Experts in incident response

Outcome-oriented cyber incident response. Trust in practitioners who have helped hundreds of Australian businesses navigate ransomware, business email compromise, and intrusion events.

Leading Australian
incident response management.

Leading breach counsel on your side means no techno-babble, no legalese, and no theatrical chasing of intruders. Just outcomes that get you back to business and ready to stand in front of regulators, customers and the public.

Ready and waiting, 24/7

Use our site chat to start a conversation with an incident responder at any hour. We onboard inside fifteen minutes and brief expert help to start responding straight away.

Experienced digital forensics

Pre-negotiated retainers with Australia's leading digital forensic investigators. Across hundreds of incidents we've briefed teams and turned their findings into decision-ready factual matrices.

Outcome focused

We care about getting you back to business — not chasing intruders. We cut the techno-babble and the legalese, and we're direct about what success looks like for your specific incident.

Regulatory & public ready

Every engagement is structured so you can stand up to regulatory and public scrutiny. Confident, ethical communications with regulators, affected individuals, and the public — proportionate and defensible.

Evidence preserved, incident contained.

A defensible response begins with a defensible record. We brief leading digital forensic investigators, contain the intrusion and preserve the factual matrix — so every later decision rests on evidence that will stand up to regulatory and public scrutiny.

  1. T-0 · on detection Handover Forensic investigator

    Digital forensic investigation

    We move quickly to engage one of Australia's leading digital forensic investigators, brief them against business outcomes, and begin painting a factual picture of how the incident has taken place. Our practitioners have analysed hundreds of forensic reports and use them as the roadmap for everything that follows.

  2. T+1 · first hours Custodian Internal working group

    Structured internal conversation

    While investigators are working, we establish rapport with your technology and business teams and stand up an internal working group. The group leads each stage of the response — discovery of at-risk data, containment and mitigation — with effective channels of internal communication.

  3. T+1 · ongoing External Regulators, customers, public

    Shape external communications

    Regulators, customers and the public are stakeholders in any cyber incident. We shape communications that are proportionate and informative — mitigating future harm to affected parties while balancing the risk of claims that may arise. A steady hand through a balancing act.

  4. T+ · statutory window Filing OAIC + co-regulators

    Satisfy regulatory requirements

    Mandatory reporting timeframes apply under the Privacy Act 1988 (Cth), alongside other circumstances where breach notification is required. We comply with these legislative requirements proactively, while co-ordinating the rest of the response and briefing directors or parties with a common interest as needed.

What to think about,
when responding to an incident.

Every Artificer-led incident moves through three deliberate stages: gather and contain, measure data impact, then notify and recover. Each stage has explicit deliverables and a clear exit. Together they produce a posture you can stand behind in front of the OAIC, your insurer and the public. Here's what to think about on the outset when considering leading your organisation through a response.

Digital forensics

The first move in any response is to contain and investigate — gathering as much evidence as the environment will yield. We engage Australia's leading digital forensic investigators from a pre-negotiated panel and move quickly to leverage that expertise.

Our practitioners have analysed hundreds of forensic reports and guided investigators to ensure their efforts align to business outcomes and legal-risk mitigation. Once the investigators complete their work, we use their reporting to build a roadmap to resolution.

Working group

While investigators are working, we rapidly establish rapport with your internal technology and business teams and prepare them for the action that's coming. A working group is stood up to own each stage of the response, with clear lines of communication end to end.

Once established, that working group can lead efforts for the remainder of the response — including discovery of at-risk data, containment and mitigation, and external engagement.

External communications

Regulators, customers and the public are just some of the stakeholders in a cyber incident. We shape communications that are proportionate and informative — effective at mitigating future harm to affected parties while managing the risk of future claims. We guide you through that balancing act with a steady hand.

Mandatory reporting timeframes apply under the Privacy Act 1988 (Cth) and a handful of other instruments. We keep that clock visible and proactively co-ordinate the response, including advice to directors and parties with a common interest as circumstances require.

Data Mapping

Often referred to as an organisation's crown jewels, we help you comprehensively identify where your most sensitive data resides on the network. We critically analyse data flows to flag where sensitive data may be residing in places it shouldn't.

This step can be undertaken prior to an incident as a preventative measure, or run concurrently with the digital forensic investigation once an incident is underway.

Map the exposure

Once we understand where sensitive data lives — and combine that with insight from the forensic investigation — we begin to build a picture of the risk the incident poses. We identify the fastest route to assess data risk, either working outward from your sensitive data or following the evidence of the intrusion to see how close an attacker came to exposing it.

Where sensitive data has been exposed, we rapidly build a comprehensive list of affected individuals to enable notification or remedial action. In appropriate cases this is done programmatically with modern data-science techniques — saving hundreds of hours of manual work.

Eligible Data Breach Assessment

Notification call

As lawyers and technologists, we analyse the facts of the incident and determine notification requirements under the Privacy Act 1988 (Cth), state-based legislation, and any organisation-specific laws that may compel notification.

The output is a defensible Eligible Data Breach Assessment, which is our advice on whether the incident meets the threshold for notification based on a risk assessment of the likelihood of harm. Get this right and the rest of the response falls into place.

Notification campaign

If notification is appropriate we produce the form of notification and run the campaign. Our approach strikes the right balance between legal compliance, helpfulness to impacted individuals, and protection of your organisation's interests. We handle foreign-jurisdiction notification through our international network where needed.

Notification is always a difficult step for an impacted organisation. With the right approach you minimise disruption to the business and present professionally to customers, regulators and the people whose data was touched.

Hardening and remediation

Cyber incidents often occur because of unforeseen vulnerabilities in the makeup of an organisation's digital infrastructure. Once identified, we recommend new or replacement technology systems to remedy those vulnerabilities and improve digital processes.

We go a step further than a typical law firm or IT consultancy — combining both disciplines to give you practical advice on mitigating the risk of future incidents, not just a post-mortem dressed up as a report.

Regulatory close-out

If regulators or third parties need to be engaged, it's important to have the best representation possible to safeguard your organisation's business interests. Combining a solid understanding of the technology with current and emerging jurisprudence, we successfully defend clients from regulatory investigation and legal claims arising out of cyber incidents.

The exit state is the one we started with in mind — a defensible posture, documented, and ready to stand in front of the OAIC, your insurer, or the public.

Need help to emerge stronger?

Use the form below to start recovery from a cyber incident. We can spin up response capability within minutes and take action to protect your organisation — note the time of discovery in your message so we're oriented as to how urgent your need is.

Get started quickly

Use this form or the website chat. We can spin up response capability within minutes and take action to protect your organisation straight away.

Ask us anything

Drop a videoconference or booking link into the form and we'll answer any questions you have before we engage.

Fast, fair pricing

Statement of Work delivered digitally at lightning speed. Don't sign anything until you've seen ours.