Ransomware Hits a Perth Office: What We Do in the First Hour

A representative walkthrough of how we respond in the first hour of a ransomware attack on a Perth small business — contain, assess, protect the backups, and start recovery — and why that hour is really decided months earlier. From Computer Mechanics, Perth IT specialists since 1997.

BrettBrett · Workshop Manager & Senior Hardware Expert
3 August 2026
5 min read
Cybersecurity
Ransomware
Backup & Recovery
Incident Response
Perth Business

This is a representative scenario, not a specific client. It's a composite of how a ransomware response actually unfolds, written to show the order we work in and why. Real incidents vary, and the details here are deliberately general.

A staff member at a Perth office can't open a file. Then another. Someone notices every document has a strange new extension, and a text file has appeared on the desktop with a ransom demand and a countdown. Within a couple of minutes it's clear: this is ransomware, and it's spreading.

What happens in the next hour matters enormously — but here's the honest truth we'll come back to at the end: most of the outcome was decided months ago, by whether the right preparation was in place. Here's how we work the first hour regardless.

Minutes 0–10: contain first, investigate second

The instinct is to figure out what happened. The correct first move is to stop it spreading. Ransomware often keeps encrypting across network shares and connected machines while everyone's still working out what's going on, so we contain before we diagnose:

  • Isolate affected machines — disconnect them from the network (unplug ethernet, disable Wi-Fi), but do not power them off if we can help it. Shutting down can destroy evidence in memory and, with some strains, corrupt any chance of recovery.

  • Cut the spread path — disconnect network shares and, if the scale warrants it, isolate the affected part of the network or pull the internet connection so the attacker loses their live foothold.

  • Protect the backups immediately — this is the single most important early action. If backups are reachable from the encrypted network, modern ransomware hunts for and destroys them first. We make sure the backup system is isolated and intact before it can be touched.

Minutes 10–30: establish scope and stop the attacker's access

With the bleeding stopped, we work out how big it is:

  • What's encrypted? Which machines, which servers, which cloud data. This tells us how much we're recovering.

  • How did they get in, and are they still in? A stolen password, a phishing click, an exposed remote-access port. We reset credentials, revoke active sessions and enforce MFA so the attacker can't simply walk back in while we're recovering.

  • Was data stolen, not just encrypted? This is the part businesses miss. Modern ransomware usually steals a copy of your data before encrypting it, then threatens to leak it — so this isn't only an availability problem, it's potentially a data breach, which in Australia can trigger obligations under the Notifiable Data Breaches scheme. We assess exfiltration early because it shapes everything that follows.

Two things we don't do in this window: panic, and rush to pay. Paying is a last resort that funds crime, often doesn't fully work, and marks you as a payer for next time — and it's almost never necessary if the preparation was there.

Minutes 30–60: begin recovery from clean backups

Once we know the scope and the attacker is locked out, recovery begins:

  • Verify the backups are clean and pre-infection, then start restoring critical systems and data from the isolated, immutable copy. This is the moment a tested backup earns its entire existence.

  • Rebuild rather than trust compromised machines — wiping and reimaging is safer than hoping an infected device is "clean now."

  • Document everything — timeline, systems affected, evidence — for insurers, the OAIC if a notifiable breach applies, and to make sure the same hole is closed for good.

For a business with immutable, tested, offsite backups, this is where a catastrophe turns into a bad day or two: systems come back from a clean copy, the ransom demand becomes irrelevant, and the leverage the attacker was counting on largely evaporates.

Why the first hour is really won months earlier

Here's the uncomfortable part. Two Perth businesses can be hit by the same ransomware on the same morning and have completely different weeks:

  • The one with immutable offsite backups, EDR, MFA everywhere, network segmentation and patched systems contains it, restores from clean copies, and is back running — no ransom paid.

  • The one without faces an impossible choice: pay criminals with no guarantee, or lose the data. That's not a technical failure in the first hour; it's the absence of preparation before it.

