Cyber incident response · Australia · answered 24/7 by a person

Under attack? Call now, any hour.

Incident response for Australian businesses: ransomware, business email compromise and data breaches, contained in the first hour and answered by a person at any hour of the day or night.

Call first and we will tell you what to touch and what to leave alone. Every engagement runs the same five stages: contain, investigate, eradicate, recover, report. You will know exactly what happened, how we fixed it, and how to stop it happening again.

Not mid-incident? Fortify is the managed security plan our responders built from cases like these.

We respond to incidents affecting businesses and organisations. For a hacked personal account or device, start with ReportCyber and IDCARE.

What happens when you call

  1. 01Your call is answered, any hourIn business hours you reach our team directly. After hours an answering service takes your details and calls our team, and a responder calls you back. Either way we start by working out what has been hit, whether the attacker is still inside, and what to touch first.
  2. 02The first hour: containAffected systems and accounts isolated, surviving backups taken offline, evidence kept. Every minute of inaction costs more, so we move first.
  3. 03Then: investigate and recoverEntry point, timeline and what was accessed. Systems verified clean before they go back online. A full report within five business days of containment.

24/7

Answered by a person

< 1 hr

Containment starts

5.0 ★

Rated on Google

24/7 response
Contain within the first hour
NDB scheme reporting support

Hit right now?

Do this first. It changes what we can recover and what we can prove.

Do

  • Isolate affected machines (unplug the network cable or turn off Wi-Fi), but leave them powered on.
  • Take your backups offline before anything else can reach them.
  • For a compromised mailbox: change the password, sign out every session, and screenshot any new forwarding or inbox rules before you remove them.
  • Keep the evidence: ransom notes, suspicious emails, logs, altered invoices. Then call us before you change anything else.

Don't

  • Don't power off, wipe or rebuild affected systems. That destroys recoverable data and the evidence of how they got in.
  • Don't run "cleanup" tools over the top of the evidence, and don't restore backups onto a compromised environment.
  • Don't pay a ransom or reply to the attacker before you have spoken to us. Payment carries its own reporting obligations.

Ransomware specifically? The ransomware recovery page covers the first hour in detail, and ScanCrypt, the free tool we built, measures how much of your data the attacker never reached. If nothing was encrypted and they are simply threatening to publish what they took, start with data theft extortion response instead.

Our methodology

Five stages. Every time.

A repeatable methodology applied to every incident. No improvisation, no wasted time working out what to do next.

The fifth stage is the report, within five business days of containment. Most responders skip it. We don't.

Contain

Immediate isolation of affected systems and accounts. Every minute of inaction costs more. We move first.

Investigate

Technical analysis to determine entry point, attacker timeline, data accessed, and whether the threat is still present.

Eradicate

Complete removal of the threat. , backdoors, compromised credentials, and persistence mechanisms. All gone.

Recover

Safe restoration of systems and operations. We verify clean state before anything goes back online. No assumptions.

Report

Full timeline, root cause and a board-ready narrative within five business days of containment. Structured for the , your insurer and your board.

From real incidents

In 2026 an Australian business came to us with Akira across two ESXi hosts, a SAN and about 20 virtual machines. We contained it, worked out how they got in, and read every machine back with ScanCrypt. Nobody paid a ransom. Every incident is different, and we can usually say within hours what looks recoverable in yours.

How Akira recoveries work →

Outcomes described are specific engagements. No recovery is guaranteed.

★★★★★
“IronSights provided exceptional support during a mission-critical ransomware incident. From the outset, their team was personable, calm and highly professional, while also being incredibly skilled and relentless in their approach. They treated every decision with the level of care and precision the situation demanded, worked through the technical detail thoroughly, and never took shortcuts. Their ability to balance urgency with discipline gave us real confidence during an extremely difficult time. I have worked with many technology providers over the years, but I have never been as impressed by a company as I was with IronSights. I would strongly recommend them to any organisation needing serious cybersecurity expertise, particularly when the stakes are high.”
AndrewVerified Google review, read on Google →
“We engaged IronSights to help us with an Akira ransomware incident that impacted one of our clients. They were great to work with and jumped in quickly to help us investigate what had happened and get the client back up and running. Ryan and the team worked well alongside our engineers and kept things moving during a pretty stressful incident. Would definitely recommend them to other MSPs needing an extra set of hands or specialist help with ransomware recovery.”

Brett

Director

Managed Service Provider

“Not all heroes wear a cape. These guys dropped what they were doing and were on the next flight to not only save our butt but crucially recover forensic IT info about our ransomware attack and help us get back up. We can’t praise Ryan and team highly enough for their 6 star effort.”

Stephen

Systems Admin

Private College

Scope

What's included
in every engagement.

Eight capabilities included as standard. No per-item billing, no surprises after containment.

24/7 availability

Active incidents don't wait for business hours. We're available around the clock for Fortify clients and retainer holders.

Technical investigation

Entry point, attacker timeline, , and data access, mapped and documented.

Threat eradication

, backdoors, persistence mechanisms, and compromised credentials fully removed before recovery begins.

