If something is wrong, start here.
Every step here works before anyone has replied to you.
The first hour.
Each step preserves evidence and shortens the response.
Isolate affected machines.
Disconnect affected machines from the network: pull the cable, drop the Wi-Fi, pause the VM. Do not wipe, reinstall, or "clean up". Responders need that evidence to establish how access happened and confirm it is closed.
Preserve what you can.
Keep logs, screenshots, ransom notes, odd emails, anything that looks wrong. Note times as you go: a plain timeline of what you saw and when is the most useful document you can hand a responder.
Contain accounts.
From a known-clean device, reset credentials for admin and email accounts, revoke active sessions, and turn on multi-factor authentication where it is missing. Do not make these changes from a machine that may be compromised.
Engage your insurer.
Cyber policies often require notification before action is taken. Do not pay, reply or negotiate without help; get advice before communicating with an attacker in any form.
Know your notification clock.
If personal information is likely involved, the Privacy Act's Notifiable Data Breaches scheme may apply, and the assessment it requires has to be prompt. We support that assessment; we do not give legal advice.
Then reach us.
Email info@blackshard.com.au with URGENT in the subject, or use the contact form on the breach track.
Who answers: senior engineers who do containment, root-cause analysis and remediation engineering.
The full service: breach remediation & incident responseIf it turns out to be nothing
Sending this one email costs nothing if it turns out to be a false alarm. If you would rather not need any of this again, incident readiness builds the plan, the practice run, and the tested recovery before you need any of it.
Containment, root cause, and remediation, handled end to end.
Brisbane head office. Work delivered across Australia.

