Software licence compliance means you hold a valid, paid licence for every copy of every program your business runs. A vendor “true-up” or audit is when Microsoft, Adobe, Autodesk or another publisher checks whether what you’ve deployed matches what you’ve bought. Get it wrong and the bill arrives at list price.
What a true-up and an audit actually are
The two terms get used interchangeably, but they’re not the same thing. A true-up is the reconciliation built into a volume licensing agreement. If you signed a Microsoft Enterprise Agreement or similar, you committed to a baseline number of licences and agreed to “true up” annually for anything extra you deployed during the year. It’s routine accounting: you report the additional seats, you pay for them, the agreement rolls on. Where it bites is when nobody has tracked the additions and the annual reconciliation surfaces twelve months of unlicensed growth at once.
An audit is the adversarial version. The vendor, or a third party acting for them, exercises the audit clause in your licensing contract and asks you to prove compliance. They’ll count installs against entitlements and present you with a “compliance gap”. A right to audit is written into almost every software agreement you’ve ever clicked through. Microsoft, Adobe and Autodesk all do it, and so do Oracle, SAP and IBM, who are notoriously aggressive about it.
Why vendors audit
Because it pays. Software is one of the few products where the customer self-reports how much they’re using, and self-reporting drifts. In any business of reasonable size, deployment creeps past entitlement as staff are added, machines are reimaged and VMs are spun up. An audit converts that drift into revenue, usually at full list price with no discount.
The triggers are predictable: a sharp drop in renewal spend, a merger or acquisition, switching away from a vendor’s product, a jump in headcount, or simply the random rotation a publisher runs through its mid-market customers. Subscription licensing has made it easier still: when your software phones home, the vendor already knows who’s using what before they send a letter.
How SMEs end up non-compliant
Almost no one sets out to pirate software. Non-compliance is nearly always sloppiness, not theft, and it accumulates quietly. These are the patterns we see most across Melbourne SMEs.
- Over-deployment. You bought 40 Microsoft 365 licences, you’ve grown to 52 staff, and the extra dozen are using the platform on borrowed credentials or seats that were never purchased. The headcount moved; the licence count didn’t.
- Wrong licence type for the use. Running software licensed for development on a live production server, or using education and not-for-profit pricing in a commercial entity that no longer qualifies.
- Mixing Business and Enterprise plans. Microsoft 365 Business plans (Basic, Standard, Premium) are capped at 300 seats. Plenty of growing firms blow past 300 users still stacking Business licences, when they should have moved to Enterprise (E3/E5) plans.
- Client Access Licences (CALs). On-premises Windows Server and SQL Server still need a CAL for every user or device that connects. CALs are the most commonly under-counted licence in Australian SMEs, because the server “just works” whether or not the paperwork exists.
- Unlicensed virtual machines. Spinning up a new VM from a template often clones a Windows Server or SQL install without anyone buying the licence to cover it.
- Shared accounts. Three people on reception sharing one Adobe Acrobat or Microsoft 365 login. Named-user subscriptions are licensed per person, not per desk, and sharing breaches the terms even though it feels economical.
The real cost of getting it wrong
When a true-up or audit finds a gap, you don’t buy the shortfall at the keen price your reseller would normally quote. You typically pay back-charges for the period you were under-licensed, the licences at full list price, and in audit scenarios potentially penalties or the vendor’s audit costs on top. There’s no negotiating leverage, because you’ve been caught short and the clock is running.
The other cost is the rushed purchase. Faced with a deadline, businesses buy whatever the vendor puts in front of them, at list, often more than they need. A manufacturer in Dandenong we work with discovered during a routine Autodesk reconciliation that several engineering machines were running design software well beyond the seats they’d paid for. The catch-up purchase, under time pressure and at list, cost several times what an orderly renewal would have. The licences were genuinely needed; the panic premium wasn’t.
How to stay compliant
Compliance isn’t a once-a-year scramble. It’s an ongoing discipline, and most of it is unglamorous record-keeping that pays for itself the first time a letter lands.
Maintain a licence register
The foundation is knowing what you own. A licence register is a single, maintained record of every software product you’ve bought: publisher, product and edition, licence type (subscription or perpetual), quantity, purchase date and proof of purchase, and any agreement number. Most SMEs don’t have one, which is exactly why audits hurt. When you can produce entitlement evidence on demand, an audit becomes an afternoon’s work instead of a crisis. This sits inside broader IT asset management, the same discipline that tracks your hardware, warranties and end-of-life dates.
Reconcile assigned versus purchased seats
For Microsoft 365, the Microsoft 365 admin centre tells you exactly how many licences you’ve purchased against how many are assigned. Under Billing > Licences, you see each product, the seats you’re paying for and the seats in use. Reconciling this regularly catches both problems at once: seats assigned beyond what you’ve bought (a compliance gap) and seats you’re paying for that nobody uses (wasted spend). Do it monthly and neither surprise builds up.
Right-size unused licences
This is where compliance work actually saves money. The same register that protects you in an audit usually reveals seats you’re paying for and not using: the staff member who left three months ago whose Microsoft 365 and Adobe licences are still billing, the premium plan assigned to someone who needs the basic one, the perpetual product everyone forgot they retired. Reclaiming those licences, or cancelling them at renewal, frequently funds the cost of the housekeeping. Compliance and cost control are the same job done properly.
Understand subscription versus perpetual
The two licensing models carry different risks, and most environments are now a mix of both.
| Subscription | Perpetual |
|---|
| What you’re paying for | The right to use the software for a set term (monthly/annual) | The right to use a specific version indefinitely, bought once |
| Examples | Microsoft 365, Adobe Creative Cloud, Autodesk subscriptions | Older Office perpetual, on-prem Windows/SQL Server, legacy Acrobat |
| Compliance risk | Over-assigning seats; the vendor can see live usage | Running more installs or versions than the licence allows; CALs untracked |
| If you stop paying | The software stops working | You keep using the version you own, but get no updates or support |
Autodesk and Adobe have moved almost entirely to subscription. Microsoft offers both, and a typical Melbourne SME runs Microsoft 365 subscriptions alongside perpetual on-premises Windows Server and its CALs. Knowing which model each product sits under tells you where your audit exposure actually lies.
SaaS sprawl makes this harder
Licence compliance used to mean counting installs on machines you owned. Now most software is bought as a subscription, often on a corporate card by whoever needed it, and the result is SaaS sprawl: dozens of overlapping tools, nobody sure who’s paying for what, and licences quietly renewing for people who left. A law firm in Hawthorn we onboarded was running three separate PDF and e-signature subscriptions across different teams, none fully used. You can’t licence-manage software you don’t know you have. The fix is the same register and the same reconciliation, applied to every subscription.
What to do if you receive an audit or true-up notice
Don’t panic, and don’t ignore it. The worst outcomes come from businesses that either go quiet, hoping it’ll pass, or that rush to admit a gap before they’ve established whether one exists.
