Download this club pack

S-116 · Theme 5

Cyber Safety Quick Guide

Use Cyber Safety Quick Guide to protect club systems and information through simple, shared security habits and a practiced response.

Where this idea came from

Playbook entry
S-116 · Cyber Safety Quick Guide
Theme
Theme 5: Digital, Data & Systems · Subtheme 8: Cybersecurity & Risk
Source material
Current playbook index title and category plus an internally authored detailed-guide draft

Initiative-specific development wave

How this draft was developed

These sources support general principles for digital, data and systems, accessibility, privacy, safety, systems or responsible governance; they are not an endorsement of Cyber Safety Quick Guide, a finding that it suits any club or approval of its local design.

Primary references consulted

  • Rotary Clubs (Rotary International)
    Used for: Rotary describes club participation through service, friendship, diversity, integrity and leadership, including online participation for people affected by schedules, mobility or distance.
  • Small business cyber security guide (Australian Signals Directorate's Australian Cyber Security Centre)
    Used for: A practical security baseline includes multi-factor authentication, software updates, regular tested backups and advice suited to the organisation's actual systems and risk.
  • Chapter 11: APP 11 Security of personal information (Office of the Australian Information Commissioner)
    Used for: Entities covered by the Privacy Act must take reasonable steps to protect personal information and destroy or de-identify it when it is no longer needed, subject to lawful retention requirements.
  • Quick reference guide for responding to data breaches (Office of the Australian Information Commissioner)
    Used for: Organisations should contain, assess and respond to suspected data breaches, determine applicable notification duties and review the event to reduce recurrence.

Candidate District material consulted

These records remain draft evidence and still need a human source decision.

  • Theme_4_All_80_Initiatives_Complete
    The exact current-title crosswalk establishes a candidate legacy record for later comparison. No legacy code, unsupported claim or unchecked operational detail was copied into this draft; current official privacy, security, accessibility and governance controls take precedence.

Theme 5 source-assurance wave

What has been checked

  • 4 current primary pages used by this guide were reopened on 9 August 2026.
  • 4 attributed source claim(s) were mapped to their bounded use in this initiative.
  • Candidate District material remains separate and does not establish this result.
See each source's scope and limit
  • Rotary Clubs
    Supports: Rotary club participation context and the value of accessible online or hybrid participation.
    Does not establish: Product configuration, legal compliance, local suitability or approval of a named initiative.
  • Small business cyber security guide
    Supports: A practical minimum cyber-security baseline for smaller organisations and volunteer-run systems.
    Does not establish: That the baseline is sufficient for a club's actual risk, system architecture, supplier arrangements or legal obligations.
  • Chapter 11: APP 11 Security of personal information
    Supports: Security, access, retention and disposal safeguards where the Privacy Act and APP 11 apply.
    Does not establish: That a club's controls are reasonable, that the Privacy Act applies or that a particular retention period is correct.
  • Quick reference guide for responding to data breaches
    Supports: A proportionate sequence for preparing for and responding to suspected personal-information breaches.
    Does not establish: Whether an incident is an eligible data breach, who must be notified or the club's legal duties in a specific event.

What still needs a person to confirm

  • Confirm which privacy, records, safeguarding and other legal duties apply to the club and this local design.
  • Confirm current ClubRunner or other platform features, permissions, licence settings and supplier instructions in the club's actual account.
  • Test accessibility and alternative participation routes with affected members rather than inferring conformance from the guide.
  • Confirm every local fact, starting point, measure, cost, owner and claim before the club decides to proceed.
  • Resolve any candidate District-source provenance and approval decision without treating the candidate as controlled authority.

The source-verification release gate remains closed.

Checks still on hold

Still an internal draft: source interpretation, local suitability, accessibility, governance and editorial approval remain open checks.

What could this idea change?

It protects trust by making safer system and information habits part of everyday club work.

It may suit: Members who use or look after club systems and information, including people who need extra help.

Could this work in our club?

