Checklist
Incident response readiness checklist
How ready are you for a cyber incident? Check each item. The gaps are the work to do before an incident, not during one.
Evidence
- Microsoft 365 audit logging on and retained
- Endpoint detection and response on every device
- Firewall, VPN and sign-in logs retained long enough to investigate
- Time synchronised across systems
Recovery
- Backups that can't be modified or deleted with everyday admin credentials
- Restore of critical systems tested, with times recorded
- Recovery order agreed with the business
- Clean build media and a way to rebuild identity systems
Read the rest of this checklist
Enter your work details to unlock this and every other guide on the site. We'll also send you a note in case you want to talk it through with an engineer.
People and contacts
- An out-of-band contact list for leadership, IT, providers, insurer and legal
- Named decision makers for shutting systems down and paying for help
- Your insurer's incident process and any required response panel known
- An incident response provider identified, or a retainer in place
Obligations
- Notifiable Data Breaches scheme assessment and notification process
- APRA CPS 234 notification if you are regulated by APRA
- SOCI Act reporting windows if you operate critical infrastructure
- Customer contract notification clauses
Playbooks and practice
- Playbooks for ransomware, business email compromise and compromised admin accounts
- A tabletop exercise in the last 12 months
- Lessons from the last exercise or incident fixed
Next step
This guide supports Incident response. Talk to an engineer if you want it worked through for your environment.
Start a conversation
Prepare the first hour of an incident now.
Talk to an engineer about an incident response retainer.
Talk to an Engineer