- Read the agreement first. Find the audit or verification clause being relied on, and check what it actually entitles the vendor to: notice periods, scope and how data is gathered.
- Reconcile your own position before you respond. Run the numbers internally, deployments against entitlements, so you walk in knowing where you stand rather than learning it from the vendor. Your licence register is your evidence; don’t volunteer deployment data you haven’t verified.
- Bring in your licensing partner. Your reseller or MSP has dealt with these before and can challenge an over-stated gap, identify licences you already hold that the vendor missed, and negotiate the commercial close rather than accepting the first number.
- Treat the deadline as real but not immovable. Reasonable engagement buys time. A measured response almost always lands better than a fire-sale purchase.
Where the MSP and CSP partner fit
Most SMEs don’t buy Microsoft licences direct; they buy through a Cloud Solution Provider (CSP), and that’s usually their MSP. A good CSP partner does more than process the order. They right-size your seats at every renewal, flag when you’ve crossed a threshold like the 300-seat Business cap, keep the licence register current, and stand beside you if an audit ever lands. As a Melbourne MSP founded in 2014 with 13 Australian-employed engineers, TechAssist runs licence reconciliation as part of ongoing Microsoft 365 management, not as a billable scramble when the renewal looms. If you’ve never been sure your setup is right-sized, our Microsoft 365 support covers exactly this housekeeping.
Frequently asked questions
How often do software vendors actually audit small businesses?
Less often than large enterprises, but it does happen, and subscription products are effectively audited continuously because usage data flows back to the vendor automatically. For Microsoft 365 and similar SaaS, the bigger risk isn’t a formal audit but the annual true-up or renewal where over-assigned seats get reconciled at once. Perpetual on-premises software (Windows Server, SQL Server, older Office and Adobe) is where traditional formal audits are still most likely.
What’s the difference between a true-up and a fine?
A true-up is the routine process of paying for extra licences you deployed during the year under a volume agreement, no penalty, just the cost of the seats. A fine or penalty comes from an audit that finds you running software with no valid licence at all, where you may pay back-charges, list-price licences and potentially the vendor’s costs. The first is housekeeping; the second is what good housekeeping prevents.
Do we still need CALs if we’re moving to the cloud?
If you still run any on-premises Windows Server or SQL Server, yes, those CALs remain a live obligation regardless of how much else has moved to the cloud. Once a workload is fully migrated to a cloud service like Microsoft 365 or Azure, the CAL requirement for that service usually falls away, because the licensing is built into the subscription. The trap is a hybrid setup where the old server still runs and everyone assumes the cloud move dealt with the licensing. It didn’t.
Getting ahead of it
Software licence compliance is far cheaper to maintain than to fix under audit pressure. A current licence register, a monthly reconciliation in the Microsoft 365 admin centre, and a CSP partner who right-sizes at renewal will keep you compliant and usually trim your spend. If you’re not confident what you own versus what you’re running, that’s worth sorting before a true-up letter forces the issue. Get in touch with our team and we’ll audit your licensing before a vendor does.
Data classification is the act of sorting your information by how sensitive it is, so you can apply the right protection to each tier. It is the step most security programs skip, and the reason so many of them are expensive and still leaky: you cannot protect what you have never bothered to identify.
Most SMEs treat every file the same. A lunch-order spreadsheet gets the same controls as a folder of client Tax File Numbers. That is how money gets spent in the wrong places and the genuinely sensitive material slips out the side door.
Why classification comes first
Every other security control assumes you already know what matters. Data Loss Prevention needs to know which data to stop leaving. Encryption needs to know which files are worth encrypting. Retention rules need to know which records have legal minimums. Even your cyber insurer’s questionnaire assumes you can describe where your sensitive data lives. Skip classification and all of these become guesswork — you end up either locking down everything (and the business grinds), or locking down nothing meaningful (and the breach finds you).
The point is not bureaucracy. It is focus. A small business has finite attention and budget. Classification tells you where to spend both. Once you know that 90 per cent of your files are mundane and 10 per cent would hurt if they leaked, you can put real controls on the 10 per cent instead of spreading effort thinly across everything.
A scheme an SME will actually use
Government departments run five- and six-tier classification schemes with handling caveats, dissemination markings and clearance requirements. Do not copy them. They are built for an environment you do not operate in, and if you impose that complexity on a 30-person business in Camberwell, staff will quietly ignore the lot and your scheme dies in a fortnight.
Four tiers is the sweet spot for almost every SME:
- Public — material you would happily put on your website. Brochures, published case studies, job ads. No restrictions.
- Internal — the default for ordinary business content. Project notes, internal emails, draft documents. Not secret, but not for outsiders. This is where most of your data lives.
- Confidential — information that would cause real harm if it leaked. Client records, contracts, financials, personal information, employee files. Encrypt it, control who can share it.
- Restricted — the small set of crown-jewel data: Tax File Numbers, Medicare numbers, health records, banking details, anything under a strict regulatory or contractual obligation. Tightest controls, smallest audience, full audit trail.
If four feels like too many, run three (Public, Internal, Confidential) and fold Restricted into Confidential with stricter handling. The exact labels matter far less than picking a set, defining each one in a sentence a non-technical person understands, and sticking to it.
Classification is useless without handling rules
A label that does not change behaviour is just decoration. The value comes from mapping each tier to concrete handling rules — where it can be stored, how it can be shared, whether it is encrypted, how long it is kept, and how it is destroyed. Write these down once, in plain language, and they become the operating manual for your whole data estate.
| Handling rule | Public | Internal | Confidential | Restricted |
|---|
| Storage | Anywhere | Approved M365 / SharePoint | Approved M365, access-controlled | Restricted sites, named users only |
| External sharing | Unrestricted | Case by case | Approved recipients, link expiry | Blocked or by exception only |
| Encryption | No | Optional | Yes (label-enforced) | Yes, plus access policy |
| Retention | As needed | Standard schedule | Legal minimum, then dispose | Legal minimum, secure disposal, audited |
| Disposal | Normal delete | Normal delete | Logged deletion | Secure, logged, certificate where required |
This is the part most people forget. Disposal and retention are as much a part of classification as protection. Holding a decade of old client files you no longer need is not caution — it is liability. The records exist to be stolen, subpoenaed or breached, and they serve no business purpose. Classification tells you what to keep, for how long, and what to destroy.
Making it real with Microsoft Purview
For the Melbourne SMEs we work with — almost all on Microsoft 365 — classification stops being a paper exercise the moment you turn it into sensitivity labels in Microsoft Purview. A sensitivity label is a tag that travels with the file or email wherever it goes, and it can enforce the handling rules above rather than just suggest them.
Map your four tiers straight onto four labels. A Confidential label can apply encryption automatically, so a file forwarded to the wrong address is unreadable to whoever receives it. A Restricted label can lock access to a named group and block external sharing outright. The classification scheme and the technical control become the same thing — which is exactly what you want.
