82Admins, Treasurers, Presidents

Digital Security & Account Hygiene for Clubs — GoClubPro

Training Module 82 | Protecting Club Accounts, Member Data, and Financial Access


What This Guide Covers

Community sporting clubs are increasingly targeted by scammers, account takeovers, and phishing. A Club Admin or Treasurer account with financial-approval access is worth real money to an attacker. A breach can result in stolen club funds, exposed member data, and reputational damage. This guide covers practical security habits for everyone in the club — but especially for Admins and Treasurers who hold the most sensitive access.

Primary audience: Club Admins, Treasurers, Club Presidents Also useful for: All members (password security, phishing awareness)


SECTION 1: THE ACCOUNTS THAT MATTER MOST

High-Value Targets in a Club's Digital World

AccountAccess LevelWhy Attackers Want It
GoClubPro Club AdminFull member data, settings, fee configurationCan change payment routing, access member PII
GoClubPro Treasurer roleApproves/rejects pending payment declarations, adjusts wallet creditCan approve fraudulent declarations; manipulate wallet balances
Club email (shared@clubname.com.au)Password reset emails land hereWhoever owns the email can reset everything else
Google Drive (committee)Minutes, financial records, member dataSensitive documents; blackmail / data sale
Association portal (your league platform / SportsTG)Player registrations, club competition entryCan deregister players; disrupt season
Club bank (online banking)Club fundsDirect financial theft
Social media accountsPublic presence; member communicationReputational damage; fraudulent posts

The cascade attack: An attacker who gains access to your club email can request password resets for every other system. Protecting the email account is the highest-priority action.


Accounts to Audit Right Now

Run this audit at least once per season — ideally at committee handover:

  • Who has GoClubPro Admin role access? Are any former members still listed?
  • Who has the GoClubPro Treasurer role? Has last year's Treasurer been removed?
  • Who knows the shared club email password? Has a departed committee member been removed?
  • Who has access to the club Google Drive? Are permissions current?
  • Who has access to online banking? Bank signatories up to date?
  • Who has access to social media accounts?
  • Who has access to the association portal (your league platform / SportsTG)?

Rule of thumb: If someone left the committee more than 2 months ago and they still have access to any of the above — fix it today.


SECTION 2: PASSWORD AND AUTHENTICATION SECURITY

The Minimum Password Standard

Account TypeMinimum Standard
Club Admin / Treasurer (GoClubPro)Unique, 16+ character password; MFA enabled
Club emailUnique, 16+ character password; MFA enabled
Google DriveVia Google account — same as club email
Online bankingBank's own MFA (usually enforced); unique password
Social mediaUnique password; 2FA enabled

"Unique" means not shared with any other account. Reusing passwords means one breach compromises everything. Use a password manager (Bitwarden, 1Password, or the browser's built-in manager) to generate and store strong unique passwords.


Multi-Factor Authentication (MFA) in GoClubPro

MFA adds a second step to login — even if someone knows your password, they can't log in without your phone.

Enabling MFA:

  1. GoClubPro → Settings → Security (or your profile → Security Settings)
  2. Enable MFA → scan QR code with an authenticator app (Google Authenticator, Microsoft Authenticator, Authy)
  3. Save backup codes somewhere safe (not in the same email account)

Who must have MFA: At minimum — Club Admin and any Co-Admins. Recommended for all members, mandatory for anyone with Treasurer access.

See Module 15 (Security Settings) for the full MFA setup walkthrough.


Shared Accounts: The Biggest Club Security Risk

Many clubs have a "shared club login" — one email and password known to multiple people. This is a serious security risk:

Problems with shared logins:

  • You can't tell who did what (no audit trail)
  • When one person leaves, you have to change the password and notify everyone remaining
  • If one person is phished or their personal device is compromised, everyone's access is lost
  • MFA is impossible to use effectively with a shared account

Better approach:

  • Each committee member has their own GoClubPro account
  • Grant the appropriate role (Club Admin, Treasurer, etc.) to that individual account
  • When they leave: change their role in Admin Panel → Player (or remove entirely)
  • The "club" credentials should only be used for things like shared email addresses — not for platform logins

SECTION 3: PHISHING AND SOCIAL ENGINEERING

The Most Common Attack Vectors on Sports Clubs

1. Fake invoice emails An email arrives that looks like it's from a supplier or association, with an invoice attached or a link to "update payment details." The attacker hopes someone pays a fake invoice or transfers funds to the wrong bank account.

