Provider security program
Manage organisational posture, risks, staff actions, websites, monitored identifiers, evidence and optional managed controls under the provider’s authority.
Guardian separates the provider security program from the participant cyber-safety experience. Providers can manage organisational risk, staff learning, monitored exposure, websites, remediation and optional managed protection while Participant Free provides education and practical self-help without silently attaching paid security services to every participant. The free participant cyber-safety experience remains separate from paid provider and participant protection services.
Guardian for Australian customers is built, operated and hosted in Australia. All Guardian customer and platform data, including backups and recovery copies, is maintained and stored within Australia.
An NDIS provider has organisational security responsibilities across staff identities, business systems, email, devices, public websites, suppliers, privileged access, backups, monitoring and incident response. Those controls require ownership, evidence and ongoing remediation in the same way they do for any organisation handling sensitive information and essential services.
A participant has a different relationship with the provider. Participant Free is designed to deliver useful cyber-safety education, checklists, provider notices and a simple reporting pathway without assuming the provider should continuously monitor the participant’s personal devices, accounts or communications.
Paid participant protection can be designed separately where there is a legitimate use case, consent, privacy model and support process. It is never implied simply because a participant has a Guardian account.
Manage organisational posture, risks, staff actions, websites, monitored identifiers, evidence and optional managed controls under the provider’s authority.
Assign required learning, measure completion, identify overdue or failed requirements and connect material human-risk gaps to remediation.
Provide education, checklists, notices and suspicious-message reporting without creating an automatic endpoint, DNS, dark-web, SMS or analyst-monitoring cost.
The provider workspace is built around the security work the organisation has to complete. The Security Dashboard surfaces material risk, overdue work and product or monitoring state. The Risk Register records material business risk, while All Actions gives staff and service providers a common queue for the changes that must be completed.
Guardian University and Human Risk supports role-based learning, assignments, due dates, assessment and follow-up. Dark Web Monitoring and Website Vulnerability Monitoring provide baseline external exposure information for the approved provider scope. Standard evidence and reporting use the same records that manage the work rather than requiring a separate spreadsheet process.
The exact staff users, participant allowance, websites, domains, email addresses, keywords and other package quantities are recorded in the applicable commercial schedule rather than being hidden inside a broad plan name.
See priority risks, material findings, overdue actions, remediation movement and unavailable or degraded product states without treating missing data as a clean result.
Assign security work to the responsible staff member, provider, developer or supplier with due dates, expected outcomes, supporting evidence and closure review.
Track approved website and dark-web monitoring scope, material findings, current response and evidence through provider-facing reporting.
Guardian University can assign published cyber, privacy and policy learning by role, group, onboarding requirement or remediation need. Staff see their assigned and in-progress learning, due dates, assessments and eligible certificates in one learner experience.
Provider managers can review completion, overdue work and failed assessment conditions without relying on annual spreadsheets. Where an approved human-risk factor or security event requires follow-up, Guardian can recommend or assign appropriate learning and create accountable remediation work.
Human-risk information is used to support education and security improvement. It is not presented as an opaque disciplinary, employment or behavioural judgement and remains subject to authorised human review.
Use onboarding, annual, role-specific, policy and remediation pathways with defined due dates and published completion rules.
Track assigned, in-progress, completed, failed and overdue status against the correct published course version and assessment requirements.
Connect overdue or risk-linked learning to an owner, due date and follow-up action instead of simply producing a completion percentage.
Guardian Dark Web Monitoring can monitor approved provider domains, staff email addresses, brands and keywords within the package allowance. Potential matches are reviewed and presented as customer-readable findings with practical response context rather than exposing raw credentials or unrestricted source material.
Guardian Website Vulnerability Monitoring provides baseline monitoring for approved public websites included in Guardian Core. Material website findings can be assigned to the provider, hosting company, developer, MSP or another responsible party and remain visible until evidence or later monitoring supports closure.
A finding is not automatically treated as a confirmed current compromise. Source age, affected identity, later observations and other available evidence are considered before the response is determined.
Approved provider domains, staff email identifiers, brands and keywords with monitored-item status, exposure findings and accountable response.
Approved public websites with baseline monitoring state, customer-readable findings, remediation ownership and later review.
Password, identity, endpoint, hosting, developer, communication or investigation work can be assigned according to the evidence and affected scope.
