Cyber Security Policy
Updated: Sep 3
1. PURPOSE
This Cyber Security Policy includes guidelines and provisions for security measures to help mitigate cyber security risk at DCIRS Community Care (“DCIRS” or “company”). It applies to all company workers, contractors, volunteers, and anyone who has permanent or temporary access to the company’s systems and hardware. Cyber security measures assist DCIRS to protect participant information, personal information, organisational information, and service-delivery systems from unauthorised access, disruption, loss or misuse. Cyber security controls should support the continuity, availability and resilience of systems required for safe service delivery.
This Policy will commence from 1 August 2026. It replaces all other cyber security policies of DCIRS (whether written or not).
2. APPLICATION
This Policy applies to employees of DCIRS. All non-employees, such as agents and contractors (including temporary contractors) of DCIRS are expected to abide by this policy for the duration of their work period or contract. All relevant individuals are collectively referred to in this Policy as “worker”. The Policy includes work that is undertaken away from the usual workplace.
3. CONFIDENTIAL DATA
Confidential data is valuable and is to be kept secret. Company confidential data includes:
Unpublished financial information
Data of participants, partners and vendors
Patents, formulas or new technologies
Customer lists (existing and prospective)
All workers are obliged to protect this data.
4. PROTECT PERSONAL AND COMPANY DEVICES
This policy should be read in conjunction with DCIRS’s Data Security Policy. When workers use a digital device to access company emails, accounts, and information they introduce security risk to company data. Workers must keep all personal and company-issued computer, tablet and mobile phones secure. To keep these devices secure workers must:
Keep all devices password protected.
Only use authorised company computer systems and equipment for work purposes.
Maintain and upgrade company antivirus software.
Not leave devices exposed or unattended.
Install security updates of browsers and systems monthly or as soon as updates are available.
Log into company accounts and systems through secure and private networks only.
Workers must avoid accessing internal systems and accounts from other people’s devices or lending their own devices to others.
When new hires receive company-issued equipment, they will receive instructions for:
Disk encryption setup
Password management tool setup
Installation of antivirus/anti-malware software
Workers are to follow instructions to protect their devices and refer to the company’s ICT provider with any questions.
5. SAFEKEEPING EMAILS
Emails can host scams and malicious software and are not always easy to spot. To avoid virus infection or data theft, workers must:
Maintain awareness of familiar and unfamiliar emails in their inbox (e.g. a message from Australia Post or the ATO that is unexpected at a work address).
Avoid opening attachments and clicking on links when the content is not adequately explained (e.g. “Watch this video, it’s amazing.”)
Be suspicious of clickbait titles (e.g. offering prizes, advice).
Check email and names of people they received a message from to ensure they are legitimate.
Look for inconsistencies or giveaways (e.g. grammar mistakes, capital letters, excessive number of exclamation marks, and the actual email address it was sent from).
If a worker isn’t sure an email they received is safe, they should refer to the company’s ICT provider. It is important that workers don’t assume something is safe or take unnecessary risks that could potentially harm DCIRS's network or computer systems.
6. MANAGING PASSWORDS AND PERSONAL IDENTIFIERS
Password leaks are dangerous, since they can compromise the company’s entire infrastructure. Not only should passwords be secure so they will not be easily hacked, but they should also remain secret. For this reason, workers are to:
Choose passwords with at least eight characters (including capital and lower-case letters, numbers and symbols) and avoid information that can be easily guessed (e.g. birthdays).
Remember passwords instead of writing them down. If workers need to write their passwords, they are obliged to keep the paper or digital document confidential and destroy it when their work is done.
Exchange personal identifiers and company system identifiers only when necessary and safe to do so. When exchanging them in-person is not possible, workers should prefer the phone instead of email, and only if they personally recognise the person they are talking to.
Change their passwords every two months.
The company will implement Multi-Factor Authentication to authorised logins to increase the security and safety of company records and information.
7. DATA TRANSFERS
Transferring data introduces security risk. Workers must:
Avoid transferring sensitive data (e.g. customer information, employee records) to other devices or accounts unless absolutely necessary. When mass transfer of such data is needed, workers must ask the company’s ICT provider for help.
