Cyber incident response. Five phases. Seven regulators. Forty-eight hours to know.
An incident-response plan is the difference between a 3-day disruption and a 3-month catastrophe. Five phases (detect / contain / eradicate / recover / notify), seven potential regulators (OAIC + APRA + ASIC + ASX + Home Affairs SOCI + ACSC + insurer), notification windows from 12 hours to 30 days. Build the runbook before you need it.
Why this lives on XIntelliSync, not on a DFIR consultancy
Incident response on a real cyber breach requires a Digital Forensics and Incident Response (DFIR) firm, cyber-specialist legal counsel, and an executive decision-maker on call. None of that runs on XIntelliSync. We do not provide incident-response services, do not author your IR plan, do not run your tabletop exercises, and do not engage with attackers on your behalf. What XIntelliSync DOES: the platform's own incident response (for any incident affecting XIntelliSync infrastructure) is documented in our /trust + /security surfaces. Your customer-side IR plan sits with your IT team and your DFIR retainer. The article below is the four-phase IR framework (preparation / detection / containment / recovery + lessons-learned) and the regulator-notification matrix (NDB to OAIC + ACSC for SOCI + APRA for APRA-regulated entities + ASIC for material disclosure).
Five-phase NIST IR framework
Detect → Contain → Eradicate → Recover → Notify.
Detect
Goal: TTD < 24 hours
Detection sources: SIEM alerts (Microsoft Sentinel, Splunk, Elastic), endpoint detection (CrowdStrike, SentinelOne, Defender for Endpoint), user reports, customer complaints, third-party notification (ACSC + competitor incidents). Time-to-detect (TTD) is the leading indicator of mature security — target < 24 hours.
Contain
Goal: containment within 4-12 hours of detection
Network isolation (VLAN segmentation, firewall block rules), credential rotation for compromised accounts, MFA reset, session revocation, system isolation (offline backups + forensic image), supplier notification if supply-chain involved. Goal: stop the bleeding without destroying evidence.
Eradicate
Goal: eradication within 5-14 days
Root-cause analysis (forensic investigation), IOC (indicator of compromise) removal, vulnerability remediation (patch the original entry vector), threat-actor persistence removal (backdoors, scheduled tasks, service accounts), credential reset for entire affected scope, threat-intelligence sharing.
Recover
Goal: business continuity within 24-72 hours
Restore from clean backups (verified backup integrity), staged restoration with monitoring, regression testing, customer-facing service restoration with phased rollout, hardened configuration to prevent recurrence, lessons-learned post-incident review documented.
Notify
Goal: regulatory notifications within obligation windows
Layered notification: NDB to OAIC + affected individuals within 30 days (Privacy Act Pt IIIC); APRA notification within 72 hours for APRA-regulated entities (CPS 234); ASIC RG 78 breach reporting for AFSL holders; ASX continuous disclosure if listed; ACSC voluntary reporting via cyber.gov.au; SOCI Act 12-hour-significant + 72-hour-other for critical infrastructure; cyber-insurer notification per policy terms.
Seven-regulator notification matrix
Which regulator. Which trigger. Which window.
OAIC (NDB scheme)
Within 30 days of awarenessYes for APP entitiesTrigger — Eligible data breach (likely serious harm)
Portal — oaic.gov.au/privacy/notifiable-data-breaches/report-a-data-breach
APRA (CPS 234)
Within 72 hoursYes for APRA-regulatedTrigger — Material info-security incident
Portal — apra.gov.au incident notification
ASIC (RG 78)
Per RG 78 timeline (typically 30 days)Yes for AFSL holdersTrigger — Significant breach affecting financial services
Portal — asic.gov.au breach reporting
ASX (continuous disclosure)
Immediately upon awarenessYes for listed entitiesTrigger — Material price-sensitive incident
Portal — asx.com.au market announcements platform
SOCI Act (Home Affairs)
12 hours significant / 72 hours otherYes for critical infrastructureTrigger — Significant cyber security incident
Portal — cisc.gov.au cyber incident reporting
ACSC (voluntary)
As soon as practicableVoluntaryTrigger — Any cyber security incident
Portal — cyber.gov.au/report ReportCyber
Cyber insurer
Per policy (often within 72 hours)Yes per policyTrigger — Per policy notification clause
Portal — Per insurer claims process
Where to report cyber incidents
Authoritative ACSC + OAIC + APRA + ASIC + Home Affairs portals.