Every one of those safeguards is exactly what proactive managed security puts in place — and it's why we keep coming back to the same message in pieces like the four IT gaps small businesses overlook and our Essential Eight guide. The Essential Eight controls — patching, application control, MFA, and regular, tested backups — exist precisely because they're what decides the first hour of an incident like this.

The takeaway

If ransomware hit your business this morning, the questions that would decide your week are simple, and you can answer them today: Are our backups immutable, offsite, and — most importantly — have we actually tested restoring from them? Is MFA on everywhere? Is our network segmented so one infected machine can't reach everything?

If you're not sure of the answers, that uncertainty is the risk — and it's fixable calmly now, rather than at 9am on the worst day. Talk to the Computer Mechanics team or call (08) 9325 1196 for an honest review of where you'd stand. We've protected and recovered Perth businesses since 1997, and the goal is always the same: make the first hour a non-event.

Brett
Written by
Brett
Workshop Manager & Senior Hardware Expert · 15+ years in IT

Brett is the Workshop Manager and a senior hardware expert at Computer Mechanics, a 15-year veteran known for rapid issue diagnosis and deep, hands-on knowledge across hardware, systems and day-to-day support. His commitment to quality has earned long-standing customer trust.

Meet the IT Support Perth team →
Brett
3 August 2026
5 min read
Cybersecurity
Ransomware
Backup & Recovery
Incident Response
Perth Business

Stay Updated with IT Insights

Get the latest cybersecurity tips and technology insights delivered to your inbox

Related Articles

Does Microsoft 365 Back Up Your Data? Why the Answer Trips Up Perth Businesses

Microsoft 365 protects the platform, not your data. A plain-English look at the shared responsibility model, the retention limits that catch businesses out, and what a real backup needs to cover. From Computer Mechanics, Perth IT specialists since 1997.

5 min read

Microsoft 365 Keeps Going Down: How Perth Businesses Can Keep Working Through the Next Outage

Microsoft 365 has had several major outages in 2026, including a wide North American incident in July. Here's how Perth businesses can keep operating when Teams, Outlook or SharePoint go down. From Computer Mechanics, Perth IT specialists since 1997.

5 min read

Your Microsoft 365 Licence Got More Secure in 2026 — But Only If You Switch It On

In mid-2026 Microsoft folded premium security tools — Defender for Office 365, Intune features, link protection — into standard Microsoft 365 licences. Many Perth businesses now pay for protection they haven't turned on. Here's what changed and what to enable. From Computer Mechanics, Perth IT specialists since 1997.

5 min read

Need Expert IT Support?

Get personalized advice from our Perth IT experts. Free consultation available.

Related Content

Continue Reading

Explore more insights and expert advice on IT support, cybersecurity, and digital transformation

Your Messages Are "Encrypted" — But the FBI Just Read Them Anyway. Here's What Every Perth Business Needs to Know.
CyberSecurity
ITSupportPerth

Your Messages Are "Encrypted" — But the FBI Just Read Them Anyway. Here's What Every Perth Business Needs to Know.

Most small business owners believe end-to-end encryption means their messages are completely private. A recent FBI case proves that assumption is dangerously incomplete.

5 min read
4/15/2026
What’s new in SMB1001:2026?
SMB1001
SMB10012026

What’s new in SMB1001:2026?

SMB1001:2026 updates for Perth SMBs: Mandatory DMARC from Silver tier, 5 maturity levels, Essential Eight alignment. Get certified, cut insurance costs, win tenders—start your roadmap today!

5 min read
2/25/2026
Does Microsoft 365 Back Up Your Data? Why the Answer Trips Up Perth Businesses
Microsoft 365
Backup & Disaster Recovery

Does Microsoft 365 Back Up Your Data? Why the Answer Trips Up Perth Businesses

Microsoft 365 protects the platform, not your data. A plain-English look at the shared responsibility model, the retention limits that catch businesses out, and what a real backup needs to cover. From Computer Mechanics, Perth IT specialists since 1997.

5 min read
8/7/2026
Call us