Tag Archives: data security

Nonprofit Radio for July 13, 2026: 5 Project Management Tools For Non-Project Managers, Cybersecurity On A Shoestring & Make Confident Tech Decisions

 

Adrienne Figus: 5 Project Management Tools For Non-Project Managers

From project charter to closing report, Adrienne Figus walks you through the essential tools to help you take control of the changes you may find yourself leading. She’s with Madison College. Here are the resources Adrienne refers to.

 

Edward Wilson & Ellen Samuel: Cybersecurity On A Shoestring

Our panel covers 10 essential security measures every nonprofit can implement right now, without an IT team and without breaking the bank. From knowing where your data is to changing default configurations. And from firewalls to offboarding data. They’re Edward Wilson at ArchTech and Ellen Samuel from Just-Tech. Here are their resources.

Simone Carvalho & Rebecca Kaplan: Make Confident Tech Decisions

Simone Carvalho and Rebecca Kaplan explain when you need an audit of your tech stack, and the steps to conduct the assessment. Along the way, you’ll lean on surveys, interviews and process maps. Simone is with Skeleton Key Strategies and Rebecca is at Feeding America.

 

Listen to the podcast

Get Nonprofit Radio insider alerts

I love our sponsor!

Bridge Conference: The conversations happening at Bridge will shape strategies, careers, and organizations long after the conference ends.

 

Apple Podcast button

 

 

 

We’re the #1 Podcast for Nonprofits, With 13,000+ Weekly Listeners

Board relations. Fundraising. Volunteer management. Prospect research. Legal compliance. Accounting. Finance. Investments. Donor relations. Public relations. Marketing. Technology. Social media.

Every nonprofit struggles with these issues. Big nonprofits hire experts. The other 95% listen to Tony Martignetti Nonprofit Radio. Trusted experts and leading thinkers join me each week to tackle the tough issues. If you have big dreams but a small budget, you have a home at Tony Martignetti Nonprofit Radio.
View Full Transcript