ACSC ReportCyber — cyber.gov.au/report
National cyber-incident reporting portal. Voluntary for most SMBs; mandatory for SOCI Act + APRA-regulated entities. Hotline 1300 CYBER1 (1300 292 371) for urgent reports.
OAIC NDB Form — oaic.gov.au notifiable-data-breaches
Mandatory for APP entities when an eligible data breach likely results in serious harm. 30-day clock from awareness. See Pillar #4 NDB cluster for full workflow.
APRA CPS 234 Incident Notification
Mandatory 72-hour notification of material info-security incidents for APRA-regulated entities. 10-business-day notification of material info-security weaknesses.
CISC SOCI Act Cyber Incident Reporting
Cyber and Infrastructure Security Centre — mandatory cyber-incident reporting under SOCI Act 2018. 12-hour-significant + 72-hour-other for critical infrastructure across 11 sectors.
ASX Continuous Disclosure
Listed entities must immediately disclose price-sensitive cyber incidents under Listing Rule 3.1. ASX market-announcements platform for the disclosure.
All 22+ industries served
Likely cyber incident scenario per industry.
Construction
Likely incident scenario — Compromised email account redirects supplier payment $50k-$500k to attacker bank account. Often discovered weeks later when supplier follows up unpaid invoice.
Healthcare
Likely incident scenario — Ransomware encrypts practice-management database. Medicare numbers + clinical notes + DD payment details all in scope. NDB notification mandatory + AHPRA professional notification + class-action exposure.
Hospitality
Likely incident scenario — POS or e-commerce platform breach exposes 10,000+ customer card details. Forensic + PCI-DSS investigation + NDB notification. Reputational + financial harm cascade.
Retail
Likely incident scenario — E-commerce checkout-page Magecart skimmer harvests card data + email + address from every checkout for weeks before detection. NDB notification to thousands of customers + PCI fines.
Professional Services / Consulting
Likely incident scenario — Spear-phishing compromise of partner email leads to engagement-server access. Client business plans + financials + PII exposed. Client breach-notification cascade + reputational damage.
Digital / Tech / SaaS
Likely incident scenario — Production database credential leaked via misconfigured cloud bucket OR supply-chain compromise of dependency. Multi-tenant SaaS breach cascades NDB to every customer.
Finance / Mortgage Brokers
Likely incident scenario — BEC on settlement redirects $300k-$1M to attacker bank. Mortgage broker liable + customer harm + ASIC breach reporting + insurance dispute cascade.
Legal
Likely incident scenario — Email compromise leads to settlement-funds redirection. Privileged matter content exposed. Law Society notification + client breach-notification + ASIC + criminal investigation cascade.
Childcare / Early Learning
Likely incident scenario — Centre-management-software breach exposes CCS + immunisation + DD payment details + identifiable child photos. NDB notification + ACECQA notification + parental class-action exposure.
Education / RTOs
Likely incident scenario — SIS breach exposes student TFNs + USIs + assessment records + financial assistance details. Multi-thousand NDB notification + ASQA + ACNC (if charitable) cascade.
Manufacturing
Likely incident scenario — Ransomware halts production line for 1-7 days. ERP breach exposes customer + supplier + employee data. Business-interruption claim + NDB cascade.
Transport / Logistics
Likely incident scenario — Ransomware on dispatch system halts deliveries. Customer + driver PII exposed. NDB notification + supply-chain customer notification + business-interruption claim.
Mining / Resources
Likely incident scenario — Foreign-state-linked actor compromises operational technology + exfiltrates exploration data. ASX continuous-disclosure trigger + SOCI Act notification + ACSC notification cascade.
Agriculture / Primary Production
Likely incident scenario — BEC on grain-buyer payment redirects $50k-$500k. Farm-management-software breach exposes seasonal worker WHM passport copies + buyer data.
Fitness / Health Clubs
Likely incident scenario — Member-management-software breach exposes health screening + DD payment + biometric templates. NDB notification + fitness-industry-association notification + reputational cascade.
Not-for-Profit
Likely incident scenario — CRM breach exposes donor giving history + beneficiary case notes + financial details. Beneficiary harm > donor harm; trauma-informed NDB notification critical.
Events / Conferences
Likely incident scenario — Ticketing platform breach exposes attendee names + dietary needs + payment details. NDB notification + sponsor notification + reputational cascade.
