Triage and contain two live security incidents
You are a security analyst.
What has happened
Two incidents are open in the Security and Safety Incident Register. At Merriwa Medical Centre the practice manager received an email impersonating a pathology supplier asking for updated bank details, which she did not click. At Harbourline Accountants a partner's mailbox was signed into from overseas at 3:10 am and an inbox rule was created forwarding mail to an external address; the account has been contained but the exposure has not been assessed. Yasmin Haddad wants both worked through the Cyber Security Incident Response Procedure today, with evidence preserved, wider exposure checked, plain language client notifications drafted and an assessment of whether personal information was accessed at Harbourline.
Deliverables
- Updated register entries with timelines and indicators
- Emergency change record
- Privacy breach assessment for the Business Services Manager
- Two client notifications
- Wider exposure check results
Documents to use
Systems to use
Security and Safety Incident Register
The register of cyber security incidents and workplace safety events with severity, containment, notification and review status.
Service Desk Tickets
The ticket queue for incidents and service requests from every managed client with priority, owner and status.
Change Request Register
The record of normal and emergency changes to client and Nova production systems with risk, approval, window and result.
Units of competency
Current on training.gov.au for the Information and Communications Technology as at 10 September 2026.
ICTCYS402Identify and confirm cyber security incidentsICTCYS406Respond to cyber security incidentsICTSAS440Monitor and administer security of ICT systemsICTICT424Address cyber security requirementsQualifications
ICT40120Certificate IV in Information TechnologyICT50220Diploma of Information TechnologyWhat to look for
Evidence guide
The student must show they preserved evidence before acting, followed the severity and timeframe rules, and checked for wider exposure rather than treating each incident as isolated. The privacy assessment must consider the type and volume of information and the likelihood of serious harm. Client notifications must be accurate, plain and free of blame.