First-hour checklist
Defensive only. Adapt to your plan. This is not legal advice and not an ACSC playbook reprint.
- 01Declare the incident. One lead. A shared timeline document, clock in UTC and AWST.
- 02Preserve: snapshot volatile systems only if you know how; otherwise do not trample logs. Export auth, VPN, EDR, mail, DNS.
- 03Contain obvious spread: isolate endpoints via EDR, disable compromised identities, block known-bad at the edge. Human gate on mass disables.
- 04Crown jewels: are identity, backups, and finance/OT reachable from the affected plane? Segment now.
- 05Facts only in the channel. What is confirmed, what is suspected. No root-cause fan fiction.
- 06Legal + privacy: is personal information involved? Start the NDB assessment clock. OAIC if it is eligible.
- 07Notify those with authority: exec, ACSC (1300 CYBER1) if you need them, insurer if the policy says so.
- 08External comms: one spokesperson. Customers later, when the facts hold.
- 09Keep a decision log: who approved isolation, who approved any shutdown.
- 10Do not rebuild yet. Recover is hour four or day two, after you know what you are recovering from.
