What to Do After a Data Breach: A Step-by-Step Response Guide
Synopsis
A data breach can be overwhelming, but taking the right steps quickly can limit the damage. Here’s a practical guide to responding to a data breach, securing your systems and protecting sensitive information.
Revealing a data breach is one of those so-called panic moments, where it can cost you more than the breach itself. The first few hours will really determine how bad it is, and how your business is perceived in the eyes of a regulator looking for someone to blame as well as customers fast to take their business elsewhere.
You do not have to play your way through this trick. And Australia has clear government-backed guidelines on what to do and when, and even what your legal duties are. This is a tangible walk-through of that process, reflecting the latest information from the Office of the Australian Information Commissioner (OAIC) and the Australian Cyber Security Centre.
Step 1: Immediately Contain the Breach
OAIC’s own guidance is strong. Step one is always containment, stop the breach from getting worse before doing anything else. Now isn’t the time to tell yourself a narrative about how this happened and who you need to call first. Now is the moment to halt the losses.
Practical containment steps typically include:
- Isolating compromised systems or accounts from the rest of your network.
- Invalidating or changing compromised passwords and access credentials.
- Shutting down accounts that appear to be compromised.
- Preserve the evidence rather than deleting logs or files, you will require this for your investigation and regulatory notification
According to the Australian Cyber Security Centre, in cases where credentials have been compromised, passwords should be reset promptly and unusual account activity should also be monitored as an indication whether the compromise is still active.
You should also prevent password reuse across critical services, as a single compromised password can open up multiple accounts for an individual that chooses the same one among email, banking and business systems.
This is an important step, don’t hurry this process. Contain first, investigate properly second.
Step 2: Analyse What Happened and Who has been harmed
After the breach is contained, you need to ascertain the actual scope of what occurred. That involves finding out what kind of personal information was in this latest breach, how many people were impacted and how the breach happened in the first place.
Under the Australian Notifiable Data Breaches (NDB) scheme, most businesses have 30 days to establish if a breach is likely to result in serious harm to any individual. This is an intentional timeframe, it doesn’t mean that you should wait 30 days to begin your search, but rather you have a smaller window in which to perform a formal evaluation as opposed to being expected to know everything within the first sixty minutes.
Determine what information the database accessed, whether they contained sensitive data such as financial information or health records, and whether the breach is still ongoing or has been completely terminated.
It is also at this point that many businesses seek external support. Technical incident response advice and assistance will be available if you report the incident to the Australian Cyber Security Centre via cyber.
Step 3: Determine What You Are Legally Required to Notify
This is where many business owners get concerned, and rightfully so. The Notifiable Data Breaches scheme under the Privacy Act also imposes an enforceable requirement whereby organisations must notify affected individuals as well as the OAIC when a breach is likely to cause serious harm.
The scheme generally applies to:
- Australian Government agencies.
- Businesses and not-for-profit organisations with annual turnover of greater than $3 million.
- Private health service providers in the medium.
- Credit reporting agencies and credit providers.
- Businesses of any size that deal with tax file numbers
Under the scheme, an “eligible data breach” is defined only in relation to the states of personal information being accessed or disclosed as well as loss of personal information without authorisation so that such action will “likely” cause serious harm to a person and you have been unable to remedy that harm through timely remedial action.
If you contain a breach swiftly, preventing any actual risk of harm, you might not even be obliged to report it, though best to document that assessment thoroughly, as the latter could easily be challenged.
Step 4: Reporting to the OAIC & individual affected
If you assess this as being an eligible data breach, notice isn’t optional. You will be required to notify the OAIC via their online Notifiable Data Breach form and also notify the individuals affected by such a breach separately.
Key things from the OAIC’s own guidance:
- Individual notifications, to be very clear with suggestions regarding what actions they must take and not merely informing of an event being taking place.
- You notify people via e-mail, text or phone call (whatever’s going to get them the message faster).
- If you really can’t reach everyone affected, you must publish the notice on your website and advertise it as actively as possible, via social media, news coverage, or advertising.
