All insights

What should a venue do after a malware incident?

2 min readBy Brendon Whiting, Founder · 23 July 2026

Contain it first, recover second, and then rebuild to a standard rather than back to what you had. Restoring the arrangement that was compromised restores the exposure that allowed it, which is the most common and most understandable mistake made in the fortnight after an incident.

Containment in the first hour means disconnecting affected machines from the network without powering them off, stopping use of connected systems, and calling for help immediately. Powering off can destroy evidence that helps establish what happened; disconnecting stops the spread. In a venue that also means deciding quickly how to keep trading, which is where the manual fallback process earns its existence.

Recovery depends almost entirely on a decision made months earlier: whether your backups have been restored and tested. A venue with proven restores is dealing with days of disruption. One that discovers its backups were failing quietly is rebuilding from nothing, with bookings, sales history and configuration all gone. That difference is not determined during the incident.

Then the part that matters most and is easiest to skip under pressure to reopen. Rebuild to a standard rather than to the previous configuration: segmented networks, guest Wi-Fi genuinely separated, multi-factor authentication everywhere, managed devices, tested backups. Karidis Corporation did exactly that after a malware incident in 2023, rebuilding to 100% Essential Eight compliance with 99.99% uptime and 600 Mbps guest Wi-Fi. That is what a recovery looks like when it is used properly. If you want help rebuilding to a standard, call 1800 456 567.

Rebuild to a standard, not to what you had

We help venues recover from incidents and rebuild to Essential Eight rather than restoring the arrangement that failed.

Frequently asked questions

Not as a reflex and not alone. Payment guarantees nothing, decryption is often partial, and it marks the business as one that pays. Get advice, involve your insurer if you have cover, and report it through ReportCyber. The decision is a serious one that should not be made in the first hour.

It depends on what was accessed. If personal information was likely exposed and serious harm is possible, the Privacy Act's notifiable breach scheme may require assessment and notification. Get advice rather than deciding alone, and do not assume that because you are a venue rather than a bank it does not apply.

Longer than anyone expects, and the variable is whether you have tested backups. A venue with proven restores is dealing with days; one discovering its backups do not work is dealing with a rebuild from nothing. That difference is decided long before the incident, which is the whole argument for testing.

Questions? Let's talk.

Call 1800 456 567 or fill out the form.

  • 30-minute discovery — no jargon, no pressure
  • Plain-English Essential Eight Cyber Security Scorecard
  • A clear plan tailored to your business

Prefer to talk?

Call 1800 456 567

Powered by Calendly — your data is handled securely.

Our office · Level 2, 25 Grenfell Street, Adelaide

By submitting, you agree to our terms and privacy policy. No spam — ever.