Guardian for NDIS providers and participants

Protect the provider organisation, improve staff cyber behaviour and give participants practical help without forcing everybody into the same service.

Guardian separates the provider security program from the participant cyber-safety experience. Providers can manage organisational risk, staff learning, monitored exposure, websites, remediation and optional managed protection while Participant Free provides education and practical self-help without silently attaching paid security services to every participant. The free participant cyber-safety experience remains separate from paid provider and participant protection services.

Australian data residency

Guardian for Australian customers is built, operated and hosted in Australia. All Guardian customer and platform data, including backups and recovery copies, is maintained and stored within Australia.

Provider security governance and remediationStaff learning and human-risk follow-upParticipant Free cyber-safety experienceOptional managed protection for approved provider devices
Two different security responsibilities

The provider operates a business. The participant receives support. Guardian keeps those responsibilities separate.

An NDIS provider has organisational security responsibilities across staff identities, business systems, email, devices, public websites, suppliers, privileged access, backups, monitoring and incident response. Those controls require ownership, evidence and ongoing remediation in the same way they do for any organisation handling sensitive information and essential services.

A participant has a different relationship with the provider. Participant Free is designed to deliver useful cyber-safety education, checklists, provider notices and a simple reporting pathway without assuming the provider should continuously monitor the participant’s personal devices, accounts or communications.

Paid participant protection can be designed separately where there is a legitimate use case, consent, privacy model and support process. It is never implied simply because a participant has a Guardian account.

01

Provider security program

Manage organisational posture, risks, staff actions, websites, monitored identifiers, evidence and optional managed controls under the provider’s authority.

02

Staff security behaviour

Assign required learning, measure completion, identify overdue or failed requirements and connect material human-risk gaps to remediation.

03

Participant cyber safety

Provide education, checklists, notices and suspicious-message reporting without creating an automatic endpoint, DNS, dark-web, SMS or analyst-monitoring cost.

Provider security foundation

Guardian Core gives the provider one place to see security posture, assign work and retain evidence.

The provider workspace is built around the security work the organisation has to complete. The Security Dashboard surfaces material risk, overdue work and product or monitoring state. The Risk Register records material business risk, while All Actions gives staff and service providers a common queue for the changes that must be completed.

Guardian University and Human Risk supports role-based learning, assignments, due dates, assessment and follow-up. Dark Web Monitoring and Website Vulnerability Monitoring provide baseline external exposure information for the approved provider scope. Standard evidence and reporting use the same records that manage the work rather than requiring a separate spreadsheet process.

The exact staff users, participant allowance, websites, domains, email addresses, keywords and other package quantities are recorded in the applicable commercial schedule rather than being hidden inside a broad plan name.

01

Security Dashboard and risk

See priority risks, material findings, overdue actions, remediation movement and unavailable or degraded product states without treating missing data as a clean result.

02

All Actions and evidence

Assign security work to the responsible staff member, provider, developer or supplier with due dates, expected outcomes, supporting evidence and closure review.

03

External exposure and reporting

Track approved website and dark-web monitoring scope, material findings, current response and evidence through provider-facing reporting.

Staff learning and human risk

Training becomes useful when the provider can see what was assigned, who is overdue and what has to happen next.

Guardian University can assign published cyber, privacy and policy learning by role, group, onboarding requirement or remediation need. Staff see their assigned and in-progress learning, due dates, assessments and eligible certificates in one learner experience.

Provider managers can review completion, overdue work and failed assessment conditions without relying on annual spreadsheets. Where an approved human-risk factor or security event requires follow-up, Guardian can recommend or assign appropriate learning and create accountable remediation work.

Human-risk information is used to support education and security improvement. It is not presented as an opaque disciplinary, employment or behavioural judgement and remains subject to authorised human review.

01

Role-based assignments

Use onboarding, annual, role-specific, policy and remediation pathways with defined due dates and published completion rules.

02

Completion and assessment

Track assigned, in-progress, completed, failed and overdue status against the correct published course version and assessment requirements.

03

Remediation follow-up

Connect overdue or risk-linked learning to an owner, due date and follow-up action instead of simply producing a completion percentage.

Provider exposure monitoring

Monitor approved provider identifiers and public websites, then turn material findings into owned response.

Guardian Dark Web Monitoring can monitor approved provider domains, staff email addresses, brands and keywords within the package allowance. Potential matches are reviewed and presented as customer-readable findings with practical response context rather than exposing raw credentials or unrestricted source material.

Guardian Website Vulnerability Monitoring provides baseline monitoring for approved public websites included in Guardian Core. Material website findings can be assigned to the provider, hosting company, developer, MSP or another responsible party and remain visible until evidence or later monitoring supports closure.

A finding is not automatically treated as a confirmed current compromise. Source age, affected identity, later observations and other available evidence are considered before the response is determined.

01

Dark web scope

Approved provider domains, staff email identifiers, brands and keywords with monitored-item status, exposure findings and accountable response.

02

Website scope

Approved public websites with baseline monitoring state, customer-readable findings, remediation ownership and later review.

03

Response workflow

Password, identity, endpoint, hosting, developer, communication or investigation work can be assigned according to the evidence and affected scope.

Participant Free

Give participants practical cyber-safety support without pretending a free account includes a managed security service.

