Pillar · Essential 8 + Cyber Compliance

Cyber incident response. Five phases. Seven regulators. Forty-eight hours to know.

An incident-response plan is the difference between a 3-day disruption and a 3-month catastrophe. Five phases (detect / contain / eradicate / recover / notify), seven potential regulators (OAIC + APRA + ASIC + ASX + Home Affairs SOCI + ACSC + insurer), notification windows from 12 hours to 30 days. Build the runbook before you need it.

Why this lives on XIntelliSync, not on a DFIR consultancy

Incident response on a real cyber breach requires a Digital Forensics and Incident Response (DFIR) firm, cyber-specialist legal counsel, and an executive decision-maker on call. None of that runs on XIntelliSync. We do not provide incident-response services, do not author your IR plan, do not run your tabletop exercises, and do not engage with attackers on your behalf. What XIntelliSync DOES: the platform's own incident response (for any incident affecting XIntelliSync infrastructure) is documented in our /trust + /security surfaces. Your customer-side IR plan sits with your IT team and your DFIR retainer. The article below is the four-phase IR framework (preparation / detection / containment / recovery + lessons-learned) and the regulator-notification matrix (NDB to OAIC + ACSC for SOCI + APRA for APRA-regulated entities + ASIC for material disclosure).

← Essential 8 + Cyber pillar · See how XGVS works →

Five-phase NIST IR framework

Detect → Contain → Eradicate → Recover → Notify.

1

Detect

Goal: TTD < 24 hours

Detection sources: SIEM alerts (Microsoft Sentinel, Splunk, Elastic), endpoint detection (CrowdStrike, SentinelOne, Defender for Endpoint), user reports, customer complaints, third-party notification (ACSC + competitor incidents). Time-to-detect (TTD) is the leading indicator of mature security — target < 24 hours.

2

Contain

Goal: containment within 4-12 hours of detection

Network isolation (VLAN segmentation, firewall block rules), credential rotation for compromised accounts, MFA reset, session revocation, system isolation (offline backups + forensic image), supplier notification if supply-chain involved. Goal: stop the bleeding without destroying evidence.

3

Eradicate

Goal: eradication within 5-14 days

Root-cause analysis (forensic investigation), IOC (indicator of compromise) removal, vulnerability remediation (patch the original entry vector), threat-actor persistence removal (backdoors, scheduled tasks, service accounts), credential reset for entire affected scope, threat-intelligence sharing.

4

Recover

Goal: business continuity within 24-72 hours

Restore from clean backups (verified backup integrity), staged restoration with monitoring, regression testing, customer-facing service restoration with phased rollout, hardened configuration to prevent recurrence, lessons-learned post-incident review documented.

5

Notify

Goal: regulatory notifications within obligation windows

Layered notification: NDB to OAIC + affected individuals within 30 days (Privacy Act Pt IIIC); APRA notification within 72 hours for APRA-regulated entities (CPS 234); ASIC RG 78 breach reporting for AFSL holders; ASX continuous disclosure if listed; ACSC voluntary reporting via cyber.gov.au; SOCI Act 12-hour-significant + 72-hour-other for critical infrastructure; cyber-insurer notification per policy terms.

Seven-regulator notification matrix

Which regulator. Which trigger. Which window.

OAIC (NDB scheme)

Within 30 days of awarenessYes for APP entities

Trigger — Eligible data breach (likely serious harm)

Portal — oaic.gov.au/privacy/notifiable-data-breaches/report-a-data-breach

APRA (CPS 234)

Within 72 hoursYes for APRA-regulated

Trigger — Material info-security incident

Portal — apra.gov.au incident notification

ASIC (RG 78)

Per RG 78 timeline (typically 30 days)Yes for AFSL holders

Trigger — Significant breach affecting financial services

Portal — asic.gov.au breach reporting

ASX (continuous disclosure)

Immediately upon awarenessYes for listed entities

Trigger — Material price-sensitive incident

Portal — asx.com.au market announcements platform

SOCI Act (Home Affairs)

12 hours significant / 72 hours otherYes for critical infrastructure

Trigger — Significant cyber security incident

Portal — cisc.gov.au cyber incident reporting

ACSC (voluntary)

As soon as practicableVoluntary

Trigger — Any cyber security incident

Portal — cyber.gov.au/report ReportCyber

Cyber insurer

Per policy (often within 72 hours)Yes per policy

Trigger — Per policy notification clause

Portal — Per insurer claims process

All 22+ industries served

Likely cyber incident scenario per industry.

