How To Protect Your IT From Charity Hack That Made National Headlines
At the beginning of the month, charity software provider Beacon CRM, had a potentially major data breach, and it threatened to throw thousands of not for profit organisations into chaos, and very expensive and damaging chaos at that. The story was all over the national media for several days, and there is an important lesson all Suffolk VCFSEs can learn from what happened. This is the story, and how to respond.
On Monday, 3 August, Beacon CRM announced it had data within its systems that may have been downloaded by a malicious third party. It issued a public statement to this effect and similarly informed clients. It stated:
‘We are currently investigating the full circumstances of the incident with external cyber-security specialists, but our current understanding is that compromised credentials were used to gain access to Beacon’ It added, copies of client database backups had been made.
So what did this mean, and what had caused the potential catastrophe?
‘Although the statement was not definitive in its content, what it said in not so many words is that the complete CRM database of every charity client may have been accessed and copied by those that had illegally got into the system. The potential for damage was huge, and placed a great many charity and voluntary groups in danger.
Information on the cause of the breach was not specific, but the suggestion was that a weak password from a former Beacon client had been bypassed by intruders, and put the entire system and its data at their mercy.
So what is happening now?
Beacon is implementing immediate measures that will secure the system, and reassured clients that the CRM system is now safe. It states that while there was a data breach, no damage was ultimately done.
Why all this is important to Suffolk VCFSEs
Some Suffolk VCFSEs will have been involved in this chain of events directly, and if they need advice they should contact me. For everyone else, there is a lesson to be learned, and that is to take cyber security extremely seriously, and be aware that threats can come from unexpected quarters, even trusted third party systems. Beacon CRM is well regarded in the IT industry and known for safe practice. So if it can fall victim we must all be aware, and there are also some practical measures that can be taken to make sure cyber attacks do not work. Apologies if what follows seems to be a repeat of what I have previously advised, but the need to implement secure practices cannot be emphasised enough.
Use Multi Factor Authentication (MFA)
If a password is stolen, MFA provides an additional layer of protection. Most Microsoft 365 and cloud services support this at no or little cost.
Keep systems updated
Software updates often contain security fixes. Delaying updates can create unnecessary vulnerabilities malicious parties are often aware of, and quick to exploit.
Review user accounts
Former employees, trustees and volunteers should no longer have access to systems. Regularly review users and delete as appropriate.
Maintain backups
A tested backup (I am not sure all readers will know exactly what this means. I don’t.) remains one of the most important safeguards against cyber incidents.
Keep staff informed
Staff and volunteers are a significant potential weak link in cyber security. It means implementing effective awareness training, and keeping everyone up to date with technical changes. Also, make regular reminders about the threat from phishing.
Review permission access regularly
Review system permission regularly to ensure those that do not need access to sensitive information cannot get to it. Usually, the level of permission is set when individuals first join an organisation, and there is no need to change it, but never-the-less, reviews should be undertaken as a matter of course.
If in doubt, seek advice
If there is any doubt about the robustness of IT security do not take chances. Get qualifiedl advice. IT Services at CAS Ltd runs light touch security audits, and supplies highly advanced endpoint protection and software. If you want to discuss any of this, please get in touch. It is better to be safe than sorry. Contact me on 01473 345321 or at [email protected]
