As more nonprofit employees work from home, scammers can seize this time of crisis to manipulate your technology to target your donors and your team.
With the COVID-19 crisis putting tremendous pressure on nonprofits to adapt and respond across multiple fronts – and fast – now is not the time to tackle complex and expensive technical rollouts. However, from team use of security settings, to strategic switches from analog to digital processes, to heightened vigilance when sending and receiving email, there are many opportunities for nonprofits to close the worst of the security gaps.
The best safeguards against cyberattack lie at the intersection of your technology and your team. All efforts should start with educating all staff members about potential risks, creating shared ownership of the both the problems and the solutions.
Here are a few ways to prevent or foil cyberattacks proactively—as a team. As Stanford University nonprofit data security expert Lucy Bernholz says: "Tools matter. People matter more."
When receiving email, caution is always warranted, especially with messages from unknown or unexpected sources. Common ploys include relying on fear-inducing subject lines—think “New Coronavirus Cases Confirmed in Your City”—from sources claiming to be reputable government agencies. Emails asking for “urgent donations” of any kind, which may include detailed wire instructions, are also highly suspect. But even more benign requests for the recipient to click a link or share detailed information should always be viewed with caution.
Employees should also use caution when sending email, whether to internal or external audiences. Some sites purporting to provide COVID-19 news updates can contain malware and adware. When possible, it’s better not to attach documents to external emails, as this is a common phishing ploy. Instead, your employees can direct recipients to trusted login portals to obtain information.
The shift to working from home means many organizations are considering shifts to digital tools to help with day-to-day necessities, like tracking grants or donor activity.
If you haven’t already, it’s worth considering where your organization can switch to all-digital: How about replacing check handling with electronic funds transfer? Or leveraging grant tracking tools instead of spreadsheets? Tools such as Quicken, Salesforce, Zoom or Skype are just some of the options in this space, and good examples of where to start.
Then, consider how your new and existing digital toolsets protect your organization’s data. Can the team quickly place hands on the organization’s existing vendor contracts to review terms of use? Is the entire team using the latest version of the tool itself? Are there administrative defaults that can be imposed to increase protective integrity?
These tools typically provide protective capabilities such as data encryption, workflow and usage tracking. One great first step to creating a team culture with a secure mindset: host a meeting where your team navigates together to the security features already existing on your digital tools – then switch them on as a group.
Going with digital options for financial activities requires extra vigilance. Any money movement should be guarded by layers of security, like multi-factor authentication or donor validation. To activate these options, just ask your financial institution and check in with the makers of any of your digital fundraising tools.
For day-to-day monitoring, consider signing up for digital statements from your financial institution. Set aside extra time for monitoring those statements for suspicious activity. If your institution offers instant notifications on account activity, even better.
Organizations often assume that anything to do with data storage and access is relegated to “the tech team.” This is not the case. Anyone within an organization can help ferret out weaknesses in data stores and access points.
Anyone on your team can start by looking at the information most often referenced when engaging with donors – names, donation history, addresses, email and more. From there, they can ask some basic questions – the same questions you ask yourself at home when thinking about your bank transactions:
It may feel overwhelming to read this right now, with so many needs requiring fast action by your organization to help the world during an unprecedented time of crisis. However, the team energy and trust needed to build and maintain a secure mindset may be closer than you think. When your goal is to protect the integrity of your nonprofit’s mission and ability to help, you will often find your team ready to step up so you can all focus on your primary mission: Helping the world.
Author
Katherine Lagana
Chief Technology Officer
Katherine Lagana joined Fidelity Charitable in 2015 and is responsible for enabling the organization to be on the cutting edge of technology and philanthropy, while ensuring reliability for all Fidelity Charitable systems.
Prior to joining Fidelity Charitable, Ms. Lagana led global product development at LexisNexis®. Before that, she was responsible for advanced global product delivery at Microsoft Office. Ms. Lagana began her career at Apple building higher education, developer, and consumer products.
Outside of the office, Ms. Lagana is an avid volunteer for Habitat for Humanity and STEM programs for young women.
Want more info before you open a Giving Account?
Sign up to receive occasional news, information and tips that support smarter philanthropic impact through a donor-advised fund.
How Fidelity Charitable can help
Since 1991, we have been a leader in charitable planning and giving solutions, helping donors like you support their favorite charities in smart ways.
Or call us at 800-262-6039