Skip to main content

Seven Cyber Gaps in Sydney Childcare Centres

25 August 2026 | By Birender Chahal

A childcare centre does not feel like a cyber target. The focus is on the children, the families, and getting through a busy day. Security tends to mean locked gates and sign-in sheets, not passwords and backups.

The trouble is that a modern centre holds some of the most sensitive personal data there is, on children and the families behind them, and it moves money every week through fees and subsidies. To an attacker, that is a quiet, valuable, and often lightly defended target. If you have read our guide to IT for childcare centres, this is the practical companion: the seven gaps we find most often when we look properly, and how to close each one.

Gap 1: Family and Child Records Sitting in the Open

Centres collect a remarkable amount: birth certificates, immunisation records, medical and allergy details, court orders, home addresses, and emergency contacts. Much of it lands in an inbox or a shared drive and simply stays there, readable by anyone with a login.

This is exactly the data a breach is most damaging to lose, because it concerns children. The fix is to know where this information lives, restrict it to the staff who genuinely need it, and stop sensitive documents drifting around in email. A few sensible permissions on your folders does most of the work.

Gap 2: Childcare Management and CCS Software Access

Your management platform runs everything: enrolments, bookings, attendance, and the Child Care Subsidy claims that bring real money into the centre. The login to that system is the most valuable key you hold, and often the least protected.

We routinely find these logins shared between staff, left active for people who have moved on, or protected by a single password. The fix is one named login per person, access removed the day someone leaves, and a second verification step on the account so a stolen password alone is not enough to get in.

Childcare worker using tablet in preschool classroom
The family record and the subsidy login are the two prizes in a childcare centre.

Gap 3: Fee and Subsidy Payment Fraud

Money in childcare moves through fee debits, parent payments, and subsidy reconciliations. That regular flow is exactly what payment fraud preys on. An attacker who gets into a mailbox can watch the rhythm and then send a convincing email asking to update bank details before the next run.

Because the request looks like it came from a familiar account, it passes the usual glance. The defence is part technical and part habit: a second verification step on every mailbox to make the break-in harder, and a firm rule that any change to bank or payment details is confirmed by a phone call to a known number, never by replying to the email.

Gap 4: High Staff Turnover and Working-With-Children Records

Childcare runs on a changing roster: casuals, students on placement, and educators moving between centres. Every arrival and departure is a small security event, and the records you keep, including working-with-children check numbers, are sensitive in their own right.

The common gap is access that never gets switched off. A departed educator still has a login to the management system or the shared drive, weeks or months later. The fix is unglamorous but effective: access granted by role when someone starts, reviewed regularly, and removed promptly the day they leave.

Gap 5: Shared Front-Desk and Floor Devices

The reception iPad, the office computer everyone uses, the tablet for sign-in and observations. Shared devices are normal in a centre, and they are a soft spot. When everyone uses the same login, there is no way to tell who did what, and one left-open session exposes everything.

You do not have to hand every educator a laptop. You do need a screen lock that engages quickly, individual logins where it matters, and the device set up so a curious child or a visitor cannot wander into family records. Encryption on those devices means a lost or stolen tablet is an inconvenience, not a data breach.

Gap 6: Multi-Factor Authentication Missing

Almost every centre has a password on its systems. Very few have the second lock. Multi-factor authentication means a login needs your password plus a prompt on your phone, so a leaked or guessed password is not enough on its own.

This single control blocks most account takeovers, and it is the one we most often find switched off, or switched on for email but missing from the management platform and remote access. The fix is to inventory every system that holds family data or touches money and enforce that second step on all of them, with no exceptions for “just this one” account.

Gap 7: Backups That Have Never Been Tested

Enrolments, attendance records, observations, and financials all live in systems you assume are backed up. The dashboard is green, so everyone relaxes. Then a device fails or ransomware hits, someone tries to restore, and the copy is incomplete or was never really running.

A backup nobody has restored from is a guess, not a safety net. The fix is to test restores on a schedule and keep at least one copy an attacker cannot alter or delete. You want to know that if the worst happens, your records and your compliance evidence come back in hours, not weeks.

Closing the Gaps

None of these are exotic, and none require pulling your centre apart. They are the everyday shortfalls that turn a preventable incident into a real one, and every one of them maps to the basics in Essential Eight, the baseline set of controls published by the Australian Cyber Security Centre. Close them in priority order and you significantly reduce your risk without disrupting the work.

The hard part is knowing which apply to you, because most stay invisible until someone looks. That is the value of an honest assessment.

Where to Start

If you recognised your centre in more than one of these, you are normal, and you are in a good position, because every gap on this list has a clear fix.

Start by getting a clear picture of where you stand. Our IT maturity assessment takes a few minutes and shows you which controls need attention first.

We are a Sydney-based team in Bella Vista, and we help childcare centres across the metro area close these exact gaps and keep them closed, with managed IT that treats security as ongoing rather than a one-off. No jargon, no scare tactics, just the basics done properly.

Birender Chahal
Founder, CIO Tech

Birender founded CIO Tech and holds an IT degree from the University of Technology Sydney. He has delivered IT projects across hotels and serviced offices, covering property management systems, guest networks, and Essential Eight hardening. More about CIO Tech.

Stop putting off IT that works

Book an IT Audit

$990 one-off. 90-day deep dive into your IT environment with a prioritised action plan.

Book IT Audit

Free IT Health Check

Takes 3 minutes. See where your IT stands and what to fix first.

Free IT Health Check

Cyber Posture Snapshot

Your details 1 / 10

How exposed is your business?

Six quick questions, two short ones to tailor the result, and you'll see where your business stands. About two minutes. Plain English, no jargon.

We'll use your email to send a copy of your result. No spam, no pushy sales calls.

Question 1 of 9

When your team logs in to email and business apps, do they need a code from their phone as well as a password?

Question 2 of 9

If a ransomware attack locked all your files tomorrow, could you restore them from a backup?

Question 3 of 9

When Microsoft or Apple release a critical security update, how fast does it land on your computers?

Question 4 of 9

How many people in your business can install software or change system settings on any work computer?

Question 5 of 9

If a staff member got a fake invoice or "urgent" email pretending to be from you right now, what would happen?

Question 6 of 9

When a staff member leaves, when does their access to email, files, and apps actually get cut off?

Question 7 of 9

How many people work in your business?

Question 8 of 9

Who looks after your IT today?

Question 9 of 9

What sort of business are you?

Tailoring your result...

Hi there, here's where your business stands.

Your Cyber Posture
Critical gaps Critical
Notable exposure Notable
Mixed picture Mixed
On the right track On track

Notable exposure

Your two biggest gaps

  1. 1
  2. 2

Where this leaves you on Essential Eight

  • MFA Multi-factor authentication
  • Backups Regular backups
  • Patching Covers 2 of 8: Patch applications + Patch operating systems
  • Admin access Restrict administrative privileges

This snapshot covers 5 of the 8 Essential Eight controls. The full IT Maturity Assessment covers all 8, plus Microsoft 365 hardening, device management, and staff training.