How to spot it:

  • Check the sender's actual email address (not the display name)
  • Hover over links before clicking — the URL should match the organisation
  • Call the supplier directly to confirm unexpected invoices

2. "Your account has been suspended" phishing Email claiming your GoClubPro or bank account is suspended and you must click a link to verify.

How to spot it:

  • GoClubPro will never ask for your password via email
  • Your bank will never ask you to enter banking details via an emailed link
  • Go directly to the website (type the URL) — don't click the email link

3. Committee impersonation ("CEO fraud") An email appearing to be from the President or Treasurer asks the Admin to urgently transfer money or change payment details.

How to spot it:

  • Urgent requests for financial action via email should always be confirmed by phone
  • Verify any request to change bank details by calling the requestor on a known number (not a number from the email)
  • Real emergencies don't punish you for taking 5 minutes to verify

What to Do If You Suspect a Phishing Attempt

  1. Do not click any links in the email
  2. Do not reply to the email
  3. Forward the email to your Club Admin and committee (so others are warned)
  4. If you think you might have clicked something: change your GoClubPro password immediately
  5. If financial details may have been compromised: contact your bank immediately
  6. Report to the Australian Cyber Security Centre: cyber.gov.au/report or 1300 CYBER1

SECTION 4: ACCESS MANAGEMENT LIFECYCLE

New Committee Member Onboarding

When a new committee member joins:

  1. They create their own GoClubPro account via the club join link
  2. Admin Panel → Members → change their role to the appropriate level (Club Admin, Co-Admin, etc.)
  3. Share Google Drive folder access for their role
  4. For Treasurers: grant online banking view access if reconciliation requires it (managed via your bank, not GoClubPro)
  5. For admins: share club email access if they need it (or create a forwarder)
  6. Brief them on this security guide

Offboarding a Departing Committee Member

When a committee member leaves:

Within 24 hours of departure:

  1. Admin Panel → Members → change their role to Player (removes admin and Treasurer access, including the ability to approve payment declarations)
  2. Revoke Google Drive folder sharing
  3. If they knew the club email password: change it now and inform remaining committee
  4. If they had bank signing authority: commence external bank process (takes longer — start immediately)
  5. Social media: remove them as an admin/manager if they had access

Never wait — access lingering post-departure is the most common source of security incidents in community organisations.


The "Hit by a Bus" Protocol

What happens if your only Club Admin becomes suddenly unavailable?

Prevention (do this now):

  • Always have at least two people with Club Admin access
  • At least one of those two people should not be the same person as the sole bank account signatory
  • The club email password should be known to at least two committee members
  • "Recovery admin" details (who to call if the primary admin is unavailable) are in the Admin Handover Guide (Module 36)

Recovery:

  • GoClubPro support can restore access to an account if proper identity verification is provided
  • Bank: if the sole signatory is unavailable, your bank's account recovery process can assist with identity-verified access restoration (this takes time — prevention is much better)

SECTION 5: MEMBER DATA SECURITY

What Member Data GoClubPro Holds

GoClubPro holds personal data including:

  • Full name, email, phone number
  • Date of birth (for age group verification)
  • Emergency contacts
  • Medical/injury notes
  • Payment history
  • For juniors: parental/guardian details

This is sensitive personal information. It must be treated with care.

Who can access what:

  • Club Admins: full member data
  • Coaches: squad members' contact details
  • Players: their own data only
  • Parents: their child's data

Preventing Inadvertent Data Exposure

Common inadvertent data exposures in sports clubs:

ScenarioRiskPrevention
Screenshot of member list shared to WhatsApp groupPersonal contact details exposedNever screenshot the Admin Panel
CSV export left on personal laptopData breach if laptop lost or stolenExport only when needed; delete after use
Broadcast to all members includes one member's personal situationPrivacy breachBroadcasts are never appropriate for individual member matters
Former admin still has access after leavingOngoing data access by non-committee personOffboard access within 24 hours
Club email auto-forwarding to a personal email no longer checkedData loss; potential data sharing with email providerRemove forwarding when committee member departs

Data Breach Response

If you suspect member data has been accessed without authorisation:

  1. Change all passwords for affected systems immediately
  2. Enable MFA if not already enabled
  3. Notify your Club Admin, President, and Treasurer
  4. Assess what data was potentially accessed (GoClubPro Admin can check activity logs)
  5. If personal data was accessed: you have an obligation to notify affected members under the Privacy Act (Module 33)
  6. If financial data was accessed: notify your bank; ask your Club Treasurer to review recent payment declarations and wallet balances for anomalies
  7. Report to the OAIC (Office of the Australian Information Commissioner) if the breach is likely to cause serious harm: oaic.gov.au

