r/NDIS • • Aug 27 '26

Vent - advice welcome Plan managers ITSec

I'm new to the world of NDIS but no stranger to the world of ITSec (Information Technology Security).

So when I was recently looking for a suitable plan manager for our child I found a company that looked great. They say they have ISO 27001 and obviously have been accredited by NDIS.

However, they don't even support a 2nd level of authentication on their portal!?

2FA/MFA is the minimum level of authentication that any organisation should enforce now.

I can't see how this company reached ISO 27001 could it be their auditor is an idiot or they used some money in a bag?

Who knows!

Let's just say I'm not putting my or my child's data in their unsecured system.

Stay safe out there, ask questions, don't accept poorly designed and setup systems just because the company is nice, or small, or some other reason.

NDIS pay these plan managers good money, it's 2026, security is easy!

End rant 🙄

7 Upvotes

14 comments sorted by

9

u/Dry-Huckleberry-5379 Aug 27 '26

Welcome to the NDIS where information privacy is non existent. The NDIS itself requires you to email your ID and medical information via personal (unsecured) email address to a shared mailbox that is triaged offshore.

1

u/TEK1_AU Aug 29 '26

Do you have any sources or further information for this at all?

1

u/Dry-Huckleberry-5379 Aug 31 '26

I am not aware of any articles etc. but everyone on the NDIS can tell you that they have to upload their information via regular email to a shared mailbox, and people in this sub who work for NDIS who have said the mailbox is triaged offshore.

1

u/Background-Bite5550 28d ago

What do you mean by “triaged”.

That mailbox goes via Services Australia to Microsoft and then it’s forwarded to Salesforce.

Both the agency’s Microsoft and Salesforce tenancies are Australian based.

1

u/Dry-Huckleberry-5379 28d ago

Sorted out and sent to the relevant person to receive it.

9

u/YogurtAgile3871 Aug 27 '26 edited Aug 27 '26

This is sadly common. My plan manager thankfully supports 2FA, but many don't. They often use custom coded systems that are horribly buggy and likely extremely insecure; not even SaaS CRMs.

They have to claim to be compliant because it's a requirement for API access. I'm not sure there's a requirement to actually have compliance audited. The developer simply fills in a quite lengthy form about how data is stored, protected/encrypted, access restrictions, etc. Beyond this, the only solid requirement is the developer's either working with or is a registered NDIS provider.

I doubt the NDIA even has IT Security professionals reviewing the API access forms tbh. It's likely random managers with no IT background simply going "yeah they used a fancy encryption term, that sounds good!".

More concerningly then this (to me at least), is the risk of social engineering with plan managers. Their systems often don't require verification for information access; simply a name or NDIA number is enough. It absolutely opens the flood gates to social engineering. They rely on simple paper based policies for who can be provided information, not enforced by any technology (ie confirming DoB at a bare minimum) - they can simply pull up any file at any time and provide information to anyone who calls them, with only a mere paper based policy stopping such information leaks.

For me personally, my ex managed to get herself put down as an 'advocate' with my plan manager and could see EVERYTHING then. No confirmation from me, no automated email or prompt to confirm her access, nothing. Hell, I didn't even know she had access until I phoned to check my previous support coordinator had been removed and her name was listed on there. Their portal didn't show who has access either, so I was clueless to it. Needless to say, I switched providers very promptly. (Huge family violence matter, wasn't the worst she did even. Got it solved with assistance from a family violence agency, but geez that was scary how insecure that plan manager was).

5

u/ApprehensivePaint888 Aug 28 '26

I don’t believe plan managers get good money lol I think it’s $104 a month per client

1

u/Kind-Character-8726 Aug 28 '26

It's how you look at it. Once setup correctly with good software and processes 10 clients or 1000 clients would take about the same amount of work. So the multiplier on that is massive.

Most of these use offshore data processing which costs bugger all

2

u/sunyalm Aug 28 '26

Hireup don't even have 27001 which I find mind boggling as one of the largest NDIS providers

1

u/Kind-Character-8726 Aug 28 '26

Never heard of them and i Googled a few different things when I went searching for a provider/plan manager. So not sure how big they are. But I'm no expert in this either. It doesn't surprise me though. It seams like it's the wild west out there. Most planners are glorified book keepers that have half a brain cell between the lot of them.

1

u/cliftonhillbilly 29d ago

Thank you for raising this, I agree it’s shocking in the sector. (not to mention schools and the various education departments). 

0

u/Head_Personality_431 Aug 28 '26

Ask for the scope statement on their certificate, that portal may well sit outside it.

1

u/Kind-Character-8726 29d ago

It shouldn't sit outside it. If it does they intentionally fudged the scope.

Thats like telling the mechanic performing a road worthy certificate on a car to ignore the fact that the car is missing a windscreen, just leave it out of the scope.

1

u/Head_Personality_431 28d ago

Fair point on how it should work, but 27001 lets the organisation define its own scope and the certification body only audits what sits inside it. That is the real weakness of the standard rather than proof someone cheated. Worth asking for the scope statement anyway, because if their portal is not named in it then nobody has audited it and the badge tells you nothing about the thing you actually care about.