Ransomware Recovery & Cyber Incident Response
If your business has just discovered ransomware, a data breach, or another active cyber incident, you need help now — not a sales pitch. Here’s what to do in the first hour, and how SSDL can step in immediately.
Call SSDL now:
1300 364 722
What to do in the first hour
Isolate affected devices — disconnect them from the network and Wi-Fi, but don’t power them off (this can destroy evidence needed for recovery and insurance claims).
Call SSDL immediately on 1300 364 722 — even if you’re not an existing client, we can advise on immediate containment steps.
Don’t pay a ransom without advice — paying doesn’t guarantee data recovery and can mark you as a repeat target.
Preserve evidence — take photos/screenshots of ransom notes or error messages, and keep logs; this matters for both recovery and any insurance claim.
Know your Notifiable Data Breaches (NDB) obligations — if personal information may have been compromised, Australian businesses may have a legal duty to notify affected individuals and the OAIC. SSDL can help you assess this.
How SSDL helps
SSDL provides rapid incident response, including isolating and containing the threat, restoring from clean backups, and hardening your systems against repeat attacks. We also help you meet your notification obligations and can work alongside your cyber insurer. If SSDL is not already your provider, we can step in on an emergency basis.
Call 1300 364 722 now, or book a free consultation to review your cyber security before an incident happens.
Ransomware Recovery FAQs
-
Disconnect affected devices from the network and Wi-Fi immediately, but don’t power them off — this preserves evidence needed for recovery and any insurance claim. Then call SSDL on 1300 364 722 for immediate guidance, even if we’re not currently your IT provider.
-
We recommend against paying without professional advice first. Paying doesn’t guarantee your data will be recovered, and it can mark your business as a repeat target. SSDL can help you weigh your options and pursue safer recovery paths.
-
If personal information may have been compromised, Australian businesses may have a legal duty under the Notifiable Data Breaches (NDB) scheme to notify affected individuals and the OAIC. SSDL can help you assess whether this applies and what to do next.
-
It depends on whether the security controls you claimed on your application (MFA, EDR, tested backups, documented incident response, patch management) were actually in place. SSDL can work alongside your insurer during the claim and help you understand your position.
-
Yes. SSDL can step in on an emergency basis to help contain and recover from an active incident, even if you’ve never been a client before. Call 1300 364 722 to speak with us now.
-
Call 1300 364 722 and you’ll speak with someone straight away who can start advising on containment immediately — this is a phone-first process, not a ticket queue.