Construction

Likely incident scenario — Compromised email account redirects supplier payment $50k-$500k to attacker bank account. Often discovered weeks later when supplier follows up unpaid invoice.

Healthcare

Likely incident scenario — Ransomware encrypts practice-management database. Medicare numbers + clinical notes + DD payment details all in scope. NDB notification mandatory + AHPRA professional notification + class-action exposure.

Hospitality

Likely incident scenario — POS or e-commerce platform breach exposes 10,000+ customer card details. Forensic + PCI-DSS investigation + NDB notification. Reputational + financial harm cascade.

Retail

Likely incident scenario — E-commerce checkout-page Magecart skimmer harvests card data + email + address from every checkout for weeks before detection. NDB notification to thousands of customers + PCI fines.

Professional Services / Consulting

Likely incident scenario — Spear-phishing compromise of partner email leads to engagement-server access. Client business plans + financials + PII exposed. Client breach-notification cascade + reputational damage.

Digital / Tech / SaaS

Likely incident scenario — Production database credential leaked via misconfigured cloud bucket OR supply-chain compromise of dependency. Multi-tenant SaaS breach cascades NDB to every customer.

Finance / Mortgage Brokers

Likely incident scenario — BEC on settlement redirects $300k-$1M to attacker bank. Mortgage broker liable + customer harm + ASIC breach reporting + insurance dispute cascade.

Legal

Likely incident scenario — Email compromise leads to settlement-funds redirection. Privileged matter content exposed. Law Society notification + client breach-notification + ASIC + criminal investigation cascade.

Childcare / Early Learning

Likely incident scenario — Centre-management-software breach exposes CCS + immunisation + DD payment details + identifiable child photos. NDB notification + ACECQA notification + parental class-action exposure.

Education / RTOs

Likely incident scenario — SIS breach exposes student TFNs + USIs + assessment records + financial assistance details. Multi-thousand NDB notification + ASQA + ACNC (if charitable) cascade.

Manufacturing

Likely incident scenario — Ransomware halts production line for 1-7 days. ERP breach exposes customer + supplier + employee data. Business-interruption claim + NDB cascade.

Transport / Logistics

Likely incident scenario — Ransomware on dispatch system halts deliveries. Customer + driver PII exposed. NDB notification + supply-chain customer notification + business-interruption claim.

Mining / Resources

Likely incident scenario — Foreign-state-linked actor compromises operational technology + exfiltrates exploration data. ASX continuous-disclosure trigger + SOCI Act notification + ACSC notification cascade.

Agriculture / Primary Production

Likely incident scenario — BEC on grain-buyer payment redirects $50k-$500k. Farm-management-software breach exposes seasonal worker WHM passport copies + buyer data.

Fitness / Health Clubs

Likely incident scenario — Member-management-software breach exposes health screening + DD payment + biometric templates. NDB notification + fitness-industry-association notification + reputational cascade.

Not-for-Profit

Likely incident scenario — CRM breach exposes donor giving history + beneficiary case notes + financial details. Beneficiary harm > donor harm; trauma-informed NDB notification critical.

Events / Conferences

Likely incident scenario — Ticketing platform breach exposes attendee names + dietary needs + payment details. NDB notification + sponsor notification + reputational cascade.

Creative / Photography / Production

Likely incident scenario — Cloud-storage credential leak exposes client deliverables + image archive. Identifiable minors or sensitive-context shots = high-severity NDB + class-action exposure.

Marketing / Advertising Agencies

Likely incident scenario — Email-marketing platform breach exposes subscriber lists + segmentation tags + campaign data. NDB notification + client breach-notification cascade across multiple clients.