Creative / Photography / Production
Likely incident scenario — Cloud-storage credential leak exposes client deliverables + image archive. Identifiable minors or sensitive-context shots = high-severity NDB + class-action exposure.
Marketing / Advertising Agencies
Likely incident scenario — Email-marketing platform breach exposes subscriber lists + segmentation tags + campaign data. NDB notification + client breach-notification cascade across multiple clients.
HR / Recruitment
Likely incident scenario — ATS breach exposes candidate resumes + reference checks + bank details for placed candidates. NDB notification cascade across multiple employer clients + candidate harm.
Insurance Brokers / Underwriters
Likely incident scenario — Claims-management-system breach exposes medical reports + claim payouts + financial-position data. APRA + ASIC + NDB cascade. Re-insurance partner exposure adds international scope.
Real Estate / Property Management
Likely incident scenario — BEC on settlement redirects $500k-$2M from purchaser to attacker bank. Real-estate agency liable + customer + bank dispute + NDB if data exposed.
FAQs
Cyber incident response — answered.
Why does the notify phase have so many regulators?
Australia has overlapping regulatory regimes: OAIC for personal-information breaches (NDB scheme); APRA for APRA-regulated entities; ASIC for financial-services entities; ASX for listed entities; Department of Home Affairs (CISC) for critical infrastructure (SOCI Act). A single incident may trigger multiple notification obligations simultaneously. Build the notification matrix into your incident response plan + know which regulators apply to your business BEFORE the incident.
How fast is "as fast as possible" for SOCI Act?
SOCI Act distinguishes two categories. (1) Significant cyber security incident — actually has, is having, or could have a significant impact on availability of essential services or significant impact on the integrity / confidentiality of essential services. Notification within 12 hours of becoming aware. (2) Other cyber security incident — material relevant impact. Notification within 72 hours. Significance assessment matters — over-report rather than under-report.
Should I do incident response in-house or hire a DFIR firm?
Most Australian SMBs benefit from a hybrid approach. In-house: detection (SIEM + EDR), initial triage, containment, communication. Engaged DFIR partner: forensic investigation, evidence preservation, threat-actor attribution, regulatory liaison, recovery validation. Top AU DFIR firms: CyberCX, Mandiant, Crowdstrike Services, KordaMentha Cyber, McGrathNicol Cyber. Pre-engagement (retainer) cuts response time + ensures forensic-grade evidence handling.
What is a tabletop exercise and how often should we run one?
Tabletop exercise = scenario-driven walkthrough of incident-response plan with key stakeholders (IT + security + legal + comms + executive). Tests: do we have the runbook? do we know who calls who? what regulators do we notify? what does the timeline actually look like? Frequency: every 6 months minimum + after any material change to systems / staff / regulatory environment. Insurers + customers increasingly require evidence of recent tabletop.
How do we handle ransomware that demands payment?
Five-step decision: (1) AUSTRAC + sanctions screening — paying a sanctioned entity is criminal regardless of duress. (2) Insurer notification + approval — most policies require pre-payment approval + use of approved negotiator. (3) Engage registered ransomware negotiator (CyberCX, Coveware, Arete) — never negotiate yourself. (4) Verify decryption capability — only ~50-70% of payments result in working decryption. (5) Plan for follow-on attacks — ~30-40% of paid victims face follow-on attacks within 12 months. ACSC + AFP advice: avoid payment if possible; if paid, expect follow-on targeting.
What records should we keep during incident response?
Forensic-grade incident log: timestamp + observation + action taken + decision-maker + evidence preserved. Treat every note as potentially admissible in regulatory or legal proceedings. Preserve: system logs (SIEM, EDR, firewall, DNS, email gateway), network captures, memory snapshots of affected systems, communication records (incident response Slack / Teams channel), executive decision documentation. Retain for 7 years minimum (Privacy Act + APRA + ASIC overlapping retention requirements).
How does XIntelliSync help with incident response?
XIntelliSync does NOT provide incident-response plan templates, does NOT maintain your regulator-notification matrix, does NOT run tabletop exercises, and does NOT track customer-side controls that affect your insurance posture. Incident response on a real cyber breach requires a DFIR firm + cyber-specialist legal counsel + an executive decision-maker on call — engage those before an incident, not during one. What XIntelliSync DOES: the platform's own incident response is documented in our /trust + /security surfaces; XGVS Stage 5 catches NDB-class silent-failure breaches on the platform itself. Your customer-side IR plan sits with your IT team and your DFIR retainer.
Continue reading