#AustralianBusiness
Jul 06, 2026
9min read

What To Do in the First 72 Hours After a Data Breach

What To Do in the First 72 Hours After a Data Breach

The moment you realise your organisation has suffered a data breach, the clock starts ticking. Those first three days are messy, stressful, and absolutely critical. What you do — or fail to do — in the first 72 hours can shape everything that follows: your legal standing, your reputation, and the trust your customers place in you.

This isn't a theory. Australian businesses face data breaches every single day, and according to industry reports from the Office of the Australian Information Commissioner (OAIC), human error and malicious attacks remain leading causes of notifiable incidents. Whether you run a small accounting firm in Brisbane or manage IT for a national retailer, the principles below apply.

Let's walk through exactly what you should do, hour by hour, day by day.

Why the First 72 Hours Matter So Much

There's a reason regulators around the world keep talking about the 72-hour window. Under the European Union's General Data Protection Regulation (GDPR), organisations must notify the relevant supervisory authority within 72 hours of becoming aware of a breach. Australia's own framework, the Notifiable Data Breaches (NDB) scheme, doesn't set a hard 72-hour rule but requires you to assess and report eligible breaches "as soon as practicable" — and typically within 30 days of becoming aware.

So why focus on 72 hours? Because the early hours decide the outcome. Evidence disappears. Attackers move deeper into systems. Customers start noticing strange activity. And every hour you delay, the damage compounds.

Think of it like a kitchen fire. The first few minutes determine whether you lose a pan or the whole house.

Hour 0 to 6: Contain Before You Do Anything Else

The very first instinct many people have is to start fixing things — deleting suspicious files, wiping infected machines, or shutting everything down in a panic. Resist that urge.

Your first job is containment, not cleanup.

Stop the Bleeding

Isolate affected systems from the network. If a server has been compromised, disconnect it — but don't power it off if you can avoid it. Powering down can destroy volatile data sitting in memory that forensic investigators may need later.

A practical example: a Melbourne logistics company discovered ransomware spreading across their shared drives. Instead of shutting down servers, their IT lead unplugged network cables and disabled Wi-Fi access points. This stopped the spread while preserving evidence. Smart move.

Preserve the Evidence

Take screenshots. Note timestamps. Record who discovered the breach and when. This sounds tedious in the heat of the moment, but a clear timeline becomes priceless later — both for investigators and for any regulatory reporting.

Assemble Your Response Team

You need the right people in the room fast. This usually includes:

  • Your IT or security lead, a senior decision-maker, and someone from legal or compliance

  • A communications person to manage internal and external messaging

If you've already run Notifiable Data Breach Response Training with your team, this is the moment it pays off. People know their roles, they don't freeze, and decisions get made quickly instead of by committee.

Hour 6 to 24: Investigate and Assess

Once the immediate threat is contained, you shift into investigation mode. The big question now is: what actually happened, and how bad is it?

Identify What Data Was Affected

Was it names and email addresses? Or was it Tax File Numbers, Medicare details, credit card data, or health records? The type of information involved directly affects your legal obligations and the level of harm to individuals.

In Australia, the NDB scheme is triggered when a breach is likely to result in serious harm to an individual. Serious harm can be financial, physical, psychological, or reputational. A leaked marketing email list is very different from a leaked database of medical histories.

Determine the Scope

How many records were exposed? Which systems were touched? Did the attacker move laterally into other parts of your network?

This is where forensic expertise matters. If your internal team lacks deep security skills, bring in external incident response specialists early. They've seen these situations dozens of times and can spot things you'll miss.

Document Everything as You Go

Keep a running incident log. Every decision, every finding, every action — with the time it happened. Regulators and lawyers will want this. Insurers, too, if you're making a cyber insurance claim.

Hour 24 to 48: Decide Whether You Must Notify

By now you should have a reasonable picture of the breach. This is when the legal and ethical decisions kick in.

The Australian Notification Rules

Under the NDB scheme, if you have an "eligible data breach" — one likely to cause serious harm — you must notify both:

  1. The affected individuals, and

  2. The OAIC, through their Notifiable Data Breach form.

If you genuinely don't know yet whether the breach qualifies, you're allowed to carry out an assessment. The OAIC expects this assessment to be reasonable and to be completed within 30 days. But "30 days" is a maximum, not a target. The sooner you act, the better.

Remediation Might Save You From Notifying

Here's something many businesses miss. If you take quick remedial action — and that action means serious harm is no longer likely — you may not need to notify at all.

For instance, if an employee accidentally emails a spreadsheet to the wrong client, but you recall the email before it's opened and confirm it wasn't accessed, the risk of serious harm may be eliminated. Document that carefully.

