A data breach is one of the most stressful things that can happen to a small business. Someone has accessed data they shouldn't have — customer records, financial details, staff information — and every hour that passes matters. The decisions you make in the first day can determine whether this becomes a manageable incident or a business-ending one.
This guide walks Australian businesses through exactly what to do, in order: containment, assessment, your legal obligations under the Notifiable Data Breach scheme, notification, and recovery. It's written for owners and managers of businesses with 5–50 staff — not security specialists — so everything is in plain English.
If you're dealing with an active breach right now: disconnect affected devices from the network (don't turn them off — that can destroy evidence), change passwords for any compromised accounts from a clean device, and get professional help immediately. You can call us on 0493 831 141, or read on for the full step-by-step process.
Step 1: Contain the Breach — Stop the Bleeding First
Before you investigate anything, your priority is stopping the attacker from doing more damage. What containment looks like depends on the type of breach:
- Compromised email or Microsoft 365 account: Reset the password immediately from a device you know is clean, revoke all active sessions, and check for malicious inbox rules (attackers often set up rules that auto-forward or hide emails). Enable multi-factor authentication if it wasn't already on.
- Malware or ransomware on a device: Disconnect it from the network — unplug the ethernet cable or turn off Wi-Fi. Do not power the machine off, as memory contents can be vital forensic evidence. If ransomware is spreading, isolating fast is everything — our guide to ransomware protection covers this scenario in detail.
- Lost or stolen device: Remotely wipe it if you have device management in place (Microsoft Intune, for example), and change the credentials for every account that device could access.
- Data emailed or sent to the wrong recipient: Contact the recipient immediately, ask them to delete it, and get written confirmation. This matters later for your legal assessment.
- Breach through a third-party supplier: Confirm with the supplier exactly what data of yours was involved, and suspend integrations or shared access until you understand the scope.
One more thing at this stage: start a written timeline. Note when the breach was discovered, what you've done, and when. You'll need this for the regulator, your insurer, and your own review afterwards.
Step 2: Assess What Happened and What Was Exposed
Once the immediate threat is contained, work out the scope. You're trying to answer four questions:
- What data was accessed or taken? Names and emails? Tax file numbers? Health records? Payment details? The type of data drives everything that follows.
- Whose data is it? Customers, staff, suppliers — and roughly how many people are affected.
- How did it happen? Phishing, a weak or reused password, an unpatched system, an insider, a supplier?
- Is it over? Does the attacker still have access anywhere — another account, a backdoor, a forwarding rule?
For most small businesses this is where you need outside help. Logs in Microsoft 365, firewall records and endpoint data can tell a clear story — but only if someone knows how to read them. This is also where EDR tooling earns its keep: businesses with it can usually reconstruct exactly what an attacker did; businesses without it are often left guessing, which forces them to assume the worst.
Step 3: Understand Your Legal Obligations — The Notifiable Data Breach Scheme
This is the part many Australian business owners don't realise applies to them. Under the Privacy Act 1988, the Notifiable Data Breaches (NDB) scheme requires certain organisations to notify affected individuals and the Office of the Australian Information Commissioner (OAIC) when an eligible breach occurs.
Does the scheme apply to your business?
The NDB scheme applies to organisations with an annual turnover of more than $3 million — but it also applies regardless of turnover if you are:
- A health service provider (including allied health — physios, dentists, psychologists, NDIS providers)
- A business that trades in personal information
- A credit reporting body or credit provider
- A business handling tax file number information (in relation to that TFN data)
If you're not sure, assume it applies and get advice. The penalties for serious or repeated privacy breaches now run into the tens of millions of dollars, and regulators have shown far more sympathy to businesses that notified promptly than those that stayed quiet.
What counts as a notifiable breach?
A breach is notifiable when all three of these are true:
- There is unauthorised access to, disclosure of, or loss of personal information
- The breach is likely to result in serious harm to one or more individuals
- You haven't been able to prevent that risk of serious harm through remedial action
“Serious harm” includes identity theft, financial loss, threats to physical safety, and serious reputational or psychological harm. Point three matters: if you emailed a file to the wrong person and they confirmed in writing they deleted it without opening it, you may have remediated the risk — and notification may not be required. Document your reasoning either way.
