Better Networks
Cyber security incident response for a hacked Geelong business

24 June 2026 · Better Networks

What to Do When Your Business Has Been Hacked

Most small businesses will face a security incident at some point. It might be a compromised email account, a ransomware infection, or a staff member clicking a convincing phishing link. What separates a costly disaster from a manageable inconvenience is how you respond in the first hour. A calm, ordered response saves money, limits data loss, and gets you back to work faster.

This guide walks through what to do when your Geelong business has been hacked, from the first 60 minutes through to recovery and reporting. If you are dealing with an active incident right now, skip ahead to getting help and call us - we respond to live breaches for businesses across Geelong, the Bellarine, and the Surf Coast.

How to tell you have been hacked

Attacks are not always obvious. Some announce themselves with a ransom note on every screen, but many run quietly for days or weeks. Watch for these signs:

  • Unusual sign-ins or login alerts from locations you do not recognise, often late at night.
  • Devices suddenly running slowly, fans spinning hard, or crashing for no clear reason.
  • Files being locked, renamed, or given strange extensions like .locked or .encrypted.
  • A ransom note appearing on your desktop or inside affected folders.
  • Missing funds, unexplained invoices, or payments sent to changed bank details.
  • Customers receiving spam or strange messages that appear to come from your email address.
  • Microsoft 365 alerts about suspicious activity, new mail-forwarding rules, or unfamiliar app sign-ins.

If two or more of these show up at once, treat it as a real incident and move quickly.

The first 60 minutes

The first hour matters more than any other. The goal is not to fix everything - it is to stop the bleeding and preserve evidence. Work through these steps in order:

  1. Stay calm. Panic leads to bad calls, like wiping a machine that held the only clue to how the attacker got in. Take a breath and move deliberately.
  2. Isolate affected devices. Disconnect them from the network and WiFi - pull the cable, turn WiFi off, or switch off the router if you have to. Do not power the devices off. Shutting down destroys the contents of memory, which often holds the evidence you need to understand the attack.
  3. Do not delete anything. No wiping browsers, no clearing logs, no removing suspicious files. Every artefact is a clue for later investigation.
  4. Note what you see. Photograph ransom notes, copy down error messages, note the time things happened, and list which accounts or machines look affected. A short timeline now saves hours later.
  5. Contact your IT or cyber security provider. Get an expert involved early. If you do not have one, contact us at Better Networks.

Contain the damage

Once the affected devices are isolated, the next job is to stop the attacker moving further or coming back. Do this from a known-clean device - not the machine you suspect is compromised.

  • Reset passwords, starting with admin and email accounts. These are the keys to the kingdom. Use a clean device and a different network if possible.
  • Disable compromised accounts so the attacker cannot sign back in while you clean up.
  • Revoke active sessions and tokens in Microsoft 365 and any cloud apps, which forces everyone to sign in again with the new passwords.
  • Block known bad IP addresses and any unfamiliar locations in your firewall and conditional access rules.
  • Preserve the logs. Export Microsoft 365 audit logs, firewall logs, and sign-in logs before they roll over. You will need them to scope the breach and for any insurance or police report.

Work out what happened and what was taken

Containment buys you time. Now you need to understand the scope: which systems were touched, what data was taken, and how the attacker got in. Without answers to those three questions, you risk cleaning up the symptoms while the root cause stays open.

Start with the Microsoft 365 audit log. Look for unusual sign-ins, mailbox access from new locations, and large downloads. Pay close attention to email rules - attackers love to create hidden inbox rules that forward incoming messages to an external address or move them straight to a buried folder. These rules often survive a password reset, so delete any you did not create.

Check which files were accessed or downloaded from SharePoint and OneDrive, and review any new app consent prompts in Entra ID. Attackers sometimes grant themselves a backdoor app that keeps reading your mail long after the password changes. This scoping work is fiddly and easy to get wrong, which is why most Geelong businesses bring in a cyber security provider for it.

