A suspicious Microsoft 365 sign-in, an invoice sent from the wrong account, or a staff member reporting a lost laptop can quickly become a data breach response situation. The first few hours matter, but the right response is not to panic or start deleting things. It is to contain the problem, preserve what happened and make considered decisions that protect your business, customers and staff.
For small and medium-sized businesses across the Central Coast, Newcastle and the Hunter, a breach can feel especially disruptive because the people handling it are often also responsible for keeping operations moving. A clear plan gives your team a practical starting point when the pressure is on.
What counts as a data breach?
A data breach occurs when personal or sensitive information is accessed, disclosed, lost or altered without authorisation. It is not limited to a large-scale cyber attack. A phishing email that captures a staff member's Microsoft 365 password, a misplaced USB drive, an email sent to the wrong recipient, or a contractor retaining access after they leave can all be breaches.
The affected information might include names, contact details, Medicare details, bank account information, employee records, client files, passwords or commercially sensitive documents. The seriousness depends on what information was involved, who may have accessed it and whether that access could cause harm.
Not every incident becomes a reportable breach. However, every suspected breach deserves a prompt assessment. Waiting to see whether a customer complains can allow an attacker more time in your systems and make recovery harder.
The first priority: contain, do not destroy evidence
When something looks wrong, the immediate goal is to stop further unauthorised access without wiping away the information needed to understand the incident. For example, if an email account has been compromised, changing the password and ending active sign-in sessions may be appropriate. But deleting suspicious emails, resetting devices without advice, or changing many settings at once can make it harder to establish what occurred.
A sensible initial response includes four actions:
- Disconnect an affected computer from the network if you suspect malware or unauthorised remote access, but leave it powered on unless advised otherwise.
- Disable or secure compromised accounts, reset passwords and require multi-factor authentication where it was not already in place.
- Preserve key details, including the time the issue was found, screenshots, sender addresses, suspicious files and the people or systems involved.
- Contact your IT provider, cyber insurer and, where appropriate, legal or privacy advisers as early as possible.
Containment has trade-offs. Taking a shared system offline may interrupt work, but leaving it connected could expose backups, file shares or other accounts. An experienced IT team can help isolate the right parts of the environment while keeping essential services available where possible.
Establish what happened before making promises
Once immediate access has been contained, the next job is to determine the scope. This is where assumptions can be costly. A compromised email account may only have been used to send phishing messages, or an attacker may have searched mailboxes, set up forwarding rules and accessed documents stored in cloud services.
Your investigation should establish when the incident started, how it happened, which systems and accounts were affected, what information may have been accessed and whether unauthorised access is still occurring. Audit logs from Microsoft 365, firewalls, endpoint security tools and backups can be valuable here.
Keep a written incident record. Note decisions, actions taken, times, responsible people and advice received. This record helps your business communicate consistently, supports any insurance claim and provides evidence that you acted reasonably.
It is also wise to nominate one person to coordinate internal updates. During an incident, well-meaning staff can unintentionally create confusion by giving customers different explanations or forwarding unverified information. Staff need enough information to work safely, but communications should be factual and controlled.
Consider your privacy and notification obligations
Australian privacy obligations depend on the nature of your organisation, the information involved and the agreements or regulations that apply to your industry. Organisations covered by the Privacy Act may need to assess whether an incident is an eligible data breach under the Notifiable Data Breaches scheme.
In simple terms, notification may be required where there has been unauthorised access to, disclosure of or loss of personal information, and the breach is likely to result in serious harm to one or more individuals. If so, the organisation may need to notify affected people and the Office of the Australian Information Commissioner.
The small business exemption does not automatically mean a business has no responsibilities. Some businesses are covered because of the services they provide or the information they handle. Contracts with customers, professional obligations, cyber insurance requirements and sector-specific rules can also require notification or particular response steps.
Avoid rushing out a broad message before the facts are clear, unless urgent action is needed to protect people. At the same time, do not delay a required notification simply because the investigation is inconvenient. Legal and privacy advice is particularly useful where medical, financial, identity or employee information may be involved.
Communicate in a way that helps people act
If customers, patients, suppliers or staff need to be notified, the message should be clear, honest and practical. Explain what happened in plain English, what information may have been involved, what you have done to contain the incident and what actions they should take.
For example, if a client email account was compromised, recipients may need to be warned not to trust recent invoice-change requests or links sent from that address. If identity information was exposed, people may need advice about watching for scams or contacting their financial institution. Do not speculate about details you cannot verify, and avoid technical language that obscures the risk.
Internally, remind staff that attackers often return after an incident. They may impersonate your IT provider, insurer, manager or bank and claim to be assisting with the breach. Any unexpected request for a password, multi-factor code or banking change should be independently verified.
Recover carefully and look for the underlying weakness
Restoring normal operations is not the same as resolving the incident. Before reconnecting devices, restoring files or re-enabling accounts, confirm that the original entry point has been addressed. Otherwise, you risk putting an attacker back into a clean environment.
Recovery may involve restoring from tested backups, rebuilding affected devices, removing malicious inbox rules, resetting credentials, reviewing privileged accounts and checking that security updates are current. The correct approach depends on the incident. A lost laptop and a ransomware event require very different recovery work.
Afterwards, hold a short review while the details are still fresh. Focus on practical improvements rather than blame. Was multi-factor authentication enforced for every account? Did staff have a safe way to report a suspicious email? Were backups protected and tested? Could a former employee still access a shared system? Were supplier payment changes independently verified?
This review often identifies small gaps that make a major difference. A clear offboarding process, password manager, endpoint protection, staff awareness training and tested backup recovery procedures are less dramatic than a breach response, but they reduce the chance that a routine mistake becomes a serious business interruption.
Build the plan before you need it
A useful data breach response plan does not need to be a thick policy document that no one reads. For most businesses, it should clearly set out who to call, who can make decisions, how accounts and devices are isolated, where critical contacts are kept, and how communications and evidence will be managed.
Test the plan with a short scenario once or twice a year. Ask what the team would do if the accounts manager received a convincing phishing email, a practice laptop disappeared from a car, or files suddenly became inaccessible. These discussions expose gaps without interrupting the business.
Simple IT works with local businesses to put practical security, backup and incident response arrangements in place before an incident occurs. The aim is not unnecessary complexity. It is making sure that, when something unusual happens at 8 am on a busy Monday, your business knows the next sensible step and has the right support close at hand.



