline backups, multi-factor authentication, restricted admin access and a team that knows the first steps. The best time to check your readiness is on a quiet day, not during an incident.
SecurityScore is a free self-assessment built for Australian businesses. Answer 27 short questions, take around 5 to 10 minutes, and you will get a personalised PDF report mapped to the ACSC Essential Eight, ISO 27001 and SOC 2, showing exactly where you are strong and where a ransomware attack could hurt you most. Take the free assessment now and see where your business stands before an attacker decides to test it.