Cyber Security Safety
We hold sensitive information about the people we support, including health details, plans, addresses and funding. Cyber criminals target care providers because this information is valuable and because busy staff can be caught off guard. This course shows you how to spot phishing emails, texts and calls, create strong passphrases and use multi factor authentication, keep work phones, tablets and laptops secure, and handle participant information safely in apps, messages and photos. You will also learn what to do if you click a suspicious link or lose a device, and how data breaches are reported under the Privacy Act, then work through two case studies. Duration: 55 minutes.
- 55 minutes
- 5 modules
- 10 interactive lessons
- Recommended training
- For All Staff
- Certificate on passing
- $55 inc GST
What you will learn
Module 1: Phishing and Scams
- Recognising Phishing
Phishing is when criminals pretend to be someone you trust to trick you into clicking a link, opening an attachment, sharing a password or sending money. It can arrive by email, text message, phone call or social media. This lesson explains the warning signs. Key points: look for urgency, unexpected requests, mismatched sender addresses and links, requests for passwords or payment details, and messages that seem slightly off; phishing is designed to make you act quickly, so the best defence is to slow down and check.
- Scams Targeting Care Providers
Some scams specifically target disability and aged care providers and their staff. This lesson looks at common examples, including fake invoices and changed bank details, messages pretending to be a manager, fake NDIS or myGov messages, and calls asking for participant information. Key points: always verify payment or bank detail changes by phone using known details, never share participant information with an unverified caller, report suspicious messages rather than deleting them, and remember that our IT team and managers will never ask for your password.
Module 2: Passwords and Multi Factor Authentication
- Strong Passphrases
Weak or reused passwords are one of the easiest ways for criminals to get into accounts. This lesson explains how to create strong passphrases. Key points: use a long passphrase made of several random words, which is easier to remember and harder to crack than a short complex password; use a different passphrase for each account, especially work accounts; never share passwords or write them where others can see them; use a password manager if one is approved; and change a password straight away if you think it has been exposed.
- Multi Factor Authentication
Multi factor authentication, or MFA, adds a second check when you log in, such as a code in an app, a text message or a fingerprint. Even if a criminal steals your password, MFA can stop them getting in. This lesson explains how to use it safely. Key points: turn on MFA wherever it is offered, especially for email and rostering apps; authenticator apps are generally more secure than text codes; never approve a login request you did not start; never share an MFA code; and report unexpected MFA prompts straight away.
Module 3: Securing Your Devices
- Phones, Tablets and Laptops
Support workers often carry work information on phones, tablets and laptops in homes, cars and the community, which makes devices easy to lose or steal. This lesson covers the basics of device security. Key points: use a screen lock with a PIN, pattern or biometric; lock your screen when you step away; install updates promptly; only install apps from official stores and those approved for work; avoid public Wi Fi for work systems unless you use approved protection; never leave devices in view in a car; and report a lost or stolen device straight away.
- Email, Attachments and Safe Browsing
Email and web browsing are the most common ways malicious software reaches our systems. This lesson covers safe habits. Key points: do not open attachments or click links you were not expecting; watch for files that ask you to enable macros or editing; check the address bar before logging in; do not use personal email or personal cloud storage for work information; keep work and personal use separate on shared devices; and if you click something suspicious, disconnect from Wi Fi if you can and report it immediately rather than hoping for the best.
Module 4: Protecting Participant Information
- Handling Participant Data Safely
Participant information is personal and often sensitive health information protected by the Privacy Act and our privacy policy. This lesson covers safe handling. Key points: only access and share what you need for your role; use approved systems and apps, not personal messaging apps or personal email; do not take photos of participants or documents on personal devices unless approved and consented; never post about participants on social media; check recipients before sending; and store paper records securely and dispose of them through secure methods.
- Data Breaches and Reporting
A data breach happens when personal information is lost, accessed or shared without authorisation. This lesson explains what to do. Key points: examples include emailing a plan to the wrong person, a lost device, a hacked account or a record left behind; report any suspected breach to your team leader straight away, because we must assess it quickly; under the Notifiable Data Breaches scheme, breaches likely to cause serious harm must be reported to the Office of the Australian Information Commissioner and the affected people; and reporting in good faith is always the right thing to do.
Module 5: Cyber Safety on the Job
- Case Study: The Urgent Invoice
This case study follows Olivia, a team leader who pays small supplier invoices for her office. An email arrives that seems to come from a regular cleaning supplier, saying an invoice is overdue and their bank details have changed. The lesson picks out the red flags, shows how Olivia verifies the request by phoning the supplier on a number she already has, and explains what happens after she reports it. Key points: never change bank details based on an email alone, urgency is a warning sign, and reporting protects the whole organisation.
- Case Study: A Lost Work Phone
This case study follows Jarrah, a support worker who realises his work phone is missing after a community outing with a participant. The phone has his work email, our rostering and notes apps and participant contact details. The lesson shows what Jarrah does first, why speed matters, and how a screen lock, multi factor authentication and keeping photos and notes only in approved apps limited the harm. Key points: report a lost device straight away, change passwords, let us lock or wipe it, and good daily habits protect participants when something goes wrong.
How the course works
Every lesson is narrated and hands on, with sorting, sequencing and flip card activities and realistic workplace scenarios. A quiz closes each module and a final assessment, with questions shuffled every attempt, confirms your understanding. Pass with 80% or more to receive your certificate.
Frequently asked questions
How long is the Cyber Security Safety course?
The course takes about 55 minutes. It has 5 modules and 10 narrated, interactive lessons, and you can stop and pick up where you left off at any time.
Do I get a certificate?
Yes. Complete every lesson and module quiz, then pass the final assessment with 80% or more. Your certificate is issued straight away, emailed to you and carries a unique ID that employers and auditors can check.
How much does it cost?
This course is $55 including GST and yours to keep. It is also included in All Access, which unlocks every course in the Academy for $260 a year.
Can I try it before I buy?
Yes. The first lesson of every course is free to try, with no account needed.
Who is this course for?
It is written for all staff in Australian NDIS and aged care services. It is recommended training for many roles.
Can I buy training for my whole team?
Yes. Contact Provider Compliance on 1800 299 452 or info@providercompliance.com.au for team access and bulk pricing.