Safe recovery

Systems restored and verified clean before they go back online. No assumptions about what was and wasn't affected.

Incident report

Full timeline, root cause analysis, and board-ready narrative delivered within five business days of containment.

NDB scheme support

Reports structured to meet notification requirements under Australia's .

Insurance claim support

Documentation structured for claim submission, including incident timeline and remediation evidence.

Post-incident hardening

Hardening recommendations based on what the attacker used. Prevent the same incident from happening twice.

How to engage us

The best time to arrange incident response is before you need it. An IR retainer gives you guaranteed response times, pre-agreed terms, and a direct line to our team at any hour.

  • Fortify clients: IR included in your managed service
  • IR Retainer: guaranteed SLA and pre-agreed terms
  • On-demand: available subject to capacity
Enquire about a retainer→

An IT provider responding for a client? Our partner program puts the terms in place in advance, and we work behind you.

What we respond to

The incidents affecting Australian businesses most. From ransomware locking you out to a rogue employee exfiltrating data. We've responded to all of them, including ransomware data recovery when the backups are gone, using ScanCrypt, the free tool we built to read data back without the key.

  • Ransomware and extortion
  • Business email compromise (BEC)
  • Data exfiltration and theft
  • Insider threat incidents
  • Credential compromise
  • Phishing-driven breach
  • Cloud environment compromise
  • Supply chain attack

After we leave

You'll be stronger
than before the incident.

A breach is not just a crisis. It's a chance to learn how they got in.

Every IronSights engagement ends with hardening based on the attacker's actual methods. Not a generic checklist.

Threat removed

Not just the visible symptoms: the full persistence chain, every backdoor, every compromised credential. Verified clean before we hand back control.

Operations restored

Business back to normal as fast as the evidence allows. We don't keep you offline longer than necessary, but we don't rush clean state verification.

Root cause understood

You'll know exactly how it happened. Entry point, attacker timeline, and what they accessed. No guessing, no 'we think maybe'.

Recurrence prevented

Post-incident hardening closes the gap the attacker used. Many of our Fortify clients came to us following an incident. The right time to build continuous security is now.

Common questions

Asked by buyers like you.

Under attack right now? Call 1300 004 766. Not in this list? Book a 30-minute consultation. No obligation.

  1. We're under attack right now. What do we do?

    Call us immediately on 1300 004 766. Do not power off systems unless instructed; this can destroy recoverable data and evidence. Do not pay a ransom without speaking to us first. We'll assess the situation and engage as fast as resources allow.

  2. Our business email has been compromised. What do you do first?

    Lock the attacker out: the affected accounts get new credentials and every active session is revoked, and the mail rules they left behind are removed. Then we trace what they read, sent and changed, including any invoices or payment details they altered, and secure the tenant so they cannot come back. If money has moved, contact your bank straight away as well.

  3. Do you respond outside Sydney?

    Yes. We are based in Sydney and respond to businesses anywhere in Australia. Containment and investigation start remotely, which is why the first hour does not depend on where you are.

  4. We are an IT provider. Can you respond for our client?

    Yes, and it is a common arrangement. We work behind you: you stay the client's provider and stay in the room, we contain the incident, preserve the evidence and hand you a report structured for their insurer and their assessment. Our partner program sets the terms up in advance so the first hour is spent containing rather than negotiating a contract.

  5. Do you help individuals with hacked personal accounts?

    No. IronSights responds to incidents affecting Australian businesses and organisations only. If your personal email, social media, phone or bank account has been compromised, report it through ReportCyber at cyber.gov.au, call IDCARE on 1800 595 160 for free identity and cyber support, and contact your bank straight away if money is involved.

  6. What's included in a Fortify managed security engagement?

    If you're an active Fortify client, incident response is included in your service. We detect the incident, contain it, and manage the response. There are no additional charges for in-scope incidents.

  7. What's an IR retainer?

    An incident response retainer is a standing agreement that guarantees defined response times and pre-agreed engagement terms. You pay a monthly or annual retainer fee. If you need us, the paperwork is done and we engage immediately. Highly recommended for any organisation handling sensitive client data.

  8. They stole our data but did not encrypt anything. Is that still an incident response?

    Yes, and it is an increasingly common one. Extortion without encryption means there is nothing to restore, so the whole job is establishing what was actually taken, closing the route in, and meeting your obligations. The attacker's claim about scope is a negotiating position, not a finding, and the logs that would settle it often have short retention. Our data theft extortion response page covers what to do in the first hour.

  9. Do you help with NDB scheme reporting?

    Yes. Under Australia's you must assess a suspected breach within 30 days and, if serious harm is likely, notify the and the people affected as soon as practicable. Our incident reports are structured to support that assessment and the OAIC statement, and we can assist with the notification process directly. Our guide to the NDB scheme sets out the detail.

  10. Can you help after the incident is resolved?

    Yes. Post-incident hardening is included in every engagement. Many clients also transition to Fortify managed security following an incident, using the response findings as the foundation for ongoing protection.

Don't wait

Set up a retainer before the incident.

An IR retainer costs a fraction of an unplanned response engagement. Get the terms agreed now, so you're not doing it at 2am.