Hello and welcome to Tony Martignetti Nonprofit Radio. Big nonprofit ideas for the other 95%. I’m your aptly named host and the pod father of your favorite Hebdomadal podcast. I have to apologize for the audio today in our 2nd and 3rd conversations. Consistent with the lackluster host that you know you suffer with, uh, he, I, Failed to plug in the, uh, microphones to my phone. For these two conversations. You see, at, at NTC, of course, I got all my remote gear. We’ve got 4 microphones set up, one for me and one for, and 3 for, uh, the other, for the panelists, the guests, and those mics go into the mixing board, and the mixing board plugs into the phone because my phone is where my recording app is. I use an app called Hindenburg. Well, for these two conversations. I didn’t realize that I had not plugged my phone in from the mixing board, so the sound you’re gonna hear in those two is just. My phone picking up voices, uh, along with all the ambient noise. So, the phone, of course, is sitting in front of me, so I’m loud and clear in these last two conversations today, but the guests are a little quiet and there’s ambient noise, and I did the very best I could to strip out the, Ambient noise as much as possible without reducing the, the guest voices, and I tried to elevate the guest voices and make them as clear as possible, but Uh, my apologies for the audio quality on the, the last two of today’s conversations. But nonetheless, I’m glad you’re with us. Cause I’d be hit with stomatalgia if I had to say the words, you missed this week’s show. Here’s our associate producer, Kate, to tell us what’s going on. Hey Tony, I’m on it. We wrap up our coverage of the 2026 nonprofit technology conference with three conversations. First 5 project management tools for non-project managers. From project charter to closing report, Adrian Figgis walks you through the essential tools to help you take control of the changes you may find yourself leading. She is with Madison College. Then cybersecurity on a shoestring. Our panel covers 10 essential security measures every nonprofit can implement right now without an IT team and without breaking the bank. From knowing where your data is to changing default configurations, and from firewalls to offboarding data. They are Edward Wilson at Arch Tech and Ellen Samuel from Just Tech. Finally. Make confident tech decisions. Simone Carvalho and Rebecca Kaplan explain when you need an audit of your tech stack and the steps to conduct the assessment. Along the way, you’ll lean on surveys, interviews, and process maps. Simone is with Skeleton Key Strategies, and Rebecca is at Feeding America. On Tony’s take 2. Thank you, N10. We are sponsored by the Bridge Conference. Tony will be with more than 2400 nonprofit professionals at Bridge, July 29 to 31 in National Harbor, Maryland. Info and registration at bridge.org. Here are 5 project management tools for non-project managers. Welcome back to Tony Martignetti nonprofit radio coverage of the 2026 nonprofit Technology conference. My guest now is Adrian Figgis, project manager at Madison College. Adrian’s topic is five project management tools you need, especially if you’re not a project manager. Welcome to nonprofit Radio, Adrian. Nice to meet you, Tony. Thanks for having me. It’s a pleasure. I love this topic, project management, something we haven’t spoken about on the show for a long time. Could you give us a high-level view before we get into some detail? Sure, so this session grows out of what I wish that I had had handed to me when I was first becoming aware of project management as a discipline and the challenges of projects generally, uh, before I became a project manager and a lot of that was handed to me, you know, here at the NTC over the years, many years ago, and so this is I’m here to try to give back and. And see how can I help at least a little bit with people who are dealing with massive projects without a specific project management background and try to increase the overall culture for project management in our nonprofit community. All right, thank you. So let’s dive in. You have, um, you have 5. 5 steps, not 5 projects, 5 tools, 55 tools that you’re, you’re giving back to the community. I love that. I admire that. Thank you. I, I consider myself a member of the community. I’m, I’m not involved at all in project management. I have a one person company, so my projects are modest, uh, by scale and in terms of yours in comparison with yours, but. I can still say thanks for giving back to the community. That’s awesome, awesome. You’re very welcome and, and thank you for the same, you know, I think you, you clearly give a lot back to this community too, and it’s really what we’re all here for here to do at NTC. We’re all contributing. All right, uh, first, before we get into the 5, let’s define what what you mean by a project. So the, you know, technical formal definition of a project is a temporary endeavor that creates something new. So that is as opposed to operations, which is the ongoing work that makes up, you know, the, what we actually are doing. Regularly on a regular basis, but those things flow together, you know, and, and there’s overlap in a lot of cases, especially in smaller, you know, organizations like, you know, yourself a solo shop or small organizations that don’t have a formal culture of project management. Um, but I think that core of it’s a new thing we’ve never done, so we don’t already have a playbook for it, and it’s, uh, a temporary thing that at some point we will hopefully succeed and be done with it, um, or it will shift and become our operation. ongoing and so project management are those tools that help us with that newness and temporarineness to then hand over to a related but different set of skills for for optimizing the operations. OK, um, is it necessarily, uh. A tech related tech project? I mean, could it be a capital project? Could could these tools apply to that kind of project or absolutely these tools are, are project type agnostic. Um, I, most of the projects that I manage have something to do with tech. I work as a project manager in an enterprise project management office in a college and we rest. Inside the tech department, so just by virtue of that there’s usually tech involved, but we’re also doing organizational change projects we’re doing, you know, things that maybe only incidentally have tech, and a lot of what I’ve learned about project management, especially through the NTC goes back to work that I’ve done in my previous career in fundraising. So a fundraising appeal can be a project because it’s, you know, that appeal itself is a new thing that will end it goes into your operational flow of projects. So really anything, um, tech is, is just the, the, the hook here. Oh, that’s our, yeah, that’s our medium here. OK, cool, yeah, um, so let’s go. Into the tools. What, uh, what are they? All right, so the 5 tools that I brought, you know, they’re, they’re by no means the only tool I talked to a project manager. There’s hundreds, but the 5 that I think are, are a good head start for people who, you know, have, have not done this before and might apply to basically any project are the project charter, the stakeholder register, the communication plan, the meeting agenda, and the closing report. Um, and do you wanna go into reasons why I chose those, or yeah, yes, but would you say them one more time for me? Absolutely. The project charter, the stakeholder register, the meet, uh, communication plan, uh, meeting agenda. And a closing report. OK. Yeah, so let’s start with the project charter. Sure, uh, so the project charter is a document, you know, it can take a lot of forms. It’s less common in organizations that don’t have formal project management, um, but you can do it in a really lightweight way. It’s essentially a contract that sets out the basic terms of what are we doing, why are we doing it? Who has given us the authority, what kind of resources do we have, both financial and people and time, um. How will we know that we did it correctly? So, so like scope, like a, a, a scope of work, yep, it includes the scope of work. Um, it includes the, the mission and vision of the project. It includes, you know, the scope of work also crucially includes what’s out of scope, what are we not gonna do, um, and it also pulls together who is in the project team, who’s in the governance, who’s responsible for the project, budgeting as well as in here. The scope is gonna impact budget, obviously, clearly, OK. Um, all right, anything else on the, on the charter? I don’t wanna go through, I don’t wanna go through them too fast. I don’t want you to give short shrift to nonprofit radio listeners. No, I could tell you’re not doing that. The, the charter is one that’s really easy to skip because it seems intimidating, especially if you don’t have a project management office, so you’re not a project manager, but even just a single one page that says this is who said it’s OK to go ahead with this project. This is what we’re doing. This is what we’re not doing, and you know we have a budget. It came from this department or whatever, um, taking the time at the start of the project to have those discussions to identify so you don’t get six months into the project and realize, oh, turns out no one actually gave us permission for this, and now we’re getting a lot of pushback, that kind of thing or what we’re not clear what the budget, yeah, I can see. I mean, like a lot of things, the preparation and the planning are valuable even though they’re a time suck, but they’re gonna pay off in ways that you may never even learn through the, the remaining 44 tools, right? I mean you, you’re gonna get creep and uh yeah, accountability and authority issues and things like that that you’re gonna avoid if you’re intentional at the. Yeah, at the outset, OK, um, I, I got an interesting question from one of the participants, um, who was describing a situation where she’s, you know, new to a, a department in her Oregon is being tasked with picking up a project that has gone adrift because there was a lot of staff turnover. The people who were on it are no longer there. There’s uncertainty of what was done. Things are in some abandoned asana boards, and she was asking about what to do to move forward. And I really think that taking some time to write a new project charter and say like this is maybe the phase two of this project we’re starting over again we’re acknowledging what was done, but we’re not gonna be bound by like a contract that was maybe implicitly created even if it wasn’t written down by people who aren’t there anymore to carry out the terms of the contract, but that’s a proxy for the conversations that have to be had anyway and it’s the the the charter as a holder for that. And then the register, the stakeholder register, so you know, projects like operational work and anything else else we do in pro in nonprofits are actually all about people, you know, nothing is gonna happen. AI is, is not there yet. Um, I, I don’t think it ever will be, but that’s not our topic. Um, anything you do in a project involves people, and the lingo in project management for people is stakeholders. The formal definition of that is basically anyone who uh will be affected by your project’s outcomes or you know the the tech work it takes to do the project, um, anyone who can affect the project either affect the outcomes or affect the way that the project works, um, and anyone who can get in the way of the project or enable the project to move forward risks exactly. So, so some of your stakeholders are, are people who may be threats but also may be your greatest allies later. Uh, so the stakeholder register is really just a list of all those people, and I’ve provided a template that is, uh, you know, it’s a simple Google sheet that gives you some ideas of things that you wanna know about those people in order to get them to contribute as best they can to the project, hold yourself accountable to checking in with them. And um if they are people who may present threats or or be you know a potential challenge for your project, how to activate them and turn them into champions and assets for your project but it all comes down to in the first place you have to know who they are and that’s what the stakeholder register is all about. OK, OK, um. Yeah, the folks who are going to be impacted by the project, I mean, I hope they have influence in the project too, so it’s not foisted on them and, and assuring, you know, non-use. And that’s one of the things that is absolutely the responsibility of the project manager. It’s also the responsibility of everyone else in the project, but I, I see an important role of the project manager as being the communications hub for the project, the, the person who anyone can come to me and say, oh well, there’s this project going on. Adrianne’s involved. I’ll just ask her what’s going on, and then I give them all that. Information even if I already emailed them 3 times, I’m always happy to tell you again because the fact that you asked me matters but I’m also accountable, you know, if I had Tony on my list of users who’s gonna be affected by this change, I have to proactively reach out to you to understand, you know, if you’re, if you’re an core user to understand what your needs are, explain to you how things are gonna be changing. But even if you know you’re my user but you’re not in my org, you know, like I don’t know you, I have to understand as much as I can about you to be sensitive to that and so sometimes you might be on my list of stakeholders, you don’t even know the project is happening, but it matters to me that it happens in a way that works for you so all of these things, um, again it just comes back to knowing. Who we’re thinking about in these projects, I could see that’s an important part of your work because you’re, you’re a big university, well, college, whatever, but a big organization. I mean big enough that it has a project management team that you’re on, so you don’t know a lot of the people unless you made projects with them before, but throughout the college, you may not know a lot of the stakeholders because you, you work in a, you work in a project management team serving the whole college. So getting to know folks, buying, getting their buy-in. I mean, I would think that’s a big part of your work as a project management. Expert team member, absolutely. Anytime I’m starting up a new project, I’m, I’m just about 2 years into my current role, so I’m just now starting to get my feet under me and understanding where all the offices are and when people use acronyms, I think I know what that that is and. At this point now I’m starting new projects that that involve people that I knew before, but it’s still my first task to say, OK, what are all the offices and people that are gonna be involved? What are the groups of students that might be affected or faculty, sometimes community members outside the college, some of those, it’s groups, you know, so maybe it’s all of the students in one, you know, area of the academic area or sometimes it’s all of the staff members in, you know, the library. Um, and so I have that group, but then I start dialing in and saying how do I learn more about that group as individuals? And then when I have actual individuals, how do I use the networking tools that I have available to me inside the organization to say, hey, like I haven’t met Mike before. What can you tell me about him? How do I, how do I talk to him in a way that makes sense to him and then introduce myself as, as the project manager, um, and help them see how they can interact. Because I, you know, you never want a project to get too far along and end up being a surprise to somebody who needs to actually be involved. Yeah, yeah, that’s, yeah, that’s poor. That’s, that’s the, that’s the, uh, antithesis of. Smart project management. Uh, number 3 is your communications plan. All right, so like how are we gonna keep in touch with all these stakeholders that we identified in the, in the, uh, register? Absolutely, yeah, and that’s they, they go hand in hand and personally I actually like to use a single spreadsheet with multiple tabs, one for my stakeholder register and one for my communication plan. I can just tab back and forth and see, OK, for each of these stakeholders, some of them individuals sometimes groups, those are audiences that I need to communicate with what can I put on the communication plan as far as one on one conversations or, you know, road show presentations or, you know, email blasts or however I can communicate but then as I’m writing out the communication. And I think of other things that I might wish to communicate and think about the audience and then if that audience isn’t in the stakeholder register, I scurry back over to that tab and add new lines. Both of those are are living documents that keep going through the whole course of the project as I learn more about the project, I learn more about the needs and the people and build it together and then next time I do a project that’s similar, I can go back and sort of take some of that information and, and start, uh, the next project. OK. Go ahead with 4, our agenda meeting agenda. So this one is a meeting agenda meeting agenda, yeah, it’s, it’s, it’s the simplest one. I, I don’t belabor it in my presentation, but it’s so important and something that is so easy to ignore. Um, I’m not an anti-meetings person, you know. I think that meetings are an important communication tool. I put them on my communication plan. Um, you know, sometimes a, a week-long email chain could have been a meeting, um. But it’s a sort of a sacred trust to ask people to come to a meeting. You’re asking them for their time. You’re asking them to put themselves out there and hopefully feel that they’re actually contributing in this case to the project, and part of that is the agenda. You need to have a goal for the meeting. You need to understand who’s invited, who of your stakeholders are invited. You need to understand what are you, uh, attempting to discuss, accomplish, what decisions do you need. But also you need everyone who’s coming to the meeting to have access to that information up front. If I just call, you know, you and, and Amy and, and 3 other people into a meeting, but I don’t tell you what’s happening, you’re coming in puzzled, annoyed with me, not ready to engage. You might just like say no at the last minute. But if I send out the agenda and say like, here is the importance of this meeting, here’s why you, Tony, are coming. And if you can’t come, I need you to delegate somebody from your team because we need this decision. sharing that information up front helps to level the playing field, make sure we have everybody in line and really get value from that meeting. So what kind of meeting cadence do we need that varies by project and we have like an 18 month project. Yeah, um, that’s something that I like to negotiate with each project. Uh, very commonly I’ll have a core team that’s usually like, you know, between 4 and 6 people who are steering the project and maybe, you know, they’re doing hands on tech work and I’ll do a weekly check-in with them and we know it’ll be sometimes a half hour just to say here’s what we’re doing. Um, which we’re ready to cancel if nothing new has happened and so that’s a big part of the agenda is like check in a few days beforehand. Can we cancel this or do a asynchronous check-in. Then I like to do sometimes like either biweekly or monthly meeting with more of a steering committee that are people that have decision making authority or who are very, uh, concerned stakeholders but maybe not doing the actual work of the project. And then I’ll often, especially in a longer project like an 18 month or a 2 year project, I’ll have subareas within where we’ll have, you know, meetings once a week for 2 months for a sub team that’s working on something really heavily in that 2 months, but it’s only the people that are actually doing that heavy work like I, I had a project where we. We’re doing um some compliance uh regulatory changes that needed some technical updates but also needed quite a bit of um information sharing and communication to bring the whole college community along because it involves some somewhat significant business process changes to meet our new state regulations. So we had a communications subproject that involved doing a lot of website updates because you know for a large institution getting all the approvals to update the website and just the mechanical work of that is a lot so we had a, a little communications strike team of of 3 people and we were meeting once a month or once a week for a short period of time while the overall project team was meeting at a different cadence. OK, so it’s uh that’s part of setting up the agenda is if it’s a recurring meeting, getting everyone to agree on the cadence and then revisiting that. I, I also like to revisit a meeting cadence about every 6 months and say, or in, in higher ed I’ll do it on a semester basis like, so you know, for spring semester we met this regularly. Do we need to do that for the summer? And on our closing report, so the closing report, you know, it’s, um, brings us back to that definition of a project that by definition it’s a temporary endeavor that means it has to end, but this is a thing that really trips a lot of us up, especially those of us that don’t, you know, currently I, I work in a place that has very defined policies around closing projects for budgetary reasons, but at my previous roles, um, it is very common, and I know a lot of people that this is very common that a project will just keep going. You know, maybe you weren’t able to accomplish what you thought you were going to or you had some staff turnover and no one’s quite sure what’s happening or like, you know, a grant got pulled so you had to put it on the back burner but you didn’t actually close it because maybe that’s admitting defeat or you’re not quite ready to declare victory and it’s just there. And then it becomes a major, you know, psychic and time weight on everyone who was involved with it because even if you’re not working on it day to day it’s in the back of your brain and you remember, oh yeah, you know that that refresh on the website that we decided not to do. I’m still gonna think about it every couple of weeks and so having a way to close a project, um, by, you know, policy and will of your organization but also a practice and a template to do that. Whether it’s because you finished the project successfully and you’re gonna celebrate it, it’s wonderful, or we’re acknowledging, you know what, having this project open no longer meets our needs, so we’re gonna just close it down and we’ll have lessons learned, no blame, it’s just, it’s OK. Um, having a template ready to go that you know at the start of the project, um, you know, would help you sort of write your charter to say how will we know that we’re done preparing yourself to then close it, I think can help lessen that pressure of just having these projects that just don’t stop. It’s uh yeah it’s a boundary like we know this is completed good hopefully not bad let’s say just good or indifferent it’s it’s wrapped up you know we’re all moving on. OK, it’s time absolutely and then the report itself can live in your organizational files if you have a PMO. It lives in your PMO, but then it’s there for re, uh sorry, project management organization, and that’s the group that I that I work in. Um, but there are organizations that have what they call a PMO, but it’s just one person who holds all the templates and the records that, that can be a PMO. But your, your way of doing projects, and maybe it’s just a file in your OneDrive, um, but if you have those records of all these past projects, then when you do a new project and you’re gonna charter a new project that’s somewhat similar, pull out the closing report from the old ones that were similar and say, what do we learn on this project about how we operate. Great things we did that ended up not being productive for us, things that were really great, um, you know, and that will make your next charter and your next set of meetings and everything else much easier and, and better for the next time. Where do we document changes, uh, uh, process changes, maybe staff changes that are that have been made? We’ve been doing it this way at the college for many, many years and now that the. Our project has closed. Uh, Business processes have changed. Maybe reporting responsibility or who’s responsible for different things that changed? Where do we document all these these organizational changes? Oh, that’s a really good point. So that’s part of the closing report is. Acknowledging that you did the handover to operations and so the closing report should document the decisions that you made, the changes that you made, but just because it’s in the closing report of a project doesn’t mean it actually happened I think is what you’re, you’re, uh, implying, uh, or or alluding to and so, um, that’s where the like projects shaking hands with operations really comes in is you’re saying OK, this project made this happen. But then some team, you know, some operational team or department or person has to take responsibility for that, so you can’t actually close the project until you’ve done the handover. So, you know, oh, I’m, I’m, you know, did this project where I, you know, helped you implement your new scheduling system for your, uh, podcast guests, um, until I hand it over and you say, OK, I acknowledge that I have this new process and it’s, it’s in my area. I can’t say my project is done because you didn’t actually take it on and agree to do it. Um, do we have a ceremony or what is there a ribbon cutting? I mean, if it’s a physical project that could, but still, even so, that’s ceremony, that’s not operational continuation. Mhm, um, yeah, so you can have, I, I highly recommend having, you know, a, uh, some sort of a ceremony to close the project, a final meeting or a pizza party or something, but that sort of that handover of the new. Things I like the idea of it having to be some sort of a pomp or circumstance to make it happen um but the recording of the new policies should be done in whatever way you are recording your policies so like however you had it written before you change and put it in now if the project was to set up a change in tracking system for your things then you’ll have it. OK interesting all right um what else, what else did you talk about in your session that we haven’t talked about with our listeners. So one of the things, and, and you know I can share with you the link to the templates, um, yeah, actually, would you do that you email me the link and then I’ll include it in the show notes. Absolutely I can do that and, and I really encourage anyone to, to take a look. They’re all um. You know, the just Google Docs and Google Sheets. Anybody can download them, brand them yourself, use them, you know, fully free. I have a little CCB license on it, but really I assume you’re gonna be changing them enough that it’s your own work if you use it, so it’s my interest to get it out there. But in each of those, um, areas. As people who work in nonprofits and mission based institutions, I think each of these tools is an opportunity for us to like express and forward our values, um, so in the project charter you should be writing your project vision or project mission in line with your vision and mission of your organization. You should be expressing your values in your stakeholder registry. You should be expressing your values based on who you are targeting as your stakeholders that you know it’s not just like you. Googled and saw, OK, who should be a stakeholder for a website change it’s, you know, your people and your people who matter to you on a deep level as an organization, go for that. Um, there are some really useful things around accessibility that you can do in a stakeholder register. You can note, you know, are there people who have specific accessibility needs like do they need a wheelchair accessible meeting room, um, so you make sure that you have that for them or you have live. Optioning so that you don’t have to keep asking people the same questions in order to make sure that they are able to be in the room with you. Same thing with your communications every project communication you send out should be an expression of your organizational values, um, and that’s gonna play out differently depending on the project, but, um, I, I think if we keep this in mind and make sure that, you know, we’re, we’re not ignoring that aspect of it just to drive a project through we’re all gonna end up with better outcomes in the end. That’s a great place to end. That’s perfect and with values. Absolutely. Adrian Figgis, project manager at Madison College, Madison, Wisconsin, thanks very much. Thank you for sharing. Well, thank you, Tony. This has been lovely. Thanks and thank you for being with Tony Martignetti nonprofit radio coverage of the 2026 nonprofit Technology conference. It’s time for a break. We are sponsored by the Bridge Conference, produced by AFP DC and DMAW July 29 to 31 at the Gaylord National Resort and Convention Center in National Harbor, Maryland. More than 2400 professionals will gather at bridge. Tony will be with them. The question is, will you? Thought leaders from nonprofits, associations, foundations, hospitals, higher ed, faith-based, and mission-driven causes across the country come to Bridge to discover new ideas, solve real challenges, and connect with smart people shaping the future of our industry. From 125+ educational sessions and hands-on pre-conference workshops to bridge tech, the faith and fundraising forum. And inspiring keynote speakers, Bridge offers something for every mission and every role. The conversations happening at Bridge will shape strategies, careers, and organizations long after the conference ends. Don’t hear about it afterward. Be in the room. Register at bridge.org. Now it’s time for cybersecurity on a shoestring. Welcome back to Tony Martignetti Nonprofit Radio coverage of the 26 NTC. That’s the 2026 nonprofit Technology Conference where we are all gathered together in technology community in Detroit. My guests now are Edward Wilson, principal at Arch Tech, and Ellen Samuel, COO at Just Tech. Edward, Ellen, welcome to Nonprofit Radio. Thank you for having us. I’m very glad you’re with us. Your topic is cybersecurity on a shoestring, safeguarding nonprofits in the age of AI. Um, Ellen, could you do, uh, just give us a 30,000 ft view of the topic before we go into the details? Sure. So we wanted to make sure that nonprofits understand the importance of, uh, cybersecurity and securing their technology and their. Staff and the client information and data and we went through how we can do this, uh, affordably or as affordably as we can. So, um, we went through the importance of why, why, um, nonprofits are at risk and how they are attacked and then, uh, some, uh, list of things that nonprofits can do. Relatively cheaply in order to maintain their security. And then we had a bit of a dive into business and compromise and wrap things up at the end with some amazing questions from the audience. OK, well, we’re, we’re gonna talk about all that and uh maybe even some of the questions. We’ll see. So we’re gonna, we’re gonna go into some details. So thank you very much for uh giving a high level view. Um, why are we, uh, Edward, let’s turn to you. Why are we, uh, nonprofits at risk? How are we at risk? That’s a great question. One of the things that we run into with most of our nonprofits is that there is more demand for their service than there is budget to help them meet that demand, and that leads to a lot of difficult decisions along the way. Nonprofits are actually the number 2 target these days for cyber criminals because they’re aware that there’s some weakness in that area where we haven’t strengthened the whole picture. We underinvest in cybersecurity because we’re more devoted to mission and programs. Yes, and sometimes I think there’s that, again, it’s an education thing, right? So we’ve seen nonprofits who have spent a lot of money potentially covering one small space of what they need to work on. But leaving other picked areas of the business not covered. And so our goal was to help them get that 360 degree coverage for less than they might spend on one fancy tool on a shoestring, or cybersecurity on a shoestring. By the way, I love we have like some symmetry. Edward Nellen, Archtech Just Tech, uh, it all, it all seems to fit together very well. I wish he had the same. I wish you had the same initials, your last initial. Maybe you could change your name to Samuel. Edward, maybe you could change your name to Samuel. Yeah, Samuel’s, yeah, Ellen Samuel. It’s cool, like Ellen Samuel, Edward Samuel, Arch Tech, Just Tech. OK, we’ll, we’ll, we’ll work with, work with what we have, you know, it doesn’t say he’s, he’s, he’s open to the idea, but he’s not about to run out and do it, so change his name. So, all right. Yeah, all right, all right. So we’ll stick with the, uh, I like the architectch just tech. All right. Um, so, I don’t know, should we just do like do ping pong? Like you have 10 essential, oh, let me, uh, I do have a threshold question, um, from your session description, 10 essential security measures every nonprofit IT team can implement right now, do we have to have an IT team? To do a lot of these 10 essential security measures, or can we do it if we don’t have an IT team? Maybe would outsource IT vendor helping us. Is that OK? Or do we need to have an internal team? Absolutely we understand that most, a lot of nonprofits don’t have probably most our listeners are small and mid-sized nonprofits. We’re the other 95, we’re the other 95%. So exactly. So we have one person who is the IT team and they’re not trained in that. Um, that’s one of the services that we as new service providers provide more affordably to nonprofits is we can give them those services and that expertise without having to hire a full time. OK, OK, so we can still take advantage. Of the 10 essential security measures that every nonprofit can implement right now without breaking the bank, we can still take advantage of these. Absolutely. Otherwise the mics are going off and we’re done. We’re done in fewer than 5 minutes. All right, that’s good. Whether they have an in-house team or they’re using an external team, that list of top 10 items is a great checklist to walk through. And say, am I covering all of these things with our in-house or external team? So for decision makers, really important. All right, let’s get into the, let’s get into the 10s, kick us off. Give us numbers 1 and 2 because we’re not going to go 1 Samuel, I mean 1 Edward, 2 Ellen, Edward, Ellen, Edward. So let’s do like 2 or 3 at a time. Edward, give us our top 2. Sure, the first thing we say is that you need to identify where all of your information systems actually are. People store information in a lot more places than they think. They may think a server or an email system, but you’ve got your accounting platforms, your HR platforms, your telecommunication platforms, your backup platforms, backup email, online giving, making sure that you understand all the places that you need to protect, controlling what we call the information system boundary. And then we want to protect access to that by protecting the users who access it with things like MFA passwords, and so on, and even protecting the devices that access that where we can. OK, is that 1 and 2? That is 1 and 2. OK, so number 2 is the protection of the data once you identify where it all is, protecting that access. Absolutely. OK, protecting access. All right. Ellen, it’s your turn. So one of the highest ROI things that police can do or organizations can do is implement MFA multi-factor authentication. And this, for anyone who doesn’t know, is a way of logging into systems. Using both a password and something else. So a token, um, a text message, we all know about this using from our bank, um, other systems. It is one of the the best ways that you can protect your users from being Attacked or or people giving up their credentials to your system and it’s usually free or easily to easy to implement and uh we see a surprising amount of organizations that just don’t have it turned on. They just haven’t checked the button and we need to do it. OK, so number 3 is do MFA.A. It’s just, it’s just an extra step. I mean. Uh, I, I think initially maybe it was annoying, but now it seems like it’s just, OK, I’ll, I’ll get the text. I don’t know. Maybe this is true on Android phones. I know on iPhones you get the text and you don’t even have to put the numbers in. If you’re on, if you’re on the phone, it just says use, use from text. Put the numbers, yes, tap that and it fills in the 5 or 6 numbers. So you don’t even have 5 or 6 keystrokes that you have to do, key taps, I should say. So, all right, do MFA number 3. All right, what else? What else for? Talk about also changing your default credentials to your hardware that you get. So you get um a camera that comes with uh default credentials that are open and available. That information’s on the internet. And anybody can come in and log into those systems and do kind of nefarious things with those. And it’s really easy and cheap. It’s free to go in and change that information on your routers, on your Internet of things devices. Just go in and change those things so that people can’t come in and look at your video or get into your system because they’re because they’re standard format defaults, right? It’s like, yeah, I just right. I just learned one, you know, on WordPress, the admin, the admin URL is standard like WordPress slash admin hyphenWP or something like that, or WP hyphen admin like, so everybody knows that and, and it’s easy for a bot to, to. To exploit it, OK. And that also, that, that also applies at home, like your, your ring, your ring system, your refrigerator, whatever, you know, whatever, like you, you mentioned the internet of things. I’m just, I’m just drilling down. Whatever you’ve got, it came with some default admin password. Your, your home, well, home as well as office, um. Um, internet access, Internet, right? It’s like Ocean 307 is your Spectrum router default, yeah, change, yeah, Ocean 307. That’s not mine, right? That’s not mine. That’s not mine. That’s not mine. Yeah, mine is 307 Ocean. I’m very savvy about, I’m very savvy about passwords. Yeah, yeah, that’s it. No, no, don’t do that. That’s bad advice. Don’t follow that. Don’t, I don’t want anybody saying I did that, and he said it was a good idea. All right. All right, so number 4, change your default configurations on all your devices. OK. All right, Edward. Edward Wilson is up. I like the next one. Update your infrastructure. So I’ve actually got a story about this one from yesterday. One of the things we do is free security and incident response for nonprofits. They can just call us and we’ll help them out if they run into a security incident. And our most recent call came in yesterday from somebody who had had their router hacked, and they were using an old Ocean Ocean’s 307. It works. It works. You use that everywhere. That they were using a Cisco router that had been installed in 2014 and had gone end of life in 2020 with no additional security updates, and the interesting thing was as we got into this and we looked at it, the last time that it had been updated, the firmware on that was in 2014. Well, they hadn’t even done the updates from 2014 to 2020 we’re 12 years behind on updates for this, and that’s one example of just needing to keep that infrastructure up to date. On our laptops it’s our Windows OS updates. It’s our third party software patching, which a lot of people don’t think about. The browsers that we run, Adobe, keeping all those other programs that are on our computers up to date, so you just click the automatic, just tap the automatic updates option. A lot of times that’s going to take care of Windows, but it might not take care of everything else, so IT teams want to be conscious of that. OK, OK. Update the infrastructures. All right, that’s incredible. So they even, I mean, so the, right, the product had been no longer um supported since 2020. But even before that, from 2014 to 2020, they hadn’t done any updates. Missing six years of so, yeah, right, like 2015, it was out of date for the, and, and, OK, that’s a bad situation. Honestly, we were a little surprised it took so long for them to get hacked given that you’ve been lucky all these years and you should be, you should be thankful. But we do these um technical assessments, both our organizations do where we’ll go in and we’ll look at organizations and one of my very favorite standards for us to look at is the HIPAA compliance standard, the HICP that the government publishes and puts out there for free. And the smallest one that’s designed for physicians’ offices of less than 10 physicians, the average score on that is about 50%. So this is common in the nonprofit world. All right, you have one more, Edward. We’re doing 2 at a time. Got it. I like using the firewall, making sure that we’ve got that set up. We used to be very complex in our firewall setups, and now that we’re more cloud-based, that becomes less important. We want to secure the user and device no matter where they are. But firewalls still have great tools to help protect us at the office. And so just making sure that we’ve implemented many of our vendor best practices. It’s the same among most brands, not using some of those default configurations, making sure that the admin access to the firewalls is MFA protected, goes back to the story I just told. Change that default, make sure you change the default admin on the firewall. Yeah, but firewalls are so annoying. Yeah, they’re going to prevent content from, they’re going to prevent pop-up windows. Sometimes I need the pop-up window because I do want to subscribe to the, to the, to the nonprofits newsletters. I want the. The firewalls are radio programs and podcasts. We don’t have, we don’t use pop-up. Yeah, we don’t even, we don’t even pop, we’re not even that sophisticated. But no, all right, so how do I overcome the objection in the firewall, uh, it’s so annoying. I have to load the content directly or I’m, I’m missing out on pop-ups. I’m getting warnings from some sites. How do I overcome? How do we, how do you two at, uh, Just Tech and Arch Tech overcome these? Naysayer objections. I think that leads nicely into one of our other top 10s, which is to train your users and explain why we’re doing these things, why they’re important, what the risks are, and what these systems do. We find that our organizations really do not put the time and effort into training the people at the organization. About how to use their technology safely and efficiently and effectively and a lot of those concerns, a lot of those issues you can handle in those trainings and talking and explaining, yeah, this might make it a little more difficult for you to do your day to day work, but it’s important because we don’t want other people getting into our system. We have really important client information that we are protecting, so. You need to make sure that you’re training, training people on technology and safety and security. OK, can we call that number 7 then? Training, training in it. OK, training, train the users. You get another one. Go ahead, Ellen. OK. Another really important thing is that when people leave your organization, you need to make sure that you are completely off boarding a lot of. Organizations just kind of missed this step. They don’t lock people out of systems. They don’t clear their computers. They, um, they don’t make sure that people don’t have access to their systems anymore, and it is a huge security risk regardless of who it is. If it’s an intern or volunteers in particular, you know, they just kind of set up. Forget about them, but people can do a lot of damage and the systems can be opened and hacked if people are not properly. OK, so it’s more than just taking back the ID card. There might be a code for entry. They might have a personal code for entry into the office. You got to disable that code. You don’t want these people coming back. You just, you just perp walk them out. Let’s not have them come back on Saturday. Using their their personal code to enter the building. Another thing that we recommend is using a password manager because a lot of our organizations, even though they shouldn’t share passwords among their staff, and for example, we do use a, we, um, work with a lot of law firms and sometimes there’s court passwords and court system passwords that you have to. Share, um, and giving those out to people and having them save them themselves is really a risk. So having that in a company provided password manager that can better protect that information as well so that when somebody leaves they don’t have access to that. Oh, that’s interesting. OK, so there are some that have to be shared. OK, yeah, Edward, one that would be really interesting, I think, for your users is to realize that when they’re on that company device and they’re saving passwords to their browser, we’ve seen people do things like log in with their personal Gmail account. Not only is this problematic in terms of saving their passwords to their personal Gmail account, but when they leave the organization and they give the laptop back to IT, there’s the potential to get in and access that information. And this will lead users to support the adoption of company password managers. Highly recommended. OK, Edward, thank you. That’s a good one. That reminds me of a story I heard. The organization provided company phones. But uh I recently. Dismissed employee. Didn’t use the company phone. All her personal info was on her own phone, and all her company info was on her own personal phone. They took the personal phone, or, or maybe it was the other way around. She, she had all her personal info on the company phone. That’s what it was. She lost all her contacts because they took back, that’s what it was. She had everything on the company phone, they took back the company phone. They took it. She lost, like she had to ask for permission, you know, can I call my husband to let her, let him know that I, I don’t, I’m not employed anymore. Um, yeah, I mean, she lost everything, all her, all her personal contacts gone because it was on the company phone. Big mistake. If your company’s giving you a phone, you gotta, you gotta use it just for company info because if, even if you’re, you know, you don’t necessarily have to be perp walked out. You might, you might resign. You might go to another job when you’re surrendering your company phone, you’re surrendering everything that’s on it. Very risky, very risky. All right, that’s a good one. OK, so off board completely, that was kind of we spun off from offboard completely. So I think we have 2 left. Is that, does that sound right? One of my favorites is to separate admin and user accounts, and this goes out to the IT staff who are logging in as an administrator every day on their systems. If you’re logged in as an administrator and somebody compromises you, then they are the administrator, right? And so it’s really important that we have a daily use account and that we keep those admin credentials separate for only admin purposes. Don’t don’t share the admin credentials because it’s easier. OK, just use this, just use this and you’ll be able to change your desktop. Never. Share admin credentials, but also if I’m an IT administrator, I need to have an account that I’m using for daily work that does not have administrative privileges. The only nonprofit I’ve ever seen truly go under from a cybersecurity personally that I’ve seen go under from a cybersecurity incident happened because the IT director was just using their admin account for regular work all day long. They hit the wrong link. They ransomware the entire organization. I see. Oh, using, OK, using their admin account for day to day. All right, now I see the implication because now the attacker had admin privilege, had admin, right, right, right. They hacked the admin account, not just the user level account. OK, that’s an excellent one. You love these. I can tell you, Edward, Edward’s like smiling. He loves all these. I mean, Ellen is smiling too, but Edward’s OK, gleeful. Edward’s like gleeful. Ellen is just smiling. All right, passionate about making affordable cybersecurity a reality for folks because sometimes these are things we don’t work, work through or think about. All right, that’s why we’re cybersecurity on the shoestring here. All right, you have one more left. Are you? Deferring to Ellen for the final. OK, OK, because by right this would be Edwards because we’re doing 2 by 2, but he’s surrendering. Chivalry is not dead. Chivalry has not died. It’s, it’s embodied here in this seat. That’s right. So it’s a trade-off. Yeah, yeah. OK, go. So another thing that organizations really need to do is have a disaster recovery and business continuity. We see again organizations this is something that you don’t need to hire somebody for, uh, but you can, um, but you need to make sure that you have a plan in place if and when you are compromised um a lot of times we hear it’s not uh a matter of if you’re gonna be compromised, it’s when, and a lot of places actually don’t even know that they are currently compromised. And there’s people in their systems you can if you get ransomware then you get locked out of your system that’s not the time you wanna figure out what are we, who am I supposed to contact? Who’s our cybersecurity insurance provider? Who are my IT people? What is the cell phone number of the IT person, right? Like these things that you need to have worked on, have written out. I even recommend printing them out like old. School having a physical printed copy because when you’re locked out of your systems, you’re not going to be able to get in there and look at the documents. You’re the, you’re the second guest here at NTC to say print your disaster recovery. She, she and I were talking about disaster recovery and incident recovery, and she was making a distinction between the two, but she and, and the business continuity plan have these things printed because when you’re locked out of the cloud. You’re locked out, so you can’t get the, you can’t get the IT cell number, so print the things and keep them in your office and and keep them at home too, keep them at home too, because a disaster might be in your office. You might have a fire or flood or some emergency that you’re not allowed in. So you go back home and there’s your printed plan and do practice runs. Because, you know, you, you don’t know where your weaknesses are, you don’t know how it’s gonna go until you’ve practiced and gone through the information with everybody on the team who needs to know that information. So do it a few times a year. It’s, it’s always more things that people have to do, but it really is gonna save you time and money and the safety of your information when you get hit. Awesome. I love this. The uh Ellen Edward show. Ellen and Edward show. We have our own Arch Tech, just architectch, Just Tech, Edward Ellen. OK. Um, so there’s our 10. We’ve, we’ve, uh, enumerated our 10 and gone into some detail on each. You mentioned business email, something about business email. Don’t hold back. You talked about it in your session. You got to share it with nonprofit radio listeners. What is it about business email that we need to know? So we’ve been doing free security and incident response for nonprofits for about 5 years now, and we’ve only seen one incident that wasn’t compromised email in some way or another, and there are two main categories of that. The first is financial compromise, and it’s not an IT item. It’s actually for the finance team. Never change a payment method or process without picking up the phone and calling somebody. We’ve seen vendors get hacked and the vendor submits an invoice and says, please pay this invoice over here, and it looks completely authentic. They pay the invoice only to find out that they paid to the wrong account, the wrong person. That money is no longer recoverable. That’s a finance issue. But even on the IT side, there’s a lot that we can do in order to protect email. And in our session we went through how to get that number to close to 0. All right, let’s do it. We’re not just going to talk about what we talked about in the session. We’re going to talk about the substance here. Excellent. What do we do? There are front end and back end protections in email. OK. Front-end protections involve products like Proofpoint, Mimcast. They scan our incoming email to find bad things and make sure you don’t click those. You can actually do a lot of this for free in Google and 365 without even using those products, and I don’t know how to tell our listeners to download things, but if you put our contact info in, they can reach out. We distributed a step by step how-to for all of the attendees to harden those email systems, and I’m happy to send that out to. OK, what you should do is give me the URL. For where that where that is, and I’ll include the URL in the show notes. Perfect. OK, we’ve got you got to make sure you do it. Somebody has to email me and then when your show is going to be aired in your episodes show notes, I’ll include the URL. Excellent. OK, OK, so we can get we’ve got several downloads in there for you. All right, all right, but we’re going to walk them through how to protect that email account and get the odds of their being compromised as close to zero as we possibly can in this technical environment, and a lot of it involves backend protection. Eventually, no matter how good your front end protections are, an email is going to get through. The user is going to click a link. They’re going to enter in their credentials, their MFA, and they’re going to give that MFA token that access to a threat actor who now has access to the email account, and our ability to detect that, respond, and to shut them out automatically becomes key. OK, OK, Ellen, is there more we can talk about around? Business email safeguards. Just to echo what Edward said, nearly every attack that we’ve seen has come in through email and somebody giving away their credentials. So you’ve got the email issue, right? If those emails never come in, that’s great. But then you also, again, have MFA. That’s if, if an email does come through and somebody tries to give away their credentials, that MFA can stop the, the bad actor from getting it. All right. Business email, very, very common method of exploiting. Nonprofits, I would guess it’s in the 99%. You said everyone, everyone, everyone except one, yeah, in a, in a test that you did or in our experience where we have nonprofits calling us and saying we’ve been compromised. What do we do, right? And we try to help them through that process along the way. It’s been email every time but one, in the last 5 years. All right, I’ll tell you what, Edward, you’re so gleeful about this, passionate, I’m passionate about it. Why don’t you take us out since Ellen gave us the overview. You could take us out with, uh, you know, inspiration and empowerment, why cybersecurity on a shoestring is so important. I want to emphasize to our audience that we want to solve the problem with one expensive fancy tool, but usually that only covers a small amount of our attack surface. We want to look 360 degrees at the whole picture, and there are two open source sources that I would like to refer people to that are free and available online. One is the HIPAA standard, the HICP. They can start with Volume One. It is simple. It is approachable. It is designed for mom and pop doctors’ offices with less than 10 physicians. It’s written in clear, clean language and we’ll give them a checklist to start walking through. OK, so it’s valuable for nonprofits even though we’re not a doctor’s office, even though you’re not a doctor’s office. Every time it says PHI, protected health information, just insert my sensitive and protected information. And you’ll be fine. Excellent. OK. And number 2, number 2 are the CIS controls, the Critical Information Security controls, and that also is open source. It’s available to everyone. I prefer the HICP because I think it’s more approachable and a bunch of really smart people sat down at the table and said, how are we actually being compromised and wrote a list on that. To protect healthcare providers and number 1 is email. All right. And the second resource was CIS, the CIS controls. And what does CIS stand for? Critical Information Security Controls. But somebody may have to test me on that acronym later. CIS controls. The CIS controls version 8. If you Google it, it’ll come right up at the top. OK, but your preferred is the H. The HIC HICP, and this is actually HIPAA, yeah, it’s put out by the Department of Health and Human Services. It’s available online. It’s a free download, HICP Volume One. Outstanding. That’s Edward Wilson, principal at Arch Tech. It’s named Arch Tech because they’re in Missouri. The Arch. Ellen told me that before. It actually was supposed to have a play on the word architecture because we believe good design can solve most of your problems in advance. OK, I thought about that possibility, but then when she said it’s arch tech, it’s not, it’s not architect. So is it, is it architect or architect? To be fair, how do you want to say? How do you want it said? We call it Arch Tech. I started pronouncing it Arc Tech, but we’re in St. Louis, so the point applies. About 6 months in, I realized it was going to be Arch Tech forever because of the St. Louis Arch. I see. All right, so it’s, it’s evolved into it is Arch Tech, so I said it correctly. All right. Can you say? I think that is pretty easy to say. Yeah, just. Just, just tech. J U S T T E C H. That’s Ellen Samuel. She’s the COO at J U S T T E C H. Just tech with a hyphen in between. Well, if you’re typing it, you, you don’t want me to say just hyphen tech. The company is just hyphen tech. No. Oh, well, all right, well, they, they’re gonna Google Ellen Samuel too, uh, but the website does have a hyphen if, if you need that. OK. Edward, Ellen, thank you very much. Great fun and value. Thank you. Thank you for the value. Thank you for sharing. Thank you. Thank you, and thank you, listener, for being with Tony Martignetti nonprofit radio coverage of the 2026 nonprofit Technology Conference. It’s time for Tony’s take 2. Thank you, Kate. Thank you and 10. This is our final show from the 2026 nonprofit Technology conference where we were all together, as you, as you hear, episode after episode in uh Detroit, Michigan. I’m just grateful for the partnership. They take good care of us. They appreciate the value that we bring to the conference, promoting it for months after the conference. Amplifying their speakers to our, our complete audience, way beyond just the folks who attend the conference. So, and I appreciate the, the value that they bring. They give us, Accessibility and, and exposure for the show. And I appreciate the, the partnership and the collaboration for N10 year after year. This year was our 13th. Next year, I’m already looking forward to it. It’s in Portland, Oregon. It’s in March of 2027, and we’ll be there for our 14th. NTC So, looking forward to that. Thank you very much again, and 10. I’m grateful. Listeners, again, I apologize about the audio. It was. It was your lackluster host. I’ll make sure, uh, well, I mean, I’ll do everything I can to make sure it doesn’t happen again. Thanks, thanks for understanding. Kate, Are we coming up on episode 800? We most certainly are. This is episode number 798. 0, 2 more. Absolutely. We’ve got just about a buttload more time. Here is make confident tech decisions, finishing our 26 NTC coverage. Welcome back to Tony Martignetti nonprofit radio coverage of the 2026 nonprofit Technology Conference. We’re all gathered in Detroit, Michigan. This is the final day. With me today is Simone Carvalho, with me right now today, Simone Carvalho and Rebecca Kaplan. Simone is principal consultant at Skeleton Key. strategies and Rebecca Kaplan is senior director of member grants strategy and operations. That’s member grants strategy, not member grants, strategy and operations. She only has two things, not 3. Rebecca Kaplan is senior director of member grants strategy and operations, so operations modifies the grant strategy and the member modifies the grant strategy. So it’s a member grant strategy and operation. No, it’s quite simple. No, no, member grant strategy. And operations at Feeding America. OK. Welcome. Welcome, Simone, Rebecca. Thank you. Good to have you both. Thanks for having us. Pleasure. It’s a pleasure. Simone, would you do an overview? Give us like a, you know, a high level view of the topic to kick us off, please? Sure. Um, so Becca’s here with me today, and we’re at non, uh, the nonprofit tech conference to talk about competent tech decisions, um, and we specifically talked about the tech assessment framework. So a technology assessment, um, is a structured evaluation of an organization’s current technology, the underlying processes, and the capacity, um, within it. Um, and we walked through, and I’ll probably we’re going to do it here, yeah, yeah, yeah, I’ll walk through in detail. We’re not going to just talk about the session here. We’re going to talk about the topic here, yeah, um, the phases of the tech assessment, when to like anticipate or when you should really consider having your own tech assessment, whether or not you should involve consultants, um, and then ultimately like what are the potential outcomes on the benefits of conducting a tech assessment. OK, thank you, and I should have said that the topic is. Assess, don’t guess, a framework for confident tech decisions. All right, all right, so thank you very much, Simone, for getting us started. You can take off your little uh Mini Mike. OK, so we have uh the the opening threshold question. Let’s turn to you, uh, do you go Rebecca or Becca, do you prefer? Either Either is fine. You go by Becca, can I call you Becca? Is that all right? OK, OK. And then at the end I’ll say Rebecca Kaplan again, keep it formal for people who want to connect with you on LinkedIn. OK, Becca. So how do we know whether we should or we are ripe for an audit, an assessment of our uh tech stack? Yeah, so I can talk about Feeding America’s experiences. We think about it as internal triggers that might indicate your needs, something like this, or external triggers. Um, so that’s when you hear people say things like, oh, I’d rather look at this in my spreadsheet, or there’s workarounds, right? So those are some common links. And for us, um, we were deep in the workaround. So, for example, I do grant making, so getting funds out to a few things. And in order to pay our grants, we needed to download payments from our grants management system, reformat them in Excel, email multiple spreadsheets, when appropriate opportunity to our finance department for finance to upload in their system. OK, like it’s 45 different steps, and a lot of it manual or it’s all manual, right? And then we had no good record of our payments. They were in email, they were in spreadsheets. Finance had them, but they weren’t connected to our brands. So that was his workaround, his back side. The other was staff morale. So our system was a legacy system. I’ve been using it over 10 years. For close to 10 years rather, and it was slow. We had permits issues and staff morale was suffering and we knew that formally from our engagement survey. OK, OK. Things look bad and lots of, lots of multi-step processes that humans are involved in and employee satisfaction was low or mediocre. We were just frustrated by the technology and so are our grantees and so when it was also affecting our network partners, that was another trigger. OK, uh, Simone, sound like, looked like you may want to add something. Yeah, yeah, I can talk about, uh, so when Becca mentioned like external and internal triggers and goals, I’m borrowing that framework actually from change management. So change, uh, management theory often talks about like organizations change basically when they’re forced to, um, and External triggers. So Becca talked about like the specific scenario of Feeding America that initiated her tech assessment, but other organizations might hear whispers of a hedge fund has purchased your product and you’re gonna be sunsetting it, or, you know, they’re going to suddenly hike up the prices. So there’s external factors that are pushing you. Um, or perhaps like an external, that would be an external trigger. An external goal would be something like we want to aspirationally just be better serving our clients. We’re expanding our geographies internal, same thing, there’s internal triggers and internal goals where it’s coming from inside the house. Um, perhaps there’s a change in leadership, like employee dissatisfaction. Employee dissatisfaction was a great one. Um, that was like super interesting to learn that it came up in like her employee surveys, um. It could be the change in leadership or you could just simply find that like the processing is taking 3 days and 6 months. OK, all right, these are troubling symptoms, but, uh, but we have a, we have a therapy, we have a treatment. It’s a, it’s a tech, tech audit. Uh, I’m going to tick through some. I, I think these are your, your, your, your phases or your processes. I want to make sure for an audit that you’re looking at there’s a discovery, analysis, prioritization, and a roadmap. OK, and you’re including your people processes and your strategy. OK, let’s talk through these. That’s, that’s a great overview, but that’s all I can do, uh, like tick through. Let’s let’s talk about who the, who the folks are and what the processes are that should be involved in your, in your, your tech audit. Um, so, taking like one step back really quickly, uh, the reason why our tech assessments aren’t just about the technology is that, um, we often think about Technology as like one leg of a three-legged stool where it’s technology, people, and process all supporting strategy. So if one of the legs of the stool is a little bit wobbly, you know, you could potentially top it over. So our tech assessments aren’t just looking at purely the technologies and the systems itself. We always in our discovery and all these phases think about the underlying processes and the capacity and the folks. So, the first phase discovery is pretty self-explanatory. It’s lots of interviews, group discussions. It’s trying to glean as much information as possible. Um, and we often Uh, are pulled in because consultants don’t always have to be involved in it, but can be helpful when you find that perhaps you don’t have the internal trust or buy-in from folks and they need like an objective third party because I think that’s the thing consultants can bring more than experience is there’s a neutral third party that folks might feel uncomfortable discussing their, you know, system secrets with, uh, so that’s discovery. You’re gleaning as much information as possible and perhaps you would have a survey in there. Um, I should also say before all of these phases, there is scope definition. Um, the one thing that I think we really pressed upon was the like the essential need to document and define the scope of the tech assessment, um, because we often find folks are really not lied about what is a tech assessment and what’s included in the tech assessment, and scope creep like just explodes, yeah. Um, so knowing definitively because we want to go deep rather than wide explicitly what systems or departments or processes are involved or are not. Let’s just turn to Becca for a second. So more than 1 2nd, even more than 1 2nd. Becca. So what was the experience at this phase for Feeding America, discovery phase? Like, were there people who wanted to participate, who shouldn’t be, or people who didn’t want to, who should be involved, and you know, how did that discovery phase go for Feeding America? Great question. So Skelton Key did probably over 50. Interviews with stakeholders across many departments. So if you think about grant making, it’s touching finance, it’s touching development, it’s touching the teams that are, um, programmatically overseeing the grants. So we were lucky that folks are really invested and interested. Helping us define the processes of understandings and responsibilities. So the discovery was exciting for us because we had a lot of feelings about our system, um, and the mostly negative. Mostly and also dreams but about potential too, good feelings about potential, but frustration in the in the moment. Exactly. So we’re excited to come through like it would be really cool if those sorts of ideas, um. So I think there’s a lot of buying in the discovery of this in America. Yeah, cool. All right, all right, um. Should we, can we move to analysis? Is that all right? So we’re in our analysis phase. Analysis is taking the blobs of information and doing something with it. So, that’s when we start like actually combing through what we’ve collected through documentation and interviews and discussions, surveys, and we’ve compiled. There’s a couple of different outputs. It ultimately depends on like, you know, back in the discovery phase and when you’re defining your scope and the, the thing that has to be clearly defined is like what question are we trying to answer for Feeding America, I’ll let Becca speak to that, but there was some big questions. So, Some of the key outputs of this um analysis is developing user stories. So these are like human centric requirements. Um, so as Becca mentioned, it was like very future facing and aspirational. As a grants manager, I wanted to XYZ in order to fulfill a specific business, uh, objective. There’s process maps, so visualizations beyond the grants of managers, the grantees, right? I’m sure you interviewed some grantees among those 50. And the aspirations for them. Oh my God, these emails that I get from Feeding America, I mean, I love having their support, but my goodness, it’s enough, enough is too much. It’s too much already. These are, these are Becca’s emails coming that they’re commenting on, but yeah, but among the grantees, right? Yeah, OK, OK. Um, and then there’s process mapping, which again is typically like aspirational and future facing and folks really like that because we are daydreaming about like what I want my pieces to look like in the future. Um, and then, as I mentioned, you just get lots of information and not all of that information is like specific to the technology and especially with New America, we just started compiling what we called a process improvements inventory because there was lots of things outside of the GMS, the grants management system, like ownership struggles, everyone owning a thing. that also needed to be addressed before we talked about the actual technology systems. OK, so there’s the processes, the people, and the technology as well. All right, cool. It sounds like you really need an outside. Facilitator, coordinator of this kind of audit, I mean, I don’t know, can an internal IT team do it now? You have to be, I’m asking you to be objective, Simone. I do actually do think so. The key question to ask or for someone to determine whether or not they can do it. Internally, there’s a couple of things. I think the first thing is capacity, because it’s, it can be done internally. It ultimately depends on what is your timeline. So if it’s an external trigger like, hey, we’re going to be sunsetting your system, you might not have the internal capacity and velocity to get it done in 6 weeks in the way you need to. Um, there is also just that, that question I raised earlier, which is, are your stakeholders going to be honest with you? Sometimes there’s like the benefit of relationships, or, I’ll say more to an outside consultant than I will to a colleague in the IT department. Sometimes we’re the therapist, the data department, yeah, OK, OK. For us it’s also leadership buy in. So we, one of the reasons we brought in a consultant was that in order to have the business case to invest in the system. They wanted the confidence that consultant. Ask members to make that decision. OK. Leadership buy-in is important for a project like this, right? Everybody’s got to be participating, uh, and that encouragement comes from the top, plus there’s the budget, the budget. Uh, I was thinking of conflict. I don’t know why I’m focused on conflict, like people who don’t want to participate that should, or I said people who should participate, don’t want to, I don’t know why I’m focused on the negative, uh, but there’s also, you know, there can be decisions to be made, like about the scope, which is going to impact the budget, the scope of the audit is going to determine how much we’re spending on this, this venture, right, OK. Yes, leadership buy-in. Thanks, Becca. Excellent. OK, um, prioritizing. Becca, can you lead with prioritizing? OK, let’s mix it up a little bit. Yeah, yeah, so we had a long list. OK, from the analysis phase, yes, right, from the analysis. Ths of the things that we wanted to do and accomplish through this transition and we used, um, Simone mentioned it, but, uh, basically a uh prioritization framework that allowed us to think about what was the effort and what was the. Where we’re going to be. Um, and we picked a mix of things on our prioritization list, some that would be the That we can actually confidently accomplish some that were going to be really difficult and really important and then some in the middle so it was a realistic mix it had to be everything, um, and that framework really helped us. You can actually accomplish. OK, you want to talk to the framework, Simone? Yeah, um, so it was a pretty simple one for Feeding America because they did have a really long list, and I think the thing I would emphasize here is, um, and as we talk about roadmap, there’s the low hanging fruit, but there was also things that needed to be immediately addressed regardless of the system. Um, that were pain points that like had to be addressed regardless of how long it took to go to from existing. OK. You might also be looking for maybe low lift and high impact or it affects a lot of people and this one is not going to be difficult to do. Boom, that’s obviously a top priority confidence and buy in into like, oh, this was worthwhile, right, like versus the other quadrant, the, the quadrant opposite that one which is high lift and low return. You probably had some of those. OK, so what happens to those? Do they, I mean, realistically, do they never get done? I mean, I hope, but that brings us to the roadmap roadmap and also the scope. I mean, there’s only so much, there’s only so much we can do together. There’s only so much Feeding America is willing to pay for, so some of these things are not going to get done this, like this year as part of this process. OK, I’m sorry, that brings us to what you say, the road mapping. OK. Oh well, well, even the lackluster host can provide a decent segue. OK, good. What’s the roadmap? Yeah, so it’s, you know, you. Collect all this information, we’ve analyzed it. You have all these artifacts, you have this list of prioritized things, but now it’s about putting it down on paper, assigning ownership and like actually planning some scenarios, allocating a budget, and putting it on. And we got asked this question a couple of times, but like, what, how big is a roadmap? Um, we tend to do like two versions of the roadmap. There’s the immediate needs roadmap, right? Like we mentioned, there’s typically things that are like immediate pain points that have to be addressed in order to like, help people and their morale while migrations take time. Um, so, you know, between choosing and actually migrating to a system that could be a little easier. And so there are things that just have to be addressed in that year. So, we usually do like a short version of the, the roadmap. So, it’s gonna be like 3 months, the next 3 months, you know, the immediate things you guys can do based on how much capacity or budget you have. And oftentimes, we’re actually not doing these activities, we’re giving it back to the client, um, and they can decide things. I know the key thing here is ownership, because nothing is, nothing’s going to get done if nobody owns it. Exactly. And nothing is more disappointing than like spending all this time and investment in a tech assessment, and it lands in a room full of people who have lots of opinions, but then there’s no one. To act on it, um, so that’s pretty critical. And then depending on again the size and the scope of the organization and the tech assessment and what they’re going through, it’s anywhere from like a 12 month roadmap to a 36 month road. And this also includes total cost of ownership as well, which is what does that mean, yeah, that, um, total cost of ownership. So in Feeding America’s scenario, I’ll let you speak to that, Becca, but like oftentimes the tech assessment comes on the heels of some external factor like we have to move off of the system. And leadership wants to know, OK, but going to this new system, scenario A, how much is it actually going to cost us? So it’s not just the licensing, you know, ongoing licensing, it’s the implementation and data migration, the training, the backfill of staff, the consultants, and then the ongoing costs like you’re going to have to change your staffing model and hire a new admin to help you support this product. So that’s the total cost of ownership. OK, that’s great, Rebecca Kaplan. Senior director of Member grants strategy and operations at Feeding America, and Simone Carvalho, principal consultant at Skeleton Key Strategies. Thank you very much, Simone, Rebecca, thanks very much for sharing. Thank you so much for having us. My pleasure and thank you for being with Tony Martignetti nonprofit radio coverage of the 2026 nonprofit Technology Conference. Next week, a wide ranging AI conversation with 3 experts. If you missed any part of this week’s show, I beseech you, find it at Tony Martignetti.com. We are sponsored by the Bridge Conference. Tony will be with more than 2400 nonprofit professionals at Bridge, July 29 to 31 in National Harbor, Maryland. Info and registration at bridge.org. Our creative producer is Claire Meyerhoff. I’m your associate producer Kate Martinetti. The show’s social media is by Susan Chavez. Mark Silverman is our web guy, and this music is by Scott Stein. Thank you for that affirmation, Scotty. Be with us next week for nonprofit radio. Big nonprofit ideas for the other 95%. Go out and be great.