Participant Free is intended to make practical cyber-safety help available without requiring every participant to purchase a commercial security product. The experience can include provider-assigned learning, scam and identity guidance, password and MFA checklists, device-update guidance, provider notices and a pathway to report something suspicious.
The participant can see their own assigned and completed learning and approved provider content. The provider can see only the participant information authorised by the relationship, role and privacy model. Participant records are not exposed across unrelated provider or participant contexts.
Participant Free does not include continuous personal endpoint monitoring, DNS protection, dark-web monitoring, SMS delivery, analyst investigation or telephone support by default. Those capabilities have real technology, privacy and operating costs and require an explicit paid or sponsored entitlement if offered.
Complete approved cyber-safety, scam, identity, password, MFA, privacy and device-security learning assigned through the provider relationship.
Use practical checklists and an approved pathway to report suspicious messages, scams or cyber concerns to the provider.
A free participant account does not silently activate continuous monitoring, device agents or analyst services that have separate consent, privacy and commercial requirements.
Provider-owned staff endpoints can add Guardian Endpoint Protection and Managed Patching where the service should include protection policy, device health, supported operating-system and application patching, restart tracking, failures and exception follow-up.
Guardian DNS Protection can add managed DNS-layer policy and malicious-destination blocking across the agreed provider scope. Vulnerability Management, Security Monitoring, Aegis Managed Defence, Svalinn managed WAF and deeper Katana website and API testing can be added where the organisation requires those outcomes.
Each managed product keeps its own protected quantity, connector, support boundary and service responsibility. A Guardian plan does not imply every control is active or that Damocles is operating technology that has not been selected and contracted.
Protect approved provider-owned devices, operate supported patching, track restart state and keep stale devices, failures and exceptions visible.
Apply approved DNS and web-application protection policy, monitor service health and follow up material policy or attack activity.
Add source health, monitoring, triage, investigation and escalation through Aegis where the provider needs a contracted security-operations service.
The package should be configured from the provider operating model rather than activated as a generic bundle.
Confirm the provider entity, staff, locations, systems, websites, monitored identifiers, devices, suppliers and security contacts.
Set business administrators, staff learners, provider or MSP access, participant relationships and the information each role is authorised to see.
Establish dashboard, risk, All Actions, University, monitoring scope, reporting and required customer ownership.
Assign the correct staff learning and make only the approved Participant Free capabilities available to participants.
Activate managed endpoint, DNS, vulnerability, security monitoring or other products only for the explicitly authorised and licensed scope.
Check completion, open risk, overdue actions, monitoring state, support boundaries, privacy, consent and product quantities as the provider changes.
Guardian does not claim NDIS accreditation, NDIS certification or automatic regulatory compliance. Damocles provides security capability and evidence; the provider retains responsibility for its legal, privacy, safeguarding and operational obligations.
Guardian and Damocles do not claim NDIS accreditation, certification or automatic regulatory compliance. The provider remains responsible for its legal obligations, privacy practices, safeguarding responsibilities, consent, records management, incident decisions and use of security information.
Participant information must be collected and exposed only for the approved purpose and relationship. Participant Free is not authority for unrestricted monitoring of personal devices, accounts, messages or identities. Any paid personal protection service requires an explicit scope, consent model, privacy treatment, support process and commercial entitlement.
Security data can support provider governance and remediation, but it does not replace professional legal, privacy, safeguarding or clinical advice where those decisions are required.
These decisions should be explicit in the proposal and onboarding record.
The provider workspace, Security Dashboard, Risk Register and All Actions, University and Human Risk, Dark Web Monitoring, Website Vulnerability Monitoring and standard evidence and reporting within the agreed allowances.
No. Managed endpoint protection and patching is a separate product applied only to the approved provider-owned device scope.
Approved learning, cyber-safety guidance, checklists, provider notices, completion and an agreed reporting pathway. Continuous paid monitoring and agents are not included by default.
Yes where an explicit provider relationship and role permissions are configured. The MSP sees only authorised customer information and retains the agreed first-line responsibilities.
Potentially, but only through a separately designed entitlement with clear consent, privacy, support, technology and commercial boundaries.
No. Guardian can provide security controls, evidence and accountable workflow, but compliance and legal obligations remain the provider’s responsibility.
Damocles will map the provider security program, Participant Free experience, optional managed products, customer and MSP responsibilities, privacy boundaries and measurable package quantities before activation.