The steps
- Use unique strong passwords per system (password manager)
- Enable two-factor authentication on email, NDIS Commission portal, PRODA, software
- Encrypt laptops and phones
- Use Australian-hosted, security-certified software where possible
- Train staff in phishing recognition
- Have a written cybersecurity policy
- Carry cyber liability insurance
Common mistakes to avoid
- Shared passwords across the team
- No 2FA on critical systems
- No staff training (most breaches are phishing)