Incident Response FAQs

How quickly can Mercury IT respond to a cyber incident?

Mercury IT provides rapid incident response for businesses across Australia. Our security team begins remote triage within one hour of notification, containing the threat and assessing the scope of the incident. For Gold Coast and Brisbane clients, on-site response is available within four hours for critical incidents. Sydney and Melbourne clients receive on-site support within 24 hours when required. We follow established incident response procedures including containment, eradication, recovery, and post-incident reporting required for notifiable data breaches under Australian law.

What is a notifiable data breach and what are my obligations?

Under the Privacy Act 1988, Australian businesses must notify affected individuals and the Office of the Australian Information Commissioner (OAIC) when a data breach is likely to result in serious harm. This includes breaches involving personal information like names combined with financial details, health information, or identity documents. Notification must occur as soon as practicable after becoming aware of the breach. Penalties for serious privacy breaches can reach $50 million, three times the benefit obtained, or 30% of adjusted turnover—whichever is greater. Mercury IT helps businesses assess breach severity, meet notification obligations, and implement improvements to prevent future incidents.

What should I do if my business suffers a cyber attack?

If you suspect a cyber attack, immediately isolate affected systems from the network to prevent spread, do not turn off computers as this may destroy forensic evidence, document everything you observe including times and symptoms, contact your IT security provider or Mercury IT's incident response team, and avoid paying any ransom demands before receiving expert advice. Time is critical—the faster you respond, the more options you have for recovery. Mercury IT provides 24/7 incident response support for managed security clients.