Pet care and boarding businesses run on trust, time and detailed customer instructions. A booking can include an owner’s name and phone number, a pet’s medical or medication information, emergency contacts, access instructions, payment history and sometimes a key, alarm code or home address. Staff work across reception desks, kennels, grooming rooms, vehicles and shared tablets. Cyber security awareness training for pet care and boarding businesses must therefore protect both customer information and the operational decisions that keep animals safe.
This guide turns those decisions into a practical, role-based programme for Australian pet sitters, boarding facilities, day-care operators, groomers and mixed-service businesses.
TL;DR
- Train reception, carers, groomers, drivers, owners, contractors and temporary staff against their actual access.
- Practise booking changes, medication instructions, emergency contacts, refunds, supplier invoices and account recovery.
- Never rely on a familiar name, profile photo or urgent message as proof of identity.
- Keep pet and owner information in approved systems, not personal photo libraries or unprotected group chats.
- Use named accounts, MFA, screen locks and a fast lost-device process on shared and mobile devices.
- Measure reporting, verification and safe handover behaviour as well as course completion.
Why this sector needs its own training plan
Pet care teams are often busy when a security decision arrives. A customer may be boarding a pet, a carer may be cleaning a room, a groomer may be moving between appointments and the owner may be answering suppliers after hours. An attacker can exploit that context with a message that appears to solve an immediate problem: “The owner changed their number,” “Please send the medication record here,” “The bank account has changed,” or “Use this link to confirm the booking.”
The systems are also interconnected. A compromise of the booking account can expose customer contacts and schedules. A compromise of the social account can damage trust and redirect new customers. A compromised mailbox can be used to request payments from suppliers or send false instructions about a pet. Staff need to recognise the human decision inside each technical event.
The NIST small-business cybersecurity guidance gives a useful baseline for small operators: identify important information and systems, protect access, detect unusual activity, respond to incidents and recover. The training plan below makes those actions specific to pet care work.
What should be in scope
Map the information and access that could harm a customer, a pet or the business if it were exposed or changed:
- Booking, point-of-sale, payment, refund and customer-management systems.
- Owner names, phone numbers, addresses, emergency contacts and communication preferences.
- Pet profiles, vaccination evidence, medication schedules, allergies, behavioural notes and veterinary contacts.
- Home-access instructions, key registers, alarm details and transport or pickup arrangements.
- Shared tablets, reception computers, staff phones, cameras and cloud storage.
- Email, SMS, social media, online reviews, advertising and website administration.
- Payroll, accounting, insurance, suppliers, food orders and veterinary service accounts.
- External groomers, walkers, cleaners, transport providers and booking-platform support.
The OAIC guidance for small business is a useful reference for deciding what personal information is held, why it is needed, who can access it and how it should be protected. A pet’s details are not a substitute for a privacy review: owner and emergency-contact information can still be personal information, and operational details such as a home address or access code deserve careful handling.
Use a cyber security gap assessment to map the most important systems, owners and missing controls. Keep the assessment connected to real tasks such as pickup authorisation, medication handover and refund approval.
Role-based training
Reception and booking staff
Reception staff manage identity, payments, schedules and customer questions. Their training should include:
- Verifying who is authorised to collect or change a booking.
- Handling requests to send vaccination, medication or behavioural records.
- Recognising fake refund, cancellation and payment-redirection requests.
- Checking a new portal or attachment before uploading a pet or owner record.
- Escalating a request to change an emergency contact or pickup person.
- Protecting the screen and desk when customer information is visible.
The correct workflow should be clear: use the existing customer record, confirm through a trusted contact method and record the verification. Do not accept a new phone number, email address or payment account from an unverified message just because the request sounds like the owner.
Pet carers, groomers and walkers
These staff may have no formal IT role but can receive sensitive instructions and use mobile devices. Teach them how to lock screens, use approved apps, report lost devices and avoid moving customer data into personal chats. A scenario might involve a fake manager asking for a key code, a supposed owner asking for a pet’s medical note or a link to a new roster.
Make the safe response fit the workday. If a carer is in a kennel, the instruction should be to pause the request, call the front desk using the saved business number and report the message when the animal-care task is safe. Never pressure a person to act on a suspicious request while they are responsible for an animal.