Nonprofit Radio for September 22, 2025: The State Of The Sector (Beginning With AI)

 

Gene Takagi & Amy Sample Ward: The State Of The Sector (Beginning With AI)

This year, any conversation about the nonprofit sector finds its way to Artificial Intelligence. So we start there, with our contributors Gene Takagi on legal and Amy Sample Ward on technology. Amy is concerned about our lack of security readiness and shares their Top 5 security must-haves. Gene explains your board’s duties around tech, budgeting and planning. They both see resilience as critical. Plus, a ton more. Gene is principal attorney at NEO Law Group and Amy is the CEO of NTEN.

Gene Takagi

Amy Sample Ward

 

 

 

 

Listen to the podcast

Get Nonprofit Radio insider alerts

Apple Podcast button

 

 

 

We’re the #1 Podcast for Nonprofits, With 13,000+ Weekly Listeners

Board relations. Fundraising. Volunteer management. Prospect research. Legal compliance. Accounting. Finance. Investments. Donor relations. Public relations. Marketing. Technology. Social media.

Every nonprofit struggles with these issues. Big nonprofits hire experts. The other 95% listen to Tony Martignetti Nonprofit Radio. Trusted experts and leading thinkers join me each week to tackle the tough issues. If you have big dreams but a small budget, you have a home at Tony Martignetti Nonprofit Radio.
View Full Transcript