HR / Recruitment

Likely incident scenario — ATS breach exposes candidate resumes + reference checks + bank details for placed candidates. NDB notification cascade across multiple employer clients + candidate harm.

Insurance Brokers / Underwriters

Likely incident scenario — Claims-management-system breach exposes medical reports + claim payouts + financial-position data. APRA + ASIC + NDB cascade. Re-insurance partner exposure adds international scope.

Real Estate / Property Management

Likely incident scenario — BEC on settlement redirects $500k-$2M from purchaser to attacker bank. Real-estate agency liable + customer + bank dispute + NDB if data exposed.

FAQs

Cyber incident response — answered.

Why does the notify phase have so many regulators?

Australia has overlapping regulatory regimes: OAIC for personal-information breaches (NDB scheme); APRA for APRA-regulated entities; ASIC for financial-services entities; ASX for listed entities; Department of Home Affairs (CISC) for critical infrastructure (SOCI Act). A single incident may trigger multiple notification obligations simultaneously. Build the notification matrix into your incident response plan + know which regulators apply to your business BEFORE the incident.

How fast is "as fast as possible" for SOCI Act?

SOCI Act distinguishes two categories. (1) Significant cyber security incident — actually has, is having, or could have a significant impact on availability of essential services or significant impact on the integrity / confidentiality of essential services. Notification within 12 hours of becoming aware. (2) Other cyber security incident — material relevant impact. Notification within 72 hours. Significance assessment matters — over-report rather than under-report.

Should I do incident response in-house or hire a DFIR firm?

Most Australian SMBs benefit from a hybrid approach. In-house: detection (SIEM + EDR), initial triage, containment, communication. Engaged DFIR partner: forensic investigation, evidence preservation, threat-actor attribution, regulatory liaison, recovery validation. Top AU DFIR firms: CyberCX, Mandiant, Crowdstrike Services, KordaMentha Cyber, McGrathNicol Cyber. Pre-engagement (retainer) cuts response time + ensures forensic-grade evidence handling.

What is a tabletop exercise and how often should we run one?

Tabletop exercise = scenario-driven walkthrough of incident-response plan with key stakeholders (IT + security + legal + comms + executive). Tests: do we have the runbook? do we know who calls who? what regulators do we notify? what does the timeline actually look like? Frequency: every 6 months minimum + after any material change to systems / staff / regulatory environment. Insurers + customers increasingly require evidence of recent tabletop.

How do we handle ransomware that demands payment?

Five-step decision: (1) AUSTRAC + sanctions screening — paying a sanctioned entity is criminal regardless of duress. (2) Insurer notification + approval — most policies require pre-payment approval + use of approved negotiator. (3) Engage registered ransomware negotiator (CyberCX, Coveware, Arete) — never negotiate yourself. (4) Verify decryption capability — only ~50-70% of payments result in working decryption. (5) Plan for follow-on attacks — ~30-40% of paid victims face follow-on attacks within 12 months. ACSC + AFP advice: avoid payment if possible; if paid, expect follow-on targeting.

What records should we keep during incident response?

Forensic-grade incident log: timestamp + observation + action taken + decision-maker + evidence preserved. Treat every note as potentially admissible in regulatory or legal proceedings. Preserve: system logs (SIEM, EDR, firewall, DNS, email gateway), network captures, memory snapshots of affected systems, communication records (incident response Slack / Teams channel), executive decision documentation. Retain for 7 years minimum (Privacy Act + APRA + ASIC overlapping retention requirements).

How does XIntelliSync help with incident response?

XIntelliSync does NOT provide incident-response plan templates, does NOT maintain your regulator-notification matrix, does NOT run tabletop exercises, and does NOT track customer-side controls that affect your insurance posture. Incident response on a real cyber breach requires a DFIR firm + cyber-specialist legal counsel + an executive decision-maker on call — engage those before an incident, not during one. What XIntelliSync DOES: the platform's own incident response is documented in our /trust + /security surfaces; XGVS Stage 5 catches NDB-class silent-failure breaches on the platform itself. Your customer-side IR plan sits with your IT team and your DFIR retainer.