The technical activities carried out by your nonprofit organization mainly range from receiving material donations through its website to collecting and storing personal information of parties who are directly or indirectly related to the organization, including donors and contributors. As a result, appropriate steps must be taken to address potential risks that threaten your organization’s cybersecurity.
In this regard, the Vice President of the National Council of Nonprofits during her tenure leading the “Risk Management Center of Nonprofits,” classified potential risks into groups according to their priority to ensure they are dealt with appropriately. Data breaches are classified as a critical risk that can cause severe damage to the organization; therefore, it is wise for every nonprofit organization to take serious steps to assess risks and protect its data from unauthorized disclosure.
The “Nonprofit Technology Network” indicated the first step is assessing the risk of leakage by inventorying all the data collected by the organization and identifying where it is stored. The network provides an inventory and assessment tool centered around the following questions: What data do we collect about stakeholders? What do we do with it? Where do we store it? Who is responsible for it? On the other hand, consideration should also be given to the cost of maintaining all that data and trying to eliminate data that is deemed unimportant to the organization, which will simplify storage and reduce risks.
The network also emphasized the need to know whether the data collected and stored by the nonprofit organization falls under federal regulations as “personal information.” If so, 47 U.S. states require nonprofits to notify individuals if their personal information has been breached, and 31 states mandate the disposal of this data in certain ways.
Additionally, the “Federal Trade Commission” law requires the proper disposal of information found in the organization’s reports and records to protect their owners. Even if the data collected is classified as “personal information,” a breach of that data can damage the organization’s reputation and its ability to raise donations.
Meanwhile, risks associated with employing an external party, i.e., one not belonging to the organization, to carry out a certain type of services on behalf of the organization arise, which is granted full access to the database and to use the electronically stored personal information. If the external party does not use the necessary protective tools to ensure data security, this is likely to expose the organization to danger. Accordingly, when hiring an external party to undertake projects that involve access to data, ensure that you are satisfied with the data security protocols adopted by this party, whether an individual or a company.
What is the likelihood of your nonprofit organization’s website being hijacked?
Hackers can breach your nonprofit organization's website, with the likelihood of this occurring depending on the strength of the site’s security and the degree to which users follow password protection protocols. In the event of a breach, the main site generally remains intact, but hackers create additional content that can harm the organization’s reputation. Therefore, it is important to keep software updated and to be cautious about usernames and passwords, as ongoing maintenance of the site is considered the best solution to mitigate data security risks.
The importance of insuring your organization’s website
Insurance policies vary to cover losses resulting from electronic breaches affecting nonprofit organizations' security and impacting information of external parties (such as patients or clients or donors). The types of losses that cybersecurity insurance can cover include the cost of notifying all individuals whose information has been stolen, the cost of repairing the site, and helping the organization restore its reputation after a security breach. Local nonprofits might assist you in finding an experienced insurance specialist to provide the appropriate coverage for your organization.
According to the “Risk Management Center of Nonprofits,” there are three key steps to follow before making a final decision on purchasing insurance for your organization’s website. These steps include understanding how a cybersecurity breach impacts the privacy of your nonprofit organization, needing to consult an insurance agent familiar with various cybersecurity insurance policies and aware of your organization’s operations and activities to protect all direct and indirect parties from harm. Additionally, closely examining the cost of the annual insurance premium.
In general, hacking your nonprofit organization’s website is a likely and very common occurrence, and therefore, caution should be taken before damage occurs. Remember that local nonprofits can provide specialized workshops or educational programs on this topic and may have connections with experts who can help your nonprofit maintain the security of your website.
——————————————————-
Website: Council of Nonprofits
Comments (0)
No comments yet. Be the first to comment!