The recent breach at Beacon and the extended downtime at CAF Bank have led to some speculation that the non-profit sector may be under particular attack at the moment. We review multiple threat intelligence sources every week and, so far, we have seen no evidence to support that view.
The reality is that all organisations are being attacked all the time.
If you have a device connected to the internet, it is constantly receiving a stream of low-level attacks. Think of someone walking down a street trying the door of every parked car. If a car is locked, they move on to the next one. They’re looking for the easy target: the car that’s been left unlocked.
Now imagine that happening every five minutes, to every car. That’s much closer to the reality of today’s internet. If you think it isn’t happening to your organisation, I’m afraid you’re probably wrong. It’s just happening in the background where you can’t see it.
We do occasionally see reports of specific non-profits being targeted. These tend to be organisations working in areas such as international human rights, where attacks appear to be targeted, politically motivated, and carried out for a particular purpose.
For most non-profits, the key message remains the same: make sure your information security practices are up to scratch. However, we have not seen any analysis or evidence suggesting that the sector as a whole is being specifically targeted right now.
We do believe this is an area where the Charity Commission could play a greater role. By working closely with other government bodies, particularly the National Cyber Security Centre (NCSC), it could help monitor emerging threats and provide proactive warnings when necessary.
What can you do?
Are you making sure your “cars are locked” (if we’re not stretching the analogy too far)?
Getting the basics right is one of the most effective ways to protect your organisation. Many attackers are simply looking for easy opportunities, so making sure the fundamentals are in place is a vital first step.
- Use a password manager and encourage everyone in your organisation to do the same.
- Enable multi-factor authentication (MFA) wherever possible, especially for key accounts such as email, financial systems, and other sensitive data.
- Provide regular staff and volunteer training. Most successful attacks begin with someone clicking a link, opening an attachment, or sharing information they shouldn’t.
Security can be inconvenient. It’s a hassle to enter an authentication code as well as a password. But, just like locking your car, that small inconvenience is far preferable to having your vehicle stolen, your data leaked, or your bank account emptied.
If you’re a Lamplight user, you can enable two-factor authentication for user logins through the System Admin page.
Photo by Jefferson Santos on Unsplash