A cyber security incident needs decisive containment before it needs a perfect explanation. This 2026 guide shows Australian organisations how to report a cyber security incident to the ACSC, capture evidence safely and keep the response moving.
Why this matters
A delayed report rarely starts with bad intent. It starts with uncertainty: an employee sees an unusual sign-in, a mailbox rule appears, a supplier invoice changes, or a device behaves strangely. People then spend time trying to decide whether the event is serious enough to mention.
That delay gives an attacker room to reuse credentials, move money, create persistence or target another person. ASD’s Australian Cyber Security Centre received more than 84,700 reports to ReportCyber in FY2024–25, an average of one every 6 minutes. The same report says phishing featured in 60% of incidents reported to the ACSC.
The working rule for 2026 is simple: report the concern internally at once, contain the immediate exposure, then use ReportCyber when the event is suspected cybercrime, a cyber security incident or a vulnerability. Cyber Aware’s human risk reporting helps MSPs keep those signals alongside training and phishing outcomes rather than leaving them scattered across inboxes.
What you will need
Prepare a short fact pack before submitting an ACSC report. Do not wait for every detail before escalating an active incident.
- The date and time the event was first seen, including time zone.
- A plain description of what happened and who discovered it.
- Accounts, devices, email addresses, systems, suppliers or data involved.
- Screenshots, email headers, log references, payment records or other evidence already collected.
- Actions already taken, such as password resets, session revocation, device isolation or bank contact.
- Known impact: credentials entered, files accessed, money transferred, service disruption or customer data involved.
- One internal incident owner and an after-hours contact route.
Keep source evidence unchanged. Save a copy before changing a mailbox rule or deleting a suspicious file, but do not open malicious attachments or visit suspicious links to collect more proof.
1. Declare the incident internally
Start with the organisation’s incident channel, service desk or security contact. State the observable event, when it occurred and whether the exposure is still active. Use a neutral label such as “suspected account compromise” rather than waiting to prove every technical detail.
The first internal report assigns ownership. A security team, MSP or IT lead can decide whether to isolate a device, block a sender, reset an account or contact a financial institution. It also prevents five people from independently changing the same system.
Set a clear 2026 escalation trigger: any suspected credential theft, unauthorised access, malicious attachment, payment diversion, data exposure or ransomware indicator is reported immediately. An employee should not need approval to raise the alert.
Expected outcome: one named owner begins triage within minutes.
Common mistake: treating a report as an accusation. The report describes a risk event; it does not need to identify an attacker or prove fault.
2. Stop the active harm
Contain what is in front of the team. The right action depends on the event.
- Credentials entered: reset the account password, revoke active sessions, check multi-factor authentication and inspect sign-in activity.
- Suspicious email or link: preserve the message, quarantine matching copies and warn affected recipients without copying the link into the warning.
- Attachment opened: disconnect the device from networks if the response process requires it and have IT inspect it.
- Payment diversion: call the bank or payment provider through a known number immediately, then preserve transfer details.
- Data exposure: prevent further sharing, record what data was exposed and bring in legal or privacy owners under the existing plan.
Containment is not a substitute for evidence. Record each action, its time and the person who made it. That timeline is useful to the internal response and to any later ReportCyber submission.
Expected outcome: the exposed account, endpoint, payment or message is no longer free to cause more harm.
Common mistake: rebooting a device or clearing browser history before the response lead has recorded what occurred. Follow the organisation’s response process first.
3. Preserve evidence without spreading the threat
Create an incident record with facts that can be checked. Include original emails, sender addresses, screen captures, suspicious URLs as text, file names, device names, event times and relevant user actions. Record whether an employee clicked, typed credentials, approved a login prompt or sent money.
Avoid theories in the first report. “A finance user opened an attachment at 09:17 AEST and the endpoint was disconnected at 09:24 AEST” is useful. “A sophisticated gang compromised the organisation” is not yet evidence.
Do not ask employees to investigate malicious material themselves. Cyber Aware phishing simulations reinforce the safer pattern: stop, report and let the response team examine the message. The platform’s simulations track reports as well as clicks, which makes reporting behaviour measurable.
Expected outcome: the team has a reliable timeline and material that can be reviewed safely.
