Guardian for NDIS providers and participants

Protect the provider, support staff and give participants practical cyber-safety help in one program.

Guardian can combine provider security management, staff learning, dark web and website monitoring, accountable remediation and a free participant cyber-safety experience without forcing participants to buy security software or managed services.

Provider security workspaceStaff learning and human-risk remediationFree participant cyber-safety experienceOptional managed protection for provider devices
Why the model is different

The provider and the participant need different levels of security service and different responsibilities.

The provider is responsible for organisational systems, staff access, customer information, public websites, devices, suppliers and incident response. That requires governed risk, staff learning, exposure monitoring and accountable remediation.

A participant free account should provide useful education, notices, checklists and self-help without creating a hard software, SMS or analyst cost for every participant. Paid monitoring or device protection is added only where it is appropriate and consented.

01

Protect the provider organisation

Use Guardian Core to manage security posture, risk, actions, staff learning, dark web exposure, website monitoring and evidence.

02

Improve staff behaviour and accountability

Assign role-relevant learning, track overdue completion and connect human-risk gaps to remediation work.

03

Support participants without hidden hard cost

Provide free cyber-safety learning, checklists, provider notices and suspicious-message reporting without continuous paid monitoring by default.

Provider package foundation

What the NDIS provider receives through Guardian Core.

Exact staff, participant, website, domain and email allowances are recorded in the applicable package schedule.

SD

Security Dashboard

See priority risk, material findings, overdue actions, remediation progress and module status in one provider-facing view.

RA

Risk Register and All Actions

Assign provider security work to owners with due dates, status, evidence and closure review.

HU

Staff learning and human risk

Assign learning, track completion and follow up overdue or risk-linked training.

DW

Dark Web Monitoring

Monitor approved provider domains, staff email addresses and brand terms within the package allowance.

WV

Website Vulnerability Monitoring

Maintain baseline monitoring for the approved public websites included in the package.

RP

Evidence and reporting

Show current posture, open work and supporting evidence using approved Guardian records.

Participant Free

Useful cyber-safety capability that does not depend on a paid licence for every participant.

LR

Assigned learning

Complete provider-assigned cyber-safety, scam, identity, password and device-security learning.

CK

Practical checklists

Use guided checklists for passwords, MFA, device updates, backups and suspicious messages.

NT

Provider notices and resources

Receive approved provider security notices and current cyber-safety guidance.

SA

Self-assessment

Review personal cyber-safety habits and receive practical next steps without an unexplained risk score.

RP

Report something suspicious

Use the approved pathway to report a suspicious message, scam or cyber concern to the provider.

CR

Completion record

See assigned and completed learning without exposing unrelated participant or provider data.

Provider-to-participant operating model

A practical lifecycle for education, reporting and follow-up.

01

Onboard the provider

Confirm the provider workspace, staff, participant allowance, roles and service contacts.

02

Assign staff controls

Set staff learning, provider monitoring, risk ownership and reporting expectations.

03

Invite participants

Provide participant access only for approved free capabilities and provider relationship.

04

Educate and notify

Deliver approved learning, checklists and provider cyber-safety notices.

05

Report and respond

Route suspicious-message or cyber-concern reports through the agreed provider process.

06

Review outcomes

Track staff remediation, participant learning and provider security actions without mixing visibility across roles.

Optional paid protection

Add managed protection where the provider or participant use case justifies the real operating cost.

Provider-owned devices can add Guardian Endpoint Protection and Managed Patching, DNS Protection, Rapid7-backed capability, Wazuh or Aegis according to the required security model.

A participant may later receive a separately consented paid protection service, but Participant Free does not include continuous personal dark web monitoring, endpoint or DNS agents, SMS delivery, analyst investigation or telephone support by default.

Important boundary

Guardian supports the provider security operating model; it does not claim NDIS accreditation or compliance certification.

The website does not represent Guardian or Damocles as an NDIS auditor, accreditation body or guarantee of regulatory compliance. The provider remains responsible for its legal, privacy, safeguarding, consent and operational obligations.

Participant data access, consent, visibility, support, retention and escalation must be defined before activation. Provider users cannot view participant information outside the approved relationship and role scope.

Build the NDIS package around the real service model

Confirm provider staff, participant allowance, websites, monitored identifiers and optional protection products.

We will define the Guardian Core band, Participant Free capability, support responsibilities, product quantities and the direct or MSP commercial relationship.