  • Consider Cyber Safety Quick Guide when access, passwords, devices, backups or incident responsibilities are unclear.
  • A club where the club has a defined user need, accountable owner, current platform information, proportionate data plan and a safe way to test and reverse the change.
  • A club with a real need for practical cyber resilience and capacity to support a maintained club artefact with a defined user, owner, version, source of truth and review cycle.
  • A 90-day trial of Cyber Safety Quick Guide with a starting point, named participants, a resource ceiling and a scheduled continue, adapt or stop decision.

Before you start

  • A board-approved brief naming which accounts, devices, data and response capability the club will protect first, the local authority, people affected, fixed constraints, resource ceiling, decision date and stop conditions.
  • A starting-point record and participant plan suited to a maintained club artefact with a defined user, owner, version, source of truth and review cycle, with accessible information, voluntary choices and a supported alternative route where needed.
  • Named delivery, evidence and decision owners, including a person authorised to pause Cyber Safety Quick Guide when a safeguard, permission or boundary is not met.
  • A proportionate check of governing documents, privacy, information security, accessibility, conflicts, safeguarding, work health and safety, records, finance and referral duties for the actual local design.

At the end: At the 90-day review, compare the recorded measures with the starting point, resolve the listed governance holds and tell participants whether Cyber Safety Quick Guide will change, continue or stop.

Made for this initiative

Tailored supporting documents

These working documents use the decisions, safeguards and evidence needs of this initiative. Complete them with the people affected and keep the agreed version with the club's project record.

01

Cyber Safety Quick Guide User Need and System Boundary Brief

Define the user problem, information flow and excluded uses.

Open supporting document
02

Cyber Safety Quick Guide Data Inventory and Purpose Map

Link every field and transfer to a necessary purpose.

Open supporting document
03

Cyber Safety Quick Guide Privacy, Consent and Notice Check

Make information handling and choices clear before collection or publication.

Open supporting document
04

Cyber Safety Quick Guide Access and Permission Matrix

Apply least privilege and accountable access reviews.

Open supporting document
05

Cyber Safety Quick Guide Accessible User Test Script

Test the real task with varied users and alternatives.

Open supporting document
06

Cyber Safety Quick Guide Configuration and Change Register

Maintain a reviewable record of settings, integrations and releases.

Open supporting document
07

Cyber Safety Quick Guide Incident, Exception and Recovery Card

Give volunteers a safe response route when the workflow fails or data is exposed.

Open supporting document
08

Cyber Safety Quick Guide Handover, Backup and Maintenance Plan

Keep the service operable beyond one volunteer.

Open supporting document
09

Cyber Safety Quick Guide Cybersecurity & Risk Delivery Check

Test whether Cyber Safety Quick Guide genuinely advances practical cyber resilience within the subtheme boundary.

Open supporting document
10

Cyber Safety Quick Guide System Ownership and Version Register

Keep the artefact current, findable, controlled and maintainable.

Open supporting document
11

Cyber Safety Quick Guide Evidence, Decision and Close-Out Record

Bring the evidence, limitations, participant response and final decision for Cyber Safety Quick Guide into one accountable record.

Open supporting document

Before your club says yes

Does the idea fit?

Talk with the people it is meant to serve and check that the need is real.

Who can say yes?

Name the person or group that can approve the work, spending and any safety arrangements.

Are people protected?

Check privacy, consent and safety. Collect only the information you genuinely need.

Can everyone take part?

Check the language, format, place, technology and cost for barriers.

Are the facts and permissions right?

Check names, claims, images, quotations, partner references and Rotary branding.

How will we learn?

Note where things stand now, check in at 30, 60 and 90 days, and decide what to do next.

Worksheets for your club

Open them online, print them or change them to suit the way your club works.

01

Safety and approval check

Use this worksheet to notice problems early, make the idea safer and know who needs to say yes or help.

Open worksheet
02

Access register

Use this worksheet to map each step and keep only the information the club genuinely needs.

Open worksheet