
Help centre / Security incidents
Security incidents
Reporting incidents to GovCert and following up on advisories.
How do I report a cyber incident affecting a government system?
Report immediately to GovCert with the affected system, time of detection and observed impact. Preserve logs and do not rebuild the host before triage.
What counts as a reportable incident?
Any unauthorised access, data exposure, ransomware, defacement, or sustained denial of service affecting a public sector system or account.
How are advisories distributed?
Advisories are sent to institutional CIO contacts and mirrored in the resource centre. Acknowledgement is expected within five working days.
Didn't find your answer?
Open a ticket and reference this topic — it routes straight to the responsible desk.
Submit a ticket