When a security incident hits, what happens in the first 15 minutes determines the outcome. GCIT’s incident response team operates across 300+ organisations, backed by ISO 27001 certified processes and 24/7 SOC monitoring through Huntress.
A user downloaded a malicious script. Our team was alerted within minutes.
One of our managed clients, a Gold Coast real estate business, had a user download a file that turned out to be a ransomware payload. In most businesses without managed security, this would have been a catastrophic incident. Files encrypted, operations halted, a six-figure ransom demand.
Instead, five separate layers of protection caught it. Our team was alerted, investigated the payload, and wiped and reset the machine per our standard incident response policy. The user was back on a clean device with minimal interruption. That’s what a structured response looks like when the preparation is already done.
In a separate case, we investigated a $40,000 invoice fraud where attackers compromised a buyer’s email, intercepted a real invoice, changed the banking details, and re-sent it. They also set up hidden forwarding rules to keep monitoring the conversation even after the password was changed. Detecting and removing those rules is part of every account compromise investigation we run.
What stopped the ransomware
1
No local admin privileges
Limited the script’s ability to execute system-level changes
2
Cisco Umbrella blocked the callback
DNS filtering stopped the connection to the malicious server
3
Huntress detected and isolated
EDR identified the behaviour and quarantined the device
4
ThreatLocker blocked execution
Application control prevented the payload from running
5
Machine wiped and rebuilt
Per GCIT policy: wipe, reset, redeploy via Intune. User back online same day.
Structured Response
Our incident response framework
GCIT’s incident response process is grounded in ISO 27001 Annex A controls and aligns with the NIST Cybersecurity Framework. Every managed client has access to this process as part of their service plan.
Our policy is straightforward: when a compromised device is identified, we don’t take chances. We wipe and reset the machine. Because we have strong onboarding policies with Intune and Autopilot, getting a user back on a clean device takes minutes, not days.
“We don’t take chances. We’re just going to wipe and reset the machine. And because we have good onboarding policies, it’s very simple to set a user up on a new computer with very little interruption.”
Elliot Munro
CISO, GCIT
1. Preparation+
Before an incident occurs, we harden your environment with endpoint protection policies, application control via ThreatLocker, conditional access policies in Microsoft Entra ID, and removal of local admin privileges. We establish monitoring baselines so our SOC knows what normal looks like for your environment.
2. Detection+
Huntress provides 24/7 human-led SOC monitoring across all managed endpoints. Microsoft Defender for Endpoint adds automated threat detection and investigation. ThreatLocker alerts on blocked application attempts. Cisco Umbrella flags DNS requests to malicious domains. Multiple signals from multiple layers mean threats are caught quickly.
3. Containment+
When a threat is confirmed, containment is immediate. Huntress can isolate a compromised device from the network within seconds. We lock affected user accounts, revoke active sessions, and block lateral movement. For network-level threats, we coordinate with your firewall and DNS filtering to cut off communication with attacker infrastructure.
4. Eradication+
Our standard practice for compromised endpoints is a full wipe and rebuild. We rotate all affected credentials, review mailbox forwarding rules, check for persistence mechanisms, and verify that no backdoors remain. We don’t try to clean infected machines. A fresh build from Intune and Autopilot is faster and more reliable.
5. Recovery+
We restore data from verified backups, validate service functionality, and confirm that users can access their applications and data. We communicate clearly with your team throughout the process so everyone knows the status and expected timeline.
6. Lessons Learned+
Every significant incident gets a post-incident report. We document what happened, how it was detected, what was done, and what controls need to change. Root cause analysis feeds directly into your security improvement roadmap. This is a requirement of our ISO 27001 processes and ensures the same type of incident doesn’t happen twice.
Detection & Response Stack
The tools that detect threats and drive our response
These are the tools our team uses during an active incident. From initial detection through to device rebuild, every step is instrumented.
Huntress EDR + SOC
24/7 human-led threat hunting with managed SOC. Detects behavioural anomalies, isolates compromised devices within seconds, and provides analyst-written incident reports.
Microsoft Defender EDR
Endpoint detection and response included in Microsoft 365 Business Premium. Automated investigation, threat analytics, and real-time alerting across all managed devices.
ThreatLocker
Application allowlisting that blocks ransomware and unknown executables before they run. Ringfencing prevents approved apps from accessing resources they shouldn’t.
Microsoft Entra ID
Identity investigation during compromise: session revocation, credential reset, conditional access enforcement, impossible travel detection, and audit log analysis.
Microsoft Intune
Device hardening and compliance enforcement: BitLocker encryption, attack surface reduction rules, credential guard, and security baselines. After compromise, wipe and redeploy a fully configured device in minutes via Autopilot.