Auto-labelling
Manual labelling depends on people choosing the right tag every time, and people are busy. Auto-labelling closes that gap. Purview can scan content against patterns — Tax File Numbers, Medicare numbers, credit card numbers, ABNs — and apply a label automatically, or recommend one to the user. A document with a dozen TFNs in it gets flagged as Confidential whether or not anyone remembered to mark it. Auto-labelling lives in the advanced Purview tier (E5 or the E5 Compliance add-on); manual labelling is included with Business Premium, which is enough to start.
What labels then power
Once data carries labels, the rest of your governance has something to act on. DLP can block a Confidential file from being emailed externally or copied to a USB stick. Retention policies can key off the label. And critically, labels govern what Microsoft 365 Copilot is allowed to surface — Copilot respects the protection on a labelled file, so a document marked Confidential and encrypted will not be casually summarised to someone who should not see it. This is why classification underpins AI governance and is not separate from it. We cover the labelling and DLP setup in depth in our guide to Microsoft Purview data governance, and the AI side in our piece on AI data governance for company data.
The human side: keep it simple or it dies
Here is the truth most vendors will not tell you. The biggest risk to a classification scheme is not the technology — it is asking people to think too hard. If staff have to choose between six labels with overlapping definitions, they will pick the default every time, or whatever is fastest, and your scheme becomes noise.
Four labels. One-sentence definitions. A sensible default (Internal) so the lazy choice is also a safe one. Reserve the friction — the encryption prompts, the sharing blocks — for the top tiers where it earns its keep. A scheme that 80 per cent of staff apply correctly without thinking beats a perfect scheme that everyone routes around. Simplicity is a security control, not a compromise.
Where classification meets Australian compliance
Classification is not just good hygiene — it is how you demonstrate compliance when someone asks. Under the Privacy Act 1988 and the Australian Privacy Principles, you are obliged to take reasonable steps to protect personal information (APP 11) and to not keep it longer than you need (and dispose of it when you do not). A working classification scheme, with labels and retention rules you can show, is exactly the kind of “reasonable steps” the Office of the Australian Information Commissioner (OAIC) expects to see. The privacy reforms moving through Parliament — tighter rules on data minimisation and automated decision-making — only sharpen that expectation.
The same scheme feeds your other obligations. DLP is meaningless without classification to tell it what to watch. Cyber insurers increasingly ask how you identify and protect sensitive data. And, as above, AI governance depends on it entirely. Classification is the foundation layer that makes the rest defensible rather than aspirational.
A Dandenong scenario
A logistics business in Dandenong we work with had grown from a handful of staff to around fifty, and its SharePoint had grown with it — no structure, broad permissions, everything in one bucket. Driver licences, customer contracts, payroll exports and old quotes all sat side by side, equally accessible. They wanted DLP and were about to switch on Copilot, and could not understand why we said classification had to come first.
We ran a discovery pass, agreed a four-tier scheme with their leadership, and built the matching Purview labels. Auto-labelling caught the TFN and licence data that manual marking would have missed. We applied encryption to the Confidential and Restricted tiers, set retention to purge expired quotes and old onboarding documents, then layered DLP on top — which now had a clear target. Only then did Copilot go live, on data that was actually governed. The whole exercise gave them a defensible answer for their insurer and a SharePoint that no longer leaked by default.
TechAssist has run Microsoft 365 for Melbourne SMEs since 2014, with thirteen Australian-employed engineers and a 24/7 NOC in Tecoma. The classification-first review has become one of the more common first steps we run before any DLP or AI rollout.
A phased rollout that works
Do not attempt to classify everything in one weekend. It fails every time. Phase it:
- Define the scheme. Agree four tiers and one-sentence definitions with leadership. This is a half-day workshop, not a project.
- Map handling rules. Decide storage, sharing, encryption, retention and disposal for each tier. Write it down.
- Build the labels. Create the matching Purview sensitivity labels, starting cosmetic (markings only) so people get used to choosing one.
- Add enforcement to the top tiers. Switch on encryption and sharing controls for Confidential and Restricted once labelling is a habit.
- Turn on auto-labelling and DLP. Run DLP in audit-only mode for a fortnight, tune out false positives, then move to blocking. Auto-labelling catches what users miss.
- Then enable AI. With data labelled and protected, Copilot or another sanctioned tool can be turned loose safely.
Each phase delivers value on its own. You are never left with a half-finished mess that protects nothing.
Frequently asked questions
How many classification levels should an SME have?
Four is ideal for most: Public, Internal, Confidential and Restricted. Three works if four feels heavy — fold Restricted into Confidential with stricter handling. Avoid the five- and six-tier government schemes; the extra complexity makes staff disengage, and a scheme people ignore protects nothing.
Do I need an expensive licence to start classifying data?
No. Manual sensitivity labels are included with Microsoft 365 Business Premium, which is enough to define your scheme, apply labels and enforce encryption on the top tiers. Auto-labelling and endpoint DLP sit in the advanced Purview tier (E5 or the E5 Compliance add-on), worth adding once the basics are bedded in.
What is the difference between data classification and a sensitivity label?
Classification is the scheme — the tiers and the rules that decide how each type of data is handled. A sensitivity label is the technical mechanism in Microsoft Purview that puts that scheme into effect, tagging files and enforcing the rules. The classification is the decision; the label is how the decision sticks to the data.
Why does Copilot need data classification first?
Microsoft 365 Copilot surfaces any data the asking user can already access, and respects the protection on labelled files. Without classification, over-permissioned sensitive data — a payroll spreadsheet in a shared site — becomes easy for Copilot to expose. Labelling and protecting that data first is what makes an AI rollout safe rather than a quiet exposure incident.
Where to start
Pick four tiers, write a one-line definition for each, and agree the handling rules. Build the matching Purview labels, start cosmetic, then add encryption to the top two. That alone puts you ahead of most SMEs and gives you the foundation every other control — DLP, retention, AI governance — depends on.
If you would like a hand defining a classification scheme, building the Purview labels and getting your data governed before you switch on DLP or Copilot, talk to our cyber security team, or get in touch with TechAssist. We will tell you plainly what to classify first and what you can safely leave alone.
Supply chain risk management is the discipline of knowing which third parties touch your data, how exposed each one makes you, and what you would do if one was breached. For an SME that means a vendor inventory, a classification of each supplier by risk, and the right questions before you hand over data.
The uncomfortable truth is that your data no longer sits in one place you control. It sits in your accounting platform, your CRM, your payroll provider, your email host and the dozen smaller SaaS apps your team signed up for. A breach at any one of them is your problem — and potentially your reportable obligation under the Privacy Act.
Why third-party risk is now a leading breach vector
For years the security conversation focused on hardening your own perimeter — firewalls, patching, multi-factor authentication. That work still matters, but attackers worked out something obvious: it is far easier to breach one supplier with weak controls and ride that access into hundreds of downstream businesses than to attack each one individually. So the breach rarely happens inside your four walls. It happens at a vendor — a software provider, an outsourced bookkeeper, a marketing platform — and your data is collateral. You did everything right with MFA and backups, and you still end up notifying customers because a supplier you trusted left a database exposed.
