You Cannot Let Your Guard Down When It Comes to Cyber Security and Fraud
Attempted fraud and cyber security breaches are increasing. At the same time, distractions from our chaotic world and new operational realities are averting our attention. This is a bad mix. We need to double-down on efforts to protect our organizations. Reputations and sustainability are at risk, and navigating these threats is even harder during a time of crisis.
This statement of reality was obvious to me. However, my experiences from this past week were still shocking and became a wake-up call to action. In the span of just over one-week from discussions with clients, participants in my eight webinars and two cyber-attacks on family members, I became highly sensitized to a new reality.
To optimize efforts to enhance cyber security and protect against fraud, it is best to organize your planning and enterprise risk management (ERM) efforts around the following three action steps:
1. Make Cyber Security and Fraud Protection an Explicit Priority
Simple and cheap but very effective, make raising awareness a high priority. Include cyber security and fraud detection in all meetings, financial analyses, and managerial discussions, just like we include mission impact and return on investment (ROI). Emphasize that you cannot wait for problems to find you, but that we must search for areas of exposure and weakness before actual attacks occur.
2. Double-Down on ERM and Security Efforts
Assume that existing systems, firewalls and protections will become inadequate earlier than you think. Accelerate your ERM analysis by adding more frequent ERM assessments. These efforts can be enhanced by temporarily adding during this crisis monthly mini-ERM assessments in between your Quarterly or Annual ERM assessment cycle. Look for opportunities to provide additional training for staff on security protocols. And consider adding third-party security services that randomly test your system’s effectiveness and track whether staff are following standard security protocols related to spam, phishing and other attempted cyber security breaches.
3. Get the Word Out
Regular communications related to cyber security awareness and fraud prevention will be as effective as actual ERM protection measures, as it will lead to more active engagement of staff with ERM measures and fewer protocol infractions. These communications should include regular updates on ERM challenges and counter measures being considered. Management should regularly seek staff input through surveys, focus groups, and information technology committees made up of a diverse, cross-section of employees. Nonprofits can also draw on volunteer resources represented by Board members, industry members, finance committee and other volunteers.
Planning Tip – Transparently share stories and experiences. If your organization experiences a breach in security or an actual fraud event, share the story with your staff. Discuss how the situation evolved, weaknesses that became exposed, damage that occurred, and remedial steps taken. If your organization is fortunate to have avoided a significant security breach, share stories from other similar sized nonprofits who have had a major security breach. Explore whether that same security attack could have happened at your organization, how you would have reacted, and damage that might have occurred. Sharing these stories will put your organization in a better position to fend off future problems.
With so many unpredictable distractions occurring, it is important that nonprofits not let their guard down, and actively work to make cyber security and fraud protection a high priority.