Hello, and my voice cracked. Welcome to Tony Martignetti Nonprofit Radio, big nonprofit ideas for the other 95%. I’m your aptly named host and the podfather of your favorite hebdominal podcast. Oh, I’m glad you’re with us. I’d suffer the effects of chondrodermatitis, nodularis helicus. If I heard that you missed this week’s show. Here’s our associate producer Kate with what’s on the menu. Hello Tony. I hope it’s so funny. It’s that voice cracks like I’m 14. Hey, Tony, I hope our listeners are hungry. The state of the sector, beginning with AI. This year, any conversation about the nonprofit sector finds its way to artificial intelligence. So we start there with our contributors Gene Takagi on legal and Amy Sample Ward on technology. Amy is concerned about our lack of security readiness and shares their top five security must-haves. Gan explains your board’s duties around tech, budgeting and planning. They both see resilience as critical, plus a ton more. Jean is principal attorney at Neo Law Group, and Amy is the CEO of N10. On Tony’s take two. Tales from the gym. The cure for dry eyes. Here is the state of the sector, beginning with AI. It’s a pleasure to welcome back Gene Takagi and Amy Sample Ward, our contributors to nonprofit radio. Gene is our legal contributor and principal of NEO, the nonprofit and exempt organizations law group in San Francisco. He edits that wildly popular nonprofit law blog.com. The firm is at neolawgroup.com and he’s at GTech. Amy Sample Ward is our technology contributor and CEO of N10. They were awarded a 2023 Bosch Foundation fellowship and their most recent co-authored book is The Tech That Comes Next, about equity and inclusiveness in technology development. You’ll find them on Blue Sky as Amy sampleward, aptly named. Welcome. Good to see you both. Gene, Amy, welcome back. Good to see you both as well. I actually got to see Gene in person this week, which was a real treat. But your faces coming through the internet. Where? Where? In DC in a in a meeting. Oh, cool. Yeah, it was wonderful to see Amy and hear a little bit more about her family and learn, learn about things going on. um, and great to see you too, Tony. Thank you. Last time we were together was the 50th. That’s right. Yes. All right, um. So Amy You have been, uh, you have lots of conversations with funders, intermediaries, nonprofits, uh, I’d like to start with you just. What are folks talking about? Yeah, I think there’s A lot of desire for thoughtful conversation across the sector right now and, and over, you know, the last handful of months and I’m sure the months to come. And that desire for thoughtful conversation is trying to be held in a time where things feel rapidly unraveling, you know, and A few, I think patterns have been coming up at least in the versions of conversations that I’m, I’m in, whether those are, you know, 1 to 1 with other intermediary organizations, capacity building organizations, um, nonprofit service groups or, or even philanthropy serving organizations or with funders themselves, and they’re, of course, different. You know, flavors of the same dish maybe, but I think everyone really wants to hear and help and It feels like there’s not that much help happening. Um, I think when you talk to funders are presume you’re talking about. How does that go? Like you you should be funding technology, you should be funding capacity building, you should be funding. that are advocating for things or yeah, I mean, part of what sees as our kind of theory of change in the way that we make impact is of course and directly supporting nonprofit staff through training but also shifting the conditions in which all of us are doing this work. Right, so asking funders to fund adequately for the technology and data that is needed to, to deliver the programs, their funding right is part of that or, or all kinds of other advocacy, um, big, big a little a, you know, influencing thropy, and they, and I, I have to do, so they take these meetings like they don’t mind being told what they ought to be funding. Oh, it’s easy to take a meeting. It doesn’t mean you’re making you’re implementing what’s what’s the outcome and what’s the action? I realize that. But I’m OK, I’m, I’m, I think that most of the, most of the conversations N10 is entered into with foundations are not necessarily on the premise of like, can you please give us this feedback to fund a certain way, right? We just say that when we have access to. To folks that we, that we could share it with, but mostly, um, I think in these times, just like honestly in 2020 funders and other philanthropy serving organizations are asking for what we see because we are able to see into a lot of different types of organizations across the sector, not even just in the. and see trends that are emerging, see what folks are really asking for help on right in a way where we’re not having to divulge, oh, this organization that’s your grantee, they don’t know how to do this, right? There there’s not that vulnerability we’re able to share trends and unfortunately, the trends aren’t aren’t new, but, but at least they’re asking about them right now and they. are very, um, vulnerable issues. Like we are seeing incredible lack of security readiness in organizations. And as we’ve talked about on this show, and Gin has talked about, you know, there’s a lot to be concerned about when you think of a nonprofit organizations like digital and cybersecurity because It’s your staff, it’s your content, but it’s also all of your constituents, all of those people who’ve received programs and services, and if you feel that your mission and your programs and services are vulnerable, those folks in your community who’ve accessed them are 10 times more vulnerable, right? um, than your organization is, and that’s something that I think for us we just. We care about that kind of more than anything and so it really has felt like a spotlight on security and even just to um illustrate, we we can created a new program just to try to help in this way, um, a 3 month just security focused program. We had a single email that said that it was open. Um, In 4 days, we had 400 applicants from 26 different countries asking to be in the 20 people, you know, cohort, so That was, I think, validation that we were really hearing the trend and hearing what, OK, what are, what’s behind some of these questions that we’re getting? What are people really struggling with and oh my gosh, OK, we’re right, they are really struggling with security. This is um let’s, let’s bring Gene in on uh on security. You’re nodding a lot, Gene. And, and we have talked about, as Amy said, uh, as they said, we, we have talked about it, but, uh, you know, it’s, it bears amplification, because we, we all have talked about cybersecurity, protecting data, but especially as Amy’s saying, the, the, the people you’re doing the work for, if you’re, if you’re involved in a people, uh people oriented work, Gene, remind us. Oh, I’m amplifying everything Amy says, as I’m wise to do, um, but maybe I’ll just add that, you know, when people think, including funders, when they think about technology and, and some of them are just focused on AI right now, but technology is much broader than that, of course. When they’re thinking about technology, they really have to think of it as one of the core assets of an organization, and that’s not all because it’s also a huge risk and liability not only to the organization but all to all its beneficiaries and its communities that they serve and it’s communities that they exist in so it’s all of that it’s it’s even more complicated. To manage if I might venture and say this, then your other main investments which are like in staffing and in facilities like this is stuff that we don’t have a lot of experience with it’s newer things that are coming up. We haven’t learned how to manage it very well. It’s a little bit out of control. as it develops as with AI going on we don’t even know what the laws are related to this um so this is stuff that funders need to fund and organizations need to invest in really badly and when they don’t think about doing this they’re they’re really. Living for the short term at the expense of the intermediate term because it’s not even that far off in the future where these risks will ripen. They will ripen very, very quickly now. um, so that’s my two cents. And add to what she’s saying. I talked to two different, um. Funders who are who are regional funders, not national funders, and said, hey, I know the folks that are your grantees, they’re um predominantly rural organizations. They’re predominantly very small organizations, you know, single digit FTEs. There are folks that we can see in our data, not as individuals or individual organizations, but by kind of organizational demographics, are, are very likely to have really low scores, you know, ineffectiveness in these areas. We have free resources. We’re not even like asking you to fund us necessarily, like, which I should have been asking, but, you know, coming at it from really how do we get these resources available to organizations who we know are vulnerable, and their feedback was, well, security is not an issue that any of our grantees have raised with us. And I just want to pause there because why would a grantee in the vast power imbalance between a very small rural two-person organization and a funder, say we don’t have a security certificate on our website, we don’t have secure, you know, donation portal, we don’t. Have a database protect like why would they surface these would be fun? Of course they had of course no one has brought this up, right? Why would they point you, you need to be thinking beyond what was in that grant application and about really the, the safeguarding of that mission. Not only why would they admit it, but it may very well have nothing to do with, although it’s, well, it is related to what they might be seeking money for, but it, it’s, it’s grant application. Yeah, it’s not, it’s right, it’s not gonna be a question on the grant application is your, you know, do you have a, do you have a secure fundraising portal? Um, Gene, you have some advice around board like this should be at a board level, board level CEO conversation, right? Yeah, I mean it’s where it starts to get started. Yeah, and, and very obviously like technology comes up as a budget item, right, for the board. So when the boards are approving annual budgets, are they leaving any space for technology changes? Well, so many organizations, including public governments, are, are just like putting patches, right? They’re investing in patches and so they’ll patch, patch, patch. Um, but the technology is advancing so much quicker than patches can actually address. And again, The persons and organizations at risk are not only the the charity itself, right? It’s all of the beneficiaries whose data they’ve compiled and potentially like just goes beyond that as well. So it’s really, really important now for the boards to say let’s think about this as one of our core assets and our core risks and figure out how we’re going to properly budget for this item. And talking about sort of risk opportunity, you know, assessments and saying, well, what happens I, I’m a big fan of scenario planning and maybe it’s hard because these things don’t have definitions but over strategic planning for like a a longer term plan. I think scenario planning right now is really important because the the environment is just shifting so quickly, right? It’s like shifting every few months it feels like so scenario planning for different scenarios and and some of that would be well what happens if we don’t change our technology or what happens if we don’t invest? What are the worst things that can happen? What are the likely things that are gonna happen? and do we actually have board members who understand any of this? Do we need to relook at our board composition? Do we have anybody younger than 50 on our board? And for a lot of organizations, too many organizations, the answer is no, which will hurt you in the fundraising sort of pipeline down the road very quickly as well. Um, we’re not incorporating enough, um, Gen Z, millennials into the governance and leadership positions as, as boomers and even, um, Gen X are are are hanging on to positions longer. You know, for, for a reason, for a good reason, but, um, we need to bring more younger people into the pipelines because they have perspectives. They have a lot of what’s at risk, um, here as well. So that’s kind of my thinking in with respect to fiduciary duties, in the budgeting, they’ve got to understand it. In the recruiting for board members, they’ve got to figure out how to develop the pipeline of who to bring in on the board, like in their duty of loyalty, like to the organization’s best interests, they’ve got to be. Thinking not only about the purpose or the mission of the organization they’ve got to be thinking of the values of the organization, including how much they value the community and all of this relates to the organization’s um what what I’ll call it’s. Reputation or it’s just um legitimacy to the public at a time when the government is poking holes at organizations’ legitimacy if you haven’t earned that from your own community fundraising and everything else will will just dry up so you’ve got to invest in legitimacy if you’re not investing in technology at this point and protecting persons that rely on you. To safeguard their data you’re gonna lose legitimacy really quickly and you’re gonna be irrelevant or or, you know, liable for, for what are two quick things to what Gene’s saying on, on the staff side but then also on the board side. Plus a million to everything Gene said about making boards more diverse, um, including age, but I don’t want folks to think that that means because you need to like have a 25 year old on your board that’s now in charge of your technology. The board’s job is not to be in charge of your technology, but having more folks in that board meeting who have perspective or experience a lot of different. Things are possible helps open up strategic conversations to say, hey, have we considered this? Not that I’m now the implementer because I’m the board member, but it really does help and I just want to draw that line that we’re not saying make someone on your board in charge of technology, but having people comfortable with technology strategy conversations is very, very valuable, of course. The other side on the staff side, You know, one thing we see in our research, um, and our, you know, different assessment tools and in our programs, yes, there are still organizations that don’t have all the policies that they could have, right? They don’t have strong data retention policy, they only think, oh well, payroll files or HR files, right? They’re not thinking about all of the data, all of the content, you know, all these different things, right? We can have a big policy book and there’s work to be done there. But the real area of vulnerability that we see is organizations likely have some policies, but they do not have staff fidelity to those policies. So you could like go through a checklist and be like, yep, data consent policy, data collection, you know, but staff don’t know the policies exist and they are not practicing them at all in a consistent way. And so I wanted to go back to the scenario planning note because I think we see some folks um. You know, yes, you could bring in a consultant or you could get some sort of big security like test going, but what you could also do is in a staff meeting just take that time and say right now if we got an email that we had been hacked, what do we all think we would do? And just talk it through together and see oh this person. Thinks we would do this and this person over here says, oh we have an account here. What do we have? What, what is our answer, right? What, what are the questions we don’t know how to answer? Let’s go answer those questions for ourselves and really have more um opportunity I think to surface with staff where people don’t know something, not in a shame way but in a like, gosh, this is what we should focus our training on isn’t just let’s draft another policy. Let’s understand how to do these things as the people doing them every day. Amy, uh, in, in a couple of minutes after Gene and I talk about something that I’m gonna ask him, then I’m gonna ask you something, but you, you, I don’t want to put you on the spot with no, no forewarning. If we have, let’s, let’s take a, let’s take a, our audience is small to mid-size, so let’s go more toward the smaller, let’s take a, let’s take a, a 15 person nonprofit. Uh, it, I’m not sure it matters what the mission is. I, I, I don’t want to constrain you. I want you to think broadly. I, I’m the CEO of a 15-person nonprofit. Uh, we’ve got a $4 million annual budget. Is that 2, maybe 33 to $4 million annual budget for 15 employees, full-time employees. Uh, what I’m gonna ask you in a couple of minutes is what, what are some, what, what basic things can you name for us that, that we ought to have? OK. You, I thought that was you know way, you know, yeah, I know you’re gonna start writing, thank you. Gene, I want to ask you, uh, I, I, let’s let’s talk about the core assets of a nonprofit. Uh, you, you, I love that you’re identifying technology as a core asset. Are there, are there other core assets that, that I’m not thinking of? The staff is typically number one, right? Facilities is typically a pretty big investment, although that’s been changing um with a lot of remote working now and organizations seeking to downsize how they allocate where their investments are, where their assets are. um, staffing is also changing and. Part because of some technology, right? So if technology isn’t in that bucket in there, you may be downsizing staffing, you may be reducing facilities, but why is that happening? Probably somewhat related to your technology. If your funding stays stable. I know that’s a big assumption, but probably technology is playing a part in that. Is your technology? Gonna break down like in a year. That’s something to really think about. If you’re now reducing staffing and reducing facilities, relying on technology that’s gonna break down in a year or give you problems in a year or create harm to your beneficiaries, that’s like the big one that that Amy raised that, that really hits home for me. It’s like. Now you’ve got to really rethink what was the board doing? Did you even think about that? Um, so you know as part of your fiduciary duty of care, and again I love to think of it in terms of both the mission of the organization and the values of the organization which if I bring it down to fundamental human rights, it’s preserving dignity to your beneficiaries, right? And if you’re not safeguarding your private data and if you’re letting health data flow away, and this includes your employees too, right? like. Like your key stakeholders, if they can’t trust you. Then your legitimacy is also gone, right? So you’re really just shooting yourself in the foot unless you’re doing that. So boards have got to now rethink like we maybe weren’t thinking about technology that way so much before, but as we’ve seen how exponentially, you know, um, exponential changes technology creates for our organizations and the environments and what we invest in and what our risks are, boards have got to be in the mix and I agree absolutely with with um. Amy, it shouldn’t be the 30 year old or 25 year old board member who’s like, OK, you’re in charge of the technology. Yeah, no, no, it’s, it’s, but it’s another perspective in there. Yeah, and it’s, it’s, it’s better informed, uh, look, I’m the oldest person on the on the meeting, uh, in our chat. Uh, they’re, they’re better informed, you know, they, they, they have a a fluidity, they think about things that, that 63 year old is not gonna think about or 55 year old is not gonna think about. Um, so I’m just kind of fleshing out, yeah, of course, different perspective, but how so? Because they, uh, depending on their age, they either grew up with, you know, uh, technology is an add-on to my life. And some people have had it since like age 5. You know, I had a rotary phone at age 5. And I always dialed it backwards. So, you know, I was challenged from the beginning. Our colleague, our colleague is looking up from our uh homework assignment, homework from their homework assignment. What, uh, what, what do you, what you, what can you enumerate for us? I have 5 things I wrote down off the top of my head. I don’t know that if I had. You know, 50 minutes instead of 5 minutes that I would write the blog post with these same 5 pieces, but I think all of them, I know you gave me an organization, kind of 15 people, 4 million, but I don’t think any of these. Are unique to that organization. So I just want to say that. The first is cyber insurance. I know everybody thinks like let’s make sure we have our DNO in place. Check the box for some insurance as well, you know, um. Let’s make sure everybody DNO directors and officers insurance in case you’re not familiar with that, that’s, that’s an essential should definitely have that directs and officers, thank you. Yeah. Yeah, the second piece I um put down was data deletion practices. I feel like there’s such a focus on preserving data and content at all human reason, um, but actually, Like, to what end do you have this, especially to to Jean’s point before about the dignity of people, and they’re not in your program, you’re not reporting on them, you know, to a funder, you’re not, why are you saving every bit of this if it means somehow that list is taken, you know, um, and we talk a lot in our kind of closed cohorts when we’re working with organizations. That it isn’t that we don’t think there’s value in being able to look at longitudinal data of your programs and, you know, do that evaluation, but you don’t need to know that Amy Sample Ward was the person in that program, right? There are ways that you could anonymize the data and still preserve the pieces that are helpful for your program like evaluation. Well, removing the, the risk of it still being me or Jean or Tony, you know, associated. So I really think deletion practices and policies that dictate when you delete things, how much of it you delete, what you um anonymize is really important. Third, This is, I think, hopefully more top of mind for folks since so many organizations. Maybe became hybrid or virtual or remote permanently from the pandemic and that’s content and machine backups and and redundancy. I see a lot of organizations who say, oh, but we use the cloud, right? Like we use Microsoft 365 or we use Google Workspace. OK, but in your day to day is every single document that someone’s working on in those systems and if they’re downloading it to work on it offline for any reason. Well, does it have data in it? You have constituent information in it, um, but also like if someone’s working on something and they’re You know, computer is stolen or broken or vulnerable, is all of that backed up somewhere? Do you, you know, there it’s quite simple to set a full machine backup to the cloud every day too, right? But it, it just takes thinking of that, prioritizing it and setting it up, um, including, including with that recognizing. That employees might be using their own devices. They, they probably shouldn’t be, you should be, or you should, you should at least be funding their technology, their, their monthly Wi Fi bill, etc. but beyond just recognizing that they may not even be using exclusively your technology and, and what’s the, what’s, so then what’s the redundancy and backup of on their own devices. Technology policies that say the only tool you could use is the laptop we gave you are intentionally limiting your own understanding of how those workers are working because there’s no way that they are only using that laptop you gave them. So, having a policy that says this is how you safely access our tools, whether you’re using our laptop or not, at least allows you to build the practices, the human side of security into that use instead of pretending it doesn’t happen, you know. Yes, yeah, OK, number 4 and number 5 are somewhat similar, but again this is where we see big breakdowns in practice. Number 4 is that Every system that can have it has two factor enabled and is required. There’s so many ways to do to factor that it isn’t an excuse to say that it’s like burdensome, it doesn’t have to be like, it doesn’t have to be a personal text message. It could be an authenticator app, whatever, but like you need to have to factor on everywhere, um. And need to be using a password manager so that staff are not sharing passwords with each other by saying, hey Gene, the password to, you know, our every.org account is is this like, oh my God, you know, that we can both we can both log in but it’s encrypted we don’t see the password, right? We’re sharing it um in a safe way. And then the last one, number 5, is that, again, a practice, organizations have established processes for admin access for if you get logged out of something that it is not. I email Tony and say, oh, hey, will you send that password to me? Like, most of the security vulnerabilities that we see with organizations isn’t because somebody was in a basement and hacked their way in. It’s they sent one phishing email and a staff person responded and was like, oh yeah, here’s your password, right? Like, it wasn’t hard to get in. So, If you have a policy that says you’ll never email each other to say I got logged out, what is, what is a more secure way? OK, well, I call you on the phone. We have this secure password that we say to each other that only staff know and like. I’m not saying that has to be your plan, right, but it isn’t just randomly, oh, the ED sends an email to the staff person that says, please reset my password. Like, I don’t think that’s gonna be foolproof, you know. OK, so it’s just as simple as like a procedure for what happens when somebody can’t can’t log in. Exactly, because that does happen. So why not create something where everybody on the team knows this is what we do. I know I’m doing it safely, you know, and following the procedure. OK, those are pretty, those are pretty simple. Um, so you might, you might say, well, cyber insurance, that’s not simple. It’s not like I can do it today, but you can talk to brokers, you can talk to insurance brokers for cyber insurance, data deletion policy. I’m gonna venture that N10 has a, uh, sample data deletion policy and its resources. There you go. Backup and redundancy. Do you have, is there advice about that in Yeah, there’s lots of it, but I’ll put it on our list to make sure that there’s some guidance on that on our cybersecurity resource hub, which is all free resources, so I’ll make a note of that. Beautiful. 2 factor and and password manager. All right, that, I think that’s pretty well understood. I mean, uh, I, I have clients that use the, uh, the, the Microsoft authenticator. As soon as, as soon as I hit, as soon as I hit enter on the, on the laptop, I can’t even turn to my phone fast enough. The Microsoft Authenticator app is already open, notified. I’ve already got the not in the, in the second it takes me to turn from one side of my desk to the other. The authenticator is open. Uh, so it’s not, there’s no, it’s not like there’s no delay. Right, um, OK, and a procedure for not being able to log in, uh, uh, I bet you could find that on the intense site too. All right, thank you for that quick, quick homework. Thank you. All right, all right, so this is eminently doable. And then there’s, you know, of course you have to go deeper. There, there are policies that you need to have, but you know, I wanted something kind of quick and dirty, so thank you for that. All right, all right. Um, Should we turn to just like general state of the sector from our cybersecurity conversation? Sure, um, Amy, you wanna, you wanna kick that off? You kick that off. Yeah, I do talk to lots of people and I think, you know, we’re hitting the two-year mark of kind of like unavoidability of people constantly talking about AI which I have my own feelings about, but, you know, If I step out of any one day’s conversations about AI and look at the last two years, we’re in a very different place of those conversations, you know, um, in a way that I think I finally feel good about how the trend is going in those conversations, um, a lot of one on one calls I have with, with really diverse organizations, you know, small advocacy organizations, global HQ or, you know, like all kinds of folks is. How do we not use the tools that are being marketed to us? And how do we build a tool that’s purpose-built, that’s closed model, that’s just the content we want it to have, right? And like actually useful for us. Which I think is really exciting, that folks are kind of seeing that it’s, it’s just technology, just like, yes, it has different capabilities, you do different things, different tools do different things, of course, but I’m really excited that it feels like folks are trending towards. Well, we have some use cases. How do we build for those use cases versus we want to adopt these things? How could we find something to do with these things we want to adopt, which I think was the reverse order of it all. You and you and I have a friend who is devoted to this exact project, uh, George Weiner, CEO Whole whale, they’ve created Cas writer. Yeah Horider.AI, which is intended exclusively for the use of small and mid-size nonprofits, limited, limited learning model, uh, your content safe within it and not being skilled in artificial intelligence, that’s about the most I can say about it. But whole well, they have a, they’ve, and they’re not the only one I’m sure, but they’ve created a product specifically, uh, to take advantage of. The technology of AI, but reduce a small and mid-size nonprofit’s risks around your use of it in terms of what it brings in and how it treats the data that you provided. Yeah, causes writer, change agent, there’s a number of folks in the community. You know, trying to help organizations in this way, which I think is great, um, but a trend, a smaller trend in the last couple months in these AI conversations, bigger trends like I said, but there’s also this piece where I’m hearing from folks saying that. They can tell, for example, a colleague used Chat GPT Gemini, and, you know, a large tool like that to to make this proposal that they sent to them or this email, and when they say, hey, it’s really clear that you used Gen AI tools to write this, could we talk about it and get into like your thoughts more about it? There where they had in the past felt that folks were like, oh yeah, I did, but like here’s what I was thinking. Now there’s just complete denial that the tools were used. They lie. People lie? Yes, that’s right. And so to, they’re like, well, how do we have strategic conversations about the way we use these tools if you’re going to deny that you’re using them. Well, let’s let’s talk about what, when you lie to someone about anything, especially I don’t, I don’t, it seems innocuous to me, but, uh, including AI, well, I’ll, I’ll, I’ll leave my own adjective out of it. I think it’s innocuous. It’s so the the technology is so ubiquitous, but all right, if you lie about anything, you, you lose legitimacy. I, if I were a funder, uh, OK, thank you very much. Goodbye, because you just, you just lied to me about something that I don’t think is such a big deal even. And I’m giving you a chance that I was able to point to it, you know, yeah, and I’m giving you a chance to overcome it. I want to have a chat human to human, and you’re denying that the premise of my question. OK. All right, I’m so I’m shocked, obviously, I really, I’m dismayed that people are lying about their use. That’s completely contrary to what the advice is ubiquitous advice is that you’re supposed to disclose the use. Right. I’ll just throw in there that. Please, Gene, get me off my, push me off my soapbox. Well, back to kind of board composition, if you ask a bunch of board members, I think many of them. Would say AI is just like one thing. They have no idea that like AI is a million things, right? And you’re probably using many, many forms already whether you realize it or not, even on a Google search, like, you know, AI is popping up now you might, that might be a little bit more obvious now, but. Just to, to know that AI if I compared it to a vehicle, for example, it could be an airplane, it could be a bicycle, it could be a tank, right? They they all have very, very different purposes and repercussions and so you have to understand that like, oh we’re gonna like invest more in AI. That doesn’t mean a whole lot. So, um, to figure out what your what your strategy is again, I, I, I think, um. Cybersecurity and when when organizations are gonna venture off into AI a little bit more they’ve got to see it as part of governance and not just information technology it’s not just the uh a management tool it’s part of their governance responsibilities. It’s time for Tony’s Take too. Thank you, Kate. Got another tails from the gym. This time, two folks whose names I don’t know yet, but I do see them. Fairly often, they’re not as regular as Rob. The marine semplify or uh Roy, I’ve talked about Roy in the past, not, not, not as common, but we’ll, we’ll, we’ll find out. Like I did find out the uh name of the sourdough purveyor, you recall that just a couple of weeks ago. Uh, I, I’m gonna hold her name, it’s in suspense now, but, uh, I learned her name, the, the one who gave the sourdough to to, to Rob. So these two folks were one of them, uh, the guy. Suffers dry eyes. And the woman he was talking to had the definitive. cure for dry eyes. You have to try this. And she was on him for like 5 minutes, you gotta try this. Hold, hold on to your, make sure you’re sitting because you know you’re not, you, you’re not gonna wanna, you’re not gonna wanna stumble and fall down when you hear the startling news of the dry ice cure of the uh of the century. Pistachios, pistachios. She was very clear. 1/4 cup. She, she did not say a handful, which to me a handful is a 1/4 cup. She didn’t say a handful. It’s a 1/4 cup of pistachios daily, right? This is a daily regimen you have to follow and you will get results within 3 to 4 hours. She swears it 3 to 4 hours, your eyes are gonna start watering. It’s gonna be like you’re crying and tearing, like you’re at a funeral or a wedding. That’s how much water you’re gonna have. All right, I editorialized that I added the wedding funeral, uh, uh, analogy, but she swears within 3 to 4 hours your eyes are, are gonna be watering. Follow the regimen, pistachios. She was also very precise. These are shelled pistachios. You don’t wanna get the, uh, the unshelled ones too much work, uh, which to me that’s interesting now that’s, that’s contrary to the advice that I’m hearing on, uh, YouTube. There’s that guy on YouTube, the commercial that I always skip, but sometimes I listen, uh, Doctor Gundry, you may have heard Doctor Gundry on the YouTube commercials. He talks about pistachios. He says get the unshelled ones because that way you won’t eat too many of them because you have to go through the task of shelling them yourself so you won’t eat too many because too many pistachios, according to Doctor Gundry now this is too many pistachios is bad, but the right amount of pistachios is, is, is, is beneficial, but he’s not as precise as the gym lady. He does not say Gundry, you can’t pin Gundry down. Of course, I didn’t listen to his 45 minute commercials, so, you know, I listened for like 7 minutes and I got the, the shelling, uh, the tip from, uh, from Gundry. So, He’s not as precise as the uh the dry eyes cure lady. A 1/4 cup of pistachios shelled every day. You’re gonna get immediate results. That’s all, it’s just that simple. cure the dry eyes. Don’t buy, don’t buy the over the counter. Don’t buy the saline in the bottle. Don’t buy the uh red eyes. Well, red eyes is a different condition that, uh, it’s different. She doesn’t claim to have a cure for that. Dry eyes, she, she stays in her lane. She’s in her lane, dry eyes. That is Tony’s take too. Kate. I like the specificity of the uh the shelled unshelled unshelled, no, no, no, get the shell, the ones without the shell, they’re already been shelled. She’s very precise cause that, because the shells are gonna take up more capacity and you know, and then you’re not gonna get the full 1/4 cup uh therapy. The treatment is gonna be lacking because you’re not gonna get a 1/4 cup because the shells are taking up space in your measuring cup. Well, then my next question would be like, salted, unsalted, old bay, no old bay. It’s like, Well, you should have been there with me. Uh, she didn’t, she didn’t specify. I think just straight up. She didn’t say salted or unsalted. That’s a good question. You’re gonna have to go on your own, let’s say if it’s a, if it’s a dry eyes regimen. Then you wanna, you wanna be encouraging fluids. So I would guess, now this is not her. I don’t wanna, I don’t wanna impugn her, her remedy, her treatment, you know, with my, my advice now I’m just stay in my lane. This is not my specialty, dry eye cures like hers. I would say you probably want the unsalted because salt, uh, salt causes, uh. More dryness, right, if too much salt, you know, you become dehydrated, I believe, so. But again, that’s not her. You know, I don’t wanna, I don’t wanna add anything on to her, her strict regimen. Um, oh, and by the way, uh, I heard one of the, uh, commentators I listened to on YouTube said, uh, somebody had Riz. I knew exactly what they meant, yeah, I knew exactly. I didn’t have to go look it up in the, I knew it, charismama. I said, oh, I know that. I don’t, I don’t have to go look it up in the uh in the slang dictionary. Oh, so proud of you. Yes, thank you. That’s just a couple of days later. All right. We’ve got Beu but loads more time. Here’s the rest of the state of the sector, beginning with AI with Jean Takagi and Amy Sample Ward. Now I asked about the state of the sector and we’re back into cybersecurity. It only took about 6 minutes, uh, and we’re like 1 minute and uh and then we just talked about it for 5.5 minutes. So, all right, where there are bigger things going on in the nonprofit sector. You know, our, our, uh, federal government, uh, the regime is, is, uh, has found nonprofits that are complicit in terms of universities. Uh, I don’t think it’s gonna stop there. um, we are, you know, both the left is, is under attack and. In a lot of different ways and that, that impacts a lot of nonprofits that do the type of work that is essential, you know, whether it’s legal rights or human rights, uh, simple advocacy, um, I mean, even feeding certain populations, uh, so obviously immigrant work, um, let’s. Uh, let’s go to the uplifting subject of, uh, the, uh, the state of the sector generally. Like, let’s put AI aside now for, for 15 or 20 minutes and just talk about. What people are, what people are feeling, what people are revealing to you. Gene, I’ll turn to you first for this, you know, what, what, what do you, what are people concerned about? What’s happening? Well, um, what’s on people’s minds is what I what I mean. Yeah, I, I think the sector is still feeling the the impact of the broader public being very polarized, um, and the effect of not only government actors on, um, uh, inflaming the polarization but on media as well, and nonprofit media is not exempt from that, uh, as well. So really is about trying to figure out, well, how do we. Move forward at a time where it is so polarized and where for many organizations the government is acting uh adverse to where our mission and our values are and they are affecting our funding and what’s gonna happen. So one of the trends going on right now I, I, I see is. There’s a greater understanding that we’re not gonna go back to the world. That, that was a year, right? We’re not going back there. We’re in this, what I’ll call is probably a transitionary period. I don’t think this period will last exactly like this either, but what’s gonna be next? What’s forthcoming? Is it gonna be worse? Is it gonna be better? And what can we do now as nonprofits to shape that direction? Like we can fight. Tooth and nail for everything right now, but if we’re not and by we, I’m including myself in the nonprofit sector, so forgive that indulgence, but if we can work towards a brighter future strategically, what are we thinking about instead of just sort of defending against every new executive order or every law and just trying to sort of fight on a piece by piece basis to just maintain scraps of of rights that. That we can preserve what what is our future plan, um, so we’re gonna also see with the diminished fundraising we’re gonna see some um consolidation in the sector, right? There’s, there’s a lot of nonprofits out there and they’re going to be a lot fewer nonprofits in 4 years. So what is gonna happen? So we’re gonna see more collaboration. We’re gonna see more mergers. We’re just gonna see a lot of dissolutions, um, and that’s gonna mean that a lot of communities are no longer gonna be served. So what other organizations are gonna pick that up? And if we have less funding to serve communities, do we need to find ways to do it in different ways, um, and so you know, back to technology, people will rely on technology, but that’s not the panacea for everything. Um, and I think collaboration is going to be a big part of it as well. So yes, there’ll be some consolidation and some mergers, but there’s gotta be other sorts of collaborations because the need is just gonna keep growing. Uh, but also trying to shape what we want in the sector is important and to understand that we’re not the only country that’s going through this, right? And we are more and more in a, you know, and this is one world and everybody impacts each other. And there are other very authoritarian countries that have really harmed their civil society and their nonprofit sectors, right? Yet there are nonprofits that continue to thrive. In those sectors, what are they doing? What can we learn from them? What gives them legitimacy when the government is not giving them legitimacy? There’s a lot to grow from here, evolve and adapt, um, but we are, and admittedly we’re in really, really harsh circumstances, so everybody is just sort of, you know, running all over the place without, without any direction still, but I think there’s more and more. Understanding that we’re gonna have to start to gather together and and and create some plans. I really agree with Jean and I, I’m also thinking about how we first started our conversation and How I said, you know, I’m experiencing folks really wanting to have thoughtful conversations, even though we may not be able to even make a container for those thoughtful conversations because of all the pressures and the anxiety and the unknowns. And I feel similarly here and in the way Gan is framed, framed the the uncertainty ahead because I see so many organizations who have never, through all the ups and downs, even if they’ve existed for 100 years, have never had to say. That their mission was political because no one has ever said that feeding hungry children was political or that housing people that don’t have a house is political or, or, you know, name most of the missions across the sector, right? Um. And now we’re in a place, you know, the last few months of the budget cycle and all of those debates made snap and uh so many programs became something where we we saw staff in the community saying like, oh gosh, well, normally I send a newsletter, normally, you know, this is my job and now I’m having to defend. That our organization exists and why we would exist and and what our programs do, but I also think to Jean’s point, there’s so much to learn and there is so much we already know. We do know how to do our work, right? Our folks who are running all kinds of missions and movements are experts and so even if we are. Um, looking at opportunities to collaborate, not just mergers and, and acquisitions or closing, but, but really collaborate in new and different ways, we don’t need to enter those conversations feeling like we don’t know anything. We know a lot. We’re just looking for maybe new venues or ways to apply that learning and that knowledge and I, I just, I wanna say that part because I, I don’t want folks feeling like they can’t enter those conversations because. They’ve just never done it before and they don’t know what what to even say. No, you know all about housing. You know all about resource mobilization in your community, whatever it might be, right? And so from there, there’s lots to grow from that that there’s already fertile ground. We, we have, yeah, we have experience, we have wisdom. Um, it sounds like, you know, you’re, you’re both talking about resilience. You know, we, we, we need, we’re, I guess in the current moment, we’re sort of treading water to see what’s coming as we’re, as we’re defending our, whatever, whatever our work is or whatever is important to us personally, because we, you know, we know that we, we can’t, we can’t take on everything, but, you know, we’re, we’re standing up for what it means the most to us. As, as individuals and as, as nonprofits. And then we’re waiting to see what, you know, what the future holds, um. I, I, I agree. I, I don’t, I don’t think it’s gonna be this extreme, but I also agree we’re not, we’re not going back to uh the 2016. Yeah, I’m just a really strong believer in, in one thing you said, Tony, about like what we want. There, there’s some things we want, and I think that is true of most of the country. I think for a lot of things, we want the same thing, right? It fundamentally it’s dignity for everybody, um. Uh, and, and dignity for our own communities. So just trying to find that and showing how nonprofits further that goal and making sure. That your representatives know that is really critical. So right now our our representatives just seem to be voting as blocks, right? They just vote along party lines and they’re not doing much more, but that would change if en masse, like the people that vote them into power say these are the things that really are meaningful to us like do something. You know about these fundamental things we wanna be able to feed our children we wanna feel safe on our streets like they’re just fundamental things, um, and then we can talk about how to accomplish that and we might have disagreements on, on that, but make sure the representatives know that they’re gonna be held accountable for helping people get what they really want and what the things that most are are most important to to them. That are meaningful to them, um, because so many things that people are shifting the arguments towards have no real meaning to their personal lives like attacking certain groups, you know, for, for, for allowing them to have rights probably, you know, the people people are attacking them. It probably doesn’t make any difference in their day to day lives or not whether those other people have rights or not when we’re speaking about certain minority groups, but why are they attacking it because that makes them or or they’ve been positioned. I, I think they’ve been. Uh again with, with technology and AI they’ve been brainwashed into thinking this is the fundamental thing that separates us versus them and we have to be better than them and um I, I, I think we’ve really got to get off of that sort of framework of thinking and really having nonprofits connected with their communities and tying them to their representatives is really really important at this time. Yeah, that that zero-sum thinking. That everything somebody else gets detracts and takes away from me, my, mine. Whether it’s an organization or person. It reminded me of a conversation we had on the podcast. I’m trying to remember when it was, it was years ago, years ago, um. And I don’t remember what if it was uh political administration change or it was natural disaster. I don’t remember what maybe the original impetus was when we, when we very first talked about this, but It is reminding me of, you know, we’ve said before the value that every organization has in, in kind of sharing the, the information and the data and the lessons and the truth of your community and your work so that when people are putting into the garbage machine, you know, tell me the tell me the real. You know, stats about hunger in my city or whatever, who, who cares about that? But if they actually came to your website as an organization that addresses hunger and you said this, these are the real numbers, right? This is what it, this is what hunger looks like. It looks like a lot of different things, right? It’s like AI hunger can be all these different things, um. That’s an important role in this time that every organization I think can be contributing, really saying this is what we know, this is what we see. This we are experts on these topics so that There’s a little, even if it’s a small antidote to the spin and the and the media and the wherever those online conversations go, at least you were kind of putting on the record what you do know and see in your work. Exactly right. I, I think I remember we were talking about how to be heard when there’s so much noise out there in the social networks and in media. How, how does, how does a nonprofit get get heard, and part of your advice was you have your own channels. So, and including your own website. Yeah. Thank you. All right. All right. What are you hearing, Tony? You get to talk to people all the time too. You have your own angle. You’re sitting over here grilling Gene and I. You got that’s not fair. I don’t see and hearing. Gene, I hate when they do this to me. Gene, help me out. No, um, alright, I’m gonna put AI aside because there is so much of that. Um, Still, you know, funding, uh, people still reeling from the USAID cuts, you know, it fucking kills me. It’s $1.5 billion which there are, there are several 1000 people in the world who could pull out $11.5 billion from their pocket and replace all the AI, all the USAID funding. See, I said AI when I’m, it’s a ubiqui it’s, it’s, we’re, we’re. We’re like, we’re, we’re conditioned that could replace all the USAID funding with a check or with a crypto transfer, and they wouldn’t actually be cash like that’s bananas, and they wouldn’t miss it. So, you know, people still reeling, um, missions still reeling from the USAIDs. I have a client that’s, but I, I, I hear about it from others as well, um. And it wasn’t just USAID, but State Department cuts that were non-USAID funds. The State Department did a lot, um. Yeah, a little, a little in media, you know, I, I listened to some media folks, um, Voice of America, trashed, trashed under, uh, what’s Carrie Lake, you know, uh, used to, used to, you know, like our, our soft. What’s it called soft diplomacy, right? Like, like bags of rice, bags of flour and sugar through USAID and State Department, news and information that was trusted, unbiased. I know there are a lot of people who would disagree that it was unbiased, but still, the, the effort was to, to be unbiased, spreading news and information around the world, around the world. Uh, and then I guess also, uh, public media cuts here in the United States where grossly, ironically, Red rural communities are most impacted because they’re not gonna get emergency flood warnings like like just failed in help me with the state was it Kentucky, the the river that flowed and the and the camp that lost 20 counselors and children, was it Kentucky, Texas. I’m sorry, it was Texas, right, thank you, um. You know, emergency warning systems, let alone news and information, you know, we’ve, we’ve gutted, uh, corporate media long ago gutted local media, but just so news and information. Lost through the Corporation for Public Broadcasting funding. Corporation for Public Broadcasting, of course, winding down in I think October. September or October, uh, so their funding lost and even just as basic as like I’m saying, you know, emergency warning systems for rural communities, horns that blow. Uh, messages that get sent at 3:30 in the morning. That that overcome your do not disturb. Lost, you know, lost. Stupidly Um, and a, a lot of this, you know, we’re just not, what, what aggravates me personally is we’re just not gonna see the impact of it, some of it for decades, and we haven’t even gotten into healthcare. But we’re, we’re maybe not even decades, but just several years. It’s gonna take several years of Fail failed warnings about things that NOAA and the National Weather Service used to be able to warn us about, you know, 8 months ago, um, and health, health impacts in terms of loss of insurance, lost subsidies around Obamacare, uh, Medicaid cuts, and Medicare cuts likely coming, you know, we’re we’re gonna see. Sicker people. We’re gonna see a sicker population, but it’s gonna take time. It’s not gonna happen in 6 weeks or even 6 months, but it will within 6 years. We’re gonna be, we’re gonna be worse off, and we’re not, and we’re gonna blame the, the current then administration, whatever form it’s in. Nobody’s gonna be wise enough to look back 6 years. And say 6 years ago, we cut Noah and that’s why now today, in 2031, you didn’t get the hurricane notice. And then of course healthcare too. How about in fundraising, Tony? I mean, what I’m, what I’m hearing is, don’t rely on the billionaire philanthropists anymore. Like, yeah, yeah, we’re over, thankfully, we’re over that. I, I, I never, I, I, you know, there’s, there’s so far and few, few and far between and, and 10,000 people, 10,000 nonprofits want to be in, um, Jeff Bezos’ ex-wife, uh, pocket, I can’t remember her name, Mackenzie Mackenzie Scott’s pocket. 10,000, 100,000 nonprofits are pursuing that, you know, the focus on your relationships, build, work on donor acquisition, but not at the billion dollar level. Work on your sustainer giving program. Work on, work on the grassroots. Can you, can you do more in personal relationship building so that, so that people of modest means can give you $1000 or $5000. And, and people who are better off can maybe give you $50,000 but they’re not ultra high net worth. But if you’re building those relationships from the sustainer base up working on your donor acquisition program, how are you doing? Are you doing with the petitions, emails, and then a welcome journey and you’re moving folks along and then you’re bringing them in and then inviting them to things, you know, work at work at the grassroots level. Among the, the, the 99.9. 8% of us that aren’t ultra high net worth. The other 95%, for God’s sake, we’ve been doing this since 2010, 2010. Yeah, 2010, 15 years, right? Yeah, 15 years, 7, yeah. The other 95% were, you know, don’t focus on the wealthy that everybody wants to, you know, the celebrity. I got a client with big celebrity problems on their board. Names you would know, 3 names you would, everybody would know. Um, they’re a headache. They don’t, they don’t make board meetings. They cancel at the last minute. They, uh, last minute, like a couple of hours. After all the work has been done, all the board books have been sent, and a couple of hours’ notice, they can’t make it. And then the and then another one drops out. Well, if she can’t, then, then I can’t also. Uh, as if that’s a reason, and then, and then the board meeting is scrubbed, and now, now we’re, you know, now they’re struggling to meet the requisite board meeting requirement in the bylaws, right? But so, you know, celebrities, you don’t need celebrities, you need dedicated folks on your board who recognize their fiduciary duties as Gene talks about often, to you, loyalty, care. Is there a duty of obedience to? Is that one? Or is that’s, no, that’s, that’s the clergy. That’s the duty of obedience. I know it’s not celibacy. I know that’s not, I know that’s not good. Amy, why did you mute your mic when you’re laughing? Come on, let us hear you laugh. Uh, now I know it’s not celibacy, but uh loyalty and obedience, loyalty and care, sorry, loyalty and care. And what’s the other? There are 3. What’s the other of obedience in the laws and internal policies. Yeah, yeah, obedience to laws and internal policies, right. So but, but care and loyalty. That’s another one, another one of these celebrities. The giving to Giving to a charity that’s identical to the, the one that I’m that I’m working with in the same community, does the exact same work and major giving to that charity. So Yeah, you, you know, focus on the, on the 99.98% of us who aren’t ultra high net worth. The grassroots, work on your work on your donor acquisition and sustainer giving and move folks along from the $5 level to the $50 level. This is how it gets done. Things are hard, and there are things we can do. Yeah, thank you. There are, there always are. Yeah. If we’re, if we’re focused in the right place and, and bring it back to artificial intelligence, you don’t even need to use artificial intelligence if you don’t want to. Amy, you’ve said this to us. You don’t need to, and it, but, you know, but that’s, it’s, that is not all of technology and that is not all of your focus in 2025 and beyond. Especially. When using it is impacting care and loyalty and obedience and data protection and everything else, right? Thank you for putting a quarter in my slot. That really worked. There’s a lot going on and there are things we can do. How about we end with that? Because that’s up, that’s upbeat. There is a lot you can do. There’s a lot you know. Amy, you were saying we have so much you can do. There’s so much you do already know and That doesn’t change because it is so hard. It just reinforces how important it is that you do know all of that, that you do know what you are doing, that you can take some actions, even if they feel small. Making sure 2 factor is enabled everywhere could be the thing that saves your organization from being in the news, you know, like, that’s worth it. And it didn’t feel that big or overwhelming. And also everything is still horrible, but you did that thing and it was important to do. Know what you know. You know, a lot of people we don’t know what we don’t know, but you, you do know what you do know. Know what you do know, and, and take action around what you do know. Whether it’s two-factor authentication or, or uh talking to your board about sound technology, investment, or it’s Focusing on your sustainer giving. And there’s a lot going on, there’s a lot you can do. Thank you. And pat yourself on the back whenever you take those small steps because they’re probably bigger than you think. That was Gene Takagi. Leaving it right there. Our legal contributor principal of NO. With Gene Amy Sample Ward, our technology contributor and CEO of NE. Thank you very much, Amy. Thank you very much, Gene. We’ll see you again soon. Thanks, Tony. Thank you Tony. Next week, better governance and relational leadership. If you missed any part of this week’s show, I beseech you. Find it at Tony Martignetti.com. Our creative producer is Claire Meyerhoff. I’m your associate producer Kate Martignetti. The show’s social media is by Susan Chavez. Mark Silverman is our web guide, and this music is by Scott Stein. Thank you for that affirmation, Scotty. Be with us next week for nonprofit Radio, big nonprofit ideas for the other 95%. Go out and be great.