The Australian context makes this concrete. The last few years have seen a string of large supplier and service-provider breaches where the headline organisation was big, but the real damage fanned out across thousands of smaller businesses whose data was processed on their behalf. When a payroll outsourcer or a legal-services platform is breached, every business that fed it data is suddenly exposed — and most had no idea how much was sitting there, or how weak that supplier’s controls were. The lesson is blunt: your security posture is only as strong as the weakest supplier holding your data.
Doing vendor risk management without enterprise GRC
Large organisations run formal governance, risk and compliance (GRC) programmes with dedicated teams, risk registers and continuous monitoring. An SME has none of that and does not need it. What you need is a “lite” version that captures most of the value for a fraction of the effort — five habits.
1. Maintain a vendor inventory
You cannot manage risk you cannot see. List every external party that holds, processes or can access your data and systems. Most SMEs are surprised by how long this list is once they write it down — accounting software, CRM, payroll, Microsoft 365, file storage, e-signature tools, the booking system, the marketing platform, the backup provider, and every smaller app a team member signed up for on a credit card. That last category is the dangerous one, and it overlaps with the problem we cover in our piece on auditing SaaS sprawl and hidden apps. The inventory does not need to be sophisticated — a spreadsheet with the vendor name, what data they hold, who owns the relationship, and how critical they are will do. The discipline is keeping it current.
2. Classify by data sensitivity and criticality
Not every vendor deserves the same scrutiny. Sort your inventory along two axes: how sensitive is the data they hold, and how badly would it hurt if they went down or were breached? The handful of suppliers that hold sensitive personal data, payment information or your core operational systems are your tier-one vendors — they get real questions and contract scrutiny. The rest get a lighter touch. Trying to assess every supplier to the same depth is how SMEs give up on vendor risk entirely.
3. Ask key suppliers the right questions
For your tier-one suppliers, a short questionnaire does most of the work. You are not auditing them; you are checking they are not obviously negligent and getting answers on the record. The questions that matter:
- Certifications. Do they hold ISO 27001, SOC 2, IRAP or an equivalent? A current certification is not a guarantee, but it tells you an independent party has looked at their controls.
- MFA and access control. Is multi-factor authentication enforced on their systems and on the admin access to your data?
- Breach notification. Will they notify you, and how quickly, if they suffer an incident affecting your data? Get the timeframe in writing.
- Data location. Where is your data physically stored and processed? Onshore in Australia, or offshore in a jurisdiction with different privacy rules?
- Sub-processors. Who else do they hand your data to? A vendor’s own suppliers become your risk, and the chain is often longer than anyone admits.
If a supplier cannot or will not answer these, that is itself a finding. A vendor that bristles at basic security questions is telling you something about how they treat your data.
4. Bake security clauses into contracts
Verbal assurances are worthless when something goes wrong. Where you have negotiating room, get the important commitments into the contract or data-processing agreement: a defined breach-notification window, a requirement to maintain reasonable security controls, restrictions on where data is stored, limits on sub-processors, and an obligation to return or destroy your data when the relationship ends. For the suppliers you choose and pay, this is where your virtual CIO earns their keep — reading the agreement before you sign it.
5. Review annually
Vendor risk is not set-and-forget. Suppliers change ownership, move data offshore, or quietly degrade their security. Once a year, pull out the inventory, confirm the tier-one suppliers still hold the certifications they claimed, and remove the vendors you no longer use. The annual review is the single habit that keeps the whole exercise honest.
A Box Hill example
A professional services firm in Box Hill we work with came to us after a near-miss. One of their outsourced administrative suppliers had suffered a data incident, and the firm spent a frantic week trying to work out whether any client data was caught up in it — only to discover they had no record of what that supplier held or where it was stored. The answer turned out to be “not much,” but the panic was real.
We built them a vendor inventory from scratch, classified their suppliers, and sent the tier-one ones a short questionnaire. Two could not confirm MFA on their admin access; one was storing data offshore the firm did not know about. None of it was catastrophic, but all of it was the kind of thing you want to know before an incident, not during one.
The flip side: your customers are now assessing you
Here is the part SMEs often miss. While you assess your suppliers, your customers — especially the larger ones — are assessing you. Vendor questionnaires flow in both directions. If you supply a listed company, a government department or any sizeable organisation, expect their procurement team to send you the same questions you should be asking your own vendors: what certifications do you hold, is MFA enforced, where is data stored, how fast will you notify us of a breach.
This is where demonstrating a recognised baseline pays off commercially, not just defensively. Holding Essential Eight alignment, an SMB1001 certification, ISO 27001 or SOC 2 turns a painful back-and-forth into a single document you hand over. We cover the SME-focused option in our guide to Essential Eight compliance for Melbourne businesses, and our cyber insurance guide for Australian SMEs shows how these credentials connect. The business that can answer the questionnaire quickly wins the work over the one that cannot.
Offboarding vendors properly
The riskiest vendors are often the ones you stopped using but never properly disconnected. A trial app that still has an active OAuth grant into your Microsoft 365, a former bookkeeper whose login was never disabled, a marketing tool with a standing API token reading your customer list — these are live doors into your environment nobody is watching.
Offboarding a vendor means more than cancelling the subscription. Revoke their OAuth app permissions in Microsoft 365 or Google Workspace, disable any service accounts or API keys, confirm they have returned or destroyed your data per the contract, and remove any standing access your staff held to their platform. Reviewing those OAuth grants routinely surfaces forgotten third-party access no one remembers approving — our cyber security services include exactly this kind of access hygiene.
Frequently asked questions
What is the difference between supply chain risk and third-party risk?
Third-party risk is the risk introduced by any external party you deal with directly. Supply-chain risk is broader and includes the parties behind those parties — your vendor’s vendors, the sub-processors handling your data further down the chain. For a small business the practical work is the same: know who holds your data, and how exposed each link makes you.
Do we need expensive GRC software to do this?
No. For an SME a maintained spreadsheet, a sensible classification of suppliers by risk, a short questionnaire for the important ones and an annual review will deliver almost all the benefit. Dedicated third-party risk platforms are built for enterprises managing hundreds of vendors under regulatory mandate. Start with the discipline, not the tooling.
What do we do if a key supplier is breached?
Check your inventory to confirm what data the supplier held, contact them for confirmation of what was affected, and assess whether the incident triggers your obligations under the OAIC’s Notifiable Data Breaches scheme. If personal information you are responsible for was likely accessed and serious harm is likely, you may need to notify the OAIC and affected individuals — far easier when you already know what the supplier held.
Where to start
TechAssist is a Melbourne-based MSP, founded in 2014, with 13 Australian-employed engineers and a 24/7 NOC at Tecoma — no offshore helpdesk. We help SMEs get a grip on third-party risk without enterprise overhead: building the vendor inventory, classifying suppliers, drafting the questions, cleaning up forgotten OAuth access, and getting you ready to answer your own customers’ security questionnaires. If you do not have a vendor inventory, that is the place to start. Get in touch and we will scope it with you.
