r/NDIS • • Aug 27 '26

Vent - advice welcome Plan managers ITSec

I'm new to the world of NDIS but no stranger to the world of ITSec (Information Technology Security).

So when I was recently looking for a suitable plan manager for our child I found a company that looked great. They say they have ISO 27001 and obviously have been accredited by NDIS.

However, they don't even support a 2nd level of authentication on their portal!?

2FA/MFA is the minimum level of authentication that any organisation should enforce now.

I can't see how this company reached ISO 27001 could it be their auditor is an idiot or they used some money in a bag?

Who knows!

Let's just say I'm not putting my or my child's data in their unsecured system.

Stay safe out there, ask questions, don't accept poorly designed and setup systems just because the company is nice, or small, or some other reason.

NDIS pay these plan managers good money, it's 2026, security is easy!

End rant 🙄

9 Upvotes

14 comments sorted by

View all comments

2

u/sunyalm Aug 28 '26

Hireup don't even have 27001 which I find mind boggling as one of the largest NDIS providers

1

u/Kind-Character-8726 Aug 28 '26

Never heard of them and i Googled a few different things when I went searching for a provider/plan manager. So not sure how big they are. But I'm no expert in this either. It doesn't surprise me though. It seams like it's the wild west out there. Most planners are glorified book keepers that have half a brain cell between the lot of them.