Nonprofit Radio for July 14, 2025: We’ve Been Hacked! & Smart Data Storage

 

Steve Sharer & Danielle Elizer: We’ve Been Hacked!

Our panel from the 2025 Nonprofit Technology Conference (#25NTC), helps you with actionable takeaways to strengthen your incident response plan. You do have an incident response plan, right? They reveal the right responses and responsibilities for your leadership, IT, communications, and other key roles. They’re Steve Sharer from RipRap Security and Danielle Eliser with Chef Ann Foundation.

Brian Cavanaugh & Tiffany Nyklickova: Smart Data Storage

Brian Cavanaugh and Tiffany Nyklickova want you to avoid common data pitfalls while ensuring your data is smart, secure and searchable. They consider the pros and cons of cloud versus onsite storage, and explain how folder structures, filenames and metadata make your data organized and easy to retrieve. Brian is at The Vilcek Foundation and Tiffany is from Services in Action. This is also part of our 25NTC coverage.

 

Listen to the podcast

Get Nonprofit Radio insider alerts

Apple Podcast button

 

 

 

We’re the #1 Podcast for Nonprofits, With 13,000+ Weekly Listeners

Board relations. Fundraising. Volunteer management. Prospect research. Legal compliance. Accounting. Finance. Investments. Donor relations. Public relations. Marketing. Technology. Social media.

Every nonprofit struggles with these issues. Big nonprofits hire experts. The other 95% listen to Tony Martignetti Nonprofit Radio. Trusted experts and leading thinkers join me each week to tackle the tough issues. If you have big dreams but a small budget, you have a home at Tony Martignetti Nonprofit Radio.
View Full Transcript