Share confidential data over the company network/system and not over public Wi-Fi or private connection.
Ensure that the recipients of the data are properly authorised people or organisations and have adequate security policies.
Report scams, privacy breaches and hacking attempts immediately.
8. REPORTING SUSPICIOUS ACTIVITY
The Company's ICT provider needs to know about scams, breaches, and malware so they can better protect DCIRS's infrastructure. For this reason, workers must report perceived attacks, suspicious emails or phishing attempts as soon as possible and directly to the ICT provider, who must investigate promptly, resolve the issue and send a companywide alert when necessary.
The Company's ICT provider is responsible for advising workers on how to detect scam emails. Workers are encouraged to reach out to them with any questions or concerns.
9. ADDITIONAL MEASURES
To reduce the likelihood of security breaches, workers are instructed to:
Turn off their screens and lock their devices when leaving their desks.
Report stolen or damaged equipment as soon as possible to the Operations Manager or the Managing Director. This includes personal devices that may contain or have access to Company information.
Immediately change all account passwords at once when a device is stolen.
Report a perceived threat or possible security weakness in company systems.
Refrain from downloading suspicious, unauthorised or illegal software on their company equipment.
Avoid accessing suspicious websites.
Participate in cyber security awareness activities and comply with organisational cyber security requirements.
Workers must also comply with policies in place relating to social media and internet usage.
Where a cyber security incident involves participant information, personal information, or privacy risks, the matter must be holistically managed in accordance with applicable privacy, risk management, safeguarding, and incident management processes.
Significant cyber security incidents, systemic vulnerabilities, and material information-security risks should be escalated to the appropriate governance and risk oversight bodies.
It is the role of the ICT provider to:
Install firewalls, anti-malware software and access authentication systems.
Arrange for security training for all workers.
Inform workers regularly about new scam emails or viruses and ways to combat them.
Investigate security breaches thoroughly.
Follow the policy provisions as other workers do.
DCIRS will maintain the necessary physical and digital shields to protect information.
10. EMERGING RISKS
Emerging technologies, artificial intelligence systems, and digital collaboration tools may introduce additional cyber and security-of-information risks. Workers must ensure that participant information, personal information, and restricted organisational information are not entered into unauthorised systems.
The us of communications and artificial intelligence systems must comply with the Artificial Intelligence Policy, Privacy and Confidentiality Policy, Data Security Policy, and other applicable governance requirements.
11. REMOTE WORKERS
Remote workers must follow this Policy. As remote workers will be accessing the company’s accounts and systems from a distance, they are obliged to follow all data encryption, protection standards and settings, and ensure their private network is secure. Remote workers are encouraged to seek advice from the company’s ICT provider to ensure the integrity of DCIRS’s systems at all times.
12. DISCIPLINARY ACTION
Workers must comply with the terms and conditions contained in this Policy. Those who cause security breaches may face disciplinary action. The type and severity of the disciplinary action will depend upon the circumstances of the case and the seriousness of the breach. In serious cases, this may include termination of employment.
In the case of contractors or agents of DCIRS who are found to have breached this Policy may have their contracts with DCIRS terminated or not renewed.
13. CONTACT INFORMATION
Bold ICT: (03) 5410 8999 or help@bold-ict.com.au
Contact the Managing Director and Bold ICT for security breaches and for all suspicious activity.
14. ASSOCIATED DOCUMENTS
Data Security Policy
Risk Management Policy
Code of Conduct Policy
Artificial Intelligence Policy
Privacy and Confidentiality Policy
15. VERSION AND REVIEW INFORMATION
DCIRS reserves the right to amend and vary this policy from time to time.
Version 1.0: 12 June 2023
Version 1.2: 5 August 2025 | Review date: 5 August 2028
Version 1.5: 1 August 2026 | Review date: 1 August 2028
© 2026 DCIRS Community Care Pty. Ltd. All rights reserved.
This policy is the intellectual property of DCIRS Community Care. No part of this document may be reproduced, distributed, copied, or transmitted in any form or by any means, including photocopying, digital scraping, or other electronic methods, without the prior written permission of the copyright owner.

Comments