AI data governance is how you stop staff pasting confidential, customer or regulated information into public AI tools where it can be retained and reused. The fix is not banning AI. It is steering people onto sanctioned, commercially protected tools and putting technical controls around the data itself.
Every Melbourne SME we work with has the same quiet problem: people are already using ChatGPT, Gemini and Copilot, whether or not anyone approved it. The data has already started moving. Governance is about catching up to that reality before it bites.
The actual risk: your data ends up in someone else’s model
When a staff member pastes a slab of text into a free, consumer AI tool, that text leaves your control. Depending on the product and the account tier, it may be stored on the provider’s servers, reviewed by humans for quality, and used to train future versions of the model. That is the part that catches people out — not a dramatic breach, just an employee trying to work faster.
The realistic scenarios are mundane and that is what makes them common:
- A bookkeeper pastes a payroll export into a free chatbot to “summarise the anomalies” — names, salaries and Tax File Numbers go with it.
- A lawyer drops a draft settlement deed in to “tighten the language” — privileged client material, now sitting on an external service.
- A sales rep uploads the full customer list to “write a follow-up campaign” — personal information of hundreds of people, handed to a third party with no agreement in place.
- A clinic manager pastes patient correspondence in to “make it sound friendlier” — health information, the most sensitive category there is.
None of these people are reckless. They are using a tool that is genuinely useful, on data they handle every day, without realising the back end works differently to Office or their line-of-business app. That is the gap governance closes.
Consumer AI vs commercial AI: the difference that matters
Not all AI tools treat your data the same way, and the difference is entirely about which account you are signed into. This is the single most important thing to get staff to understand.
Consumer tiers — a free ChatGPT account, a personal Gmail’s Gemini, a chatbot someone signed up for with their own email — generally reserve the right to retain prompts and use them to improve the model. The provider’s consumer terms, not a commercial contract, govern what happens to your data.
Enterprise and business tiers — the paid, commercially licensed versions tied to your organisation — come with explicit data-protection commitments. Prompts are not used to train the underlying models, data stays within a contractual boundary, and you get administrative controls. The same brand can sit on either side of that line depending on the plan.
| Tool | Consumer / free tier | Commercial / enterprise tier |
|---|
| ChatGPT | Prompts may be retained and used to improve models | ChatGPT Team / Enterprise — prompts not used for training, data stays in your workspace |
| Microsoft Copilot | Personal Copilot — consumer terms apply | Microsoft 365 Copilot — commercial data protection, prompts and data not used to train foundation models, stays within the Microsoft 365 service boundary |
| Google Gemini | Personal-account Gemini — may be reviewed and retained | Gemini for Google Workspace — enterprise data protection, content not used for training |
The practical instruction for staff is short: if AI work involves anything that is not already public, it goes through the sanctioned, organisation-signed-in tool — never a personal or free account. Microsoft 365 Copilot in particular sits inside the same service boundary as your existing Microsoft 365 data, which is why it is the natural starting point for most Melbourne SMEs already on Business Premium. Our guide to what is included with Microsoft 365 support in Melbourne covers where Copilot fits.
The Australian regulatory angle
This is not just a tidiness issue. Feeding personal information into an uncontrolled AND offshore service can put you on the wrong side of the Privacy Act 1988.
Under the Australian Privacy Principles (APPs), you must take reasonable steps to protect personal information (APP 11) and you carry obligations when personal information crosses borders to an overseas recipient (APP 8). Most consumer AI services process data offshore, which means an employee pasting customer data into a free tool can quietly trigger a cross-border disclosure you never assessed or agreed to.
The privacy reforms passed in late 2024 sharpened the picture. They introduced a statutory tort for serious invasions of privacy, strengthened enforcement powers for the Office of the Australian Information Commissioner (OAIC), and signalled tighter expectations around automated decision-making and transparency. The direction of travel is clear: regulators expect organisations to know where personal information goes and to be able to show they controlled it.
Sensitive information — health, biometric, and similar categories — attracts a higher bar again. A health service that lets staff paste patient details into a consumer chatbot has a genuine problem, not a theoretical one. If you operate in that space, our note on healthcare IT support and OAIC obligations is worth a read. The point for everyone else: regulated and customer data needs governance before it goes anywhere near a model.
The technical controls that actually work
A policy document on its own changes nothing. The control that holds is the one that does not depend on every employee remembering a rule at the moment they are busy. Here is the stack we put in place, roughly in order.
An AU-aligned AI acceptable use policy
You still need the policy — it sets the expectation, names the sanctioned tools, and gives you something to point to. The key is that it must be specific to your tools and your obligations, not a generic template. We have written separately about building an acceptable use policy that staff actually follow; the short version is that it should name which tools are approved, what data must never go into any AI tool, and who to ask when unsure. Treat the policy as the starting line, not the finish.
Sanctioned tools, properly licensed
Give people a good, approved option and most of the problem evaporates. Staff reach for free tools because nothing better was offered. Roll out Microsoft 365 Copilot or Gemini for Workspace on the right licence, sign them in under the organisation account, and the data stays inside the commercial boundary by default. Sanctioning a tool is cheaper than cleaning up after an uncontrolled one.
Microsoft Purview sensitivity labels and DLP
This is where governance gets teeth. Sensitivity labels tag and can encrypt your most sensitive files, and Data Loss Prevention (DLP) inspects content and acts on it. A DLP policy can warn or block when someone tries to send a document full of Tax File Numbers or Medicare numbers to an external destination — including, increasingly, paste actions into a browser-based AI tool via endpoint DLP. Labelling and DLP are also what govern what Copilot itself is allowed to surface internally. We cover the full setup in our piece on Microsoft 365 data governance, but the headline is that labels plus DLP are the data-layer control that does not rely on goodwill.
Conditional access
Identity controls decide who can reach the sanctioned tools and from where. Conditional access policies let you require a managed, compliant device and an MFA-verified identity before someone touches the corporate AI tools, and let you block access from unmanaged personal devices where you have no visibility. This is the difference between “we hope people use the right account” and “the wrong account simply cannot reach our data”.
Staff training
Controls reduce the blast radius; training reduces how often the trigger gets pulled. People need to understand, in plain terms, why a free chatbot is different from the signed-in corporate one, and what counts as data they must not paste. A fifteen-minute briefing that shows the consumer-versus-commercial difference does more than a fifty-page policy nobody reads.
Govern before you adopt
The mistake we see most is enthusiasm-first: a business rolls AI out across the company, then thinks about data governance when something goes wrong. Reverse it. Decide what data is sensitive, label and protect it, set DLP rules, pick and license your sanctioned tools, lock access with conditional access, then turn AI loose. Governance first is not slower — it is the only version that does not generate a clean-up project six months later.