And welcome to Tony Martignetti Nonprofit Radio, big nonprofit ideas for the other 95%. I’m your aptly named host and the podfather of your favorite hebdominal podcast. And I’m glad you’re with us. I’d suffer the embarrassment of Salpingium fraxis if I had to hear that you missed this week’s show. Here’s our associate producer, Kate, with what’s coming. Hey Tony, this week we return to our 25 NTC coverage with. We’ve been hacked. Our panel from the 2025 nonprofit technology conference helps you with actionable takeaways to strengthen your incident response plan. You do have an incident response plan, right? They reveal the right responses and responsibilities for your leadership, IT, communications, and other key roles. They are Steve Scherer from a riprap Security and Danielle Ellizeer with Chef Anne Foundation. Then Smart data storage. Brian Kavanagh and Tiffany Nilikova want you to avoid common data pitfalls while ensuring your data is smart, secure, and searchable. They consider the pros and cons of cloud versus on-site storage and explain how folder structures, file names, and metadata make your data organized and easy to retrieve. Brian is at the Vilcek Foundation, and Tiffany is from Services in Action. On Tony’s take 2. Self-care. Here is, we’ve been hacked. Hello and welcome to Tony Martignetti nonprofit radio coverage of 25 NTC, the 2025 nonprofit Technology Conference at the Baltimore Convention Center. Our coverage is sponsored by Heller Consulting, technology consulting for nonprofits. With me now are Steve Scherer and Danielle Elliser. Steve is CEO and co-founder of Rip Riprap Security, and Danielle Elliser is senior director of technology at Chef and Foundation. Steve, Danielle, welcome. Thanks so much. Thanks. Thank you. Last year’s NTC as well. Um, your session topic. We’ve been hacked! exclamation mark an interactive incident response tabletop exercise workshop. It’s a lot there, yeah, but you did, yeah, there’s only one verb in all that, right? There is only one verb in all that in that in those two sentences. Um, Steve, our resident security expert, uh, why don’t you give us a High level view of what your session covered yesterday, yeah, yeah, so our session was all about how to prepare for a cybersecurity incident and how one of the main ways that you can prepare is by undergoing a tabletop exercise to simulate what an an incident is like uh with your staff before you actually have an incident so you get a chance of what it feels like and. And what you should be doing and if your plans are are set up in a way that’s actually gonna help you. All right, now we’re not gonna have the luxury of an exercise here on nonprofit radio, but I know you both have takeaways, uh, either from the strategies in general, but also maybe takeaways from yesterday’s session. Um, so let’s see, uh, Danielle, why don’t you, why don’t you start with some substance like what should we be thinking about? This is all in preparation. Uh, so we’re not gonna have, like I said, we’re not gonna be doing the exercise, but what should we be thinking about in advance so that when we do call Steve because we’ve been hacked, uh, his response can be, I guess, as as seamless as possible or at least we’re we’re best prepared as we can be for the for the what we hope never happens. Sure, um, I think the big thing we realized when we were putting this presentation together was that a a tabletop game is very similar to a cybersecurity incident and that. You have some rules but you don’t know all of the information and it’s going to change and you are not gonna be able to predict where you go um and so you really have to be flexible when an incident occurs I think the first step is calling someone trusted or having someone on your team to cover the security um and then just giving them as much information that you know. And working from there um it’s a really flexible process that you have to be able to pivot through um depending on what you find out. So you really would like to know who you’re gonna be calling. Maybe maybe it’s two different teams in case one is not available or something or. I step one is have somebody on your phone, yeah, um, because time is of the essence um and you don’t have a lot of time to spare so knowing who you’re gonna call is is probably the the first step, um. We were very fortunate that when we had an incident we had riprap um already contracted with us and they were my very first call and they jumped in right away um so knowing who you have on your team that’s gonna be able to help support you is gonna be such such an easier path than. Trying to figure it out when you’re in the crisis. Yeah, I mean you’d be interviewing firms in the midst of a crisis. Your head is not gonna be on the the interview process and you know what’s your timeline and what’s our budget? I mean, we need to, right, so these things all need to be in place should be having these conversations. Now unfortunately it’s very common to find somebody while you’re in the middle of a crisis. I know um Steve has mentioned that a little bit of they often get these panicked calls and you know everybody jumps on board and does the best they can but it’s so much easier to have somebody beforehand. Oh, they don’t know your platforms, they don’t know your user base. I mean, well, Steve is gonna tell us all the things that he wants to know when you make that call. Um, what can you share about the the chef Anne hacking? Yeah, so I’ll keep it general, um, we had actually started working with Rip rap a couple of months prior and so we had some things in place but not nearly we weren’t, you know, robust uh in the way that we had hoped and um you know we just started getting prepared and uh and an email came through to our accounting department they had they had the right form they had the right invoice they had everything looked good um I was like oh my gosh, we have to get this check out by the end of this week. Can you guys just make this happen? Everything looked good. Um, and somebody within our accounting platform just flagged it a little bit of like this is unusual usually I hear about this beforehand and pass it up to me or instinct instinct is Steve instinct for sure there’s a ton of value and instincts, yeah, for sure. I mean it’s that listen to your gut that if it looks weird, smells weird, it most likely is weird yeah yeah a flag like this person in accounting, and she was even apologetic too. She was like, I, I just don’t wanna bother you and I was like, oh no, no, no. You think this is weird? I think this is weird. Let’s go, um, and so we were able to bring in riprap immediately and resolve it, um, and thankfully there was no impact, um, we caught it early, but I I can’t overstate how quick it was, um, and how um unexpected it was, you know, it was a random Tuesday, you know, like nobody expects this on a Tuesday, um. And so it was really, really, really beneficial to have somebody on our side already um and just not something we ever expected even though we had already been preparing with them. So it can really happen to anyone. And after the fact that you rip wrap like maybe did forensic work for you or something. Did you figure out was it, was it uh based on artificial intelligence or had they penetrated part of your system to, to get the, you said it looked authentic, it had, it had the right data and what how did they how did they get what they needed to make it look so good? Yeah, um. I’m trying to remember, this is about a year ago. Yeah, so a lot of times the attackers will try to um Illicit like payment forms, invoice forms from organizations by pretending to be somebody that’s maybe in the world or in the network saying hey we’re a new vendor, and they’ll get some of this paperwork already um even if they haven’t conducted a breach of the actual nonprofit so that that wasn’t their case luckily they didn’t have the attackers did not have access to the Chef Anne Foundation computing resources, which is, which is great, um but you these these attackers, they don’t. Needed a lot of the times they can they can socially engineer and elicit a lot of this information from the finance staff and the other staff that are out there in the community. I have a panel coming up on the show, uh, yeah, later later today talking about the use of artificial intelligence in in in gathering personally personally identifiable information. So then not not again like to your point, not needing to go into the platform or the resources of the organization. But through artificial intelligence, putting it all together to make an invoice look real or you know whatever it is that they’re whatever they whatever their mechanism is for infiltrating making it look very authentic because it has so much personal data. Yeah right, right. So but that didn’t, that didn’t happen in your case, uh just before the explosion of large language models and BT a little ahead of a little ahead of that, yeah, OK. Oh, you said last year it was sometime last year. OK. Uh, so Steve, uh, all right, so hopefully, uh, folks have, uh, riprap security or another, uh, exemplary. It’s hard to imagine, uh, any other firm being as good as riprap Security, but, but, uh, you have, uh, you found one of the few that are, or you’re using riprap. What do you wanna know? Uh, first call, yeah, yeah, so I mean I, I think the, the first call we, we try to understand what are the timelines, who’s involved, like what are the broad sketches of the story, what’s happened to dates and what what systems are affected? What things are do we suspect that the attacker might have access to and that sort of starts to help us orient who in the organization that we’re working with we should talk to, what systems we should start focusing our forensics and technical experts on. And really start trying to work the problem and understand. I mean, um, a lot of the times our our customers when they have an incident they’re they have limited information they, they know that they had a weird email on a Tuesday and but they’re they’re looking to fill in the gaps, right? This is, this is as much of those kind of classic mysteries, you know, as it’s no longer, it’s not just a, you know, 22 minute like murder mystery on TV. It’s usually many days, but we, we try to sketch out and do that kind of. Investigative work to understand the timeline of that incident. I just thought of another reason why you’d want to have an agency lined up ahead of time for for you obviously need remote access immediately. Now we’ve got, you know, maybe we have to go through a hurdle to get that done. If it’s not lined up in advance, time is of the essence as you said, Danielle. And I, I think trust is a big area too, right? By the time the chef and staff had their incident, we had already spent much, a lot of time with Danielle and with the executive staff and other members that are, you know, doing the more hands-on work. So they knew me. They knew our team, they were comfortable with us. We didn’t have to build that rapport, you know, in a relatively short time. It’s just, it’s just a lot better and in the midst of a crisis in the midst of a crisis, right? I don’t know if I can trust these people, but he said something weird, but I don’t have time to worry about it, right? So I have a flag, but I can’t wave it. No. All that is resolved if you, I’ve already hopefully encouraged folks to have a relationship in advance. You know who you’re gonna call. OK, OK, um. All right, next step. I don’t know, Steve, you want to lead us through. All right, so you’ve gotten your preliminary information. Do you need the client to do something or what’s next? Yeah, yeah, so something we covered in the talk is how, how can you how can you best use the organization’s existing capabilities, tools and talents to help you with the incident. So we often talk a lot about engaging the communications and the marketing staff because they they know they already have a way that they communicate with their with their donors with their stakeholders with the with the the beneficiaries of the of the organization and by using their expertise you can craft really really clear transparent timely uh communications to the people that might be affected with the incident. We, we see that’s interesting so you’re you’re the guy you’re the you’re the tech guy, but you’re concerned about the, the outward communication. Absolutely, because I mean what what’s a nonprofit without a lot of trust, right? And, and we, we see a lot of examples in the tech industry in broader business world and nonprofits that. Organizations that have incidents that aren’t transparent about it that aren’t sharing the whole story they’re not being timely about sharing the information the trust in their reputation is severely damaged and so they get less interest they have you know if they’re a company they they lose a lot of customers um and. The instant response process is about trying to maintain that trust and that reputation and reduce the impact of the incident. Danielle, so what’s going on at the Chef Ann Foundation now in the 24 hours since you’ve called Steve, what’s happening. So Steve is doing, Steve and his team are doing all the investigative work of like, OK, what has truly gone wrong? Like what do we need to find what’s out there? What’s the scope of this because often it feels just like the tip of an icebergs are they. In the system, you know, um, and so he’s handling a lot of that also communicating to my team. My role at the time was to communicate to our internal team because I know Steve. I’ve been on a call with Steve every week for 3 months, but they may not know Steve as well, and now my board wants answers. So my role turned into very much that internal communication network of like, OK. C-suite, here’s what’s going on on the edge of the cliff. I know, I know the ending was I already know the ending, but I’m still intrigued by the by the time by the unfolding. Yeah, because everyone’s everyone’s concerned, everyone’s just here to do their job to make the world a better place. That’s what we’re here for. We’re not here to build like a Fort Knox system, so when something goes wrong, it’s like, oh no, have we been too focused on. The healthy meals for kids, it’s chef Anne for sake, it’s not we make lovely food. It’s not, uh, you know, it’s, it’s not nuclear nuclear arms negotiations. Does someone have a vendetta against whole grains? I don’t know. I really like quinoa, you know just not agree with my stomach. And I’m lashing out. She had a recipe on she had a quinoa pudding recipe on the website just last week and I was very annoyed. So let’s go ahead and, yeah, exactly. So it’s, it’s, it’s a big sea change for the organization, um, especially the teams that you work regularly with to shift and say, oh no, this is actually now a current crisis and something we have to worry about that presentation next week is no longer my priority. And so it’s often a lot of soothing the internal team and also trying to communicate in the easiest method possible to the internal team like they don’t care that it was a business email compromise with uh like an MFA concern like they don’t want to know all of that they just wanna know we’re safe, we’re OK, we’re working on it, keep doing your job, we’ll let you know when we need something from you. And same with the board. The board just wants to know we’ve got it covered, so it was a very easy thing to be able to call my CEO and say hey this is what’s going on. I have this update. I’m gonna send this to the board. I just want you in the loop. You can send it to the board. I don’t really care how this process works. I just need to communicate what I have, um, and so it really became more of a like a switchboard operator of trying to keep the organization. Calm and steady and on the right path while rip rap was able to like resolve and actually investigate a lot of these technical pieces. And how about with your uh your marketing communications team that Steve mentioned were you were you talking to them or did Steve talk to them directly or what we loop them in um Steve’s recommendation. Uh, we were very fortunate that we didn’t have a public, uh, kind of incident. Um, it was very internal, so we, we loop them in just in case there was a larger impact that we needed to involve them on, but, um, they were, they were ready they were right on board. I mean the marketing teams can spend on a dime, so they were prepped, they were ready they had some language already written up by the end of the first day just in case. So it was really a coordination between all of the parties in the first 24 hours you’re not sure what Steve’s. All I know is that all of my meetings have been canceled and my CEO was trying to buy me pizza and my husband was bringing me coffee and I was like, alright, we’re we’re in it now, you know, um, you’re still in the eye of the storm. Um, all right, what, uh, Steve, lead us to the timeline. So we’re outside the 24 hours now. You, you know more. What, what, what have you, what did you, were you, yeah, what are you able to uncover in the 1st 24 hours? Yeah, so it’s, it’s a lot of um timeline information, right? When is the, when is the email sent? When is it opened? How many people receive it? How many people looked at it in the organization, um, what can we learn about the the information that you don’t get to see in the body of the email but that’s attached to it so information about the email itself when it was sent who sent it doing that kind of deep forensics work to understand can we track down who was responsible for it. Um, and can we, can we report them right, and, and try to shut down the fraud. That’s good. All right, let’s keep that open. There’s a mystery that I don’t know the answer to, um, but there is, there’s a ton of email sometimes you see it when, uh, an email is undeliverable, then you see all this string of, I don’t know if it’s called metadata or accompanying like emails fly all over the world instantaneously and, and sometimes you see this. This is just to me it’s just meaningless characters, but you can decipher a lot of information about an individual message. Exactly, yeah, so we we get a lot of information about how the email traveled across the internet from where it was sent, the computer that it was sent to where it was received. Uh, we can understand if the person sending the email uh is trying to hide their the the true email address of the um the person that sent it. Um, and we, we can use it to uncover all of these indicators that yes, it is a malicious email because a normal person isn’t sending an email with all these weird kind of factors in this metadata that you see. And so it it is um it is a lot, it is possible to. Um, understand a lot more by looking at this metadata and then to use that to pivot the investigation to say have we ever seen the same person try to attempt the same thing against the organization or other organizations that might be in the chef An network right partner organizations, um, you know, beneficiary organizations to say let’s just make sure that. Um, the attacker, if they really do hate quinoa that they’re not going into the quinoa Association and trying the same attack on them and so we, we look for these opportunities to say, hey, how can we help other people in the network or how can we make sure that other people in the network aren’t affected because we know nonprofits are so highly connected. Oh wow I’m I’m impressed by your uh. Holistic thinking like the marketing communications team, get them involved. I wouldn’t have expected the IT forensics, you know, expert to suggest get marketing involved and same thing with, you know, other agencies that we don’t even work with, you know, but can we support the network or at least, you know, inform the network about potential, should we? I’m impressed by your holistic approach we try because I think. So much of the risk is from third parties, right? It’s not always your organization that’s gonna get attacked. It’s maybe your vendor that gets attacked and that they the the attacker is able to gain access to that vendor’s email system and then the attacker is sending invoices from a legitimate vendor’s email address to you to try to get you to send money to a new bank account, right? That’s a very common thing we see. So it’s not even, you know, the chef and foundation can do everything right 100% of the time with security. But if their partner organizations aren’t doing the same thing, they’re they’re still potentially at risk for getting these, these kind of attacks. All right, take us through the timeline now. We’re beyond 24 hours. What’s unfolding? Sure, so we, we think we, we really understood after that 24 hour period that the incident was really limited, that there was, there was the funds were stopped. That’s, you know, of course the main thing. There was no access from the attacker into the organization. Danielle, what was the? I think they timed it perfectly. It was like 49,000. It was just under the cusp of that 50,000 where a lot of organizations want to review. OK, maybe require more signatures or or additional review. 9 999 car dealership. OK, I’m sorry, that’s OK. Yeah, so I think knowing being able to communicate that there that while there was the email that got sent, there wasn’t a true incident in that no money exchanged hands. There was no um breaching of chefan accounts or computer systems. And then being able to communicate that it just sort of brings down the stress level of everyone and says, OK, like this is, it was, it was an event, right? It’s not an incident because there’s no real impact because there’s no money changed hands. It’s very limited scope you can reassure the board, CEO, yeah, my accountant can stop hyper hyperventilating, uh, you know, like so everybody can just kind of calm a little bit and and we start, we start turning. We start moving towards closing out the incident, but and but it’s, it’s and this is where we say we like to use the phrase like never waste an incident. Right, never, never waste the opportunity to learn from what happened in the incident and make changes based of it. We see a lot of organizations that have these lesson learned sessions afterwards. Oh, we did this well, we didn’t do this well, but what we see the gap is nobody is assigned specific action items with due dates of things like, hey, we want you to go and turn on this technology or for any invoice over $5000 it needs to have a second set of eyes on it. And so taking these learnings and applying them to the organization and working it into the workflows, not just the IT and the technology side, but the finance side and the and the communication side just so that you’re more prepared next time and you’re you’re. You’re, you’re building some muscle memory for the Danielle, so in the session, uh, what did you see what shortcomings did you see that folks, you know, in their in their tabletop exercises were not, you know. Yeah, it was really interesting um so the way we structured the session was the 1st 20 minutes were like a quick. Slide show presentation of here’s what you need to know. He’s kind of the stuff that’s gonna come at you and then the incident that the exercise began and um it was really interesting because they wanted more information oftentimes they’re like, OK, so somebody sent you know somebody sent a bad invoice now what? and I was like, yeah, now what. You get to figure that out and they’re like, no, but the page is only like, yeah, that’s part of it like you only get like 3 touch points of information to lead your way into this process um and it was really interesting to see how that clicked on and they were like, oh this is this is like just like it would be, um, and they started asking the questions of like, well, could we do this? Could we do that? How, how did you handle this, Danielle and I was like yeah yeah. You’re gonna have Danielle’s expertise. Daniel’s wisdom from born from born of experience when you have your crisis. Right, right. I mean we do want to give them a little, a little nudge here and there, but there are no wrong answers, just trying to learn the process and I think the other thing was a lot of them saw um how stressful it can be um even in a purely hypothetical. You’re at a table with 5 strangers at a conference rolling a dice, you know, it’s still stressful, right, there’s this is, this is purely hypothetical, but still imagining your organization going through something like that or making it real of like who would I call? What would I say to the CEO who who’s the marketing head? Um, was a really good way for them to kind of envision and realize, oh this is just, this is at the lowest possible stake level, which means when this happens, if this happens, this is going to be so much more stressful and we really need a plan. Um, all right, so I don’t know who I should ask to, uh. Uh, we opened with you, Danielle, so I’ll give Steve the opportunity to bring closure to, uh, to our incident. Uh, what, what, who is it from? What were we able to find out? We were there any we able to point the finger at a person or an agency or a company or a country or and, and what, what was the. Yeah, yeah, yeah, so often times these things are the the sort of uh the the end of the story, sort of the the final uh solving of the mystery is is kind of anticlimactic. I I know I wish I could point to, oh yeah, that guy Paul in Saint Louis, like he was the guy that sent it. You often can’t get that level of information. Um, but we’re, we were able to understand, hey, these are the computers that send these emails we’re able to disclose them to entities like the FBI just to make it part of their larger cybercrime tracking domestic it was from inside the US it was from inside the US, um, and then what we, what we really spent a lot of time on is, hey, is the plan that we’ve made for cybersecurity in the road map we’ve worked on with Danielle and her team, what changes do we need to make? Uh, to that plan of how we’re gonna improve how we’re gonna work together to improve cybersecurity based on what we learned from the incident. There are certain projects that we, we pulled up, may may happen sooner, some we delayed, um, and it really, it really. Led to a situation where we’re just constantly able to update the, the strategy for the Chef Anne Foundation to say, hey, we have this thing we learned a lot from it and here’s how we’re gonna apply that in all the work that we do, uh, going forward. Danielle, I guess, uh, kind of epilogue, what made you contract with riprap three months in advance? What obviously not knowing what was coming. Well, what, what was the impetus for putting a relationship in place? Yeah, actually a little bit of a full full circle, um. I had attended the uh nonprofit tech conference in Denver and that’s where I met Riprap um at their presentation was just 2 years ago that was 2 years ago yeah and so um started working with them after that and I really really enjoyed our partnership. They completed a full road map assessment and so it’s um it’s pretty fun that we met at an NTC and now we’re presenting about this at an NTC. That’s great. I got chills synes. I got I got chills um so that’s. Good. The the epilogue is is excellent. All right, even if the, the outcome, so, uh, just going, Steve, going back to the uh what you were able to pinpoint like could you get to a county or a state? We have a rough like right we we get rough information, right? You get like, you know, rough geography here’s the the town or the city that they’re kind of by was, you know, I think Washington state based somewhere in in the Seattle area, but from there it’s a little hard to to to pinpoint beyond that. You have to really be law enforcement. or you know some spy agency that you can’t glean from from our side or while they’re doing all this incredible investigative work, you know, I’m trying to keep my people calm, having that final report to my board, to my C-suite to say, hey, here’s what we learned, here’s what we’re doing, here’s how we’ve processed this was really, really tremendously helpful. It gained a huge amount of trust from the board that our organization was taking this seriously and that we were prepared. Um, and we’ve gotten so many kudos from them on that incident, so it was, it was truly a learning opportunity that we were able to grow into something more. Yeah, and I appreciate the trust building too that they know that you’re on top of, well, you are the senior senior director of technology that they know technology is secure. It’s something that, you know, maybe you’ll report once a year or something, you know, but they don’t have to be concerned about as a board or even the CEO, you know, all right. Outstanding. It’s a good story. It’s a good story. It’s a good story with a good ending. Yeah, yeah, I’m glad we got the epilogue out. That was very good. Uh, they are Steve Scherer, CEO and co-founder of Riprap Security, and Danielle Eller, senior director of technology at the Chef and Foundation. Steve and Danielle, thanks. Thanks very much for sharing that story. Thanks for having us. Good to see you again. Thank you so much. Thank you and thank you for being with nonprofit Radio’s coverage of 25 NTC, the 2025 nonprofit technology conference where we are sponsored by Heller Consulting. It’s time for Tony’s take two. Thank you, Kate. Self-care. We just had the long holiday weekend, 4th of July. I hope you took care of yourself as well as family or friend obligations. Hope you’re taking care of yourself this summer with time. With the sort of chaos that’s uh emerged from the, the budget bill that passed and it’s bad impacts in a lot of areas including Our community. I it’s just so important for you to be thinking about yourself. It’s not selfish to do self-care. That is not selfish. That’s the best way. For you to care for others. You have to take care of yourself first on an airplane, you put your oxygen mask on first, then you help them, then you help the children who are with you, right? You put your mask on first. You gotta take care of yourself first, then you can be your best person bringing your best self to taking care of others, helping others, even working, just working with others. So please, uh, several weeks ago, I reminded you about your meds from Mico Marquette Whitlock, taking care of mindset, exercise, diet, and sleep, the meds. And I would also refer you to an episode from March, March 31st. It was with Jennifer Walter, the social worker. That episode was Mental Wellness Among the chaos, March 31st. Please Take care of yourself this summer. It’s essential. That’s Tony’s take too. Kate Though I was gonna miss my cue, didn’t. You thought I was gonna miss my cue again. You set you up I set you up. People can’t see obviously as when we, when we speak as a podcast, but Uncle Tony kind of, he leaned in and then like took it back and then he went for it. Yeah, set you up. led you in, led you in thinking, oh my God, 2 weeks in a row, he’s gonna miss his cue or miss the queue, miss my cue, I should say. Well, at least you’re not forgetting my name. Yes, right, we’re improving. It’s, it’s an upward slope. Things are getting better. I remembered your name this week. We’ve got Beu but loads more time. Now it’s time for smart data storage. Hello and welcome to Tony Martignetti nonprofit radio coverage of 25 NTC, the 2025 nonprofit Technology Conference at the Baltimore Convention Center. We’re sponsored here by Heller Consulting. Our topic right now is data disasters, smart storage for nonprofits. Bringing that to us are, uh, Brian Cavanaugh, director of digital at the Vilcek Foundation, and Tiffany Nilikova, the information specialist at Services in Action. Welcome, Brian, welcome Tiffany. Thank you for having us. Thank you pleasure, pleasure. Um, let’s start with an overview. Uh, why don’t we start with you, uh, Brian, just as we have plenty of time together, but if you could just give, uh, an overview of the Amy, he’s gonna do an overview of his session and, uh, what, uh, why, why you, you all believe this is important for, uh, for our, for our nonprofit community. Well, we’re using data disasters that nonprofits face, uh, the hardware failures, natural disasters, uh, staff turnover, funding cuts, etc. uh, as ways to talk about data resilience and how data resilience can make organizations information more smart, secure and accessible, uh, to deliver programs, uh, and mission critical work. OK, now you did not put data resilience in your session topic. Maybe that was, uh, maybe I was gonna turn people off like data resilience. Oh my God, I can’t imagine anything duller than the data disaster. Now we’ve got, now we’ve got an alliteration. We’ve got disasters, we’ve got crisis like there’s tornadoes whirling around us. There’s a sense of urgency, yeah, right, um. uh, but you, Tiffany, please, uh, why don’t you define data resilience for us? Data resilience is about taking care of your data in a way that protects the organization’s, uh, integrity. It’s uh. Data resilience is about um building a structure where you can rely on it we talked about how you can manage your information in a way that it’s faster it’s quicker you can respond to things a lot better when you manage your data and the resilience of it. Um, so I imagine there are some things that we’re not doing quite right about, uh, data, data management, and you specifically say data storage. Uh, I think we want to talk about, uh, cloud versus uh local. Why don’t you keep going for the time being, Tiffany, um, lead us into like some, some of the pitfall. What, what’s some things we should be doing smarter? So like you said, there are local storage solutions and their cloud-based storage solutions, and they offer a lot of pros and. Cons and it really depends on what you’re looking for. So with the cloud obviously you can work collaborative collaboratively with your colleagues you can access your data from anywhere. It’s a very robust system it can grow with your organization the fees are fairly low, uh, but you do have the risk of unauthorized access. uh, you know there are cyber threats that are much more real. Um, also you have authorized access so one of the things that we were discussing is when you click I agree, what are you exactly agreeing to? That nobody reads all that, right? I mean there’s 19 pages scroll to the bottom to say I agree. Absolutely sometimes I think it’s a game to see how fast, well, you know, no I don’t, not every time but before this session I specifically do sometimes, but you know what, this is a great way to use chat uh use AI Chat GPT can read it for you now and you can ask the chat GPT questions. What do I care about? What stands out for me? How does this compare against other companies? Uh, and one of the things that I care a lot about is the authorized access. So when I click I agree, I’m giving, let’s say Google Drive access to my data. They scan it for their own compliance with uh policies, but also, um, they might use it in their marketing. How do I feel about that? Is my community vulnerable or are they up against discrimination possibly? So what are my responsibilities with that and when, when I expose my data. I’m exposing a lot of people, so your local solutions are, you know, uh, external hard drive or network attached storage or a solid state drive, uh, external hard drives, there’s all sorts of ways that you can move your data from when you’re working on it to storing it that doesn’t involve the Internet. So the pitfalls of that are you can’t just access it from everywhere. You don’t work collaboratively, so you might end up with tons of drafts of the same document. Uh, but you also have much more control because it remains within a physical space. Uh, you are, it is, um, vulnerable to attacks to, uh, sorry to inadvertent loss or to, um, to, you know, damage it can be, you know, fire, fire damage we talked about, uh, just going kind of extinct some, you know, like floppy disks where are they? No’s using those anymore, you know, so that can happen in the future. So like I said, there’s pros and cons to both. Um, what else in terms of, uh, pitfalls, what, what else, Brian, could we be doing smarter besides uh storage? Uh, well, we need to think about antigrated file types. Uh, so we’re talking about the WordPerfects and the quark files and the floppy disks and all the type of data that may not be as accessible as it once was. And so we need to think about futureproofing that data by using recommended and preferred file types. Um, which is something that that the Library of Congress does very well, uh, by researching and publishing, uh, those recommended file formats in a statement, um, and so you can, you know, think about your data, uh, as a long term investment. Um, by using those recommended file types so that you can have access, you know, long into the future. What are the preferred formats? Are you able to name the top two or three? Sure, so for digital text-based formats, um, you’re gonna look at PDF, uh, PDFA, uh, for digital images, you’re gonna be looking at TIFS primarily, uh, JPEG 2000s, um, and for video you’re looking at IMF. What is um what is PDFA? What does that mean? There are different types of uh coding uh in in the PDF, uh, and oftentimes if you’re using a solution like Acrobat or some of the other free tools, um, you can save the PDF in in multiple different formats and they go back into the early 2000s. Uh, it’s just different layers of uh options and features and functionality. Um, that are built in and every year they advance, um, so the most, you know, the most common has, you know, a wider set of features um than it once did. OK, so there are preferred formats for files and why, why is this? Oh, just so they don’t get out outdated for one. OK, yeah, exactly, yeah, otherwise. You’re stuck, um, you know, using an emulator or a very old machine that may not be secure in the first place to try to open up, you know, some type of file that you haven’t needed or wanted access to for, you know, 15 years, but now you need it and you can’t can’t open it. Yeah, OK, or you’ve got some legacy machine to do it and has its own vulnerabilities, right? OK. I could be a data data storage scientist, aren’t you? That’s not true at all, um. Uh, searchable so we need to be able to get our data, right, Tiffany, let’s talk about accessing the data. I mean, yeah, let’s talk about you gotta get the data out. You gotta be able to find your data so you have to be able to to categorize it and label it in ways that make sense to you. I mean we can get deep into a database structure system, but I’m gonna talk a little bit more about just the files that people use every day. Uh, you know, how do you know that the file you’re looking for is the most recent version, or, uh, you know, let’s say you have an opportunity to write a grant application, but it’s due at 5 o’clock and you know you’ve written a document before that would apply to this. Where is it? So that’s when what you label your document is particularly important. I used to label documents, Tony. I used to label them by the mood of my day and I never could find things again and that is a terrible way to name documents. There’s a lot of swear words in it, but and so it’s cathartic, but it’s not very helpful when you’re looking for things. So the analogy to that is having on your desktop. Oh my goodness, I sometimes I go and I see someone’s desktop. I think my heart rate starts increasing. Yeah, I feel how can you like the desktop is just loaded with folders and files. I feel that way when I see an inbox with like thousands of unread messages. Yeah, you learned you’ve you’ve come to the bright side now from your, from your archaic dark dark days of file naming. So there now there’s two ways of doing things now you might surprise you, but I’m a bit type A, so I prefer a deep hierarchy where you have things, you know, in general, and they get narrow and narrow and narrow and it’s really important when you label a document that it doesn’t duplicate any of the naming. Sure that you’ve used in the folders before that so you don’t have to repeat the year again and again and again um some people prefer to leave everything on like a flat surface on their desktop and then use their search that’s one way not my preferred method so what I’m gonna say when you’re labeling things you use descriptors that everybody agrees on is it a letter or is it um a document or is it communication you have to agree on the terms you’re using as a group. It’s got to go deeper than that. That that’s just, that sounds like a very basic policy place to start. By the way, I love the hierarchy. I mean, I’m very hierarchical thinking you look, uh, look, I use Apple, uh, laptops and, you know, I don’t repeat. I I don’t say that client name, you know, contract. I just say contract because it’s in the file for legal for the. For that, for that client, which is in clients current, exactly not clients historical, that’s a different. I move them from clients current to I hardly ever have any clients leave, of course, not so much client current file is loaded clients historical is is infinitely small. It’s like 2 now there are 2. I mean, I’ve been in business for 28 years, so I haven’t, you know, a couple have just ended, uh, very amicable, but now so anyway. The hierarchy, very, I, I just, I, but that’s the way I think. But suppose somebody doesn’t think that way. That’s not you suppose the organization thinks that way, but you don’t personally. You gotta be dragged along, right? You do. So when you use descriptive words, people who prefer to search and leave everything flat now know the terms in which to search. Things have changed over the years because now. We have AI embedded into our own databases so for example if you use Google Drive, Gemini is within there. Now the policy say because I read them, uh, that it doesn’t share your database with its own it doesn’t teach it’s own AI based on your data, but who’s to say that’s gonna change so you can search now within Gemini of your own database to find things so your naming structures a little less particular. But I’m still gonna say the more descriptive you can be, the more you can match both those type A and type B people. OK, OK, um. What else? So this has to be a written, written policy in terms of file naming. Now what about folder naming? How is that different than file naming or is basically the same regimen? Yeah, I would say the same thing same with what you just described like legal contract. I would say it’s the same thing. Yeah, OK, so hierarchical is preferred we’re not using the Dewey decimal system. OK. Oh, I love the DDS. Oh, the DDS. I never heard I gee I didn’t you go to the library you have a degree in library, it’s like, yes, I did library. Does anybody still use the library still use Dewey Decimal or that that that. The spine of the books suggested they have card catalogs in libraries? No, no, no, I haven’t seen in ages ages. Thank you very much, Tiffany. OK, um, we should talk maybe about cost, cost, uh, let’s go to you, Brian. Uh, I mean, we spend a lot. I guess we can get the ultimate in security and storage and cutting edge, but we got to spend a lot, right? Where do we find our balance? Yeah, and the reality is that a lot of nonprofits don’t have the budgets to spend a whole lot. Um, the good thing is that, you know, a lot of the solutions that we’re looking at in the session um are low cost and and free. Um, you know, a lot of the solutions like Google Drive and Dropbox, Box, etc. um, they provide discounts to nonprofits, uh, free and low cost solutions, um, but to your point, uh, the more features and security that you’re looking for data loss prevention, data classification tools, they may be at a higher tier and so you may have to, you know, be paying for uh some additional things like that, um. That said though, um, you know, you need to be considering your backup solutions and other types of costs as as a holistic view of your organization’s data practices and security and so it may not just be enough to consider the cost for storage, but you also need to consider the cost of your backup and other policies and tools that your governance policy dictates. Let’s talk about doing some sample retrievals, right, so let’s say we use the cloud. I think most, most nonprofits probably use the cloud now. I mean, is it? Yeah 100%. There are some people who have local storage, I guess, but let’s let’s go with a cloud-based example. Should you be testing your, your retrieval every once in a while, make sure this, this structure is working like I’m trying to find this, maybe I know exactly what I’m looking for, but I’m gonna try to find it without going right to it. Yes, uh, yeah, OK, absolutely. Like any policy, uh, or protocol that the nonprofit has in place, you need to be testing it regularly. Um, so that includes going into your storage, uh, platform solution, um, finding and retrieving things, downloading them, um, and you know some advanced tools will do data verification checksums for you, um, but more often than not, um, just having that one on one experience of finding something, retrieving it, understanding what your users will be going through. Um, and simulating that action for them to understand, are there any pitfalls, are there any difficulties in doing this, and also just making sure the data is valid, um, that the file is working, it’s not corrupt, um, and, uh, that, you know, it will set your users up for success. Uh, we have jargon jail on the nonprofit radio. You mentioned, uh, data verification and checksums. You need to flesh that out to get yourself on probation parole, parole. You’re already in jail. Uh, so, uh, when, when you’re validating data, uh, you’re looking at, you know, things like file size, um, all the different types of metadata that are embedded within that file. Um, and some solutions will check over time, uh, if they have changed, um, and if there’s something that goes awry. Uh, you know, a check some verification or data valification can send up a red flag and and alert someone. OK, so it’s a way of verifying data integrity that happens automatically. It can, yeah, OK, OK. um, Tiffany, you asked a rhetorical question earlier about making sure, how do you know whether you have the most recent version of a file. Uh, right, we’re in the cloud. I see, or some, some, somebody did not or some, let’s just one person, uh, 11. Scofflaw, the word I was looking for. One scofflaw did not follow the policy. And now we’ve got, I see multiple versions. I see multiple files with the exact same file name. What do I do? I used to work with this guy. Oh my goodness, he was such a treat. He had, he was, oh, he was, but he was the boss was he was actually a felon, not just a scofflaw, and to me a scofflaw is like turnstile jump right but this guy sounds like a felon. Yeah, somewhere in there he had master document. I was looking for something. I was helping him organize his uh information management system, and I found what I what what was called the master file. And I thought well that’s gotta be it, right? That’s gotta be it. And then I found Master File too. And then master file 3 and then master file 4 and I don’t know the end number so I don’t know how many master files I’m looking for so that was like that was a whole day of like finding all the master files I could when you, when you have that you have to well, ensure that the last one is the best one and then delete just delete them, get rid of them, move them off maybe you want to store them in a secret spot from the scuff law so he doesn’t keep make I’m referring to him you know because this guy’s in my mind. Um, but you, you know, maybe move them to the side for a little while, yeah, in the archive, your secret one, so it’s not lost forever, but it can’t be part of your system because it’s just gonna clutter it. uh, I’m a big fan when you’re working on a project, have like the whole story complete when you’re done, put everything in one file and it’s all complete and it’s all there and you know where it is and you don’t have those extra drafts because they’re gonna get confusing even if it’s just. Copy and paste or cut and paste put it all into one thing and then follow the naming convention exactly and then you always know where it is and then you have your cultural posterity. Like your your cultural, your organization’s culture, you’ve got your, um, but, you know, do I need this file name can I just use keyword searches? I know the I know the word that’s in there, at least I, I believe I do until my search is unsuccessful. I’m screwed. Mhm. Yeah, we have to accommodate them don’t we? We do we do because we expect them to get up and running right away and if you know if they come in and there’s all these names that don’t mean anything, they’re not going to be able to do that not gonna be able to find things and they’re gonna start doing things from the very beginning, writing that grant proposal from the very beginning, yeah, and they don’t, you know. They’re just redoing work and it’s just a waste of time and energy. Logarithmic, uh, file, file creation, right? I mean, I guess it just plateau eventually, but it could be, it could go crazy with new, a couple of new employees recreating everything and now we’ve got duplicate files and and half of them aren’t named right and you’ve lost your donors. you’ve lost your volunteers along the way. See, this is all motivation maybe we should talk about this. Well, you have a lackluster host, not scofflaw, but lackluster, um, you know, we should talk about in the beginning, but these folks have been with us for 19 minutes, so hopefully they’re seeing now why these things are important. You have to pay attention to data integrity, data management, right, um. What haven’t we talked about user friendliness. There’s something else from your, from your session, uh, description, user friendliness. We’ve got these policies, but, uh, people don’t, you know, they’re not adhering because they’re too technical or something, you know, again, balancing, right? Brian, uh, balancing Brian, what, you know, what are we gonna do? Uh, we now we got trouble, people are not using them, uh. You need to be able to show why there’s value in doing things like file naming conventions, folder name conventions, um, so to your point about, you know, using keyword searching it works until it doesn’t work, uh, and so show people the value, uh, in, you know, adhering to the policies, um, and working through a lot of the steps that may feel like extra work to be honest, um. And then once you demonstrate that value, it begins to sink in that you can then take it to the next step, provide more training and resources and education. Um, it might take a crisis to make the point. It it might because we have the grant deadline that you hypothesized before and, uh, Tiffany, and we don’t have it. We haven’t found it. We blew the deadline. That’s a disaster. That’s disasters. All right, now we all learned a lesson. OK, sorry. It’s OK, um, uh, or you know, let’s say someone accidentally deleted a file or misplaced it or overwritten it, it’s, it’s gone. Um, and that keyword search no longer works because you’re trying to recover something that’s based on either a piece of metadata or a file name, um, and so, you know, in that instance, uh, you may not be able to recover that data and you know it’s lost and it impacts someone’s job. Yeah. All right. Uh, we can wrap up. Let’s see, uh, who opened? Tiffany, did you open? I think I did. Let’s give Brian a chance to close. Leave us some with some, uh, not motivation, we just did motivation. We just spent 10 minutes on motivation, but, uh, some promising words. Yeah, some promise for our for our future. Let’s look forward to a bright future with no data disasters. Bring us, bring us to this nirvana. Thank you. Uh, let me recognize, uh, Mark Topher, uh, the Vilcek Foundation’s archivist, uh, who, who’s not joining us here today, but, but joined us for the session here at NTC, um, and to, to his point and to in using his words, you know, consistency is key. Uh, and so making sure that everyone in the organization is on board, um, they’re using the best practices, um, and they’re making sure that they’re taking proactive steps to make sure the information that they are, um, good stewards of, um, is smart and secure and in doing so, um, we’re going to be protecting, um, the, the people that matter most to our organizations because at the end of the day. Um, we’re here to serve people and um all those people, whether they are in vulnerable, um, populations, um, or you know just in tricky situations these days, um, that’s what matters most and we want to be good stewards of data um and and make sure that you know nothing bad happens um to those communities. That’s Brian Cavanaugh, director of digital at the Vilcheck Foundation. With Brian is Tiffany Nicklichkova, information specialist at Services in Action. All right, Brian, Tiffany, thank you very much for sharing. Thanks for having us. Thank you. Thank you. My pleasure and thank you for being with Tony Martignetti nonprofit radio coverage of 25 NTC, where we are sponsored by Heller Consulting. Next week, our 25 NTC coverage continues with your intergenerational people pipeline. If you missed any part of this week’s show. I beseech you. Find it at Tony Martignetti.com. Our creative producer is Claire Meyerhoff. I’m your associate producer Kate Martignetti. The show’s social media is by Susan Chavez. Mark Silverman is our web guy, and this music is by Scott Stone. Thank you for that affirmation, Scotty. Be with us next week for nonprofit Radio, big nonprofit ideas for the other 95%. Go out and be great.