Global Considerations

If your organisation handles data of people in other countries, you may have additional obligations. The GDPR's 72-hour rule applies if EU residents are affected. Many US states have their own breach notification laws. If you operate internationally, loop in legal counsel familiar with each jurisdiction.

DATA BREACH DECISION FLOW (Australia)   Breach detected

         │

         ▼

   Contain & assess

         │

         ▼

   Likely "serious harm"? ──No──► Document & monitor

         │

        Yes

         │

         ▼

   Can remediation remove the risk? ──Yes──► Document, no notice needed

         │

         No

         │

         ▼

   Notify OAIC + affected individuals


Hour 48 to 72: Communicate Clearly and Honestly

If you've decided notification is required, how you communicate matters enormously. Done well, it can actually preserve trust. Done badly, it makes things worse than the breach itself.

Notify the Affected Individuals

Your message to customers or staff should be plain, honest, and helpful. Tell them:

  • What happened, what information was involved, and what you're doing about it

  • What steps they should take to protect themselves

Avoid corporate jargon and avoid downplaying the situation. People can smell spin a mile away. A genuine, straightforward tone goes much further than a polished legal statement.

Give People Practical Advice

If passwords were exposed, tell people to change them and to enable multi-factor authentication. If financial data was involved, suggest they watch their accounts and contact their bank. If identity documents were leaked, point them toward IDCARE, Australia and New Zealand's national identity and cyber support service — a genuinely valuable resource that helps individuals recover from identity theft.

Manage Internal Communication Too

Don't forget your own people. Staff often hear about breaches through rumours or the media before management says anything. That breeds panic and distrust. Keep your team informed with clear, regular updates — even if the update is simply "we're still investigating."

Handle the Media and Public Statements

If the breach is significant, expect questions from journalists. Prepare a holding statement. Be honest about what you know and what you don't. Promising you'll share more as the situation develops is far better than guessing and being proven wrong later.

A short story worth remembering: when a large company faced a major breach a few years back, their initial silence drew more criticism than the breach itself. The lesson stuck with the industry — silence reads as guilt.

Beyond the First 72 Hours: Setting Up for Recovery

The 72-hour mark isn't the finish line. It's the point where you move from crisis response into recovery and prevention. Still, what you set in motion during those first three days shapes everything that follows.

Patch the Hole

Once forensics confirm how the attacker got in, close that gap properly. A rushed fix that leaves the door slightly open invites a repeat attack — and attackers often come back to organisations they've already breached.

Review and Strengthen

Look at what failed. Was it a weak password? An unpatched system? A phishing email someone clicked? Each breach teaches a lesson, if you're willing to learn it.

Update Your Response Plan

If you discovered during the incident that nobody knew who to call, or that your backups were untested, fix that now while it's fresh. The best time to improve your plan is right after it's been tested under fire.

Common Mistakes That Make Breaches Worse

Over the years, certain mistakes show up again and again. Avoid these:

Waiting too long to act. Hoping the problem will quietly disappear is the most expensive decision you can make.

Destroying evidence. Wiping machines or deleting logs out of panic can cripple your investigation and even create legal problems.

Hiding the breach. Failing to notify when you're legally required to can result in significant penalties under Australian privacy law — and the reputational hit when it eventually comes out is far worse.

Vague communication. Telling customers "some data may have been affected" without specifics just makes everyone anxious and angry.

The Human Side of Breach Response

It's easy to treat a data breach as a purely technical event. It isn't. Behind every leaked record is a real person — a customer worried about their bank account, an employee anxious about their personal details, a patient fearing their medical history is now public.

The organisations that handle breaches best are the ones that keep that human element front and centre. They respond with empathy, not just process. They over-communicate rather than under-communicate. And they treat the affected people the way they'd want to be treated.

This mindset doesn't just feel right — it's genuinely good for business. Customers forgive companies that handle a breach honestly. They rarely forgive ones that hide it.

Preparation Is Everything

Here's the uncomfortable truth: the businesses that survive data breaches well are almost never the ones figuring it out on the fly. They're the ones who prepared in advance.

They had a written incident response plan. They knew their legal obligations. They'd practised. They had relationships with forensic specialists and legal advisors already in place. When the breach hit, they didn't waste precious hours scrambling — they executed.

You can't control whether you'll ever face a breach. Statistically, most organisations will at some point. But you absolutely can control how ready you are.

Investing in proper Notifiable Data Breach Response Training for your team is one of the smartest, lowest-cost decisions you can make. It turns a chaotic emergency into a managed process — and that difference can save your reputation, your customers, and potentially your business. Don't wait until a breach forces your hand. Equip your team today so they're ready to respond with confidence when it matters most.