From panic to a practical response plan
The right solution depends on the evidence, not the loudest symptom. A ransomware note, suspicious login, fake invoice, lost laptop or strange phone setting all need different handling. This page groups the common response pathways.
Preserve evidence first
Capture screenshots, original messages, logs, device details and a timeline before changing systems aggressively.
Contain the risk
Secure accounts, isolate affected systems, revoke suspicious access and stop avoidable loss without destroying evidence.
Assess impact
Identify affected people, systems, payments, files, customers, suppliers and privacy obligations.
Prepare the right referral
Some matters need forensic specialists; others need IT, lawyers, insurers, police, banks, platforms or safety services.
Solution pathways by issue
- Phishing investigation
- Ransomware response
- Business email compromise
- Insider misuse investigation
- Spyware and monitoring concerns
- Data breach investigation
- Website compromise triage
- Identity theft and account takeover
A solution does not always mean a full forensic investigation. Sometimes the best outcome is a clear brief, urgent containment and referral to the correct specialist pathway.
Related help
Evidence checklist
A practical list of what to preserve before logs, screenshots or account records disappear.
Request specialist consultation
Send the facts you have and we will help organise the next steps.
Australian cyber resources
Helpful public resources for cyber, privacy, scams and online safety.