Skip to main content

Seven Cyber Gaps in Sydney Community Orgs

10 September 2026 | By Birender Chahal

Community organisations rarely see themselves as a cyber target. The mission is to help people, the budget is tight, and IT is whatever keeps the laptops running. Security feels like a corporate concern, something for the businesses you sit alongside rather than for a not-for-profit.

That is exactly why the sector gets caught. Community organisations hold some of the most sensitive data there is, run on volunteers and casual staff who change often, and handle grants and donations that move real money. They also tend to run on ageing equipment and stretched resources, which is precisely the soft target an attacker looks for. If you want the wider picture, start with our guide to IT for community services. Here are the seven gaps we find most often, and the practical fix for each.

Gap 1: Vulnerable Client Data Is Exposed

Community organisations often hold the most sensitive personal information of anyone: case notes, health details, family circumstances, records about people who are already at risk. A breach here is not just a privacy fine, it can put vulnerable clients in real danger.

We routinely find this data spread across spreadsheets, email attachments, and shared drives where far too many people can see it. The fix is to know exactly where client data lives, restrict it to the staff who genuinely need it for their role, and protect those systems properly. The duty of care you have to your clients in person extends to their information, and it deserves the same standard.

Gap 2: Volunteer Access Sprawl

The sector runs on volunteers, and access tends to spread with every new helper who needs to log in to something. Over time, far more people can reach client records, the donation system, or shared drives than anyone realises, and much of it belongs to volunteers who left months or years ago.

Every active login is a potential way in, and a former volunteer’s forgotten account is a quiet one. The fix is to grant access by role, keep it to what each person actually needs, and switch it off promptly when someone stops volunteering. A simple register of who has access to what, reviewed regularly, turns sprawl back into something you control.

Diverse team socialising in office breakroom
In community services, protecting client data is part of the duty of care.

Gap 3: Grant and Donation Payment Fraud

Money moves through community organisations in ways attackers love to exploit: grant payments, donor transfers, supplier invoices, and reimbursements, often handled by a small finance team or a single bookkeeper.

An attacker who gets into one mailbox can watch the money flow and then send a request that looks genuine, asking to update bank details before a grant lands or a payment goes out. Because it comes from a real-looking account, it passes the usual checks. The defence is multi-factor authentication on every mailbox to make the break-in harder, plus a firm rule that any change to payment details is confirmed by a phone call to a known number, never by replying to the email.

Gap 4: Ageing, Unpatched Equipment

Tight budgets mean equipment gets kept long past its prime. We often find community organisations running computers on a version of Windows that stopped receiving security updates, or machines that are years behind on patches because money for replacements never quite arrives.

An unsupported or unpatched machine is an open door, because most attacks use a flaw that already had a fix available. The good news is that closing this gap rarely means buying everything new at once. It means actively managing updates on the machines you have, and replacing the few that can no longer be protected, in priority order rather than all at once.

Gap 5: No Multi-Factor Authentication

Almost every organisation has a password on its email and its key systems. Far fewer have a second lock. We regularly find multi-factor authentication switched on for nothing, leaving the accounts that hold client data and control the money protected by a single password that may already have leaked.

Attackers look for the one account with only a password in front of it. The fix is to inventory every system that holds sensitive data or money and turn on a second verification step everywhere, starting with email. It is the single control that blocks most account takeovers, and it costs nothing to switch on in tools you already use.

Gap 6: Untested Backups

Backups are “running”, the dashboard is green, and everyone assumes the client records and case files are safe. Then a device fails or ransomware hits, someone tries to restore, and the files are incomplete, corrupted, or encrypted along with everything else.

For an organisation that holds irreplaceable client histories, this is not a gap you can afford. A backup nobody has restored from is a guess. The fix is to test restores on a schedule and keep at least one copy an attacker cannot alter or delete, so a bad day means a few hours of recovery rather than the permanent loss of records people depend on.

Gap 7: Donated Security Licensing Left Unused

This one is almost unique to the sector, and it is good news. Many community organisations qualify for heavily discounted or donated software through programs for not-for-profits, and a lot of that licensing includes serious security features that are simply never switched on.

We routinely find organisations already paying for, or entitled to, protections like multi-factor authentication, advanced email filtering, and device controls that sit unused because nobody set them up. The fix is the cheapest one on this list: turn on the security you already have access to. Closing this gap is often a configuration job, not a purchase.

Closing the Gaps

None of these are exotic. They are the everyday shortfalls that turn a stretched but well-run organisation into a breach victim, with vulnerable clients paying the price. Most of them are settings you can tighten or protections you already qualify for, not a budget you do not have.

The hard part is knowing which gaps apply to you, because most are invisible until someone looks. That is the value of an honest assessment.

Where to Start

If you recognised your organisation in more than one of these, you are normal, and you are in a good position, because every gap here has a clear fix. The starting point is the same for everyone: get a clear picture, then close the biggest gaps in order.

Our IT maturity assessment takes a few minutes and gives you a plain-English read on where you stand. For the structured version of the basics, it is worth reading what Essential Eight is, the baseline published by the Australian Cyber Security Centre.

We are a Sydney-based team in Bella Vista, and we work with community services organisations across the metro area. We understand tight budgets and a duty of care to vulnerable people, and we help you protect both. Talk to our team when you are ready.

Birender Chahal
Founder, CIO Tech

Birender founded CIO Tech and holds an IT degree from the University of Technology Sydney. He has delivered IT projects across hotels and serviced offices, covering property management systems, guest networks, and Essential Eight hardening. More about CIO Tech.

Stop putting off IT that works

Book an IT Audit

$990 one-off. 90-day deep dive into your IT environment with a prioritised action plan.

Book IT Audit

Free IT Health Check

Takes 3 minutes. See where your IT stands and what to fix first.

Free IT Health Check

Cyber Posture Snapshot

Your details 1 / 10

How exposed is your business?

Six quick questions, two short ones to tailor the result, and you'll see where your business stands. About two minutes. Plain English, no jargon.

We'll use your email to send a copy of your result. No spam, no pushy sales calls.

Question 1 of 9

When your team logs in to email and business apps, do they need a code from their phone as well as a password?

Question 2 of 9

If a ransomware attack locked all your files tomorrow, could you restore them from a backup?

Question 3 of 9

When Microsoft or Apple release a critical security update, how fast does it land on your computers?

Question 4 of 9

How many people in your business can install software or change system settings on any work computer?

Question 5 of 9

If a staff member got a fake invoice or "urgent" email pretending to be from you right now, what would happen?

Question 6 of 9

When a staff member leaves, when does their access to email, files, and apps actually get cut off?

Question 7 of 9

How many people work in your business?

Question 8 of 9

Who looks after your IT today?

Question 9 of 9

What sort of business are you?

Tailoring your result...

Hi there, here's where your business stands.

Your Cyber Posture
Critical gaps Critical
Notable exposure Notable
Mixed picture Mixed
On the right track On track

Notable exposure

Your two biggest gaps

  1. 1
  2. 2

Where this leaves you on Essential Eight

  • MFA Multi-factor authentication
  • Backups Regular backups
  • Patching Covers 2 of 8: Patch applications + Patch operating systems
  • Admin access Restrict administrative privileges

This snapshot covers 5 of the 8 Essential Eight controls. The full IT Maturity Assessment covers all 8, plus Microsoft 365 hardening, device management, and staff training.