Nonprofit Radio for March 13, 2023: Beat Back Cyberattack

 

Michael EnosBeat Back Cyberattack

Cyberattacks against nonprofits are on the rise. While you cannot avoid them, you can make them a lot less likely to cost you big money, your data, your reputation, your donors, and your employees. Michael Enos from TechSoup helps us out.

 

 

Listen to the podcast

Get Nonprofit Radio insider alerts!

 

 

Apple Podcast button

 

 

 

We’re the #1 Podcast for Nonprofits, With 13,000+ Weekly Listeners

Board relations. Fundraising. Volunteer management. Prospect research. Legal compliance. Accounting. Finance. Investments. Donor relations. Public relations. Marketing. Technology. Social media.

Every nonprofit struggles with these issues. Big nonprofits hire experts. The other 95% listen to Tony Martignetti Nonprofit Radio. Trusted experts and leading thinkers join me each week to tackle the tough issues. If you have big dreams but a small budget, you have a home at Tony Martignetti Nonprofit Radio.
View Full Transcript

Transcript for 631_tony_martignetti_nonprofit_radio_20230313.mp3

Processed on: 2023-03-11T01:00:20.020Z
S3 bucket containing transcription results: transcript.results
Link to bucket: s3.console.aws.amazon.com/s3/buckets/transcript.results
Path to JSON: 2023…03…631_tony_martignetti_nonprofit_radio_20230313.mp3.38068433.json
Path to text: transcripts/2023/03/631_tony_martignetti_nonprofit_radio_20230313.txt

[00:01:26.42] spk_0:
And welcome to Tony-Martignetti non profit radio big, non profit ideas for the other 95%. I’m your Aptly named host of your favorite abdominal podcast. Oh, I’m glad you’re with me. I’d suffer the embarrassment of a phone. Yah. If I had to speak the words you missed this week’s show, beat back, cyber attack, cyberattacks against non profits are on the rise while you cannot avoid them, you can make them a lot less likely to cost you big money, your data, your reputation, your donors and your employees, Michael Enos from Techsoup Global helps us out on tony steak too. Get in people’s faces again. It’s a pleasure to welcome Michael Enos to non profit radio He is senior director of community and platform for Techsoup Global. He began his professional career in technology in 1996 and has since led team, tech teams at the national and individual office levels in increasing responsibilities on Mastodon. He’s at Michael underscore Enos at public good dot social and tech soup is where you’d expect them to be at techsoup dot org. Michael, welcome to non profit radio

[00:01:42.03] spk_1:
It’s great to be here. Tony Thank you for having me.

[00:01:46.69] spk_0:
My pleasure. My pleasure. Let’s please explain the work of tech soup. I think it’s so valuable, so many billions of dollars of software and hardware transferred to nonprofits. Make sure, let’s make sure everybody knows what techsoup is doing,

[00:02:52.57] spk_1:
you know? Absolutely. I mean, essentially our, our mission is to help civil society, organizations worldwide um better leverage technology to create impact in the missions um that they serve and to build communities. Um You know, that, that then can then foster that, that, that, that impact globally. Um We do that through a number of different ways. We do that by facilitating philanthropy from large tech donors. Um And you know, most of which are the ones that are just, you know, household names. Um We also do it through uh courses, services, consultations, um and through connecting organizations with each other and through also through engagements like this where we try to really uh to blogs, webinars and other facets where we help organizations understand how they could use tech um and protect their tech to uh enable uh and further have impact for their, their communities. They serve,

[00:03:17.12] spk_0:
I saw on tech soups website today, Microsoft Office or Microsoft 3 65 for a dollar. So

[00:03:18.55] spk_1:
that’s an example, right? And if you were to go to uh you know, Microsoft for nonprofits or Google for nonprofits, for example, um you know, the data validation platform that validates organizations worldwide is managed by Texas So, ultimately, we, we, we do many things but we’re also sort of a, I guess, data leading partner for, for a lot of these organizations that want to understand and make sure that their philanthropy is going into the right hands.

[00:03:48.25] spk_0:
You have, you have local uh connect groups to techsoup, connects groups.

[00:03:54.10] spk_1:
That’s great. That’s right.

[00:03:56.21] spk_0:
Yeah. You know, I know, I know you’re, well, you’re director of community and platform. So is that, is that part of your work

[00:04:42.76] spk_1:
director? I mean, you know, you know, I support that, that organization that we um we have, we have lots of different um areas and, you know, and, and in my role, I support them all um platform is a lot of the, you know, I oversee our enterprise, infrastructure and security as one of my fundamental sort of roles. I mean, obviously with the, with their expansive amount of technology that we have, that runs our platforms that, that consumes a lot of my time, but also the community side because of my background working in the tech for good space, you know, since, you know, for the length of my vocation, um you know, I have, I’ve accessed as a resource for a lot of other groups, including the connect group for when they need, you know, to understand, you know, how to, you know, for, for things like this and for, for other things um to help our communities um better leverage to the tech that they use. I mean, it’s one thing to, to uh provide the technology. It’s another thing to actually help people, you know, provide them the enablement to be able to use it and optimize it.

[00:05:08.91] spk_0:
Are there local meetups are the group’s going back

[00:05:50.06] spk_1:
to? Exactly. There are, there, there are, you know, communities within the regional and our, and that’s part of our connect program. Um And eli, the guy who runs that and, and the group that runs that are very, very energetic and it’s very community driven, which, which is fantastic and we’re sort of an enabler and facilitator in that work, which is wonderful. And that stems from the early days of us being part of the early groups that were involved with the, you know, tech for good space way back when technology was first getting launched, you know, and the internet was first launching different

[00:05:51.33] spk_0:
types of work. I mean, you know, n 10 doesn’t do consulting, which I wanted to ask you about very shortly. But, you know, they don’t do tech grants necessarily, but all, all very parallel with, with N 10.

[00:06:26.73] spk_1:
Yeah. Correct. And, and we, we have a close partner to put 10, 10 and, and we attend the events and such and we’ve long been sort of affiliated with that demand and other and other groups like like 10, 10. Um and we have partnerships that sort of expand throughout the different communities. Um And, and we try to be involved globally as well. You know, so there’s this sort of, you know, there’s the U S side of it, but then there’s also the everything that we’re doing outside of the U S and abroad because, you know, it’s um civil society is international and so, and tech soup is really involved with, with things not just within our own borders but, but outside of them um globally.

[00:06:50.58] spk_0:
Are you going to 23 NTCC the conference?

[00:06:51.42] spk_1:
Um myself. No, I’m not the, I know we have some, some other representatives that are there. I’ve been to many of those uh this year. I’m not specifically going, but we will have some representative from Texas there. I’m

[00:07:03.64] spk_0:
sure. Yeah. And non profit radio will be there as well. We’ll be on the exhibit floor.

[00:07:07.67] spk_1:
Excellent. That’s fantastic. Yeah. Yeah. Well, I’m sorry, I’m not going to be there to be in person to meet

[00:07:12.61] spk_0:
you. That’s all right. There. There are others every, every spring and

[00:07:17.31] spk_1:
virtually, by the way,

[00:07:18.97] spk_0:
that’s true. There is hybrid this year. That’s right. Um And, and texture is also consultants to consultants to nonprofits. Let’s make sure folks understand that too.

[00:08:46.84] spk_1:
Yeah, I mean, we, we provide, essentially, we help organizations connect with other organizations that then provide consultant services. We do some ourselves, but it’s very specific to some of the um because we, we provide a lot of, you know, what we’re doing to, to skills. So to speak what we, what we have is we’ve partnered with other organizations through our platforms to, to align organizations depending on exactly what type of consultation they need to inappropriate sort of resource for them. Um And that’s more uh our, our model in terms of we’re sort of a connector. So for example, if somebody needs, you know, specific sort of technology assessment uh for implementing uh Microsoft, we may do some, but then if it’s more advanced, we may work for them to, to impact or an organization that we partner with and then they provide that as a service to that organization. So, and we have other partners like that, who provide those similar sorts of services that are more hands on and direct than what tech soup can provide at this moment. And we may may expand that more and do some of that um more, more stuff ourselves and, and we are developing that and some of our customers success programs. Um and we do run a lot of sort of in the office programs where people could have webinars. And I’ve spoken in a few of those where we do it in in depth dive of a particular technology so that organizations can learn how to use them.

[00:09:00.19] spk_0:
I’ve always considered the big three to be Tech Soup N 10 and tech impact in terms of technology for nonprofits and, and all three of those of course, are nonprofits themselves. Right.

[00:09:12.87] spk_1:
Exactly. Yeah. All right,

[00:09:15.44] spk_0:
let’s talk about cyber attacks. Uh They are on the rise against nonprofits. What, what, what are you, what are you seeing? We’re going to get into the details, of course, but overall general, you know, kick us off. What are you seeing on this front?

[00:11:31.28] spk_1:
What, what we’re seeing is a lot more, um, targeted attacks, which, which is, which is unique because there’s, you know, speaking broadly about cyber activity, you know, there’s a lot of noise on the internet. There’s, you know, just all these robotic sort of in these bots that are flying around trying to find targets, right? And they’re sort of just, you know, you know, I guess, you know, they’re, they’re doing drive by sort of evaluations to see of anything, you know, just to see if there’s anything that they could get a finger in or, you know, just to explore and see if there’s sort of a, you know, something that they could find in there. What we’re seeing now is more targeted attacks, meaning there’s a specific purpose to it. Like somebody’s like, well, you know what we think that, you know, this is a, you know, a specific type of organization, they’re involved with a particular type of activity and we’re interested in knowing who’s donating to that activity and whether or not we could possibly have access to that information because that might be valuable or perhaps to the constituents that they’re serving because maybe that information is valuable as well, maybe for either financial reasons or, or, or or political reasons. And so we’re seeing a little bit more of that or, or perhaps because we really want to cause disruption in critical infrastructure. And one thing that um this is sort of a broader trend in cyber security around targets towards critical infrastructure and myself and and others in this space believe that civil society, organization data is part of critical infrastructure and critical infrastructure. So I mean, people are targeting things like, you know, we’ve we’ve heard about the target on power grids and uh gas pipelines and such. And you know, if you think about data that’s relative to communities that are specifically vulnerable in certain context or, or have access to information about others, then that’s critical infrastructure because we need these organizations to function in society. And so, you know, there could be other actors who say we want to disrupt that particular critical infrastructure for some reason and that reason could be varied just like it is for why people would disrupt any sort of critical infrastructure.

[00:12:55.08] spk_0:
I have an example that is pretty close to home. I I I own two homes in North Carolina. One of them was affected by that shooting at uh at the electrical substation in that was, that was in Moore County, North Carolina. Um And there’s a, there’s a possible correlation that, that that attack was to prevent a drag queen show from going on in the little town of Southern Pines, North Carolina, which is served by that substation that got shot at. Um So, I mean, it sounds like you’re saying, it’s not that far a leap like, you know, 11 cadre of bad actors uses guns. Another cadre of miscreants could be hackers that are looking for data at that maybe at that theater or, uh you know, among a nonprofit that may have been involved with

[00:13:45.30] spk_1:
maybe maybe the intent at the attendance list or the people who are donating to that event. And so, you know, this is the type of data and like I said, there’s, there’s different reasons why somebody might be targeting certain data. But this, these are the, this is, you know, this is like bingo on the nose, this is the kind of stuff that, that we’re seeing more and more and we’re very concerned about and why we’re really like soup is really sort of launching this um effort to help educate organizations on how to improve uh and understand what cyber security means in this space and how to prioritize it, but also how to um sort of get through the sort of complexity of it and, and, and find simple ways to knock off low hanging fruit to make it sort of actually, you know, doable for them with given their budgets and given their constraints that we a lot of smaller organizations in the, in the space you know, have, generally,

[00:14:39.67] spk_0:
it feels like in our polarized culture that there isn’t a nonprofit mission category that would be exempt from, from possible attack. I mean, you know, even feeding, feeding the hungry, you know, I could conceive of that being objectionable to some group of people that feels like why do those folks get food and, and I don’t get food or why are they entitled? And I’m not, or, you know, something that seems innocuous and purely beneficial. I, I can imagine, uh, another cadre of bad actors deciding that it’s, it’s, it’s worthless or worth worse than worthless. It’s detrimental to our culture for some reason and wanting to attack it. It doesn’t, it doesn’t feel like any particular mission would be more vulnerable or less than, than any other.

[00:15:59.15] spk_1:
Um, you’re correct. And one of the other things that is, has changed in, in this, in this sort of, you know, over time that I’ve seen is the availability of the tools to be able to perform exploits before you would actually have to be, you know, pretty well versed in hacking to be able to do any harm right now. It’s, you can, you can buy the service. I mean, you could just go to the market on the dark web and just say, hey, you know, I want to buy this, you know, uh, this hacking kit, you know, and, and, and, and there’s youtube tutorials on how to do it. I mean, it’s becoming, and, and these are, the tools are free and readily available. So what we’re seeing more of is not only just this trend of people wanting to and, you know, and maybe that hasn’t changed, it’s just that it’s more accessible, right? But, you know, people wanting to, you know, target communities and, and, and, and also try to find valuable data within these communities, but also their ability to do so it’s become easier and there, you know, and, and so you combine those things together and that’s why we’re seeing the trends we’re seeing. That’s one of the reasons

[00:16:21.11] spk_0:
you no longer have to be a sophisticated computer user. It doesn’t take a lot of study, you’re saying these things are available for cost or free to cause harm. All

[00:16:29.81] spk_1:
right.

