The short answer
After a cyber attack, a small business should contain the incident, report it through ReportCyber at cyber.gov.au, call its bank immediately if any payment may have been redirected, and then protect cash flow. That means building a short-term cash forecast, contacting key suppliers and the ATO early if payments will be late, chasing insurance promptly, and arranging a facility to cover lost trading days and recovery costs before the gap becomes a crisis.
Key points
- Report the incident through ReportCyber and call your bank straight away if money has moved.
- Cyber incidents hit cash three ways: lost trading, recovery costs and redirected payments.
- A 13-week cash forecast shows the gap before it becomes a crisis.
- Talk to suppliers, customers, your insurer and the ATO early.
A cyber incident rarely announces itself as a cash flow problem. It starts with locked files, a strange email from your own account, or a supplier asking why they haven’t been paid. Within days, though, most affected businesses find the real damage is to cash: days of lost trading, unexpected recovery bills, and sometimes money sent straight to a criminal. This guide walks through what to do, in order, with the cash decisions at each stage.
How does a cyber attack hit cash flow?
In three main ways:
| Impact | Example | Cash effect |
|---|---|---|
| Lost trading | Point-of-sale or booking system down; staff can’t work | Revenue stops while costs continue |
| Recovery costs | IT specialists, new hardware, legal advice, customer communications | Unplanned spending, often urgent |
| Redirected payments | Business email compromise changes a supplier’s bank details, or your customers pay a fake account | Money lost, or received by someone else |
Some businesses also face delayed receipts while invoicing systems are rebuilt, and extra costs from notifying customers if personal information was exposed.
What should you do in the first 24 hours?
- Contain it. Disconnect affected devices from the network, change passwords from a clean device and turn on multi-factor authentication. If you have an IT provider, call them now.
- Call your bank if money may have moved. If a payment was sent to changed bank details, or your banking may be compromised, phone the bank immediately. The faster it acts, the better the chance of recovering funds.
- Report it. Use ReportCyber at cyber.gov.au, the Australian Government’s reporting point for cybercrime and cyber security incidents. The Australian Cyber Security Centre also offers a small business cyber resilience service with free, tailored support.
- Notify your insurer if you have cyber cover. Many policies require prompt notification and provide access to response specialists.
- Warn staff, key customers and suppliers, by phone, if your email may be compromised — so they don’t act on fake payment instructions.
- Start a log. Record what happened, when and what you’ve done. It helps with insurance, reporting and any lender conversations.
If personal information may have been accessed, get advice about your obligations under the Notifiable Data Breaches scheme.
What should you do in the first week?
Once the immediate threat is contained, turn to cash.
Build a 13-week cash flow forecast. Week by week, list expected money in and out. Be realistic about:
- lost revenue while systems are down and the time to rebuild bookings or sales;
- recovery costs already committed or likely;
- receivables that may be delayed because invoices couldn’t be sent;
- wages, super (now paid each payday under Payday Super), rent and supplier payments;
- your next BAS due date.
Find the lowest point and the size of the shortfall. That tells you what you need to solve.
Talk to people before payments are missed:
- Suppliers — explain briefly and agree revised terms if needed. Most would rather know.
- Customers — confirm your genuine bank details by phone and follow up outstanding invoices.
- The ATO — if a BAS payment will be late, contact them before the due date.
- Your landlord and lenders — early conversations keep options open.
How do you fund the recovery gap?
If the forecast shows a gap, arrange funding before it arrives rather than after:
| Situation | Option to consider |
|---|---|
| Short, temporary gap while trading recovers | A line of credit or short-term loan |
| Insurance claim approved but not yet paid | Short-term funding repaid when the claim pays out |
| Receivables delayed by invoicing disruption | Invoice finance once invoices are re-issued |
| Larger losses or recovery costs | A working capital loan or property-secured facility |
| Replacement hardware | Equipment finance, rather than cash |
Lenders understand that one-off events happen. They’ll want to know what happened, what’s been fixed, and that the business was trading soundly beforehand. A short written summary, your forecast and recent bank statements make that conversation much easier. You can start with a 60-second enquiry — no credit check to enquire.
What if money was paid to a scammer?
Business email compromise is one of the most costly forms of cybercrime for small businesses. Typical patterns include a fake invoice with changed bank details, or an email appearing to come from the owner asking staff to make an urgent payment.