VISUAL: Security Posture Checklist

ACCOUNTS
 ☐ Each admin has their own account (no shared logins)
 ☐ MFA enabled for all Admins and Treasurers
 ☐ Departed committee members removed from all systems
 ☐ At least 2 people with Club Admin access

PASSWORDS
 ☐ Club Admin account: unique 16+ char password
 ☐ Treasurer account: unique 16+ char password + MFA
 ☐ Club email: unique 16+ char password + MFA
 ☐ Password manager in use (Bitwarden, 1Password)

PHISHING AWARENESS
 ☐ Committee briefed on fake invoice emails
 ☐ Financial requests verified by phone, not email
 ☐ Unknown links never clicked; go directly to URLs

DATA
 ☐ CSV exports deleted after use
 ☐ No screenshots of member data shared externally
 ☐ Google Drive access audited this season

RECOVERY
 ☐ At least 2 Admins; at least 2 people with bank signing authority
 ☐ Club email password known to 2 committee members
 ☐ Handover documentation exists (Module 36)

TOOLTIPS & HINTS

  • Club email is the master key — secure it first; everything else can be reset via email
  • MFA is non-negotiable for Admins — one compromised password without MFA = full club access for an attacker
  • Phone before paying — any unexpected financial request should be verified by phone on a known number
  • Offboard within 24 hours — every hour of lingering access after a committee departure is an unnecessary risk
  • No shared logins — individual accounts with individual roles is the only safe model

FAQ

Q: A former treasurer is refusing to hand over online banking access. What do we do? A: You don't need them to — the bank account belongs to the club entity, not the individual. Contact your bank with proof of your club's identity (ABN, incorporation certificate, current committee evidence from ASIC/Fair Trading) and request a signatory change. This is a known scenario; banks have a process for it. Their GoClubPro Treasurer role can simply be revoked immediately in Admin Panel → Members — no cooperation required for that part.

Q: Our club email is a personal Gmail (president@gmail.com). Is that a problem? A: Yes — when the President leaves, the club loses that email address and all the history, reset emails, and account links attached to it. Set up a club-owned email (e.g., admin@clubname.com.au via Google Workspace or similar) as soon as practical.

Q: We got an email claiming to be from GoClubPro saying our account will be suspended unless we verify our payment details. Is it real? A: Almost certainly phishing. GoClubPro will not ask you to verify payment details via a linked email. Go directly to the GoClubPro website by typing the URL — if there's a real issue with your account, it will be visible when you log in. Report the email to GoClubPro support (Module 38).

Q: How do we store the backup MFA codes safely? A: Print them and store them in your club's physical records (locked filing cabinet), or store them in a shared password manager vault. Never store them only in the same email account that MFA is protecting.


COMMON MISTAKES

MistakeConsequencePrevention
Shared club login (one email, multiple people)Unauditable access; MFA impossible; breach cascadeIndividual accounts; individual roles
No MFA on Admin accountPassword compromise = full access for attackerMFA mandatory for all Admins; enforce before next season
Former treasurer retains Treasurer role or bank accessUnauthorised financial access; potential theftOffboard GoClubPro and bank access within 24 hours of departure
Clicking links in unexpected "your account is suspended" emailsCredential theftGo directly to the URL; never click email links for login
Only one Club AdminSingle point of failureTwo Admins minimum at all times

SHORT ONBOARDING SCRIPT

"The two highest-priority security actions for any club: enable MFA on your Admin and Treasurer accounts, and remove departed committee members from all systems within 24 hours. The club email is the master key — whoever controls the email can reset everything else. Never share login credentials between multiple people; give each admin their own account with the right role. Verify any unexpected financial request by phone before acting. And run an access audit at the start of each season — it takes 20 minutes and can prevent a devastating breach."


MICRO-TRAINING QUICK TIPS

  • MFA on all Admins and Treasurers — no exceptions
  • Departed committee: remove from GoClubPro + online banking + Google Drive + social media within 24 hours
  • Unique passwords for every account; use a password manager
  • Unexpected financial request? Verify by phone before doing anything
  • At least 2 Admins and 2 people with bank signing authority at all times
  • Club email: club-owned address (not personal Gmail); MFA enabled
  • Data: no screenshots; CSV exports deleted after use; no broadcasts with individual member details

Training Module 82 | See also: 15 Security Settings · 36 Admin Handover Guide · 33 Data Privacy · 37 Payment Collection Today · 38 Help & Support