- In cases where multiple organisations jointly hold the same information, typically only the entity with the most direct relationship to affected individuals should be responsible for notification
Why wait for a “complete” picture before notifying? The OAIC expects that you will give notice promptly upon concluding on reasonable grounds that there is an eligible data breach, not when every minute technical detail has been fully resolved.
Step 5: Review and Reinforce Your Defences
Following the incident, the Australian Cyber Security Centre recommends businesses consider starting with the Essential Eight; a set of baseline security controls designed to protect systems and data from common cyber threats. These important and, more practically, actionable steps to prioritise include:
- Make forced password resets mandatory
- Have multi-factor authentication across all remote access and sensitive systems
- Train staff to spot phishing attempts as any good IT person will tell you credential theft through fake login pages continues leading the way breaches kick off.
A good post-breach review should address both the initial security hole and the flaws in how you responded to it. Did containment happen fast enough? Did you bring the right people into the project early enough? Has the 30-day assessment window been used appropriately, or just as a last-minute rush? What distinguishes a business that bounces back well from one that finds itself caught out the same way twice, is documenting these lessons and following up on them in practice.
Who Should Be Notified First?
Internally this typically means your incident response lead or senior management and your IT or security team as they must initiate containment right away. For a breach as a result of an actual cyber attack (not just human error), then report to the Australian Cyber Security Centre via cyber. gov.au. With gov.au right from the start, you can access technical response advice while working out what damage has been done. Your assessment will only tell you after the fact that notification to both the OAIC and affected individuals is required, not before you sufficiently understand what even happened.
When to Notify Impacted Customers
Straight away or as soon as you have a good reason to believe that really serious harm will occur. With alerting, notifying users before you actually understand what data has been compromised can mean stirring unnecessary panic and confusion, while delaying the notification too long deprives people of taking steps to protect their accounts such as changing passwords and keeping an eye out for scams. The OAIC gets the balance here: assess swiftly but notify without delay, that is, when you believe there are actually grounds for the breach to be notifiable.
How To Prevent A Data Breach From Occurring Again
Prevention comes down to a combination of technical controls and everyday habits. The Australian Cyber Security Centre (ACSC) has been fairly consistent about the measures that make the biggest difference. Some of the main priorities include:
- Requiring users to change their passwords regularly and setting stronger length and complexity requirements to make brute-force attacks harder to carry out
- Enabling multi-factor authentication for all remote access to business systems, as well as for users carrying out sensitive or privileged actions
- Locking accounts after multiple failed login attempts
- Discouraging staff from reusing passwords across critical services, such as using a banking password for another, less important account
- Training employees to recognise phishing attempts, since stolen credentials from fake login pages remain one of the most common ways breaches begin.
- Staff should also be reminded never to enter their credentials on a page reached through a link in an email or message.
For businesses looking for a more formal approach, the Australian Signals Directorate’s Information Security Manual and the NIST Cybersecurity Framework are also referenced by the OAIC as useful standards, particularly for organisations that handle large amounts of sensitive personal information.
None of these measures can guarantee that a business will never suffer another breach. No security framework can provide that kind of protection. But consistently applying these basic controls can shut down many of the most common routes attackers use, including stolen credentials, phishing and weak access controls, and greatly reduce the chance of making the same mistake twice.
Getting Help While You Respond
If you are responding to a breach, then the “Have you been hacked? tool at cyber. gov.au is immediately useful, taking you through real-world steps based on what sort of information was leaked. There’s also a comprehensive quick-reference guide and self-assessment checklist for determining your notification obligations, both of which are hosted on the website of the OAIC. None replaces hiring the right internal team, and if necessary external forensic or legal assistance, quickly.
At Inspirepreneurs Magazine, covering entrepreneurship, business failures, and the human stories behind the world's most ambitious founders. She writes at the intersection of strategy and storytelling.
You Might Also Like
Disney vs YouTube: Channels Off Air, Stocks Fall 8%
NRL Magic Round 2026: The Must-Watch Clashes Set to Light Up Brisbane