Cyber security awareness training for pet care and boarding businesses

Build cyber security awareness training for pet care and boarding businesses, covering customer data, pickup changes, shared devices and phishing.

Pet care and boarding businesses run on trust, time and detailed customer instructions. A booking can include an owner’s name and phone number, a pet’s medical or medication information, emergency contacts, access instructions, payment history and sometimes a key, alarm code or home address. Staff work across reception desks, kennels, grooming rooms, vehicles and shared tablets. Cyber security awareness training for pet care and boarding businesses must therefore protect both customer information and the operational decisions that keep animals safe.

This guide turns those decisions into a practical, role-based programme for Australian pet sitters, boarding facilities, day-care operators, groomers and mixed-service businesses.

TL;DR

Why this sector needs its own training plan

Pet care teams are often busy when a security decision arrives. A customer may be boarding a pet, a carer may be cleaning a room, a groomer may be moving between appointments and the owner may be answering suppliers after hours. An attacker can exploit that context with a message that appears to solve an immediate problem: “The owner changed their number,” “Please send the medication record here,” “The bank account has changed,” or “Use this link to confirm the booking.”

The systems are also interconnected. A compromise of the booking account can expose customer contacts and schedules. A compromise of the social account can damage trust and redirect new customers. A compromised mailbox can be used to request payments from suppliers or send false instructions about a pet. Staff need to recognise the human decision inside each technical event.

The NIST small-business cybersecurity guidance gives a useful baseline for small operators: identify important information and systems, protect access, detect unusual activity, respond to incidents and recover. The training plan below makes those actions specific to pet care work.

What should be in scope

Map the information and access that could harm a customer, a pet or the business if it were exposed or changed:

The OAIC guidance for small business is a useful reference for deciding what personal information is held, why it is needed, who can access it and how it should be protected. A pet’s details are not a substitute for a privacy review: owner and emergency-contact information can still be personal information, and operational details such as a home address or access code deserve careful handling.

Use a cyber security gap assessment to map the most important systems, owners and missing controls. Keep the assessment connected to real tasks such as pickup authorisation, medication handover and refund approval.

Role-based training

Reception and booking staff

Reception staff manage identity, payments, schedules and customer questions. Their training should include:

The correct workflow should be clear: use the existing customer record, confirm through a trusted contact method and record the verification. Do not accept a new phone number, email address or payment account from an unverified message just because the request sounds like the owner.

Pet carers, groomers and walkers

These staff may have no formal IT role but can receive sensitive instructions and use mobile devices. Teach them how to lock screens, use approved apps, report lost devices and avoid moving customer data into personal chats. A scenario might involve a fake manager asking for a key code, a supposed owner asking for a pet’s medical note or a link to a new roster.

Make the safe response fit the workday. If a carer is in a kennel, the instruction should be to pause the request, call the front desk using the saved business number and report the message when the animal-care task is safe. Never pressure a person to act on a suspicious request while they are responsible for an animal.

Drivers and pickup teams

Pickup and transport staff need a short mobile path covering identity checks, route information, customer addresses, phone security and lost-device reporting. Practise what happens when a person at a pickup location claims the booking has changed or asks the driver to send a photo of a key or access point.

Use the minimum necessary information. A driver may need a route and pickup confirmation, not the full customer history or every note about a pet. Limit access by role and remove it when the person stops doing transport work.

Owners, managers and administrators

Owners control payment, social, website and booking accounts. Their training should cover a password manager, MFA, administrator separation, supplier verification, backup access and incident decisions. A request to change the bank account for food, veterinary or cleaning invoices should be confirmed independently before payment.

Managers also need to model good behaviour. They should not ask staff to send records through a personal account, share an MFA code or bypass pickup verification because the business is busy. If a real emergency requires an exception, document who approved it and restore the normal process afterward.

Contractors and casual staff

Include temporary carers, freelance groomers, bookkeepers, web providers and platform administrators. Give each person a named account, limited access and an end date. Keep a simple leaver checklist: remove the account, recover keys or devices, revoke shared links and confirm that customer information is not retained in personal storage.

The scenarios worth practising

Build training around these events:

  1. Fake owner request: someone asks for a pet’s medical or behavioural record from a new email address.
  2. Pickup change: a person claims another individual will collect the pet and asks staff to update the booking immediately.
  3. Medication alteration: a message requests a change to medication or feeding instructions without a verified source.
  4. Payment redirection: a supplier sends new bank details or asks for an urgent invoice payment.
  5. Refund impersonation: a customer asks staff to refund to a different account or to bypass the normal check.
  6. Roster link: a fake manager sends a document or login page for the next week’s schedule.
  7. Access-code request: a message asks for a home address, key location or alarm code.
  8. Social account takeover: an administrator receives a request to connect an unfamiliar application or “verify” the business page.
  9. Lost tablet: a shared device containing customer contacts or pet notes disappears after a shift.

The Scamwatch business email compromise guidance is directly relevant to supplier and invoice scenarios. Its practical lesson is to verify payment changes through a contact method already held by the business, not the details supplied in the request.

