Estimated Reading Time: 7 minutes
Lead Consultant and Editor
The email came from someone I knew. It linked to a document I was expecting to receive. But the link looked bland and generic—the way examples of phishing scams look.
I was tired. I wanted to click, get the document and get on with my day.
I thought about the Take 9 campaign from Craig Newmark Philanthropies (“Take a 9-second pause and think before you click, download, share.”) OK, I thought, I can take 9 seconds.
When those 9 seconds were up, I knew I should dial the phone, just to check. So I did. I left my contact a voicemail. They responded right away, sounding surprised to hear from me but glad to confirm they sent the document.
Double-checking where that link came from cost my nonprofit zero money and very little time.
I might click a malicious link or attachment someday. Anyone might. But plenty of free or low-cost steps like the one above can help your team strengthen its cyberdefenses and make it more likely that you can consistently keep your nonprofit’s data safe.
Why Cybersecurity Matters
If you think your nonprofit doesn’t have any data cybercriminals would want, think again.
All nonprofits collect personally identifiable information. Your digital and paper files are likely full of phone numbers, email addresses, and physical addresses of clients, team members, volunteers, and more. Somewhere in your systems, you likely store even more sensitive information, like credit card numbers and bank account data. You may have demographic information about the ethnicity or gender of participants, volunteers, and staff.
Every piece of that information belongs to a person: a valued team member or client. That means your mission includes protecting those people’s data from misuse.
Common examples of cybersecurity breaches nonprofits experience include:
Start with Humans
How do you address the risks of those types of cyberattacks?
The human beings in your organization are its strongest and weakest link when it comes to cybersecurity. Your team members’ quick thinking could thwart an attack, while one seemingly small mistake could compromise your entire network and cost you millions of dollars. To fortify your cyberdefenses, it makes sense to start with your people.
If you don’t already send your team members phishing simulations, where a third party tests them on how they would respond to common social engineering scenarios, that’s a great place to start. Your IT provider may be able to provide these as part of your existing relationship, or you may be able to take advantage of these features in software like Microsoft Defender. You can also access free resources like KnowBe4’s option to send free phishing simulations to up to 100 users.
Some great cybersecurity practices to instill in your team:
Build on the Basics
Make sure your nonprofit has the basics in place on passwords and multifactor authentication to reinforce system security, too.
Multifactor authentication provides an extra layer of security for your organization’s accounts. At its simplest, multifactor authentication requires additional information beyond a login and password to access organizational systems—for example, a number entered from an authentication app. Multifactor authentication creates additional hurdles for outside actors to break into a system; they’d need not only your login and password, but also the authentication code.
Organizations should consider and address the potential for bias in multifactor authentication. Concerns about that have led some nonprofits to avoid authentication options that involve facial recognition. Of the major biometric authentication methods in use, facial recognition is the least accurate, raises extensive privacy concerns, and current implementation of the technology “involves significant racial bias, particularly against Black Americans,” according to Harvard.
Here are some additional steps to strengthen your cyberdefenses.
Update software, firewalls, and email filters regularly. I know—it seems like those update messages pop up every day. But taking a few minutes for updates can save hours, days, or weeks of headaches down the road. Software updates can patch vulnerabilities hackers could use to get into a product. They also help protect the personal information on your devices. Encourage your team members to set reminders to download updates when they step away from their computer for lunch or a break.
Remove old user accounts when staff or volunteers leave your organization. Make sure you revoke all their accesses to your systems, from email to shared drives. Create a standardized process for this, so team members aren’t scrambling every time someone leaves.
Standardize where you store files in your organization. Store documents in approved cloud software with access controls rather than local copies on personal devices.
Create tiered data access. Make sure that only employees who need to access specific data, especially sensitive data, have the ability to do so.
Restrict who can install software on organizational devices. Check that your process is simple and seamless. Don’t incentivize the action you’re trying to avoid: staff downloading software on their organization-issued laptops because it ‘takes too long’ to get help from the colleague assigned to help.
Set security standards and protocols for employees who access your organization’s computer system from home or on the road. Make these standards and protocols simple, jargon-free and easy to access.
Collect only the data you really need. Stop collecting data you can’t or won’t use! And follow a practical schedule and protocol for data deletion. If your organization doesn’t collect it, hackers can’t steal it (at least not from you!)
Cyberbreaches: Get Ready to Be Ready
The bad news: Your nonprofit could take all the above steps and still experience a data breach. Cybercriminals are persistent, and they constantly evolve their tactics, including using artificial intelligence to help infiltrate systems.