- Call your bank immediately, even if days have passed.
- Report through ReportCyber.
- Contact the genuine supplier or customer using a phone number you already have, not one in the suspicious email.
- Record everything for your insurer and your accountant.
For the future, set a firm rule: any change to a supplier’s bank details must be confirmed by phone using a number already on file.
Which costs are worth tracking for a claim?
Keep a running list, with receipts, of every cost linked to the incident: IT response and forensic work, replacement hardware and software, legal and notification costs, overtime, temporary staff and extra marketing to rebuild bookings. Note lost trading days, too, with a comparison to the same period last year. Whether or not you hold cyber cover, this record supports any claim, helps your accountant with the tax treatment and gives a lender a clear picture of what happened.
What should you do in the first month?
- Review the forecast weekly and adjust as trading recovers.
- Follow up the insurance claim and keep evidence of costs.
- Tighten security using the ACSC’s small business guidance: multi-factor authentication, regular tested backups, automatic updates, and staff training on scams.
- Rebuild your buffer. Once trading returns to normal, set aside a cash reserve so the next surprise doesn’t become a crisis.
What should a cyber-ready cash plan include?
The businesses that recover fastest usually had a few things in place before anything went wrong:
- a cash buffer covering at least a few weeks of fixed costs;
- a standby facility, such as an undrawn line of credit, arranged while trading was strong;
- offline copies of key contacts — bank, IT provider, insurer, accountant, major suppliers;
- tested backups of accounting, invoicing and booking data;
- a written payment-verification rule that staff know to follow.
None of these are expensive, and together they turn a crisis into a disruption. A standby facility in particular is far easier to arrange before an incident than during one.
How should you talk to a lender after an incident?
Be direct. Explain what happened, what it cost, what’s been fixed and what your forecast shows. Provide recent bank statements covering the period before the attack, so the lender can see normal trading. Lenders see one-off events regularly; what they want to know is whether the business is fundamentally sound and whether the funding will bridge a temporary gap rather than cover a permanent one.
Worked example (illustrative)
Illustrative only. A physiotherapy clinic’s booking and billing system is hit by ransomware on a Monday. For four days it can’t take online bookings or process health fund claims electronically, and appointments drop sharply. Its IT provider restores from backups, but the clinic needs new hardware and a security review.
The owner reports the incident through ReportCyber, notifies the insurer and builds a 13-week forecast. It shows a shortfall in three weeks, when wages, super and rent coincide with delayed health fund receipts. She arranges a short-term facility sized to that gap, funds the replacement computers through equipment finance and talks to her landlord about deferring half a month’s rent. By week eight, bookings and receipts are back to normal and the facility is repaid.
Recovering from an incident? Protect your cash flow now.
A cyber attack is stressful enough without a cash crisis following it. Funding sized to your recovery gap can keep staff paid and suppliers onside while you get back to normal. Tell us about it in about 60 seconds — there’s no credit check when you first enquire, and your details won’t be passed around a list of lenders. A real person reviews your situation and calls you. Please be accurate about your normal turnover and the size of the gap so we can match the right option first time.
Frequently asked questions
Where do I report a cyber attack on my business?
Through ReportCyber on the cyber.gov.au website, run by the Australian Signals Directorate's Australian Cyber Security Centre. It's the Australian Government's central reporting point for cybercrime and cyber security incidents.
What should I do if a supplier payment was sent to a scammer?
Call your bank immediately and ask it to try to recall or freeze the payment. Speed matters. Then report it through ReportCyber and contact the genuine supplier by a phone number you already have on file.
Will my business insurance cover a cyber attack?
Only if you hold cyber cover or your policy specifically includes it. Many general policies exclude cyber events. Check your policy wording and notify your insurer promptly, as late notification can affect claims.
Do I have to tell customers about a data breach?
If your business is covered by the Privacy Act and the breach is likely to cause serious harm, the Notifiable Data Breaches scheme may require you to notify affected individuals and the OAIC. Get advice quickly if personal information was involved.
Can I get a business loan while recovering from a cyber attack?
Often, yes, particularly if the business was trading well before the incident and can show the disruption is temporary. Lenders will want to understand what happened and what's been fixed.
How can I reduce the risk of it happening again?
The Australian Cyber Security Centre's small business guidance covers the essentials: multi-factor authentication, regular backups, automatic updates, and staff awareness of email and payment scams.