The safe response

Use a five-step instruction that staff can remember during a busy shift:

  1. Stop the request: do not click, upload, pay, disclose or change the record.
  2. Check the existing record: compare the request with the authorised contact, booking and role.
  3. Verify independently: call a saved number, speak to the manager in person or use the approved portal.
  4. Report discreetly: send the message and context to the nominated owner or security contact.
  5. Document the outcome: record what was changed, what was not changed and what follow-up is required.

If the request relates to medication, an emergency contact or pickup authorisation, the operational owner should decide how to keep the pet safe while verification is completed. Security should never be used as a reason to ignore a genuine animal-welfare issue; it should make the emergency process clear enough that staff can act safely without improvising.

Shared tablets, cameras and mobile devices

Pet care businesses often use shared devices. Set rules for:

Keep the policy realistic. If staff need to photograph a pet for a customer update, provide an approved method. If the booking system is unavailable, define the temporary paper or phone process and how records are reconciled later. An impossible policy creates workarounds.

Phishing simulations for pet-care teams

Start with a safe fake roster or booking notification. The goal is to teach people to inspect the sender, avoid unfamiliar logins and use the reporting route. Follow with a supplier invoice or social-account scenario for the people who manage those systems.

The phishing simulation workflow can support recurring practice and follow-up learning. Do not create a message that could cause staff to cancel a real booking, change medication or ignore a real customer. Use synthetic records, safe destinations and a clear explanation after the exercise.

Measure whether people report the simulation, ask for verification and use the approved route. A click can identify a training need, but a good programme also checks whether the business process made the safe choice possible.

Privacy and information handling

Teach the minimum-necessary rule:

This is not about making carers legal experts. It is about giving them one safe default and one clear escalation path.

A practical 30-60-90 day rollout

Days 1–30: map the information and access

List the booking, payment, messaging, social, accounting and device environment. Identify who can change pickup details, release records, issue refunds, access customer addresses and approve supplier payments. Deliver a baseline lesson and test the lost-device route.

Days 31–60: train by decision

Give reception, carers, drivers, managers and contractors different short scenarios. Run a safe roster or booking phishing exercise. Fix shared-account, old-user and unapproved-storage issues found during the training.

Days 61–90: repeat and evidence

Run a comparable exercise, review reporting by role and close overdue training. Document content versions, assignments, results, incidents, access reviews and process changes. Add a new scenario whenever the business adds a service, platform or supplier.

What to measure

Track:

Human risk reporting can combine training, quiz and phishing signals into an operational view. Use it to prioritise coaching and technical fixes, not to create a permanent label for a carer or receptionist.

Common mistakes

Training only the person at reception

The highest-risk request may reach a driver, groomer, owner or contractor first. Include anyone who can access records, devices, keys, payments or customer communication.

Treating a pet’s record as harmless

The pet record can include the owner’s identity, address, contact details and access information. Limit it to the people who need it and keep it in approved systems.

Leaving old accounts active

Casual staff and contractors change frequently. Make access removal part of the shift or engagement closeout, not an annual project.

Making emergency work impossible

A safe process must cover urgent animal-care situations. Define the emergency contact and escalation route so staff do not bypass verification simply because the business is under pressure.

Using one phishing test as the programme

A single click-rate report does not show whether staff can verify a pickup change, spot a fake invoice or report a lost tablet. Practise the decisions that matter.

FAQ

What should cyber security awareness training for pet care businesses include?

Cover phishing, payment redirection, booking and pickup changes, pet and owner information, medication instructions, shared tablets, social-account security, lost devices and incident reporting. Assign extra content to managers, reception, drivers and contractors based on access.

How should staff verify a change to a pet booking?

Use the existing customer record and an independently held contact method. Do not rely on a new email address, caller ID or a link supplied in the request. If the change affects pickup, medication or emergency contacts, escalate it before updating the record.

Can pet carers use personal messaging apps?

Only when the business has approved the app, audience, information type and retention process. Keep full owner details, medical notes, access codes and payment information in the approved business system instead of informal chats.

How can a small boarding business protect shared tablets?

Use named accounts where possible, screen locks, MFA for cloud services, automatic updates, minimal access and a rapid lost-device process. Review which records the tablet can access and remove access when the device or user leaves the business.

What should happen after a supplier sends new bank details?

Pause payment and verify the change using a phone number or portal already held by the business. The Scamwatch guidance highlights payment-redirection risk, so treat the request as high impact even when the sender name is familiar.

How often should pet-care teams practise phishing reporting?

Use recurring, low-risk practice that fits the team’s workload. Change the scenario across booking, roster, supplier and account-recovery workflows, then compare reporting and verification behaviour over time.

Can training protect a business if its booking provider is breached?

Training cannot prevent every supplier incident, but it can reduce secondary harm by teaching staff not to trust unexpected recovery requests, new links or urgent instructions. Keep vendor contacts and account-recovery steps documented outside the compromised channel.

One last thing

The security question in pet care is rarely “Can this person spot a sophisticated attack?” It is “Will this person pause before changing a pickup, sending a record, sharing an access code or paying an invoice?” Build that pause into the workflow, give staff a known way to verify and report, and protect both the business and the animals in its care.

Related guides

Sources

Ready to deploy

Same playbook.
Your brand.

Cyber Aware's Human Risk Score works the same way for every MSP partner - under your brand, on your cadence.