The good news: If you’ve taken the above steps, you’re likely to incur less damage in a breach. And if you take a little time now to prepare for what you would do in the event of a breach, that stressful time will be less painful. Here are some steps to help.
Identify now who your team will call if a cybersecurity breach occurs. Cyber insurance providers often have “breach coaches” who can lead an insurance response for nonprofits. Put your legal counsel on the list of people to call, along with any cybersecurity law or forensic experts your counsel recommends. Your list might also include your information technology and security vendors, operations, human resources, communications, and management.
Identify which systems and data are mission critical. What systems would render your organization inoperable if you didn’t have access to them? Make sure you have backups in place on those systems. This may happen automatically through your software programs. Double-check whether it does, and if not, make the necessary backup provisions.
Craft a contingency plan. What work could you do if your organization’s major digital systems were unavailable? Who would lead your response to a cyberbreach, and who is that person’s backup?
Keep Learning, Keep Preparing
If you’ve read this far, you know cybersecurity isn’t one and done. Like so many things in our nonprofit organizations, improving our cybersecurity is a journey. If you put some basic safeguards in place, create a plan to keep learning, and share and discuss what you learn, you’ll be well on your way to improved cyberhygiene.
Rachel Sams is Lead Consultant and Editor at the Nonprofit Risk Management Center. She is a firm believer in the power of the firewall update on a lunch break. Reach her with thoughts and questions about this article at rachel@nonprofitrisk.org or (505) 456-4045.
“One thing I love about the Risk Summit is the opportunity to connect and learn from other risk managers, nonprofit professionals, and NRMC staff. I have attended the Risk Summit multiple years and always look forward to connecting with returning attendees and meeting new people. The Risk Summit brings together a diverse and engaged set of professionals who are ready to learn, share, and connect.”
“I love the Risk Summit because I always learn something valuable, such as new approaches to the issues I’m grappling with. I always leave the Risk Summit with a notebook full of practical ideas. I also leave with an expanded network of professional acquaintances and a feeling it was the most useful conference I’ve been to in quite a while. I am in awe how such a topic as risk management can be artfully delivered.”
“One thing I love about the Risk Summit is the ability to see and feel the passion of nonprofit leaders as they learn and share together.”
“One thing I love about the Risk Summit is connecting and learning from / with really great people.”
“First let me congratulate you on a conference well done. I had a great time at the Nonprofit Employee Benefits Conference and walked away with some valuable tools and questions that we’ll need to be addressing in both the short and long term. Thanks to you and your staff for all you do to provide us with quality resources in support of our missions.”
“BBYO’s engagement of NRMC to conduct a risk assessment was one of the most valuable processes undertaken over the past five years. Numerous programmatic and procedural changes were recommended and have since been implemented. Additionally, dozens (literally) of insurance coverage gaps were identified that would never have been without the work of NRMC. This assessment led to a broker bidding process that resulted in BBYO’s selection of a new broker that we have been extremely satisfied with. I unconditionally recommend the Center for their consultative services.
“Melanie Herman has provided expert, insightful, timely and well resourced information to our Executive Team and Board of Directors. Our corporation recently experienced massive growth through merger and the Board has been working to better integrate their expanded set of roles and responsibilities. Melanie presented at our Annual Board of Director’s Retreat and captured the interest of our Board members. As a result of her excellent presentation the Board has engaged in focused review which is having immediate effects on governance.”
“The Nonprofit Risk Management Center has been an outstanding partner for us. They are attentive to our needs, and work hard to successfully meet our requests for information. Being an Affiliate member gave us access to so many time- and money-saving resources that it easily paid for itself! Nonprofit Risk Management Center is truly a valued partner of The Community Foundation of Elkhart County and we are continuously able to optimize staff time with the support given by their team.”
“The board and staff of the Prince George’s Child Resource Center are extremely pleased with the results of the risk assessment conducted by the Nonprofit Risk Management Center. A thorough scan revealed that while we are a well run organization, we had risks that we never imagined. We are grateful to know that we have now minimized our organizational risks and we recommend the Center to other nonprofits.”
Great American Insurance Group’s Specialty Human Services is committed to protecting those who improve your communities. The NRMC team has committed to delivering dynamic risk management solutions tailored to nonprofit organizations. These organizations have many and varied risk issues, hence the need for specialized coverage and expert knowledge for their protection. We’ve had Melanie speak on several occasions to employees and our agents. She is always on point and delivers such great value. Thank you for the terrific partnership and allowing our nonprofits to focus on their mission!
Subscribe to the Risk eNews today to expand your perspective and deepen your knowledge on key risk topics.
Plus, get a free download of our current Risk Insights report!