Act in this order: (1) isolate affected devices from your network immediately, (2) reset compromised passwords from a clean device, (3) contact your bank if financial credentials were exposed, (4) report to the Australian Cyber Security Centre at cyber.gov.au, and (5) notify affected clients if personal data was compromised — you may have mandatory reporting obligations under the Notifiable Data Breaches scheme if your business turns over more than $3 million annually.
What it depends on
The full answer depends on your specific circumstances. Here’s what matters.
What was compromised
A phishing attack's severity depends on what the attacker accessed. Email credentials? They may be reading your messages and intercepting financial instructions. Banking credentials? Contact your bank immediately — most banks have a 24-hour fraud line. Client data? You may have a legal obligation to report under the Privacy Act 1988 (Notifiable Data Breaches scheme).
Your reporting obligations
Businesses with annual turnover above $3 million, health service providers, and Australian Government agencies must report eligible data breaches to the Office of the Australian Information Commissioner (OAIC) and affected individuals. An "eligible" breach means serious harm is likely — financial loss, identity theft, physical harm. You must report within 30 days of becoming aware.
Whether the attack is ongoing
Many phishing attacks install persistent access — the attacker may still be in your systems even after you change the password they stole. Email forwarding rules, OAuth app permissions, and remote access tools should all be checked. If you're not confident the attacker has been fully removed, get professional help before reconnecting devices.
Your insurance position
Cyber insurance may cover incident response costs, forensic investigation, legal fees, and business interruption. Check your policy — many standard business insurance policies exclude cyber events. If you have cyber insurance, notify your insurer early as they often have pre-approved incident response partners.
The last 10%
What a qualified professional can add
The answer above covers the general position. Here’s where professional judgement — applied to YOUR specific situation — makes the difference.
- Conducting a forensic assessment to determine exactly what was accessed, whether the attacker is still present, and what data was exposed
- Guiding you through your Notifiable Data Breaches obligations — including whether your specific incident meets the threshold for mandatory reporting
- Implementing immediate containment measures that go beyond password resets: checking for persistent access, forwarding rules, and compromised tokens
- Designing a post-incident improvement plan so the same attack vector can't be used again
Questions to ask before you engage one
If you decide to engage a professional, these questions help you evaluate whether they’re right for your situation.
Can you assess whether the attacker is still in our systems before we reconnect anything?
Do we have mandatory reporting obligations under the Notifiable Data Breaches scheme for this specific incident?
What is the scope of your incident response — does it include forensic analysis, or just containment?
How do you charge — flat fee for incident response, hourly, or retainer?
After the immediate crisis, what are the three most important changes we should make to prevent a repeat?
General Advice Warning
The information on this page is general in nature and does not take into account your personal objectives, financial situation or needs. It is provided by Global Mutual Funds Pty Ltd (ABN 20 090 555 436, AFSL 222640) and should not be relied upon as a substitute for professional advice. Consider whether the information is appropriate before acting on it. Read our Financial Services Guide.