Ten Signs Your Business May Already Be Breached And What to Do About It
Cybercriminals rarely need to break anything to get in anymore. Stolen credentials or a missed patch will do the job quietly, and an attacker can sit inside a network for weeks before anyone notices something’s off. Australian organisations took an average of 48 days just to identify a breach in 2025, then another 86 days to report it to the regulator. Add that up and you’re looking at close to three months where someone could be moving through your systems while everything on the surface looks fine.
The numbers behind this have been climbing. The Office of the Australian Information Commissioner logged 1,205 data breach notifications in 2025, the highest since the scheme started back in 2018 and 8% more than the year before. IBM’s latest Cost of a Data Breach Report puts the average Australian incident at $4.22 million, a 38% jump since 2019. Detection speed turns out to matter a lot here businesses that took longer than 200 days to contain a breach paid $5.17 million on average, compared to $3.26 million for those who got it under control faster.
None of that is a reason to panic every time your laptop lags. It’s a reason to know the actual warning signs of a data breach, so if something happens, you’re catching it in days instead of months. Here are ten worth watching for, and what to do once you spot one.
1. Systems slow down and nobody can explain why
Background processes running malware or moving stolen data around eat up resources. If performance drops and there’s no new software, no heavier workload, nothing hardware-related to point to, that’s worth a proper look rather than a shrug and a reboot.
2. Logins happening at odd hours
Pull your access logs occasionally and check the timestamps. An admin account authenticating at 3am on a Sunday almost certainly isn’t your admin. This is one of the more dependable early signs that someone else has valid login details.
3. A run of failed login attempts
Dozens or hundreds of wrong password tries hitting the same account in a short window usually means a brute-force attack is underway. Lock the account and force a reset straight away you can sort out who or what caused it afterwards.
4. Files or settings changing on their own
A document goes missing. A configuration shifts and nobody on the team touched it. Attackers frequently make small, quiet changes like this to cover what they’ve been doing or to widen their access. Treat anything unexplained as suspicious until someone can account for it.
5. Outbound traffic that doesn’t match normal patterns
Most businesses watch what’s coming into the network far more closely than what’s leaving it. A spike in uploads to an unfamiliar destination is a fairly classic sign that data is being copied out before it’s used against you.
6. Emails going out that you didn’t send
If a client mentions getting a phishing email that looks like it’s from your business, chances are a mailbox has already been compromised. Attackers rely on trusted addresses precisely because people let their guard down for senders they recognise.
7. New accounts nobody remembers creating
Backdoor accounts are one of the more common ways attackers keep access after the initial break-in. A monthly audit of user accounts is a small habit that catches this before it becomes a much bigger problem.
8. Security alerts drying up
If your antivirus or intrusion detection tools go quiet, that’s not necessarily good news. Attackers sometimes disable or tamper with monitoring tools specifically so nothing gets flagged. A gap in logging deserves investigation, not the benefit of the doubt.
9. Ransom notes or pop-ups that shouldn’t be there
A message demanding payment to unlock your files is about as unambiguous as it gets. Slightly less obvious: unexpected prompts to install “updates” from sources you don’t recognise, which can turn up before the ransom note does.
10. Someone outside the business tells you first
Sometimes a customer, a supplier, or your bank flags unusual activity tied to your business before your own team notices anything. When that happens, it’s worth treating the tip as credible from the outset rather than waiting for internal confirmation.
What to do once you notice something
Disconnect the affected system before you do anything else. Containment comes first; working out exactly what happened can wait a few minutes.
Get your incident response plan moving. If you don’t have one written down and tested, that gap needs closing now, not mid-crisis and a cybersecurity partner can step in if the internal team doesn’t have the bandwidth.
Tell the people who need to know: leadership, affected clients, and, where the breach qualifies under the Notifiable Data Breaches scheme, the OAIC.
Once things are contained, investigate properly. Understanding how the attacker got in matters more than how fast you patch things up, because a quick fix that leaves the same door open just delays the next incident.
Then harden everything. Reset passwords on anything affected, switch on multi-factor authentication wherever it isn’t already running, and clear the backlog of pending security patches.
A quick self-audit
When did you last patch every critical server and application, honestly?
Is your monitoring actually catching high-severity issues, or just logging them for someone to review eventually?
Has your incident response plan been tested in the past twelve months, not just written and filed away?
If any of those made you hesitate, that’s the one to fix first.
A few questions worth asking
How long can an attacker realistically stay hidden in a network?
In Australia, the average sits around 48 days to detect and another 86 to reportĀ well over four months combined in plenty of cases. Regular log reviews and better detection tooling are what close that window.
Is this really a risk for smaller businesses, or mostly the big end of town?
Smaller businesses get targeted often, partly because defences tend to be lighter and detection slower. Size doesn’t buy protection on its own.
If a business could only do one thing right now, what would move the needle most?
Multi-factor authentication paired with a tested incident response plan consistently shows up as the biggest lever for both faster detection and lower breach costs in industry reporting.
Don’t wait for the ransom note
Most breaches don’t get caught because someone was watching closely. They get found by accident, months after the fact, usually when the damage is already done. Checking your systems against the list above, and actually testing your incident response plan rather than just having one on file, costs a lot less than cleaning up after the event. If any of this sounds a bit too familiar, it’s worth getting a cybersecurity professional to take a proper look before it turns into something bigger. What does your business currently do to catch a breach in its first week, rather than its fourth month?