Common mistake: collecting evidence in personal chat threads. Put it in the approved incident record where access, handover and retention are controlled.
4. Decide whether ReportCyber is appropriate
ReportCyber is the Australian Government’s reporting service for cybercrime, cyber security incidents and vulnerabilities. ASD’s Annual Cyber Threat Report 2024–25, published 14 October 2025, directs organisations and individuals that observe suspicious cyber activity, incidents or vulnerabilities to ReportCyber or the Australian Cyber Security Hotline on 1300 CYBER1.
Use the official ReportCyber reporting service when the event is a suspected crime or security incident. Examples include unauthorised access, phishing that captured credentials, malware, ransomware, online fraud, business email compromise, impersonation that caused harm, or an exposed vulnerability.
If money has been transferred, contact the bank first as well. If there is immediate danger to people or property, use emergency services rather than relying on an online report.
Expected outcome: the event reaches the correct national reporting path without slowing containment.
Common mistake: using ReportCyber as the only action. An external report does not reset compromised accounts, block a malicious domain or restore a disrupted service.
5. Submit a report that is useful on first review
Use the report form to give a chronological account. Start with the first observed event, then state the affected systems and people, the suspected method, evidence held and containment already completed.
A practical structure is:
- What happened and when.
- How it was discovered.
- Accounts, devices, domains, phone numbers or financial details involved.
- The impact already known.
- Steps taken to contain it.
- Supporting material available on request.
- A safe contact route for follow-up.
Use exact times where they are available. Mention uncertainty plainly: “The attachment was opened; the effect on the device is under investigation.” Clear uncertainty is better than a confident but inaccurate statement.
The ACSC’s report recorded over 42,500 calls to the Australian Cyber Security Hotline in FY2024–25, up 16% year on year. That volume is a reason to make the first report concise and factual, not a reason to delay it until every detail is known.
Expected outcome: the report can be understood without a long follow-up call.
Common mistake: attaching passwords, one-time codes or unrestricted copies of sensitive customer data. Provide only what the official form requests and use approved secure channels for additional material.
6. Notify, review and improve
Assign specific actions to IT, finance and management, then send affected employees one clear instruction. Do not repeat malicious links or attachments in a broad notice.
Close with a short review: detection time, containment time and the decision that slowed the response. Use a focused Cyber Aware lesson or simulation on that decision, such as supplier verification or suspicious-message reporting. A gap assessment can document response ownership and control evidence against Essential 8, ISO 27001 and NIST.
Track time from observation to internal report and time from report to containment in 2026. Completion rates alone do not show response readiness.
Troubleshooting
The incident is unconfirmed
Report the suspicious activity internally and preserve the evidence; triage decides severity.
MFA was enabled
Reset the password and revoke sessions anyway. MFA does not remove the need to investigate abnormal activity.
Bank details changed
Verify them through a trusted supplier contact, never through the suspicious message.
The email was deleted
Record the sender, subject, approximate time and recipient actions; mail tracing may recover the detail.
Tools and resources
- ASD’s phishing guidance covers common phishing tactics and reporting routes.
- ReportCyber is the official reporting service for cybercrime, incidents and vulnerabilities.
- Cyber Aware training supplies recurring staff education and completion reporting.
- Cyber Aware human risk reporting brings phishing, training and risk signals together.
FAQ
How do I report a cyber security incident to the ACSC?
Contain the immediate risk, record the facts and submit the event through ReportCyber. Use the Australian Cyber Security Hotline on 1300 CYBER1 when official guidance directs a call.
What belongs in an incident report?
Include what happened, when, affected accounts or systems, observed impact, evidence available and containment already completed.
Should I report before I know the full impact?
Yes. Report internally and start containment as soon as suspicious activity is identified, then update external reporting with confirmed facts.
Does ReportCyber replace internal response?
No. The organisation still needs to reset accounts, isolate devices, contact banks and manage communications.
What if someone clicked a phishing link?
Report it immediately, preserve the email and check the affected account or device. Reset credentials and revoke sessions if they were entered.
When should a business contact its bank?
Immediately when payment was made, bank details changed or payment credentials may be exposed.
One last thing
A useful incident report is not the longest report. It is the one that gives the next responder the event, time, impact and action already taken in under 2 minutes of reading.