Recover safely

Recovery is where businesses tend to relapse. If you restore systems before the entry point is closed, the attacker walks straight back in. Follow this sequence:

  • Confirm the entry point is fixed - patched vulnerability, revoked stolen token, removed backdoor app, whatever it was.
  • Rebuild affected machines from clean images rather than trying to clean them in place. You can never be fully sure a compromised machine is safe again.
  • Restore data from verified, pre-incident backups. Scan backups before you restore them - ransomware can sit quietly in backups for weeks.
  • Watch closely for persistence and backdoors in the first week after recovery. Re-infection inside 48 hours is common when something has been missed.

Bring systems back one at a time, in order of importance, and verify each before moving on. A phased return is slower than flipping everything on at once, but it is far safer.

Report it

Reporting is not optional, and it is in your interest. The right reports unlock help, satisfy your insurance, and may be legally required.

  • ReportCyber at acsc.gov.au.This is the Australian Cyber Security Centre's national reporting portal. It is free, and the information helps track active campaigns targeting local businesses.
  • Police. If money has been stolen, file a report with your local police. Your cyber insurance will usually require a police report number before paying out.
  • Notify affected clients. If customer data was exposed, tell them promptly and honestly. A clear, early notification builds far more trust than a denial that falls apart later.
  • Notifiable Data Breaches scheme. If personal information was involved and the breach is likely to cause serious harm, you may be legally required to notify the Office of the Australian Information Commissioner.

Stop it happening again

Once you are back up, the focus shifts to making sure this does not repeat. The basics that prevent most attacks are unglamorous but they work:

  • Multi-factor authentication on every account, especially email and admin. MFA blocks the overwhelming majority of credential-stuffing attacks.
  • Consistent patching of operating systems, browsers, and third-party apps. Most intrusions start with a known, already-patched vulnerability.
  • Essential Eight basics.The ACSC's Essential Eight is a practical baseline for small-business defence. See our Essential Eight compliance service and our Essential Eight cyber security guide for what is involved.
  • Staff training. A five-minute phishing refresh every quarter stops more attacks than any single piece of software.

Getting help

You do not have to work through this alone. Better Networks runs incident response and ongoing cyber security for small and mid-sized businesses across Geelong, the Bellarine, and the Surf Coast. We help you contain the attack, scope what was taken, recover safely, and put the controls in place to prevent a repeat.

If you are mid-incident, head straight to our cyber security services page or contact us directly. The sooner we are involved, the shorter and cheaper your recovery will be.

FAQ

Hacked? FAQs

Straight answers, no fluff.

No. Powering off can destroy valuable evidence stored in memory and makes it harder to work out how the attacker got in. Disconnect it from the network or WiFi instead so it cannot talk to anything else, then leave it running and call your IT or cyber security provider.

We do not recommend it. Paying does not guarantee you will get your data back, it marks you as a willing payer for future attacks, and in some cases it is illegal under Australian sanctions law. Focus on restoring from clean backups and closing the entry point instead. Talk to us before you respond to any ransom demand.

Check your audit logs - Microsoft 365, your firewall, and any cloud apps - for unusual sign-ins, large downloads, or new mail-forwarding rules. Attackers often quietly copy data for weeks before you notice. If personal information was involved, you may need to notify people under the Notifiable Data Breaches scheme.

It depends on the scope. A single compromised email account is often contained and recovered within a day. A ransomware attack that has spread across multiple machines can take one to three weeks to fully rebuild and verify. The faster you isolate and get help, the shorter and cheaper the recovery.

You can take the first isolation steps yourself, but proper incident response - scoping the breach, removing backdoors, safely restoring systems, and reporting - is best done with a cyber security provider. Doing it alone risks missing persistence left by the attacker and re-infection a few days later.

Get Started

Think you have been hacked? We can help right now.

If you are dealing with an active incident, contact us. We will help you contain it, work out what happened and get you back up safely.

Book a Free Call →