Introduction to Cyber Security for Social Workers

As a social worker, you hold a position of deep trust. Whether you're supporting individuals and families through trauma, advocating for vulnerable communities, or managing complex case files, your clients rely on you to protect not only their wellbeing but their personal information.

In today’s digital world, that trust extends to how you store, manage, communicate and protect sensitive data. From case notes and referral letters to financial records and personal disclosures, your systems are a target for cyber criminals.

The information you hold is highly valuable. Health and social care records contain detailed personal histories, mental health assessments, child protection files, and legal documents. Data that can be exploited for identity theft, blackmail, or sold on the dark web. Unlike financial data, which can be changed or cancelled, personal and psychological information is permanent. Once exposed, it cannot be undone.

Cyber criminals know that small to medium social work practices, including sole traders, often lack the defences of larger organisations, making them easier targets. That’s why social workers regardless of size, must treat cyber security as a core part of ethical and professional care.

The Cost and Impact of Cyber Attacks

Small businesses, including many social work practices, are increasingly targeted by cyber criminals. According to the Australian Cyber Security Centre Annual Threat Report 2024-25, the average cost of a cyber attacks in Australia is now $56,600 for small business. Healthcare and social assistance sector accounted for 6% of all reported incidents, making it one of the top 10 targeted sectors.

These figures highlight the urgent need for robust cyber security measures. A single breach can have devastating financial, operational, and reputational consequences, especially for organisations entrusted with sensitive client information.

Emerging Threats in Cyber Security

The cyber threat landscape is constantly evolving. In addition to traditional risks like phishing and ransomware, social work practices now face emerging threats such as:

  • AI-driven attacks: Cyber criminals are using artificial intelligence to craft more convincing phishing emails and automate attacks.
  • Supply chain vulnerabilities: Attacks can occur through third-party vendors or software providers.
  • Data theft for extortion: Sensitive client data is increasingly targeted for blackmail or public exposure.
  • Attacks on cloud services and mobile devices: As more practices use cloud storage and mobile technology, these platforms are becoming prime targets

Staying informed about new threats and regularly updating your security practices is essential for protecting your clients and your practice.

A Cyber Threat Scenario

Imagine a small community-based social work practice uses a shared laptop to manage client records, send emails, and store scanned intake forms. One morning, the owner arrives at the practice only to discover their device was locked by ransomware.

A message received from cyber criminals demanding $8,000 in cryptocurrency to unlock the files or the data stolen will be leaked online. A message was also sent to clients whose data was leaked also demanding payment to prevent their data being sent to employers and posted online.

The breach occurred after a staff member clicked on a phishing email disguised as a funding update. The attackers gained access to sensitive client data, including case notes, housing applications, child protection files, and mental health assessments.

The practice had no multi-factor authentication, no encryption, no data backups, and no breach response plan. The practice, because of the highly valuable nature of the information leaked, were required to notify affected clients, report the incident under the Notifiable Data Breaches (NDB) Scheme, and engage a cyber security consultant. The emotional and reputational impact was immediate.

The impact on clients was equally profound. Many received direct threats from the attackers, demanding payment to prevent their personal information from being sent to employers or posted online. This caused:

  • Fear and anxiety about exposure and retaliation
  • Distrust in the practice and the broader system
  • Emotional retraumatisation, especially for those with histories of abuse, mental health challenges, or child protection involvement

Some clients withdrew from services, while others expressed anger and disappointment. The breach fractured the relationship and undermined the sense of safety that is essential in social work.

Social workers are trained to support others through crisis but when the crisis is digital and internal, the emotional burden can be overwhelming. This example highlights why cyber security is not just about technology, it’s about protecting people, relationships, and wellbeing.

By investing in secure systems, staff training, and breach response planning, social work practices can prevent these threats and uphold the trust placed in them by vulnerable individuals and communities.

How This Could Have Been Prevented with a TSSP

The devastating breach experienced by the community-based social work practice was not inevitable. It was preventable. Had the practice partnered with a Technology Services and Security Provider (TSSP), many of the vulnerabilities exploited by the attackers could have been addressed.

Here’s how a TSSP could have made a difference.

1. Email Filtering and Phishing Protection

The phishing email that triggered the attack would likely have been blocked before it reached the staff member’s inbox. TSSPs implement advanced email filtering systems that detect and quarantine suspicious messages.

2. Multi-Factor Authentication (MFA)

Even if login credentials were compromised, MFA would have added a second layer of protection, making it significantly harder for attackers to gain access to systems and data.

3. Encryption of Sensitive Data

With proper encryption in place, even if files were stolen, they would have been unreadable to the attackers. This could have prevented the extortion of clients and the threat of public exposure.

4. Automated, Secure Backups

A TSSP would have ensured that encrypted backups were performed regularly and stored securely. The practice could have restored its systems quickly without paying the ransom.

5. Breach Response Planning

A TSSP would have helped the practice develop and maintain a breach response plan aligned with the Notifiable Data Breaches (NDB) Scheme. This would have enabled a faster, more compliant, and less chaotic response.

6. Ongoing Monitoring and Risk Management

With 24/7 monitoring, unusual activity could have been detected early, possibly before the ransomware was deployed. A TSSP also conducts regular risk assessments to identify and fix vulnerabilities before they’re exploited.

7. Staff Training and Awareness

TSSPs often provide cyber awareness training to help staff recognise phishing attempts, use secure passwords, and follow safe data handling practices.