ScreenConnect + RMM
Remote access for live investigation and remediation. Server status checks, service restarts, log collection, and coordination across multi-site environments during outages.
Scenario Response
What happens when…
Real scenarios. Real responses. Here’s exactly what our team does.
A phishing email gets through?+
Avanan catches most phishing inline before it reaches the inbox. If one gets through and a user clicks the link, Cisco Umbrella blocks the connection to the malicious site. If credentials are entered, Microsoft Entra ID conditional access policies detect the unusual sign-in pattern. Huntress identifies any post-compromise behaviour. Our team resets the user’s credentials, revokes all active sessions, reviews mailbox forwarding rules and audit logs, and confirms no data was accessed.
Ransomware is detected on a device?+
ThreatLocker blocks the ransomware from executing because it is not on the approved application list. Huntress detects the behavioural pattern and isolates the device from the network. Microsoft Defender flags the malicious file. Our team is alerted within minutes. Per our policy, we wipe and rebuild the device from Intune and Autopilot. Data is restored from verified backups. The user is back online the same day.
A user account is compromised?+
Microsoft Defender alerts on unusual sign-in activity, such as impossible travel or sign-ins from unfamiliar locations. Our team revokes all sessions, resets the password, reviews authentication methods for tampering, checks mailbox rules for hidden forwarding, and inspects the audit log for data access. If the account was used to send phishing emails internally, we contain and remediate those as well.
A data breach requires notification?+
Under the Notifiable Data Breaches scheme, Australian organisations must assess a suspected breach within 30 days and notify the OAIC and affected individuals if serious harm is likely. GCIT supports this process by documenting the incident timeline, identifying what data was accessed, containing the breach, and preparing the information your legal team or cyber insurer needs for notification.
Systems go down after a power outage?+
Our team remotely triages affected sites using ScreenConnect and our RMM platform. We check server status, verify backup integrity, coordinate with ISPs for connectivity restoration, and confirm that critical applications are back online. For clients with multiple sites, we prioritise based on business impact and work through each location systematically.
Industry-Specific Response
Every industry has different incident response obligations
Select your industry to see how GCIT tailors incident response to your compliance requirements and risk profile.
Healthcare & Health Networks
Health organisations are subject to the Notifiable Data Breaches scheme and the My Health Records Act. Patient data breaches carry strict reporting obligations and significant penalties.
GCIT supports medical practices, PHNs, and allied health organisations with response procedures aligned to Australian healthcare privacy law. We understand Best Practice, Medical Director, and Primary Sense, and how to protect the data they hold.
Key risks and obligations
Notifiable Data Breaches scheme
Assessment within 30 days, OAIC notification if serious harm likely
My Health Records Act
Additional protections for My Health Record data
Healthcare data sovereignty
Patient data stored and processed under Australian privacy law
Cyber insurance coordination
Incident timeline and evidence for insurer claims
Finance & Professional Services
Financial services firms handle sensitive client data and are prime targets for business email compromise and invoice fraud. A compromised email account can result in direct financial loss within hours.
Firms over $3M revenue must assess and report breaches to the OAIC
ASIC and AUSTRAC reporting
Regulatory notification requirements for financial data incidents
Forwarding rule detection
Attackers set hidden rules to monitor payment conversations post-compromise
Legal Firms
Law firms hold privileged client communications protected by legal professional privilege. A breach doesn’t just expose data, it can compromise active matters, settlements, and client trust.
GCIT supports legal practices with incident response procedures that account for privilege obligations, document management system security, and the sensitivity of matter-related communications.
Key risks and obligations
Privileged communications
Exposure of legally privileged client-solicitor correspondence
Trust account and settlement fraud
BEC attacks targeting conveyancing, settlements, and client payments
Law Society reporting obligations
QLS and professional body conduct rules require breach notification
Privacy Act and NDB scheme
Mandatory breach assessment and OAIC notification for client data exposure
Not-for-Profit Organisations
NFPs often handle sensitive participant, donor, and beneficiary data with limited IT budgets. Government-funded NFPs increasingly face compliance requirements around data handling and incident reporting.
GCIT supports not-for-profit organisations with incident response that’s proportionate to their risk profile and funding requirements, including support for NDIS, ACNC, and government reporting obligations.
Key risks and obligations
Participant and beneficiary data
Sensitive personal and health information for vulnerable populations
Government contract reporting
NDIS, ACNC, and state funding bodies mandate incident disclosure
Essential Eight compliance
Increasingly mandated for government-funded organisations
Privacy Act obligations
NFPs over $3M revenue are subject to mandatory breach notification
Real Estate
Real estate agencies handle large financial transactions and personal identification documents daily. They are consistently targeted by business email compromise attacks, particularly around settlement and rental bond payments.
