If your business pays a ransomware demand, you have 72 hours to report it. SOCI entities have as little as 12 hours to notify an incident. These clocks start whether or not your plan is ready, so the useful work happens before the incident. That work is what we do. When something does happen, specialist forensics partners handle the investigation and your plan tells everyone else what to do while they work.
In the middle of an incident, someone has to decide whether to pay, who to call, what to tell the regulator, what to tell customers and what to tell the board, all at once and mostly before the facts are in. Every one of those decisions can be roughed out in advance, on a quiet Tuesday, by people who are not frightened. That is the whole argument for readiness work.
The reporting obligations have teeth now. The Cyber Security Act's ransomware payment reporting started on 30 May 2025 and applies to businesses with turnover above A$3 million and every SOCI responsible entity, with 72 hours to report a payment to the Cyber and Infrastructure Security Centre and no grace period. SOCI incident notification runs 12 to 72 hours depending on severity. The OAIC allows 30 days to assess a suspected notifiable data breach, and APRA expects CPS 234 notification within 72 hours. Your playbooks need each clock, each form and each phone number written down before you need them.
We are clear about where we stop. We build plans, run exercises and prepare your people. We do not do digital forensics or incident response operations ourselves. For that we arrange retainers with specialist DFIR firms before you need one, because signing a retainer during an incident is the most expensive way to do it.
A response plan sized to your organisation, with scenario playbooks for ransomware, data theft and business email compromise. Short enough to be read, specific enough to be followed at 2am.
Executive tabletops that rehearse the decisions, and technical tabletops that rehearse the containment. Each one ends with a written list of what broke in the exercise, so it doesn't break in the incident.
Playbooks for each obligation you carry: Cyber Security Act ransomware reporting, SOCI notification, OAIC notifiable data breaches and APRA CPS 234. Who reports, to whom, by when, with the forms ready.
Our consultants have carried incident and crisis roles inside banks and critical infrastructure operators, where the notification clocks bite and the board wants answers hourly. The plans we write reflect how incidents unfold, including the parts where nobody can reach the one person who knows the system.
Because we do not sell DFIR services, our advice on retainers and escalation is not steering you towards our own response team. We help you pick the partner, then we stay in your corner.
Short documents, clear roles, no laminated binders that nobody opens.
CISC, SOCI, OAIC and APRA obligations mapped to your business, with the forms pre-staged.
The board and executive rehearse their decisions too. Most incident chaos starts above the security team.
We don't sell the forensics, so the readiness advice serves you, not a services pipeline.
A first tabletop exercise takes half a day and tells you more about your readiness than any document review. Most clients start there.