
3 Sept 2026
Hidden Vulnerabilities: Cyber Security and Essential Community Services in NSW
By WorkVentures and commissioned by the NSW Council of Social Service (NCOSS)
This report looks at cyber security in NSW's not-for-profit social service sector. Written by WorkVentures for NCOSS, it assesses 14 organisations and finds none reached a mature standard, scoring an average of 57 out of 100. It sets out why the gap matters and what could close it.
View resourceSummary
This report, developed by WorkVentures and commissioned by the NSW Council of Social Service (NCOSS), examines cyber security across 14 not-for-profit organisations in the NSW community services sector. It was funded through the NSW State Peaks Program and the Australian Government Department of Industry, Science and Resources.
Each organisation was scored across four areas: operational practices, legal and regulatory compliance, systems, and network controls. None reached the benchmark for a mature cyber security posture, with an average score of 57 out of 100. The report points to common gaps, including weak password habits, low uptake of staff training, and a heavy reliance on cyber insurance and IT providers rather than active prevention. Smaller, lower-revenue organisations tended to score worse.
It highlights the real risks facing services that hold sensitive data, such as domestic violence and disability support, and recommends targeted government funding, a tailored cyber assessment and uplift program, and a national cyber security standard built for the sector. It's most useful for NFP leaders, board members and funders looking to strengthen digital security across community services.

We’d love to hear from you!
Reach out to one of our team members, and share input and ideas about how we can evolve Understorey.
Get in touch