Participant Free is intended to make practical cyber-safety help available without requiring every participant to purchase a commercial security product. The experience can include provider-assigned learning, scam and identity guidance, password and MFA checklists, device-update guidance, provider notices and a pathway to report something suspicious.

The participant can see their own assigned and completed learning and approved provider content. The provider can see only the participant information authorised by the relationship, role and privacy model. Participant records are not exposed across unrelated provider or participant contexts.

Participant Free does not include continuous personal endpoint monitoring, DNS protection, dark-web monitoring, SMS delivery, analyst investigation or telephone support by default. Those capabilities have real technology, privacy and operating costs and require an explicit paid or sponsored entitlement if offered.

01

Learn

Complete approved cyber-safety, scam, identity, password, MFA, privacy and device-security learning assigned through the provider relationship.

02

Check and report

Use practical checklists and an approved pathway to report suspicious messages, scams or cyber concerns to the provider.

03

Keep free and paid services separate

A free participant account does not silently activate continuous monitoring, device agents or analyst services that have separate consent, privacy and commercial requirements.

Optional managed protection

Add managed security controls to provider-owned systems where the provider needs Damocles to operate them.

Provider-owned staff endpoints can add Guardian Endpoint Protection and Managed Patching where the service should include protection policy, device health, supported operating-system and application patching, restart tracking, failures and exception follow-up.

Guardian DNS Protection can add managed DNS-layer policy and malicious-destination blocking across the agreed provider scope. Vulnerability Management, Security Monitoring, Aegis Managed Defence, Svalinn managed WAF and deeper Katana website and API testing can be added where the organisation requires those outcomes.

Each managed product keeps its own protected quantity, connector, support boundary and service responsibility. A Guardian plan does not imply every control is active or that Damocles is operating technology that has not been selected and contracted.

01

Endpoints and patching

Protect approved provider-owned devices, operate supported patching, track restart state and keep stale devices, failures and exceptions visible.

02

DNS and application protection

Apply approved DNS and web-application protection policy, monitor service health and follow up material policy or attack activity.

03

Managed defence

Add source health, monitoring, triage, investigation and escalation through Aegis where the provider needs a contracted security-operations service.

NDIS provider onboarding

Build the program around real people, systems, responsibilities and consent.

The package should be configured from the provider operating model rather than activated as a generic bundle.

01

Define the provider scope

Confirm the provider entity, staff, locations, systems, websites, monitored identifiers, devices, suppliers and security contacts.

02

Define roles and access

Set business administrators, staff learners, provider or MSP access, participant relationships and the information each role is authorised to see.

03

Configure Core

Establish dashboard, risk, All Actions, University, monitoring scope, reporting and required customer ownership.

04

Invite staff and participants

Assign the correct staff learning and make only the approved Participant Free capabilities available to participants.

05

Add paid products

Activate managed endpoint, DNS, vulnerability, security monitoring or other products only for the explicitly authorised and licensed scope.

06

Review the operating model

Check completion, open risk, overdue actions, monitoring state, support boundaries, privacy, consent and product quantities as the provider changes.

Responsibility, privacy and safeguarding boundaries

Guardian supports the provider security program but does not remove the provider’s legal, privacy or operational responsibility.

Guardian does not claim NDIS accreditation, NDIS certification or automatic regulatory compliance. Damocles provides security capability and evidence; the provider retains responsibility for its legal, privacy, safeguarding and operational obligations.

Guardian and Damocles do not claim NDIS accreditation, certification or automatic regulatory compliance. The provider remains responsible for its legal obligations, privacy practices, safeguarding responsibilities, consent, records management, incident decisions and use of security information.

Participant information must be collected and exposed only for the approved purpose and relationship. Participant Free is not authority for unrestricted monitoring of personal devices, accounts, messages or identities. Any paid personal protection service requires an explicit scope, consent model, privacy treatment, support process and commercial entitlement.

Security data can support provider governance and remediation, but it does not replace professional legal, privacy, safeguarding or clinical advice where those decisions are required.

Questions providers usually need answered

Make the package, responsibility and participant boundary clear before rollout.

These decisions should be explicit in the proposal and onboarding record.

Q1

What is actually included in Guardian Core?

The provider workspace, Security Dashboard, Risk Register and All Actions, University and Human Risk, Dark Web Monitoring, Website Vulnerability Monitoring and standard evidence and reporting within the agreed allowances.

Q2

Are staff devices protected automatically?

No. Managed endpoint protection and patching is a separate product applied only to the approved provider-owned device scope.

Q3

What does Participant Free include?

Approved learning, cyber-safety guidance, checklists, provider notices, completion and an agreed reporting pathway. Continuous paid monitoring and agents are not included by default.

Q4

Can an MSP operate the provider account?

Yes where an explicit provider relationship and role permissions are configured. The MSP sees only authorised customer information and retains the agreed first-line responsibilities.

Q5

Can participant security services be added later?

Potentially, but only through a separately designed entitlement with clear consent, privacy, support, technology and commercial boundaries.

Q6

Does Guardian make the provider compliant?

No. Guardian can provide security controls, evidence and accountable workflow, but compliance and legal obligations remain the provider’s responsibility.

Design the NDIS program around the actual provider

Define the staff, participants, systems, websites, monitored identifiers and managed controls that belong in scope.

Damocles will map the provider security program, Participant Free experience, optional managed products, customer and MSP responsibilities, privacy boundaries and measurable package quantities before activation.