A Box Hill scenario
An accounting firm in Box Hill we work with came to us after a partner noticed staff using personal ChatGPT accounts to draft client letters — pasting in figures, names and TFNs as they went. Nobody had done anything malicious; the firm had simply never offered an approved tool or said where the line was. We rolled out Microsoft 365 Copilot under their existing Business Premium licences, applied Confidential sensitivity labels with encryption to their client folders, set DLP rules on TFNs and Medicare numbers, and used conditional access so the corporate tools only worked from managed devices. We paired it with a short staff session on the consumer-versus-commercial difference. The firm now has a faster, sanctioned tool and a defensible answer if the OAIC or their professional indemnity insurer ever asks how client data is controlled.
TechAssist has run Microsoft 365 for Melbourne SMEs since 2014, with thirteen Australian-employed engineers and a 24/7 NOC in Tecoma. The govern-then-adopt review has quietly become one of the more common pieces of work we do as AI tools spread through workplaces.
Frequently asked questions
Is it safe to use ChatGPT for work?
It depends entirely on the account. A free or personal ChatGPT account may retain your prompts and use them to improve the model, so it is not appropriate for confidential, customer or regulated data. ChatGPT Team or Enterprise, signed in under your organisation, does not use your prompts for training and is a reasonable sanctioned tool. The rule of thumb: anything not already public goes only through the approved, organisation-licensed tool.
Does Microsoft 365 Copilot use our data to train its models?
No. Microsoft 365 Copilot operates under commercial data-protection commitments. Your prompts, responses and organisational data are not used to train the underlying foundation models and stay within the Microsoft 365 service boundary. That is precisely why it is a safer default than a personal AI account for business data.
Can staff pasting data into AI tools breach the Privacy Act?
It can. Pasting personal information into a consumer AI service that processes data offshore can amount to a cross-border disclosure under APP 8 and a failure to take reasonable security steps under APP 11. Sensitive information such as health data raises the bar further. Sanctioned tools, sensitivity labels and DLP are how you keep that data inside controls you can demonstrate to the OAIC.
How do we stop people using free AI tools without banning AI entirely?
You give them a good sanctioned alternative and put controls around the data. License a commercial tool such as Microsoft 365 Copilot or Gemini for Workspace, apply Purview sensitivity labels and DLP, enforce conditional access so the corporate tools only work from managed devices, and back it with a short, specific acceptable use policy and training. Most uncontrolled use stops once a better, approved option exists.
Where to start
You do not need to solve everything at once. Decide which data is genuinely sensitive, license one sanctioned AI tool, switch on a couple of DLP rules in audit mode, and run a fifteen-minute staff briefing. That alone moves you from “people are doing whatever” to a defensible, governed position.
If you would like a hand scoping an AI data governance rollout — sanctioned tools, Purview labels and DLP, conditional access and a policy that fits your obligations — talk to our cyber security team, or get in touch with TechAssist. We will tell you plainly what to lock down first and what you can safely leave alone.
Microsoft Purview is Microsoft’s data governance and compliance suite inside Microsoft 365 — the rebranded, expanded successor to what used to be called the Microsoft 365 Compliance Centre. It is how you classify, protect, retain and audit your organisation’s data, and it is the layer that decides what Copilot is allowed to see.
For a Melbourne SME, the practical question is not “what is Purview” but “which bits do I already pay for, and what should I switch on first?” This post answers both, without the marketing gloss.
What Microsoft Purview actually is
Purview is an umbrella brand. Under it sit a set of tools that used to be scattered across separate portals. They are now grouped at purview.microsoft.com and broadly cover two jobs: knowing where your sensitive data is, and controlling what happens to it.
The capabilities that matter to most small and mid-sized businesses are:
- Sensitivity labels — tags like Confidential or Internal that travel with a file or email and can enforce encryption and access rules.
- Data Loss Prevention (DLP) — rules that stop sensitive data, such as credit card or Tax File Numbers, from leaving the organisation by email, Teams or to USB.
- Retention policies and labels — rules that keep records for a set period and delete them when they expire, which is how you meet records-keeping obligations without hoarding everything forever.
- eDiscovery — the ability to search across mailboxes, SharePoint and Teams to find content for a legal matter, dispute or regulator request.
- Audit — a searchable log of who did what: who opened a file, who deleted a mailbox item, who changed a permission.
- Insider risk management — analytics that flag risky behaviour, such as a departing employee mass-downloading client files.
- Communication compliance — monitoring of internal messaging for harassment, code-of-conduct breaches or regulated-industry conduct rules.
You will not use all of these on day one, and you should not try to. The point is that Purview is where data governance lives once you decide to take it seriously.
What you get with Business Premium, and what needs E5
This is where most decisions get made, because the licensing split is real and it is easy to overspend or assume you have features you do not.
Microsoft 365 Business Premium — the plan most Melbourne SMEs land on — includes a genuinely useful slice of Purview. You get manual sensitivity labels, basic DLP for Exchange, SharePoint, OneDrive and Teams, basic retention policies, standard audit logging, and basic eDiscovery (search and export). For a business under 300 seats, that is enough to make a real difference.
The advanced tier sits behind Microsoft 365 E5, the E5 Compliance add-on, or standalone Purview add-ons. That is where you find automatic labelling, DLP that extends to endpoints and browsers, communication compliance, insider risk management, eDiscovery (Premium) with legal hold and review sets, and longer audit retention.
| Capability | Business Premium | E5 / E5 Compliance |
|---|
| Sensitivity labels (manual) | Yes | Yes |
| Automatic labelling | No | Yes |
| DLP for Exchange, SharePoint, OneDrive, Teams | Yes (basic) | Yes |
| Endpoint DLP (USB, browser, copy) | No | Yes |
| Retention policies and labels | Yes (basic) | Yes (auto-apply, event-based) |
| eDiscovery | Standard (search and export) | Premium (legal hold, review sets) |
| Audit | Standard | Long-term retention |
| Insider risk management | No | Yes |
| Communication compliance | No | Yes |
The honest advice: do not buy E5 because the feature list looks impressive. Buy it when you have a specific obligation — a regulator, an insurer, a contract — that needs automatic labelling, endpoint DLP or insider risk. Most SMEs get years of value out of the Business Premium tier first. If you are weighing up the plans, our guide to what is included with Microsoft 365 support in Melbourne sets out where the lines fall.
What to do first: labels and DLP
If you take one thing from this post, take this. Start with sensitivity labels and DLP. They give you the most protection for the least effort, and everything else builds on them.
Sensitivity labels
A sensitivity label is a tag a user applies to a document or email. A typical SME set is three or four labels: Public, Internal, Confidential, and perhaps Highly Confidential. The label can be cosmetic (a footer marking) or it can enforce real controls — encryption, a watermark, blocking external sharing.
Start cosmetic, get people used to choosing a label, then add enforcement to the top one or two. A label that encrypts Confidential files means a document forwarded to the wrong address is unreadable to the recipient. That single control has saved more SMEs than any firewall rule.