GCIT supports real estate agencies with rapid BEC response, trust account protection, and identity document handling aligned to Queensland’s upcoming cyber regulations for the property sector.
Key risks and obligations
Settlement payment interception
Attackers alter banking details on settlement instructions
Identity document exposure
Drivers licences, passports, and financial records in property files
QLD cyber regulations (July 2026)
New mandatory cyber obligations for Queensland property sector
Privacy Act breach notification
Agencies holding personal data must report eligible breaches to the OAIC
Manufacturing & Construction
Manufacturing and construction businesses face operational technology risks alongside traditional IT threats. Ransomware can halt production lines, and the cost of downtime is measured in hours of lost output, not just data.
GCIT supports manufacturing and construction businesses with rapid containment, backup restoration for production systems, and response procedures that prioritise operational uptime.
Key risks and obligations
Production downtime
Ransomware can halt manufacturing lines for days or weeks
Legacy system exposure
Older Windows machines and flat networks increase lateral movement risk
WHS and safety system obligations
Cyber incidents affecting safety systems trigger WHS reporting duties
Backup-dependent recovery
Production data restoration is the critical path to resuming operations
Beyond Response
Incident response is part of a bigger picture
Incident response doesn’t exist in isolation. It connects directly to your business continuity planning, disaster recovery procedures, and ongoing security posture improvement.
GCIT manages cloud backup and disaster recovery for all managed clients. We document RTO and RPO targets, run regular recovery drills, and maintain immutable backups that can’t be encrypted by ransomware. When an incident occurs, recovery is not a scramble. It’s a documented, tested process.
300+
Organisations monitored
15 min
P1 response target
24/7
SOC coverage via Huntress
ISO 27001
Certified response processes
Your certified incident response team
Certified Management Systems
Microsoft Certifications
Security Assessors
Credibility & Recognition
Trusted by industry leaders to detect and respond
Real incident response outcomes, industry recognition, and practical security knowledge shared with the community.
GCIT is a Microsoft Solutions Partner for Modern Work, meeting advanced certification requirements for Microsoft 365 deployment, security, and identity management since 2002.
Common Questions
Frequently asked questions
How quickly will GCIT respond to a security incident?+
Our target response time for critical security incidents is 15 minutes during business hours. After hours, Huntress SOC provides 24/7 monitoring and can automatically contain threats, such as isolating a compromised device, within seconds of detection. Our on-call team responds to critical alerts around the clock.
Do you provide 24/7 incident response?+
Yes. Huntress SOC operates 24/7/365 and provides human-led threat detection and response. Automated containment actions, like device isolation, happen without waiting for our team. For incidents requiring manual intervention outside business hours, our on-call technicians are alerted immediately for P1 critical issues.
What frameworks does your incident response align to?+
Our incident response process aligns with ISO 27001 Annex A controls (specifically A.5.24-A.5.28 for incident management) and the NIST Cybersecurity Framework Respond and Recover functions. We also support clients with ASD Essential Eight alignment, which includes controls relevant to incident prevention and response.
Do you support OAIC breach notification requirements?+
Yes. We assist with the assessment, documentation, and containment steps required under the Notifiable Data Breaches scheme. We document the incident timeline, identify what data was accessed, and prepare the information your legal team or cyber insurer needs. The formal notification to the OAIC is typically handled by the organisation’s legal counsel, but we provide all the technical evidence.
How does incident response integrate with your managed service plans?+
Incident response is included in every GCIT managed service plan. It’s not sold separately. All the tools, monitoring, and response capability described on this page are part of your base service. You don’t need to buy additional security packages to get incident response coverage. See our managed cybersecurity services page for the full security stack.
Can you help with cyber insurance claims?+
Yes. When a client has cyber insurance, our first recommendation is to contact their insurer. We then work alongside the insurer’s incident response team, providing technical evidence, containment confirmation, and timeline documentation. Our ISO 27001 certified processes and detailed incident logs are exactly what insurers need to process a claim efficiently.
Related Service
Suspect an insider threat?
When the threat comes from inside your organisation, you need forensic evidence, not just incident response. Our insider threat investigation service analyses Microsoft 365 audit logs, email traces, and cloud storage activity to identify exactly what was taken and build a court-ready evidence package.
Don’t wait for an incident to find out if your provider can respond.
Book a free security assessment. We’ll review your current incident readiness, identify the gaps that matter most, and show you what a structured response capability looks like for your business.