[00:16:39.80] spk_0:
Alright. So how do we, how do we break this down for folks in small and mid sized nonprofits, you know, that, that they can sort of prioritize? I mean, is it as simple as let’s start having universal two factor authentication for everybody on your teams or maybe that’s passe maybe, maybe we’re past that now. I don’t know, how should

[00:19:30.66] spk_1:
we, you know, you, you make a good point. So for example, like the first thing I think people should do is, you know, or, or what you know, uh would be recommended and to think about it is to do the basics. Okay. What things like what you mentioned is like like multifactor authentication, um you know, anti malware on their clients, keeping things up to date and, and making sure you have backups of your data, these are sort of the basics, right? And so apart from the basics, though, you know, the next step above that is to then start looking at what we call privileged access management or role based security, not everybody needs to have access to everything, right? So, so, so let’s say, for example, a system was compromised with somebody’s permissions or credentials, depending on what they have access to, they could only do so much. And so there’s a, there’s a, there’s an important concept in cybersecurity that we call the privilege, the principle of least privilege. So, and that sort of dictates that a person really only needs access to the information that they need to do the role that they’re trained to do in their specific function. So if, if, if somebody is, you know, in I T, somebody who’s familiar with I T systems, uh they understand sort of the complexity involved and they may have access to privileged systems where they can perform things and have access to that sensitive data, but not the entire organization, right? And so we call that privileged access management. And sometimes, especially with today’s as we’ve moved into the cloud more when things get fired up and somebody spins up an app in the cloud, the cloud as well, generally have some basic role based permissions like the admin, you know, maybe a super user and then maybe some groups and then, and then just the regular users, right? You don’t want to give everybody admin rights. And so because then if somebody, if that just, that just provides more exposure and so these are small things that don’t take a lot of time or effort really to just sort of that, that’s a little bit beyond the basics though because um you know, and you know, for, you know, tech soup, for example, provides, you know, office 65 or 65 go for, for, for work space organizations. And once we, they provision, the next step is to really go in there and sort of harden them a little bit and lock them down and to go through that steps and understand what that looks like. So that um as people start doing things like maybe downloading spreadsheets that contain donor data or customer data that it’s not, somebody can’t accidentally just share that with somebody, you know, outside the organization or, or that becomes available on the general public internet.

[00:20:02.06] spk_0:
So how do we execute some of these things that are, that are more advanced, you know, beyond the backing up the multi factor authentication. Alright. So if you move into privileged access management, we need a, we, we either have a C T O which most listeners probably don’t or we need some outside help.

[00:21:13.19] spk_1:
No, actually, I think that a lot of these, you know, cloud based applications will provide guidance. The good news is is that they have an interest in protecting and wanting you as a, as a customer as well as, you know, the fact that it’s a shared data model. And so the the better that they do in terms of providing information about how this works, the better, you know, the, the the, you know, the people who use that product is going to benefit from it. And so generally in these, you know, you know, and these things aren’t if you have somebody who is at least responsible for the deployment of the technology and they don’t have to be an advanced, you know, computer scientists to do the work of the cloud app then. But somebody should be sort of designated within the organization to ensure some of the basics about the way data is handled. And, you know, getting to one of the export points, I wanted to bring up one of the most important things to understand for an organization is what data do they have? Where does it live and what is the value of it? And what is the value of Michael before we, before

[00:21:22.02] spk_0:
before we move to what, what’s our data inventory? I want to emphasize this, I wanna emphasize the value of being in the cloud. So there is there is value to using uh CRM databases that are cloud based versus server based at, in your office anymore.

[00:22:47.49] spk_1:
Correct. And for so many reasons and, you know, uh, and, and moving to that topic because a lot of the ways that systems are oftentimes breached is because what things we mentioned earlier, such as they’re not patched, there’s, um, not, not very good perimeter security on them. These things are taken care of for you, um, and they’re not backed up regularly. Um, those things, these things are taken care of for you in a sassy application. Um If it’s, if it’s a robust SAS application, like the kind that takes provides. And so when we, when we go to, you know, vet an offer that’s going to be in our marketplace, we we, we go through the list to ensure that this is gonna be a product that will serve the pole, the test of time and actually will, will be robust in, in the requirements necessary for our organization to protect their data. And so, and, and so that leads to, you know, also that making it more but maybe a little bit easier for organizations to then lock down their cybersecurity because they don’t have to have experts come into their closet or their data center and, and do this configuration and do all these updates are very technical on their firewalls and all the hardware and everything all the time in their own infrastructure, it can be managed within the cloud by people who are not necessarily have that sort of, you know, the Cisco CCN a sort of certification? Alright,

[00:23:07.85] spk_0:
thank you. I just, I wanted to drill down absolutely. Very

[00:23:11.75] spk_1:
good point.

[00:23:15.98] spk_0:
The value of from a security perspective, the value of the cloud. Alright, so let’s go to what you were, you were headed to what your data inventory, what what do you have? What what do we need to be? What do you want us to think about their?

[00:23:32.71] spk_1:
Yeah, so no data is not all data is not created equal, so to speak, right? So we have, we have data that it’s just things like, you know, my notes when I’m, you know, talking in a meeting or something like that. Okay. There’s nothing valuable with that. It’s, you know, generally not containing anything that’s sensitive. It’s sort of my notes from a meeting. Okay. Now, if that is something that, you know, maybe I don’t want to share, but it’s not something that, you know, if a hacker birds look at that so I can’t sell this and it doesn’t contain anything that’s gonna, I can do any harm with. Right.

[00:24:09.30] spk_0:
Well, it might depend, it might depend who’s leading the meeting. You might have different, you might have different sets of notes depending on who’s leading your meeting. You know, you might be commenting on the commenting on their uh I don’t know their, their capacity. I mean, not to suggest

[00:24:16.36] spk_1:
that people

[00:24:30.71] spk_0:
know, I’m actually, I’m actually having fun with you like, if somebody at tech soup was not a very good, not a very good speaker or supervisor, you know, then those notes you might not want in the public domain. But if the person is carrying their weight and they’re generally a good, good employee, you know, you have a brighter set of notes that you wouldn’t feel bad about getting exposed. That was my, my point. I guess I wasn’t, I wasn’t coming, I was coming across so dry. It was, it was desert, it was desert dry.

[00:27:18.46] spk_1:
No, I’m glad you brought into it. The, the, yeah, the types of data that you know, we think about when we think about the difference between data privacy and data protection to me, they’re very linked, right? So we, we have a responsibility to protect people’s data and the privacy of their data, but also to protect the security of that data. And so, you know, fundamentally speaking, generally in organizations in the sector, there’s gonna be some, you know, information that’s sensitive or may have some value and if we identify that and identify where that lives and then focus our energy on securing that, making sure that that data is backed up. Um and, and testing access to it, that’s, that’s, you know, if you have limited resources, that’s the place to really focus your attention. And then the other stuff is great. I mean, and use using robust tools like we provide um in our marketplace such as box for document repositories or even sharepoint, those can all be really configured for. So any type of theater, like even my notes from, you know that, you know, or my supervisor notes about me or your notes about me can be secured, you know, um you know, in a very robust way or shared. And one of the things we’re seeing, for example, especially the document collaboration software, it’s very easy to share things. They make it very easy to share with anybody, right? Just click and it always says like share with anybody with link, you know, you know, and so if you, if it’s something like, oh, you know, um uh oh somebody just sent me, you know, or they told me to put in my, you know, take a picture of my passport or something and, and stick it in here, right? And, and I, and the somebody has in the human resources once said, oh, I’m just gonna share this link and make it copied everybody. Now everybody has access to your past potential, everybody has access to your passport photo and I D so, you know, these are the things that we just have to sort of like start thinking twice, which brings me up to my next point. Um Security awareness within organizations, cybersecurity awareness, I cannot stress enough how important it is for organizations to have a cyber security awareness program within the organization. This these programs don’t cost a lot of money. They don’t take a lot of time and they go a long ways to prevent Uh an internal mistake that could lead to something 80% of cyber attacks happen from the inside.

[00:27:27.33] spk_0:
What does this cyber security awareness program look like?

[00:28:34.34] spk_1:
So essentially, so for example, um they’re usually conducted on point of like orientation for an employee that comes into an organization and they go through a video, you know, provided by a platform like no before which is in our marketplace. And, and what they do is they sort of go through this, this methodical sort of, you know, force to teach somebody about fishing about sensitive data about ways that people try to get access to information, either through cell phone, fishing through text fishing through um email phishing or through other means to or even on Slack to say, to try to fool you into providing some information um that they, that they can use a huge trend in this arena is what we call impersonation fishing. It’s a specifically targeted phishing email that looks like it’s coming from somebody within your organization such as your CEO, your CFO or uh the human resources director asking you to provide or update your banking information. And it’s very carefully crafted, crafted, it looks just like that and you really have to do a lot of due diligence to really go through there and say, oh, did this really come from our CEO having

[00:29:03.26] spk_0:
Haven’t there been cases where like a spoof email like this says, you know, wire $50,000 to this vendor account. You know, we’re, the payment is overdue. We need to wire this payment ASAP. And of course, it goes to the Bad Actors account. Isn’t there? Stuff like that? It looks like it’s like the treasurer saying, send a wire or the CEO saying, send, make a payment.

[00:29:40.35] spk_1:
That’s right. Exactly. And, and, and we’ve, um, and if you have an organization and people haven’t been trained to recognize that, you know, if somebody’s asking you for something and it’s something of value, double check it, you know, and, and to contact that individual in a different channel and say, did you really need me to send $50,000 in this wire transfer? I just want to check is this actually came from you? There’s other ways that they teach you in these orientation platforms or in these um security awareness platforms to check the email headers and, and the simple things, but essentially that’s the gist of it. And that’s why security awareness training is so important. So, so people are on their toes when they’re actually doing their work,

[00:30:03.43] spk_0:
do you recommend then ongoing training? You talked about orientation,

[00:30:51.51] spk_1:
there’s, there’s an orientation training and then, you know, most organizations will have it mandatory that they do an annual training and, and this just as a refresher course and also things change. So, you know, the space changes. Sometimes people are doing it now because of the trends more often like every six months. And then specifically for people who are in jobs where they’re doing data handling for, let’s say they’re doing data processing, they work in the donor uh services program or something where they’re managing sensitive data all day long. They’ll be specialized courses for people who are, are actually dealing with data on a day to day basis. So that’s a little bit more involved in terms of actually how to understand and, and that goes into things like, don’t download, you know, a C S V file on your computer and stick it onto a, you know, um, a thumb drive on your computer or transported or, you know, don’t, you know, send out, you know, via email to, to a coworker and, and these sorts of things that are specific to handling sensitive data.

[00:31:04.59] spk_0:
Okay. Interesting. Yeah. So even, even just emailing internally from employee to employee can be risky,

[00:31:37.20] spk_1:
yes, it can be stiff. It’s, and, and there’s because, for example, if, because that’s actually it’s going to stay within that email store wherever that is located. And it’s, um, if it’s unencrypted, it’s gonna be, it’s gonna be encrypted during transit, for example. Um, and, and encrypted at rest. But if somebody else had access to that access to your email server or a privileged access in your system, they could potentially go in and, you know, take over that account, log in as the CEO and have access to the deed and actually browse emails for, you know, and actually do queries and look for credit card information or, or look for email addresses and then they could potentially find information about donors or, or, or, or constituents that sensitive.

[00:35:08.08] spk_0:
It’s time for Tony’s take two. It’s time to get back in people’s faces. Again. Last month, I did a in person live face to face in person training on Long Island. I was in New York City for several days. What a joy. What a pleasure. What a difference, an improvement, you know, over virtual trainings. I mean, look zoom is, I’m all flustered. Zoom is, is necessary and I’m not saying necessary evil. It’s, it’s, it’s a part of the culture, whether it’s zoom or teams or Google meet, you know, whatever virtual meetings, they’re just a part of our lives now. No question about it. But don’t make those the default if you have the option to get back in front of people in person, I urge you choose that option. Uh You know, I could have passed on the opportunity to do the in person training, but I didn’t want to, I didn’t want to donor meetings to while I was in the city face to face meetings again, coffee lunches. It’s just so much better, so much more real than anything virtual can offer. Um I had a meeting, lunch meeting just about 10 days ago or so with someone from Heller consulting, which is gonna be Team Heller. They’re going to be our 23 NTC sponsors at the nonprofit technology conference coming up in Denver And the woman who works for Heller happens to live within 45 minutes of where I live in North Carolina. So we got together for a, a real lunch. We had lunch together over the same table. Remarkable. You know, it’s yeah, more real authentic. I urge you if you can meet someone in person instead of virtual, do it, do it. It makes the world of difference. It’s time to get back in people’s faces again. Don’t make virtual your your default. If there’s another way first, I urge you to do it. That is Tony’s take two. We’ve got Boo Koo but loads more time for beat back cyber attack with Michael Enos. Talk about not preserving data that you don’t need to preserve. Like credit card numbers, full numbers for instance, or dates of birth or other things that aren’t necessary for you to preserve. Isn’t there, isn’t there value in trimming down sensitive data that you don’t really need?

[00:35:40.17] spk_1:
Yes. And and one of the principal aspects of data handling is an optimization of data. So you know, there’s there’s transactional data that happens. And oftentimes, for example, with credit card things are processed nowadays, you’ll usually use a payment processor. So, you know, hopefully you’re not actually you know that server that actually storing that information is not on your box anymore because there’s, you know, you know, you can use an API and a web site and then it happened somewhere else and they take care of all that stuff for you. So, if your systems were hacked, they wouldn’t have access to the credit card data

[00:35:55.19] spk_0:
or,

[00:39:00.73] spk_1:
or Braintree or one of these sorts of services, you know? Exactly. And, and, and so those go to those payment processors and they manage all that, um, which is great because then you, it reduces the amount of exposure on your e commerce site or fundraising donor donation site. And if you’re using a donation software program, like, you know, donor perfect or one of these sites, that’s what they’re doing as well. You know. So they, you know, because, because they, they want to use because that you really have to have the best of breed technology to be able to make sure that that stuff gets that, that’s really super secure and they have higher standards and compliance standards by which they attest to the. Um, and so however though, let’s say you’re, you’re doing an email list to your constituents, right? Um You know, you’re gonna need some marketing data, you’re gonna, you know who to send this, this information to, but you don’t need everything about that individual. You don’t need things like that really. I mean, you may need the basics but you should be using a marketing provider that is secure and you should, you should transfer, get that information to them in a secure way and you should ensure that if that individual wants to opt out. Um and they, all these things should be an organization’s privacy policy so that people understand how their data is being used if they sign up for a newsletter or things of that nature. However, you know, I think your point specifically um oftentimes reports about, you know, activities, engagement, you know, that go into reports for executive or for things that are put into a PDF or in another format, the data should be anonymized. So the only thing that’s there is, you know, aggregated information about, you know, the engagement and not all they shouldn’t be able to drill down and see, oh who is this exact individual? Now if they need to know if it, if they want a donor report about, you know, I want to know exactly to see who um are the top donors and, and such, you know, there should only be limited people within the organization who have access to that data, to be able to see that information that goes back to my other point about um privileged access management. There are gonna be some, there’s gonna be some reason why people aren’t gonna wanna know specifically about, you know, who’s engaging with the community. And also oftentimes on the client level, we need to know that the people who are providing services to communities need to know exactly who these individuals are and more sense of information. And that’s why I was talking about earlier about, you know, understanding where that data lives and, and only having as much as you need to fulfill the function of that, you know, whatever you’re doing. Um and, and having that, you know, and making sure that’s really locked down when I worked in the food down. When I worked in the food and security sector, we had people going out in the communities and helping sign them up for, you know, um cal fresh, you know, essentially benefits, you know, for people to get, you know, you know, government assistance and they had to collect really sensitive information. But what they did is they had ways to you securely transmit that information to the local human resources agencies so that it was all encrypted, it was protected and then once we transmitted that we didn’t have access to it,

[00:39:44.68] spk_0:
what about vetting vendors? You know, if, if you’re offices using a male house, uh you know, some of the data that you just talked about for, for mailing? Um I can’t, I can’t think of other examples of vendors that could be. Well, events, events could have, could event management might have some sensitive data. What, how do you vet your vendors to make sure that they’re taking appropriate actions to prevent theft, fishing, you know, to, to defeat defeat, or at least you can’t defeat them, but at least minimize the threats. How do you, how do you check these third parties that you’re working

[00:41:16.80] spk_1:
with? Well, you know, that’s a big part of my roller tech soup. So whenever we, whenever we work with, with, whenever we’re going to be using a new product or app or something like that, it’s my job to go in and actually check and organizations, these, you know, these application providers will provide um on their site or they should and if they don’t, you shouldn’t use them, but most of them will provide on their site access to their information security program and what they do where their data is located, what they do to protect it, their compliance levels, their certification levels, um whether they do audits, whether or not they do penetration tests And what type of and, and, and everything to that order and that should be vetted by, by somebody before they onboard an aunt. And we do this all the time. We use a lot of different apps to Texas north of 100. And so we, every time we were on board one for some utility within the organization, we make sure that they meet this standard. There’s, and we actually, since we’re a third party vendor for other people, they have the same for us so that a lot of the work I do as well as to, you know, report out periodically to all the people who are using our, our platform to facilitate their data to organizations and you know, what sex, what tech soups information security program like. So this is, you know, because creates transparency, but it also helps people understand what the risks are, which helps when you’re in a situation where I needed to go and advocate for resources to institute a cybersecurity program.

[00:41:47.96] spk_0:
I want to ask you about the board’s role in all this. But, but is there anything more that you want before we get to the board? Anything more you want to talk about threat minimization policies? Anything we haven’t covered that you want folks to know about?

[00:44:14.11] spk_1:
Yeah, I think that one of the things that is, you know, that we haven’t mentioned yet is preparedness for an incident, essentially a security incident, incident response plan. This, you know, is another thing in that sort of list of five that an organization should understand. Um if you have a situation where your data’s been um breached. And, and one thing I do want to do is to describe quickly, even this kind of a dry topic is there is a difference between a security incident and a security data breach. A security incident is could be something as innocuous as somebody just knocking off your website and taking it down with a DDOS attack. Now that sounds in Oculus because it’s just, it doesn’t sound innocuous because it’s disruptive because nobody can get your website, but nobody’s taking the data. And as soon as that denial of service attack is stopped, your website maybe still functioning. Um But that’s an incident and a data breach is different because now you’ve got to do a couple different things. You’ve got to number one, find out how the breach occurred, which you should also do in case of the DDOS attack. Um But above that, you also need to then understand how to respond to, you know, what data was breached. What’s the scope of that data and who are the individuals and, and what’s our plan to reach out to those individuals and notify them about the breach? And was our policy around that? And who do we have to include in terms of communications internally and legally and, and to provide that transparency because for a number of different reasons, number one, it’s the right thing to do. Um and number two, because it actually helps build trust within, within communities because if people understand that, you know, these things happen and they happen to some very, very large organizations, right? We, we know about these, these really large breaches, but the more transparent they are the more the consumers or the constituents who used those products. Think gosh, they really responded well to this and they acted immediately, they communicated appropriately and they remediated, you know what happened and, and that was the responsible thing to do and you don’t wanna be doing that in the middle of a breach. So, having a plan up front helps during that process because otherwise it’s just too much at one time, everything and

[00:44:21.00] spk_0:
the plan is gonna lay out who’s in charge, who makes, what kinds of decisions, um,

[00:44:27.43] spk_1:
notify. Right. And what’s the playbook essentially? Yeah.

[00:44:52.19] spk_0:
Like, I mean, it could even, it could even break down to needing a remote place to work. I mean, go go that far or because we’re because we’re hopefully in the cloud we don’t like like if our physical infrastructure gets um compromised, do we need to go off site? And, and what’s the technology, the technology capabilities in our, in our off site work location?

[00:45:17.93] spk_1:
Well, that’s actually a little different. Um so we usually talk about that in terms of business continuity plan. So and, and that would be the same sort of plan you would enact case of a natural disaster or something like that. I mean, is a business continuity and, and that’s far exceeding the scope of what we can discussed today, although I’d be happy to discuss that. Let’s not let’s not

[00:45:22.65] spk_0:
I don’t want to panic folks. Okay. Alright.

[00:45:25.60] spk_1:
Alright. Alright,

[00:45:27.20] spk_0:
you got me focused on, you got me focused on like I don’t know, natural disasters and terrorism. All right, let’s

[00:48:44.52] spk_1:
go to the board. Okay. Alright. So, so one of the things that boards were all right. So organizations nowadays are let’s put cybersecurity is becoming and, and is becoming as important as sort of financial security with an organization. The two are becoming linked together An organization. And so for many years, as we all know, uh 501 C3 organizations in the us are generally bound to having a financial audit annually. Right. And then they report to the board and the board will make sure that, you know, there’s a financial audit to ensure that the funds are used judiciously. Um there’s oversight and governance over these matters. Cyber security is becoming as important as financial security because the two are linked together. If there’s a because it could affect it. If you have a ransomware attack, it could affect the viability and the business sustainability of an organization. So it’s a very serious matter. It’s becoming a very, very serious matter for organizations to then think about cybersecurity as a compliance issue, not just nice to have. And so helping the board’s understand that this has shifted from a situation where, oh, well, you know, there’s nobody’s going to attack a nonprofit and uh you know, and if they do, you know, it’s, our data isn’t very important. Um It’s things have shifted, right. So I think recently there was a community, um it’s one of these cities, for example, was an entire city was, has been locked down for days because our grants were attacked and so nothing can function within the city because, you know, um that’s going to affect everything within the city, not just their continuity and safety of people, but also um it’s gonna have a financial impact. So cyber security is becoming more like a compliance issue and a governance issue. And so I think if boards understood that, then they would understand the need to prioritize and to provide funding and resources for those within the organization. Whether that if a small organization that the CFO or the C 00 or even the CEO to then say, look, we need to carve out some resources to be able to understand our risk and the best way to do that would be to do a third party risk assessment and with, with somebody to come in and actually do an evaluation and say, because they’ll come in and do, you know and come in and say, hey, look, these are the, you know, we come in and, and these people are vetted, their, this is their job and you know, they’re safe to work with and go in and say this is where you really need to. These are the critical things, these are, you know, not important things and these are the nice to have and they’ll, they’ll lay it out for you and then you can develop as part of your strategic plan as an organization just like it should be part of your business plan and should be linked to the business plan because the strategic plan for the organization and then the funding, the budget resources, the resource planning and all these things should be baked into the operational strategic plan for an organization. That’s where we’re going in the sector.

[00:49:03.09] spk_0:
Okay. It belongs as part of your strategic plan, your business plan. Alright.

[00:49:50.46] spk_1:
Yeah, and, and that’s where I think that it’s um uh it’s just like I said, I think where a board comes in is to helps understand that so that they could then authorize and, and oversee and ensure that an organization is doing this work and it’s hard work because, you know, you may have limited resources where we’re gonna carve where we’re gonna carve this out. And however, the good news is that there are people who want to fund this, there are grantmakers who are super would be super happy to be able to say, look, I’m gonna help, I’m gonna capacity impact um grant to this organization to help improve their cybersecurity because of these trends that we’re seeing. And so, and then you can use that as a mechanism to possibly help fundraise to offset some of the funny. So it doesn’t have to come out necessarily of your operational costs.

[00:50:23.28] spk_0:
Okay. There are foundations that will fund fund this. Yeah. Alright. All right, we’re gonna leave it there, Michael. Thank you, Michael from Montana, Michael Eno’s Senior Director of Community.

[00:50:26.28] spk_1:
And it’s

[00:51:30.65] spk_0:
my pleasure to thank you, senior director of Community and platform for Techsoup Global he’s on Mastodon at Michael underscore Eno’s at public Good dot Social and Tech soup where you’d expect them to be techsoup dot org. Next week, I’m working on it. Uh, and I assure you that there will be a show next week because this is show number 630. And I’ve been producing a show every week for 13 years close to. So I assure you there will be a show next week. I just don’t know what it’ll be about, but don’t bet against me because there is gonna be a show. You know, you’re gonna lose if you bet against there being a show next week. If you missed any part of this week’s show, I beseech you find it at tony-martignetti dot com. Our creative producer is Claire Meyerhoff shows. Social media is by Susan Chavez, Mark Silverman is our web guy and this music is by Scott Stein. Thank you for that affirmation. Scotty B with me next week for nonprofit radio big nonprofit ideas for the other 95% go out and be great.