Data Loss Prevention
DLP inspects content against patterns and conditions you set, then acts. The patterns Australian businesses care about are built in or easy to define: Tax File Numbers, Medicare numbers, credit card numbers, ABNs, driver licence details. A starter DLP policy might warn a user — or block outright — when they try to email a spreadsheet containing more than a handful of TFNs to an external address.
Begin every DLP rule in audit-only mode. Let it run for a fortnight, see what it would have flagged, and tune out the false positives before you switch to blocking. Turn DLP straight to block on day one and you will have the finance team locked out of legitimate work by Tuesday. DLP sits naturally alongside the rest of your cyber security services stack — it is the data-layer complement to identity controls like conditional access.
Retention, eDiscovery and audit: the records side
The governance half of Purview is about keeping the right things for the right length of time, and being able to find them.
Retention answers a question every business eventually faces: how long do we keep this? Some records have legal minimums — employee records under the Fair Work Act, financial records under the Corporations Act, health records under state health-records legislation. Retention policies enforce those minimums automatically and, just as importantly, delete data once the obligation lapses so you are not holding a decade of client files that are now pure liability.
eDiscovery earns its keep the day you receive a subpoena, a Fair Work claim or an OAIC enquiry. Instead of an engineer manually trawling mailboxes, you run a content search across Exchange, SharePoint and Teams and export exactly what is in scope. Standard eDiscovery in Business Premium handles most SME needs.
Audit is the quiet hero. When something goes wrong — a deleted file, a mailbox rule someone did not set, a permissions change — the audit log tells you who and when. It is also frequently the first thing a cyber insurer or incident responder asks for. If you are thinking about coverage, audit logging is part of what makes a claim defensible; our cyber insurance guide for Australian SMEs covers the broader picture.
Governance before AI: Purview and Copilot
This is the use case pushing Purview up the priority list for 2026. Microsoft 365 Copilot answers questions using your organisation’s data — every file, email and chat the asking user already has permission to see. That is the catch. Copilot does not break permissions; it surfaces what loose permissions already expose.
If your SharePoint has a “Company” site everyone can read, and someone parked the payroll spreadsheet there three years ago, Copilot will happily summarise salaries when an employee asks. The file was always accessible — nobody ever browsed to it. Copilot removes that friction.
This is why governance comes before AI, not after. Sensitivity labels let you mark and encrypt the data Copilot should never reuse. DLP and retention reduce the volume of stale, mislabelled data sitting in shared locations. Auditing tells you what Copilot has been asked. Switching on Copilot without doing this first is how a tidy-looking rollout becomes a quiet data-exposure incident.
The same logic applies to the Privacy Act 1988. Under the Australian Privacy Principles, you are obliged to take reasonable steps to protect personal information and to not keep it longer than needed. Reforms now working through Parliament are tightening those expectations, including around automated decision-making and data minimisation. Purview’s labelling, DLP and retention are precisely the “reasonable steps” the Office of the Australian Information Commissioner (OAIC) expects you to be able to demonstrate.
A Hawthorn scenario
A professional services firm in Hawthorn we work with wanted to roll out Copilot across forty staff. Before flicking it on, we ran a labelling and permissions review. We found three SharePoint sites with broad read access holding client financials and a folder of scanned passports from an old onboarding process. We applied Confidential labels with encryption to the sensitive sites, tightened the permissions, set a DLP rule on TFNs and Medicare numbers, and added a retention policy that purged the passport scans that should have been deleted years earlier. Copilot went live two weeks later — on data that was actually governed. The firm now has something concrete to show their professional indemnity insurer.
That sequence — govern, then enable — is the whole game. TechAssist has run Microsoft 365 for Melbourne SMEs since 2014, with thirteen Australian-employed engineers and a 24/7 NOC in Tecoma, and the Purview-before-Copilot review has become one of the more common pieces of work we do.
Frequently asked questions
Is Microsoft Purview a separate product I have to buy?
No. Purview is the brand for governance and compliance tools built into Microsoft 365. A meaningful set is already included with Business Premium. You only pay extra — through E5 or the E5 Compliance add-on — for advanced features such as automatic labelling, endpoint DLP and insider risk management.
What is the difference between sensitivity labels and retention labels?
Sensitivity labels control protection — encryption, access and markings on a file. Retention labels control lifecycle — how long an item is kept and when it is deleted. They solve different problems and you typically use both: sensitivity to protect, retention to keep or dispose.
Do I need Purview before turning on Copilot?
You should. Copilot surfaces anything the asking user can already access, so existing over-permissioned data becomes far easier to stumble across. Sorting out labels, permissions and DLP first stops Copilot turning a hidden exposure into an obvious one.
Does Purview help with the Privacy Act?
It helps you demonstrate compliance. The Australian Privacy Principles require reasonable steps to protect personal information and to not retain it beyond need. Purview’s DLP, sensitivity labels and retention policies are practical, auditable controls that show the OAIC you have taken those steps.
Where to start
Do not boil the ocean. Pick three or four sensitivity labels, switch on a couple of DLP rules in audit mode, and set retention on your one or two most regulated record types. That alone puts you ahead of most SMEs and gives you a defensible governance baseline — and the foundation you need before any AI tool touches your data.
If you would like a hand scoping a Purview rollout, sorting your Microsoft 365 licensing, or running a governance review before you enable Copilot, get in touch with TechAssist. We will tell you plainly what you already have, what is worth turning on, and what you can safely leave alone.
NDIS IT support means keeping participant records, claiming systems and a distributed support workforce running securely — to the standard the NDIS Quality and Safeguards Commission and the NDIS Practice Standards now expect. Get it wrong and you risk a reportable breach, a failed audit, or support workers locked out of care plans.
Disability service providers sit on some of the most sensitive personal data in the country and run it across phones, tablets and vehicles spread over the whole of Melbourne. That combination — concentrated risk and a mobile workforce — is what makes the IT demanding. Here’s what providers actually need, and where most are exposed.
Registered, unregistered, and the range of services
“NDIS provider” covers a wide spread of organisations, and the IT requirements shift depending on where you sit. A registered provider has been audited against the NDIS Practice Standards and carries explicit obligations around governance, incident management and the handling of participant information. An unregistered provider working with plan-managed or self-managed participants has fewer audit obligations but holds the same sensitive data and the same duty under the Privacy Act — so “we’re not registered” is no reason to run loose IT.
The service types pull in different directions too. A support coordination business is mostly office and laptop work: managing plans, liaising with participants, writing reports. Supported Independent Living (SIL) and community-access services run more like a 24/7 operation across multiple houses, with workers on shift, rosters that change daily, and behaviour-support information needed at the point of care. The software looks similar from outside; the network, device and access design underneath is genuinely different.
The compliance layer: the Commission and the Practice Standards
The NDIS Quality and Safeguards Commission regulates registered providers, and a meaningful slice of its expectations land on IT. The NDIS Practice Standards include governance and operational management requirements, and the Privacy and Information Management requirements expect providers to keep participant information confidential, accurate and secure, and to control who can access it. That is an identity and data-security problem as much as a policy one.
