|
All of us at Association Technologies, AT, hope you are all doing well during this pandemic which has changed many of your businesses. Many of you have spoken with us about working from home or moving conferences online. Unfortunately, hackers have also changed their business plans in response to Covid-19. Hackers are attacking remote-working technologies and sending convincing, but fake, emails relating to Covid tests, vaccines, school openings, etc. all in an attempt to steal from you and your company. Sadly, it is working. The FBI reports that cyber-attacks have increased by 400% during the Covid-19 pandemic.
Many not-for-profit organizations do not realize the potential repercussions of a cyber-attack. They feel that their member data is not confidential, like medical data or trade secrets. However, member data is protected by federal and state law, and must be protected with “reasonable security measures". Even data that can be obtained in a phone book must often be treated and protected as confidential data when it is given to you by a member. Failure to properly protect member data could result in FTC regulatory action. Credit cards are used by all of our customers, and a few stolen credit card numbers can result in investigations costing tens of thousands of dollars. The most valuable data an association holds is usually staff information. Between payroll, taxes, and healthcare, companies store a great deal of valuable information about their own staff. If stolen, this data can allow identity theft, bank fraud, healthcare billing fraud and other problems for your staff.
The good news is you can help prevent an attack. Every staff member can play a part in keeping company data secure because according to Kaspersky* and IBM**, staff mistakes are responsible for up to 90% of successful attacks. These attackers take advantage of confusion, chaos, or excitement to trigger emotions that bypass your normal suspicions to get you to email a password or click on a fraudulent link. Please use the following tips to help your company keep data secure:
- Review your online security training plan with AT so your staff are empowered to protect your organization from these types of attacks.
- Access company data only from company equipment, due to installed security systems
- Do not let your kids or spouse use your company computer
- Do not click on links in emails: If you believe you received a legitimate link in an email, browse directly to that website to follow-up
- Start using a password manager so that no two websites have the same password tied to you. Hackers use passwords from one hacked site to logon as you on other websites and to work computer systems
- If you accidentally click a fraudulent link or think you made a mistake, or see something suspicious; call AT. The sooner you catch a problem, the more opportunity we have to prevent or limit any damage.
With proper vigilance you can avoid falling victim to a hacker's tricks and we are here to help keep you and your company safe and secure.
* https://www.kaspersky.com
** https://www.ibm.com |
|
|