Cyber Security Action Month 2026: Why taking a second matters in early childhood education

Educators and providers rely on digital systems to communicate with families, document children’s learning and run their services. This October, Cyber Security Action Month is a reminder that protecting those systems starts with the decisions people make each day.
A message appears to come from a parent asking for an urgent change to their child’s collection arrangements. An email asks a service manager to approve a payment. A tablet used for learning documentation prompts an educator to sign in again.
Each request may take only a moment to answer. That moment is also an opportunity to pause and check.
The theme of Cyber Security Action Month 2026, “Take a second. Stay secure.”, encourages Australians to make safer choices before clicking links, sharing information or responding to unexpected requests.
For early childhood education and care (ECEC) services, the message has particular weight. Digital platforms can hold children’s images and learning records, family contact details, medical information, attendance records and staff information. They also support everyday tasks, from rostering and enrolments to communicating with families.
A suspicious message in this setting is more than an inconvenience. Acting on it could expose sensitive information or disrupt a service’s ability to communicate and operate.
Cybercriminals often create a sense of urgency. A message might claim that an account is about to be locked, a payment has failed or a family’s details need to be updated immediately. It may use a familiar name or logo.
If a request is unexpected, educators and service leaders can take a second to verify it through an established channel. That might mean opening a platform directly instead of following an email link, calling a family using the number already held in the service’s records, or checking a payment request with a colleague through a known contact method.
The eSafety Commissioner’s guidance on spotting online scams outlines warning signs and steps to take if information has already been shared.
Cyber security is easier to sustain when staff know what to do with the devices and accounts they use at work.
Services can review who has access to family communication platforms, enrolment records and administrative systems, including whether former staff members still have access. They can enable multi-factor authentication where available, keep devices and apps updated, and make sure staff know how to report a suspicious message or an unfamiliar sign-in request.
It is also worth checking what information each app can access and whether staff understand the service’s process for sharing documents and images. The eSafety Commissioner’s guide to managing digital safety settings provides a practical starting point.
For ECEC providers, device security also sits alongside child safety requirements. ACECQA’s guidance on digital devices in centre-based services explains the rules that commenced on 27 February 2026, including restrictions on personal devices when working directly with children and requirements concerning devices used to capture, store or transmit children’s images. Providers must ensure service-supplied devices are configured in line with relevant child safety and device security policies and procedures.
These requirements give services another reason to look closely at how their digital policies work in practice: which devices educators use, who can access the content on them, and what happens when a device is lost or a staff member leaves.
Children’s and families’ information is routinely collected so services can provide safe, responsive care. That makes careful handling essential.
Before sending a record or image, staff can check the recipient and consider whether the information needs to be shared. Providers can review account permissions, storage arrangements and their process for responding if information is sent to the wrong person or an account is compromised.
Encryption can help protect information when it is stored or sent, but it does not remove the need to check who can access it or who will receive it. The eSafety Commissioner’s encryption guide explains the technology in everyday terms.
The Australian Signals Directorate’s Cyber Action Year 2026 also calls on organisations to turn awareness into sustained action, including preparing for cyber incidents. For an ECEC provider, a useful starting point is to ask: if a key account became unavailable or information was exposed today, who would staff tell, how would the service continue operating, and how would affected families be supported?
No service needs to address every cyber security risk in one month. Checking access to one platform, updating service devices or walking staff through how to report a suspicious request are practical steps that can become part of the routine.
Take a second. Stay secure.

