Cyber Security Matters in Social Work

Social workers often operate in environments with limited technical support, private practices, NGOs, outreach programs, or as sole traders. These settings are increasingly vulnerable to cyber threats, including:

  • Phishing scams targeting email accounts
  • Ransomware attacks locking access to client files
  • Data breaches exposing confidential information
  • Unsecured devices used for mobile casework

A single breach can cause serious harm to your clients, disrupt your practice, and trigger legal and ethical consequences under Australian privacy laws.

What is at risk?

  • Client records often contain:
  • Names, addresses, and contact details
  • Case histories and mental health assessments
  • Legal documents and court orders
  • Financial and housing information
  • Sensitive disclosures about trauma, abuse, or risk

This data is highly valuable. Cyber criminals target small practices because they often lack the defences of larger organisations.

Your Legal and Ethical Responsibilities

Social workers are bound by both legal and professional obligations to protect client information:

  • Privacy Act 1988 (Cth) – Requires “reasonable steps” to protect personal information
  • Notifiable Data Breaches (NDB) Scheme – Mandates reporting if a breach is likely to cause serious harm
  • State Health Records Laws – May impose additional obligations in NSW, Victoria, and other jurisdictions
  • Professional Codes of Ethics – Emphasise confidentiality, integrity, and responsible data handling

Failure to meet these obligations can result in investigations, fines, reputational damage, and loss of registration or employment.

In anticipation of future regulation and in alignment with current professional expectations social workers must demonstrate responsible data handling and cyber security practices. This is especially important for maintaining membership with professional bodies like the AASW, which uphold ethical standards and require practitioners to:

  • Protect client confidentiality
  • Maintain secure records
  • Comply with privacy legislation
  • Engage in ongoing professional development

Poor cyber security practices, such as failing to secure client data, ignoring breach protocols, or using unsecured devices can lead to:

  • Loss of professional membership
  • Breach of ethical codes
  • Legal liability under the Privacy Act 1988 (Cth)
  • Reputational damage and loss of client trust

If you're a member of the Australian Association of Social Workers (AASW), you are bound by its Code of Ethics and Practice Standards, which include obligations around confidentiality, privacy, and responsible data handling. Breaches, such as leaking client data online due to poor cyber security, can result in:

  • Loss of AASW membership
  • Professional misconduct investigations
  • Exclusion from AASW-endorsed roles or panels

While this isn’t formal deregistration, it can significantly impact your professional credibility and employability.

Cyber Security Expectations: The Essential Eight

The Essential Eight is a set of cyber security strategies developed by the Australian Cyber Security Centre (ACSC). These are scalable and relevant for all health service providers:

 

Strategy

What It Means

Why It Matters

Application Control

Only allow approved apps and programs to run on your systems.

Stops malware from running in the first place.

Patch Applications

Regularly update software (e.g., browsers, Microsoft Office, PDF readers).

Fixes security holes that hackers can exploit.

Configure Microsoft Office Macro Settings

Block risky macros from running  in documents.

Macros are a common way for viruses to get in.

User Application Hardening

Disable unnecessary features in apps (like Flash, ads, Java).

Reduces the number of ways hackers can get it.

Restrict Admin Privileges

Only IT/admin staff should have full access to systems. Regular users get only what they need.

Limits the damage if someone's account is hacked.

Patch Operating Systems

Keeps Windows, MacOS, or other operating systems updated.

Prevents known security flaws from being used against you.

Multi-Factor Authentication (MFA)

Require users to enter a second code (e.g., from an app or SMS) when logging in. 

Makes it much harder for hackers to break into accounts.

Regular Backups

Automatically back up your data, and test restoring it.

Essential if you're hit by ransomware or system failure.

 

Device Security and Management

For businesses and sole traders, managing and securing devices is a critical part of commercial level cyber security. This involves ensuring that all devices used within the business, such as computers, smartphones, and tablets, are protected against cyber threats and managed effectively.

Key aspects of device security and management include:

  • Regular updates to ensure that all devices have the latest security updates and patches installed.
  • Mobile device management tools to allow businesses to manage and secure employees mobile devices ensuring compliance with security policies and industry recommendations.
  • Device encryption on devices to protect sensitive information in case of loss or theft.

Working with a Technology Services and Security Provider (TSSP)

Managing cyber security doesn’t have to be overwhelming. A Technology Services and Security Provider (TSSP) can help you:

  • Protect sensitive client and organisational data
  • Stay compliant with Australian privacy laws
  • Monitor systems remotely and respond to threats quickly
  • Improve system performance and reduce risk
  • Implement secure backups and breach response plans
  • Align your systems with the ACSC Essential Eight framework

A TSSP acts as your digital safety partner so you can focus on supporting your clients, knowing your systems are secure and compliant.

How Harvey Norman Technology for Business Supports Social Workers

At Harvey Norman Technology for Business, we specialise in complete IT solutions built for businesses of all sizes, from one to 300 employees. Our services include:

  • Advanced cyber security protection
  • Compliance support for the Privacy Act and NDB Scheme
  • 24/7 system monitoring and help desk support
  • Risk assessments and breach response planning
  • Secure backups and data recovery solutions
  • Device and cloud security management

Whether you’re working independently or as part of a team, we help you simplify cyber security, minimise risk, and provide strategies that assist with compliance, so you can focus on what matters most: your clients.

Cyber Security Is Client Care

In social work, protecting your clients means protecting their data. Cyber security is not just about technology it’s about ethics, professionalism, and safety. By taking proactive steps and partnering with a trusted provider, you strengthen your practice and uphold the trust placed in you by vulnerable individuals and communities.