Drivers and pickup teams
Pickup and transport staff need a short mobile path covering identity checks, route information, customer addresses, phone security and lost-device reporting. Practise what happens when a person at a pickup location claims the booking has changed or asks the driver to send a photo of a key or access point.
Use the minimum necessary information. A driver may need a route and pickup confirmation, not the full customer history or every note about a pet. Limit access by role and remove it when the person stops doing transport work.
Owners, managers and administrators
Owners control payment, social, website and booking accounts. Their training should cover a password manager, MFA, administrator separation, supplier verification, backup access and incident decisions. A request to change the bank account for food, veterinary or cleaning invoices should be confirmed independently before payment.
Managers also need to model good behaviour. They should not ask staff to send records through a personal account, share an MFA code or bypass pickup verification because the business is busy. If a real emergency requires an exception, document who approved it and restore the normal process afterward.
Contractors and casual staff
Include temporary carers, freelance groomers, bookkeepers, web providers and platform administrators. Give each person a named account, limited access and an end date. Keep a simple leaver checklist: remove the account, recover keys or devices, revoke shared links and confirm that customer information is not retained in personal storage.
The scenarios worth practising
Build training around these events:
- Fake owner request: someone asks for a pet’s medical or behavioural record from a new email address.
- Pickup change: a person claims another individual will collect the pet and asks staff to update the booking immediately.
- Medication alteration: a message requests a change to medication or feeding instructions without a verified source.
- Payment redirection: a supplier sends new bank details or asks for an urgent invoice payment.
- Refund impersonation: a customer asks staff to refund to a different account or to bypass the normal check.
- Roster link: a fake manager sends a document or login page for the next week’s schedule.
- Access-code request: a message asks for a home address, key location or alarm code.
- Social account takeover: an administrator receives a request to connect an unfamiliar application or “verify” the business page.
- Lost tablet: a shared device containing customer contacts or pet notes disappears after a shift.
The Scamwatch business email compromise guidance is directly relevant to supplier and invoice scenarios. Its practical lesson is to verify payment changes through a contact method already held by the business, not the details supplied in the request.
The safe response
Use a five-step instruction that staff can remember during a busy shift:
- Stop the request: do not click, upload, pay, disclose or change the record.
- Check the existing record: compare the request with the authorised contact, booking and role.
- Verify independently: call a saved number, speak to the manager in person or use the approved portal.
- Report discreetly: send the message and context to the nominated owner or security contact.
- Document the outcome: record what was changed, what was not changed and what follow-up is required.
If the request relates to medication, an emergency contact or pickup authorisation, the operational owner should decide how to keep the pet safe while verification is completed. Security should never be used as a reason to ignore a genuine animal-welfare issue; it should make the emergency process clear enough that staff can act safely without improvising.
Shared tablets, cameras and mobile devices
Pet care businesses often use shared devices. Set rules for:
- Named user access where the system supports it, rather than one permanent shared password.
- Automatic screen locking and MFA for cloud accounts.
- No customer or pet records in personal photo libraries.
- No access codes or full addresses in unprotected group chats.
- Approved camera storage and a defined deletion schedule.
- Updates, antivirus or device protection appropriate to the operating system.
- Immediate reporting for lost devices, suspicious pop-ups or unexpected login prompts.
- Access removal when a shift worker or contractor leaves.
Keep the policy realistic. If staff need to photograph a pet for a customer update, provide an approved method. If the booking system is unavailable, define the temporary paper or phone process and how records are reconciled later. An impossible policy creates workarounds.
Phishing simulations for pet-care teams
Start with a safe fake roster or booking notification. The goal is to teach people to inspect the sender, avoid unfamiliar logins and use the reporting route. Follow with a supplier invoice or social-account scenario for the people who manage those systems.
The phishing simulation workflow can support recurring practice and follow-up learning. Do not create a message that could cause staff to cancel a real booking, change medication or ignore a real customer. Use synthetic records, safe destinations and a clear explanation after the exercise.
Measure whether people report the simulation, ask for verification and use the approved route. A click can identify a training need, but a good programme also checks whether the business process made the safe choice possible.
Privacy and information handling
Teach the minimum-necessary rule:
- Share only the information needed for the task.
- Use the approved system and audience.
- Confirm who is authorised before releasing a pet record or pickup detail.
- Keep medical and behavioural notes out of casual social or staff channels.
- Do not reuse a customer’s contact details for marketing without the approved basis and process.
