Omnicron
CybersecurityDifficulty: IntermediateEstimated time: 1–2 hoursUpdated

How to Create a Basic Cyber Incident Response Plan

Write a simple, one-page plan so your team knows exactly what to do in the first hours of a cyber incident.

Why this matters

When a cyber incident happens, the first few hours matter most. Without a plan, people waste time working out who to call, may destroy evidence or make the problem worse. A simple written plan helps everyone act calmly and quickly.

What you'll need

  • Key contact details (IT provider, insurer, bank, managers)
  • A list of your critical systems
  • Time with the business owner or manager

Step-by-step instructions

  1. Step 1

    Define what counts as an incident

    Give examples staff will recognise: ransomware messages, suspected compromised email, lost laptops, fake invoice payments or unusual account activity.

  2. Step 2

    Assign roles

    Name a person who leads the response, who contacts the IT provider, and who handles communication with staff, clients and insurers. Include backups for each role.

  3. Step 3

    List your key contacts

    Record phone numbers (not just emails) for your IT provider, cyber insurer, bank, legal adviser and the Australian Cyber Security Hotline (1300 CYBER1).

  4. Step 4

    Write the first-response steps

    Keep it short and practical.

    • Disconnect affected devices from the network but leave them powered on
    • Do not delete emails, files or logs
    • Call the incident lead and IT provider
    • Change passwords from a clean device if accounts are affected
    • Contact the bank immediately if money has been sent
  5. Step 5

    Cover notification obligations

    Note when you may need to notify the Office of the Australian Information Commissioner (OAIC) under the Notifiable Data Breaches scheme, your insurer and affected customers.

  6. Step 6

    Record where backups are and how to restore

    Document what is backed up, where, and who can restore it.

  7. Step 7

    Store it offline and practise it

    Print the plan and keep a copy outside your normal systems. Walk through a scenario once a year.

Summary

A short, practised plan turns a chaotic incident into a series of clear steps and dramatically reduces downtime and damage.

Still Need Help?

Some IT problems are easier to solve with a professional. If you've followed the guide and still need help, the Omnicron team can assist.

  • Business IT

    How to Prepare for a Cyber Incident

    Put the people, information and safeguards in place now so your business can respond quickly if something goes wrong.

    Difficulty: IntermediateEstimated time: 1–2 hours
    Read Guide
  • Cybersecurity

    How to Protect Your Business From Ransomware

    Reduce the chance of ransomware locking your files, and make sure you can recover quickly if it does.

    Difficulty: IntermediateEstimated time: 30–60 minutes to review
    Read Guide
  • Business IT

    How to Create a Business Backup Strategy

    Decide what to back up, how often and where, so your business can recover from ransomware, mistakes or hardware failure.

    Difficulty: IntermediateEstimated time: 1–2 hours
    Read Guide