A childcare centre does not feel like a cyber target. The focus is on the children, the families, and getting through a busy day. Security tends to mean locked gates and sign-in sheets, not passwords and backups.
The trouble is that a modern centre holds some of the most sensitive personal data there is, on children and the families behind them, and it moves money every week through fees and subsidies. To an attacker, that is a quiet, valuable, and often lightly defended target. If you have read our guide to IT for childcare centres, this is the practical companion: the seven gaps we find most often when we look properly, and how to close each one.
Gap 1: Family and Child Records Sitting in the Open
Centres collect a remarkable amount: birth certificates, immunisation records, medical and allergy details, court orders, home addresses, and emergency contacts. Much of it lands in an inbox or a shared drive and simply stays there, readable by anyone with a login.
This is exactly the data a breach is most damaging to lose, because it concerns children. The fix is to know where this information lives, restrict it to the staff who genuinely need it, and stop sensitive documents drifting around in email. A few sensible permissions on your folders does most of the work.
Gap 2: Childcare Management and CCS Software Access
Your management platform runs everything: enrolments, bookings, attendance, and the Child Care Subsidy claims that bring real money into the centre. The login to that system is the most valuable key you hold, and often the least protected.
We routinely find these logins shared between staff, left active for people who have moved on, or protected by a single password. The fix is one named login per person, access removed the day someone leaves, and a second verification step on the account so a stolen password alone is not enough to get in.

Gap 3: Fee and Subsidy Payment Fraud
Money in childcare moves through fee debits, parent payments, and subsidy reconciliations. That regular flow is exactly what payment fraud preys on. An attacker who gets into a mailbox can watch the rhythm and then send a convincing email asking to update bank details before the next run.
Because the request looks like it came from a familiar account, it passes the usual glance. The defence is part technical and part habit: a second verification step on every mailbox to make the break-in harder, and a firm rule that any change to bank or payment details is confirmed by a phone call to a known number, never by replying to the email.
Gap 4: High Staff Turnover and Working-With-Children Records
Childcare runs on a changing roster: casuals, students on placement, and educators moving between centres. Every arrival and departure is a small security event, and the records you keep, including working-with-children check numbers, are sensitive in their own right.
The common gap is access that never gets switched off. A departed educator still has a login to the management system or the shared drive, weeks or months later. The fix is unglamorous but effective: access granted by role when someone starts, reviewed regularly, and removed promptly the day they leave.
Gap 5: Shared Front-Desk and Floor Devices
The reception iPad, the office computer everyone uses, the tablet for sign-in and observations. Shared devices are normal in a centre, and they are a soft spot. When everyone uses the same login, there is no way to tell who did what, and one left-open session exposes everything.
You do not have to hand every educator a laptop. You do need a screen lock that engages quickly, individual logins where it matters, and the device set up so a curious child or a visitor cannot wander into family records. Encryption on those devices means a lost or stolen tablet is an inconvenience, not a data breach.
Gap 6: Multi-Factor Authentication Missing
Almost every centre has a password on its systems. Very few have the second lock. Multi-factor authentication means a login needs your password plus a prompt on your phone, so a leaked or guessed password is not enough on its own.
This single control blocks most account takeovers, and it is the one we most often find switched off, or switched on for email but missing from the management platform and remote access. The fix is to inventory every system that holds family data or touches money and enforce that second step on all of them, with no exceptions for “just this one” account.
Gap 7: Backups That Have Never Been Tested
Enrolments, attendance records, observations, and financials all live in systems you assume are backed up. The dashboard is green, so everyone relaxes. Then a device fails or ransomware hits, someone tries to restore, and the copy is incomplete or was never really running.
A backup nobody has restored from is a guess, not a safety net. The fix is to test restores on a schedule and keep at least one copy an attacker cannot alter or delete. You want to know that if the worst happens, your records and your compliance evidence come back in hours, not weeks.
Closing the Gaps
None of these are exotic, and none require pulling your centre apart. They are the everyday shortfalls that turn a preventable incident into a real one, and every one of them maps to the basics in Essential Eight, the baseline set of controls published by the Australian Cyber Security Centre. Close them in priority order and you significantly reduce your risk without disrupting the work.
The hard part is knowing which apply to you, because most stay invisible until someone looks. That is the value of an honest assessment.
Where to Start
If you recognised your centre in more than one of these, you are normal, and you are in a good position, because every gap on this list has a clear fix.
Start by getting a clear picture of where you stand. Our IT maturity assessment takes a few minutes and shows you which controls need attention first.
We are a Sydney-based team in Bella Vista, and we help childcare centres across the metro area close these exact gaps and keep them closed, with managed IT that treats security as ongoing rather than a one-off. No jargon, no scare tactics, just the basics done properly.