Cyber incidents are among the few business crises where the technical response and the legal obligations run simultaneously, under time pressure, usually with incomplete information.
The first hour
- Contain. Disconnect affected systems from the network. Do not power them off if you can avoid it — volatile memory holds evidence, and shutting down destroys it.
- Preserve. Do not wipe, reimage or “clean up” affected systems. You will need them for investigation, and for any insurance claim.
- Assess scope — what systems, what data, whether it is still spreading.
- Assemble the response — IT, management, legal, insurer, and external incident response if you have it.
- Change credentials for administrative accounts, from a clean device.
- Contact CERT NZ, which provides free guidance to New Zealand organisations.
The instinct to restore service immediately is strong and frequently wrong. Restoring from backup into a compromised environment reinfects it, and rebuilding before understanding the entry point means it happens again.
The privacy obligation runs during the chaos
Under the Privacy Act 2020, where a privacy breach has caused or is likely to cause serious harm, you must notify the Privacy Commissioner and affected individuals as soon as practicable after becoming aware of it.
That obligation applies while you are still fighting the incident, which is why the decision path should be written down beforehand.
Assessing serious harm involves considering the sensitivity of the information, whether it was protected by security measures, who obtained or may obtain it, and the nature of the harm that may result.
Notification can be made before the full picture is known and updated later. Waiting for complete information is a common error.
Ransomware specifically
Additional considerations:
- Assume data was exfiltrated, not just encrypted. Most ransomware now steals data before encrypting, which makes it a privacy breach as well as an availability incident.
- Check your backups are clean and were not encrypted too. Attackers target connected backups specifically.
- Payment decisions should involve legal advice. Payment does not guarantee recovery or that data will not be published, and there are sanctions considerations depending on the actor.
- Do not communicate with attackers without advice.
Business email compromise
The most financially damaging attack on New Zealand businesses. An attacker gains access to email, watches, and sends an invoice with altered bank details at the right moment.
If funds have been sent: contact your bank immediately, because recovery is sometimes possible within a short window. Report to police and to CERT NZ. Check whether other payments are in train.
Then check the scope — how long was the mailbox accessible, what was in it, were forwarding rules created. Attacker-created mail rules frequently persist after a password reset and are missed.
Communication
Decide early who speaks and what is said. Points that matter:
- Do not speculate about cause while the investigation is running.
- Tell affected people what they should actually do — change passwords, watch for fraud, be alert to follow-up phishing that references the breach.
- Tell staff something. An information vacuum produces rumour and inconsistent external messaging.
- Be straight. Organisations that minimise and are later found to have known more do far more damage to themselves than the incident did.
Insurance
Notify your insurer immediately. Cyber policies frequently require use of the insurer’s panel incident responders, and engaging your own first can prejudice cover.
Note that standard business interruption insurance generally requires physical damage to your property and will not respond to a cyber event. Cyber cover is a separate product.
Afterwards
The post-incident review is where the value is. Establish the entry point, why controls did not prevent or detect it, and what changes.
The controls that would have prevented most New Zealand incidents are unglamorous: multi-factor authentication on email and remote access, patching of internet-facing systems, tested offline backups, and the procedural rule that bank account changes are verified by phone using a number you already hold.
Prepare now
Write down, on paper or somewhere not dependent on your systems: who to call in what order, insurer and policy number, CERT NZ contact, your legal adviser, the privacy notification decision path, and how to reach staff if email is unavailable.
That page is the difference between a managed incident and an improvised one.
CERT NZ and the National Cyber Security Centre publish free incident guidance for New Zealand organisations, and the Office of the Privacy Commissioner publishes breach notification guidance and an online notification tool.
General information only, not legal advice. Take advice on notification obligations.