- Dispose of printed forms, labels and notes securely.
- Report misdirected emails, exposed spreadsheets and lost paperwork quickly.
This is not about making carers legal experts. It is about giving them one safe default and one clear escalation path.
A practical 30-60-90 day rollout
Days 1–30: map the information and access
List the booking, payment, messaging, social, accounting and device environment. Identify who can change pickup details, release records, issue refunds, access customer addresses and approve supplier payments. Deliver a baseline lesson and test the lost-device route.
Days 31–60: train by decision
Give reception, carers, drivers, managers and contractors different short scenarios. Run a safe roster or booking phishing exercise. Fix shared-account, old-user and unapproved-storage issues found during the training.
Days 61–90: repeat and evidence
Run a comparable exercise, review reporting by role and close overdue training. Document content versions, assignments, results, incidents, access reviews and process changes. Add a new scenario whenever the business adds a service, platform or supplier.
What to measure
Track:
- Completion by role, site and due date.
- Overdue work and unresolved leaver access.
- Phishing report rate, click rate and time to report.
- Payment-change requests independently verified.
- Pickup or record-change requests escalated before action.
- Lost-device reports and time to revoke access.
- Repeated questions that show the workflow needs improvement.
Human risk reporting can combine training, quiz and phishing signals into an operational view. Use it to prioritise coaching and technical fixes, not to create a permanent label for a carer or receptionist.
Common mistakes
Training only the person at reception
The highest-risk request may reach a driver, groomer, owner or contractor first. Include anyone who can access records, devices, keys, payments or customer communication.
Treating a pet’s record as harmless
The pet record can include the owner’s identity, address, contact details and access information. Limit it to the people who need it and keep it in approved systems.
Leaving old accounts active
Casual staff and contractors change frequently. Make access removal part of the shift or engagement closeout, not an annual project.
Making emergency work impossible
A safe process must cover urgent animal-care situations. Define the emergency contact and escalation route so staff do not bypass verification simply because the business is under pressure.
Using one phishing test as the programme
A single click-rate report does not show whether staff can verify a pickup change, spot a fake invoice or report a lost tablet. Practise the decisions that matter.
FAQ
What should cyber security awareness training for pet care businesses include?
Cover phishing, payment redirection, booking and pickup changes, pet and owner information, medication instructions, shared tablets, social-account security, lost devices and incident reporting. Assign extra content to managers, reception, drivers and contractors based on access.
How should staff verify a change to a pet booking?
Use the existing customer record and an independently held contact method. Do not rely on a new email address, caller ID or a link supplied in the request. If the change affects pickup, medication or emergency contacts, escalate it before updating the record.
Can pet carers use personal messaging apps?
Only when the business has approved the app, audience, information type and retention process. Keep full owner details, medical notes, access codes and payment information in the approved business system instead of informal chats.
How can a small boarding business protect shared tablets?
Use named accounts where possible, screen locks, MFA for cloud services, automatic updates, minimal access and a rapid lost-device process. Review which records the tablet can access and remove access when the device or user leaves the business.
What should happen after a supplier sends new bank details?
Pause payment and verify the change using a phone number or portal already held by the business. The Scamwatch guidance highlights payment-redirection risk, so treat the request as high impact even when the sender name is familiar.
How often should pet-care teams practise phishing reporting?
Use recurring, low-risk practice that fits the team’s workload. Change the scenario across booking, roster, supplier and account-recovery workflows, then compare reporting and verification behaviour over time.
Can training protect a business if its booking provider is breached?
Training cannot prevent every supplier incident, but it can reduce secondary harm by teaching staff not to trust unexpected recovery requests, new links or urgent instructions. Keep vendor contacts and account-recovery steps documented outside the compromised channel.
One last thing
The security question in pet care is rarely “Can this person spot a sophisticated attack?” It is “Will this person pause before changing a pickup, sending a record, sharing an access code or paying an invoice?” Build that pause into the workflow, give staff a known way to verify and report, and protect both the business and the animals in its care.
Related guides
Sources
- NIST Cybersecurity for Small Business, National Institute of Standards and Technology.
- Small business, Office of the Australian Information Commissioner.
- Business email compromise scams, Scamwatch.
- NIST SP 800-50 Rev. 1: Building a Cybersecurity and Privacy Learning Program, National Institute of Standards and Technology.