At a glance
Cyber security incidents can disrupt operations, expose sensitive information and affect critical services. Report incidents as early as possible, even if the threat is only suspected. We can provide immediate technical advice and support to help you respond and recover. Some sectors also have mandatory reporting requirements. Information voluntarily shared with us by Australian organisations is protected by law.
Call our hotline on 1300 CYBER1 (1300 292 371), 24 hours a day, 7 days a week.
The impact of cyber security incidents
A cyber security incident is an unexpected event(s) that has compromised, or could disrupt, business operations. This could include unauthorised access to, modification of, or impairment to systems, data, programs or communications. It may also affect their availability, reliability, security or operation.
Malicious cyber activity remains a serious threat to Australia's security and prosperity. As cyber threats evolve and new technologies emerge, our households, businesses, critical infrastructure and government continue to be targeted.
Common incidents include:
- Denial of Service attacks
- scanning and reconnaissance
- intentional or malicious unauthorised access to network or device
- data exposure, theft or leak
- malicious code or malware
- ransomware
- phishing and spear phishing
- other irregular cyber activity that causes concern.
When to report
Report a potential incident as soon as possible, even if you think it may be a false alarm or it happened some time ago.
Contacting us early and providing detailed information helps us:
- respond to incidents
- reduce cyber harms
- warn Australians about potential threats.
Why your report matters
Your report helps us understand the cyber threats affecting Australian organisations and entities. We analyse and combine this information with intelligence sources to build a national picture of cyber threats.
Your report also helps us:
- update cyber security advice, capabilities and techniques
- prevent and respond to evolving cyber threats
- warn Australians about emerging threats.
We may use anonymised information from reports to create public alerts, awareness campaigns and cyber threat reporting. Products and announcements can include:
- advisories published on our Partner Portal
- alerts published on cyber.gov.au
- quarterly trends and insight reports
- our Annual Cyber Threat Report.
We may also share some anonymised technical details, such as indicators of compromise, through our Cyber Threat Intelligence Sharing (CTIS) platform. To access the CTIS, you’ll need to become a network partner.
How we help during an incident
After we receive your report, we'll contact you with immediate advice and support. This may include:
- information on how to contain and remediate the incident
- advisory products to support your incident response
- referrals to other government agencies that may be able to help
- assessing the incident to determine whether further action is needed.
What you may need to provide
We may ask you to provide data relating to the cyber security incident. This may include:
- logs
- memory dumps
- disk images
- network traffic captures
- network diagrams or documentation
- indicators of compromise
- samples of malware
- other analysis or reporting products.
We may also discuss safe ways to collect this data and secure methods for transferring it to us.
While collecting this data can be time-consuming, the more information you can give us helps us provide more effective support. It will also help us develop advice that can protect others from similar cyber threats.
Additional information we may need
We may ask for details about your organisation's cyber security arrangements so we can tailor our advice and support. This may include:
- your cyber security incident response plan and whether it has been activated and can be shared
- whether you have access to technical resources to investigate and respond to the incident, such as an incident response provider
- actions taken so far and how they have been recorded
- steps taken to contain the threat and whether the threat actor still has access to your systems
- whether you can identify and isolate affected workstations or systems
- your next steps for investigating and responding to the incident.
More specialist support
After providing you with immediate advice, we may also provide more hands-on assistance.
If the incident has had a significant impact on Australia or involves a sophisticated malicious actor, we may also:
- refer an incident response specialist to support your investigation
- engage our digital forensics specialists to analyse evidence
- provide guidance on how to communicate to industry and stakeholders about the incident
- help coordinate technical briefings with government agencies or industry partners involved in the response.
Technical briefings may involve chief information security officers from:
- federal, state and territory government
- law enforcement agencies
- international cyber partners.
We can also help connect you with the National Office of Cyber Security and the Australian Federal Police.
Supporting your incident response team
If you have engaged an incident response provider or legal practitioner, we can work with them to clarify the full nature and extent of your incident. Sharing technical expertise and threat intelligence helps support a more effective investigation.
Your organisation can support this collaboration by authorising the sharing of information between us and your incident response team or legal representative. Information they provide is covered under our limited use obligation. For more information, learn how we protect your privacy.
The role of ASD and the National Office of Cyber Security in a cyber security incident
Finalising the investigation
Once investigation is complete, we may be able to provide information and reports to help finalise your response.
We can also connect you with our other services for ongoing support. This includes our cyber resilience uplift activities and the ASD Cyber Security Partnership Program.
How we protect your privacy
Information you voluntarily provide us about a cyber security incident or vulnerability is protected by a Limited Use obligation under law. This means information you provide to ASD can’t be used as evidence against you in civil or criminal proceedings.
Learn more about our Limited Use obligation.
When we may contact you about a cyber security issue
We may contact you if we identify a vulnerability or compromise (potential or confirmed), even if you haven’t reported it or contacted us.
We’ll share as much information as we can about the issue. This information may come from trusted sources or our monitoring of the cyber threat environment.
Information we provide may include:
- indicators of the compromise
- compromised credentials
- ransomware precursor activity, such as malware or spear-phishing activity
- interactions between malicious infrastructure and Australian networks or devices.
If you’re unsure whether a call from us is genuine, end the call and contact us directly on 1300 CYBER1 (1300 292 371).
If you have an incident reference number, please quote it when you call.
Become a network partner
Join the ASD Cyber Security Partnership Program to stay informed about cyber security threats and access the latest cyber security advice.
The program is free and provides access to:
- threat intelligence, news and advice
- collaboration opportunities
- resilience-building activities such as exercises, discussions and workshops
- our state and territory network
- access to the partner portal where information is shared.
If you're already a partner, make sure your contact details are up to date, including your out-of-hours contact details in case we need to reach you quickly.