The 30-day assessment window
If you suspect a breach may be notifiable but aren't sure, you have a maximum of 30 days to conduct a reasonable and expeditious assessment. That's a ceiling, not a target — if it's clearly notifiable on day two, notify on day two.
Step 4: Notify the Right People
If the breach is notifiable, here's who needs to hear from you and when:
| Who to Notify | When | How |
|---|---|---|
| The OAIC | As soon as practicable after confirming an eligible breach | Online NDB statement form at oaic.gov.au |
| Affected individuals | As soon as practicable — usually alongside or shortly after the OAIC | Direct contact (email or letter) where possible; public statement if you can't reach everyone |
| ACSC / ReportCyber | Promptly for cybercrime (ransomware, business email compromise, hacking) | cyber.gov.au — ReportCyber portal |
| Your cyber insurer | Immediately — before engaging external help, if possible | Your policy's incident hotline |
| Your bank | Immediately if financial details or payments are involved | Business banking fraud line |
| Affected businesses or partners | As soon as practicable if their data or systems are at risk | Direct contact |
When notifying individuals, your statement must include: your business name and contact details, a description of the breach, the kinds of information involved, and recommended steps people should take (changing passwords, monitoring bank statements, contacting IDCARE — Australia's free identity support service — on 1800 595 160).
Two practical tips. First, notify your insurer early — many cyber insurance policies require it and can void cover if you engage responders without approval. Second, resist the urge to downplay the breach in your communications. Vague or minimising statements almost always come back to bite, both legally and reputationally. Customers respect honesty; they don't respect spin.
Step 5: Recover and Rebuild Trust
With containment done and notifications made, recovery has two tracks: technical and reputational.
Technical recovery
- Rebuild, don't just clean. Compromised machines should be wiped and rebuilt from known-good images, not just scanned with antivirus. Attackers leave persistence mechanisms that scanners miss.
- Restore from backups that predate the breach — and verify they're clean before restoring. This is where a tested disaster recovery plan pays for itself many times over.
- Reset all credentials, not just the obviously affected ones. If the attacker had access to one mailbox, assume they harvested passwords from it.
- Close the door they came through. Patch the vulnerability, enforce MFA everywhere, remove unused accounts, and review admin access.
- Monitor for follow-up attacks. Breached businesses are frequently re-targeted within weeks. Dark web monitoring can tell you if your stolen credentials are circulating.
Reputational recovery
Keep affected people updated as you learn more, provide a single point of contact for questions, and — once the dust settles — tell customers what you've changed. “Here's what happened, here's what we've done about it” is a genuinely trust-building message when it's backed by real action.
Not sure whether your business could contain a breach — or even detect one? We'll assess your current security posture for free and give you a plain-English report on where you stand. No jargon, no pressure.
Book Your Free Assessment →Step 6: Run a Post-Incident Review
Within a couple of weeks of the incident closing, sit down (with your IT provider if you have one) and answer honestly:
- How did the attacker get in — and would our current controls stop the same attack tomorrow?
- How long between the breach occurring and us noticing? Days? Weeks?
- Did we know who to call and what to do, or did we improvise?
- Were our backups usable? How long did restoration actually take?
- What did this cost us — in dollars, hours, and customer trust?
Then turn the answers into an action plan. For most Australian SMBs, the highest-impact improvements are the ones in the ACSC's Essential Eight: MFA everywhere, prompt patching, restricted admin privileges, and regular tested backups. None of them are exotic, and together they would have prevented the majority of breaches we see hitting small businesses.
The Bottom Line
A data breach doesn't have to be a catastrophe — but only if you act fast, in the right order: contain, assess, meet your NDB obligations, notify honestly, recover properly, and fix the root cause. The businesses that come out of a breach with their reputation intact are the ones that moved quickly and communicated openly.
The businesses that suffer most are the ones that had no plan, no monitoring, and no idea what data they even held. If that description is uncomfortably close to home, the best time to fix it is before the breach — and our cybersecurity services are built for exactly this: giving Australian SMBs enterprise-grade protection, detection, and a team on call when something goes wrong.