Two points catch providers out. Accountability stays with you — “we outsourced it to an IT company” is not an answer the Commission accepts. And you have to be able to show it: if a verification or certification audit asks how participant records are protected and who can see them, you need documented access controls, an offboarding process, and evidence your backups work. Most providers can describe their intentions; far fewer can produce the evidence.
PRODA and the NDIS portals
Almost every NDIS provider lives in the government portals, and access is an identity issue with real consequences. PRODA (Provider Digital Access) is the Commonwealth identity gateway that gets staff into the myplace provider portal, the NDIS Commission systems, and the claiming and payment functions. Each PRODA account is tied to an individual, secured with two-factor sign-in, and linked to your organisation.
The risk sits in lifecycle management. When a payments officer leaves and their PRODA access isn’t revoked, you have an orphaned door into participant payment data. We treat PRODA and portal access with the same identity discipline as everything else: documented who-has-what, removed the same day someone leaves, and never shared. Shared logins remain the most common control failure we find in this sector.
Participant management and claiming software
The system at the centre of an NDIS provider’s day is its participant management platform — handling records, plans, shift notes, invoicing and the claim file that goes to the agency. That usually means Lumary, ShiftCare, Brevity, SupportAbility or Carelink, often with finance and payroll alongside.
Whether these run in the cloud or on a server in the comms room, the IT job is the same: they must be available, fast, backed up, and reachable wherever support happens. We treat them as the priority for monitoring, patching and uptime.
A SIL provider in Dandenong we work with runs records, rostering and claiming on one cloud platform. The risk was never the software — it was everything underneath: a single shared login, a flat network where one compromised PC could reach everything, unmanaged personal phones, and backups nobody had tested. None of that is the vendor’s responsibility. It’s the MSP’s, and it’s where the real exposure sits.
Protecting highly sensitive participant data
NDIS providers hold a concentration of sensitive information that makes them a deliberate target: disability and health records, behaviour-support plans, medication details, NDIS numbers, bank and plan-management details, guardianship and next-of-kin information, and often data about minors. Under the Privacy Act and the Australian Privacy Principles, much of this is “sensitive information” attracting the highest protection, and a breach likely to cause serious harm is reportable to the Office of the Australian Information Commissioner (OAIC) under the Notifiable Data Breaches scheme.
Attackers know care providers often run lean IT and a workforce that’s easy to phish, and the data is high-value — the cyber insurance market has noticed too, with premiums and required controls reflecting the risk.
The defensive baseline we hold NDIS clients to is the Australian Cyber Security Centre’s (ACSC) Essential Eight: application control, fast patching of applications and operating systems, Microsoft Office macro settings, user application hardening, restricted administrative privileges, multi-factor authentication, and regular tested backups. Most breaches we’re called in after would have been stopped or contained by getting it genuinely in place rather than half-done. If you want the staged version, we’ve written up how to reach Essential Eight maturity in 90 days.
A mobile workforce: devices, rostering and remote access
Rostering and field devices
SIL and community-access providers run on rosters that change constantly, and support workers need to see shifts, log visit notes and read care plans on a phone or tablet wherever they are. Those devices carry participant data out into the world, so they have to be managed centrally. If a tablet is lost between a shift in Footscray and the next in Sunshine, you need to remotely wipe it within minutes — not discover it’s been sitting unencrypted in a glovebox. Mobile device management through Microsoft Intune, enforced encryption, and conditional access tied to a managed device are what make field devices defensible.
Secure remote access for support workers
Workers reaching rosters and care plans from homes, group residences and their cars need access that’s both easy and locked down — not VPNs into a flat network, but identity-based access where each worker signs in as themselves, MFA is enforced, and what they reach is scoped to their role. A support worker should see their participants and shifts, not the organisation’s whole record set. We run conditional access in Microsoft 365 and build around least privilege, so one compromised account can’t expose every participant.
Identity for a high-turnover workforce
Disability services have significant staff churn — casuals, agency workers, people moving between providers. Every starter needs the right access on day one and every leaver needs it gone the same day, including PRODA. Orphaned accounts are how breaches happen months after someone’s left. We run it properly: standardised onboarding and offboarding, role-based access, and MFA everywhere.
Backups and incident readiness
A tested, isolated backup is the difference between a ransomware incident being a bad week and an existential event for a provider that can’t access medication or behaviour-support records. We cover this in our guide to backup and disaster recovery for Melbourne businesses, and it applies double when records relate to vulnerable people. Incident readiness goes further: logging, a rehearsed response plan, and the ability to retrieve records quickly when the Commission, an insurer or a family asks.
What good NDIS IT support actually covers
| Area | What it looks like done properly |
|---|
| Participant systems | Lumary, ShiftCare, Brevity, SupportAbility or Carelink monitored, patched and prioritised for uptime; backups tested |
| Portal access | PRODA and myplace access tied to individuals, no shared logins, removed same-day on departure |
| Data protection | Essential Eight aligned, MFA everywhere, tested isolated backups, OAIC breach readiness |
| Mobile workforce | Intune-managed phones and tablets, enforced encryption, remote wipe for lost field devices |
| Remote access | Identity-based, least-privilege, conditional access on Microsoft 365 — no flat-network VPNs |
| Compliance evidence | Documented access controls and offboarding ready for Practice Standards audits |
TechAssist is a Melbourne-based MSP, founded in 2014, with 13 Australian-employed engineers — no offshore helpdesk touching participant data. We price per user on a fixed monthly basis with no hourly billing for in-scope work, which matters in a sector budgeting against plan-funded revenue. Our cybersecurity services and broader managed IT services carry this regulated, always-on workload, and our 24/7 network operations centre in Tecoma means support doesn’t stop when a SIL house needs help overnight.
Frequently asked questions
Do the NDIS Practice Standards require specific IT controls?
They don’t prescribe particular products, but the Privacy and Information Management and governance requirements mean providers must be able to show participant information is kept secure, accurate and access-controlled. In practice that points straight at Essential Eight controls, MFA, managed identity and tested backups — and the accountability stays with the registered provider, not the IT vendor.
We’re an unregistered provider — do these IT requirements still apply?
The audit obligations differ, but the data doesn’t. You hold the same sensitive participant information and the same duty under the Privacy Act, and a breach likely to cause serious harm is still reportable to the OAIC. Running lean IT because you’re unregistered is a risk, not a saving.
How should we handle PRODA access when a staff member leaves?
Revoke it the same day, alongside their email, portal and system access, as part of a standard offboarding process. PRODA accounts are tied to individuals and must never be shared. Orphaned access is a live door into participant payment data and a common audit finding.
Where to start
If you’re unsure whether your IT would stand up to a Practice Standards audit or a breach, the honest first step is an assessment: where participant data lives, how access and PRODA are controlled, whether your backups actually restore, and where the Essential Eight gaps are. Most providers we assess have two or three serious exposures they didn’t know about — usually shared logins, unmanaged devices, or untested backups. Get in touch with TechAssist and we’ll give you a straight read on what to fix first.