Tag Archives: disaster recovery

Nonprofit Radio for July 13, 2026: 5 Project Management Tools For Non-Project Managers, Cybersecurity On A Shoestring & Make Confident Tech Decisions

 

Adrienne Figus: 5 Project Management Tools For Non-Project Managers

From project charter to closing report, Adrienne Figus walks you through the essential tools to help you take control of the changes you may find yourself leading. She’s with Madison College. Here are the resources Adrienne refers to.

 

Edward Wilson & Ellen Samuel: Cybersecurity On A Shoestring

Our panel covers 10 essential security measures every nonprofit can implement right now, without an IT team and without breaking the bank. From knowing where your data is to changing default configurations. And from firewalls to offboarding data. They’re Edward Wilson at ArchTech and Ellen Samuel from Just-Tech. Here are their resources.

Simone Carvalho & Rebecca Kaplan: Make Confident Tech Decisions

Simone Carvalho and Rebecca Kaplan explain when you need an audit of your tech stack, and the steps to conduct the assessment. Along the way, you’ll lean on surveys, interviews and process maps. Simone is with Skeleton Key Strategies and Rebecca is at Feeding America.

 

Listen to the podcast

Get Nonprofit Radio insider alerts

I love our sponsor!

Bridge Conference: The conversations happening at Bridge will shape strategies, careers, and organizations long after the conference ends.

 

Apple Podcast button

 

 

 

We’re the #1 Podcast for Nonprofits, With 13,000+ Weekly Listeners

Board relations. Fundraising. Volunteer management. Prospect research. Legal compliance. Accounting. Finance. Investments. Donor relations. Public relations. Marketing. Technology. Social media.

Every nonprofit struggles with these issues. Big nonprofits hire experts. The other 95% listen to Tony Martignetti Nonprofit Radio. Trusted experts and leading thinkers join me each week to tackle the tough issues. If you have big dreams but a small budget, you have a home at Tony Martignetti Nonprofit Radio.
View Full Transcript

Hello and welcome to Tony Martignetti Nonprofit Radio. Big nonprofit ideas for the other 95%. I’m your aptly named host and the pod father of your favorite Hebdomadal podcast. I have to apologize for the audio today in our 2nd and 3rd conversations. Consistent with the lackluster host that you know you suffer with, uh, he, I, Failed to plug in the, uh, microphones to my phone. For these two conversations. You see, at, at NTC, of course, I got all my remote gear. We’ve got 4 microphones set up, one for me and one for, and 3 for, uh, the other, for the panelists, the guests, and those mics go into the mixing board, and the mixing board plugs into the phone because my phone is where my recording app is. I use an app called Hindenburg. Well, for these two conversations. I didn’t realize that I had not plugged my phone in from the mixing board, so the sound you’re gonna hear in those two is just. My phone picking up voices, uh, along with all the ambient noise. So, the phone, of course, is sitting in front of me, so I’m loud and clear in these last two conversations today, but the guests are a little quiet and there’s ambient noise, and I did the very best I could to strip out the, Ambient noise as much as possible without reducing the, the guest voices, and I tried to elevate the guest voices and make them as clear as possible, but Uh, my apologies for the audio quality on the, the last two of today’s conversations. But nonetheless, I’m glad you’re with us. Cause I’d be hit with stomatalgia if I had to say the words, you missed this week’s show. Here’s our associate producer, Kate, to tell us what’s going on. Hey Tony, I’m on it. We wrap up our coverage of the 2026 nonprofit technology conference with three conversations. First 5 project management tools for non-project managers. From project charter to closing report, Adrian Figgis walks you through the essential tools to help you take control of the changes you may find yourself leading. She is with Madison College. Then cybersecurity on a shoestring. Our panel covers 10 essential security measures every nonprofit can implement right now without an IT team and without breaking the bank. From knowing where your data is to changing default configurations, and from firewalls to offboarding data. They are Edward Wilson at Arch Tech and Ellen Samuel from Just Tech. Finally. Make confident tech decisions. Simone Carvalho and Rebecca Kaplan explain when you need an audit of your tech stack and the steps to conduct the assessment. Along the way, you’ll lean on surveys, interviews, and process maps. Simone is with Skeleton Key Strategies, and Rebecca is at Feeding America. On Tony’s take 2. Thank you, N10. We are sponsored by the Bridge Conference. Tony will be with more than 2400 nonprofit professionals at Bridge, July 29 to 31 in National Harbor, Maryland. Info and registration at bridge.org. Here are 5 project management tools for non-project managers. Welcome back to Tony Martignetti nonprofit radio coverage of the 2026 nonprofit Technology conference. My guest now is Adrian Figgis, project manager at Madison College. Adrian’s topic is five project management tools you need, especially if you’re not a project manager. Welcome to nonprofit Radio, Adrian. Nice to meet you, Tony. Thanks for having me. It’s a pleasure. I love this topic, project management, something we haven’t spoken about on the show for a long time. Could you give us a high-level view before we get into some detail? Sure, so this session grows out of what I wish that I had had handed to me when I was first becoming aware of project management as a discipline and the challenges of projects generally, uh, before I became a project manager and a lot of that was handed to me, you know, here at the NTC over the years, many years ago, and so this is I’m here to try to give back and. And see how can I help at least a little bit with people who are dealing with massive projects without a specific project management background and try to increase the overall culture for project management in our nonprofit community. All right, thank you. So let’s dive in. You have, um, you have 5. 5 steps, not 5 projects, 5 tools, 55 tools that you’re, you’re giving back to the community. I love that. I admire that. Thank you. I, I consider myself a member of the community. I’m, I’m not involved at all in project management. I have a one person company, so my projects are modest, uh, by scale and in terms of yours in comparison with yours, but. I can still say thanks for giving back to the community. That’s awesome, awesome. You’re very welcome and, and thank you for the same, you know, I think you, you clearly give a lot back to this community too, and it’s really what we’re all here for here to do at NTC. We’re all contributing. All right, uh, first, before we get into the 5, let’s define what what you mean by a project. So the, you know, technical formal definition of a project is a temporary endeavor that creates something new. So that is as opposed to operations, which is the ongoing work that makes up, you know, the, what we actually are doing. Regularly on a regular basis, but those things flow together, you know, and, and there’s overlap in a lot of cases, especially in smaller, you know, organizations like, you know, yourself a solo shop or small organizations that don’t have a formal culture of project management. Um, but I think that core of it’s a new thing we’ve never done, so we don’t already have a playbook for it, and it’s, uh, a temporary thing that at some point we will hopefully succeed and be done with it, um, or it will shift and become our operation. ongoing and so project management are those tools that help us with that newness and temporarineness to then hand over to a related but different set of skills for for optimizing the operations. OK, um, is it necessarily, uh. A tech related tech project? I mean, could it be a capital project? Could could these tools apply to that kind of project or absolutely these tools are, are project type agnostic. Um, I, most of the projects that I manage have something to do with tech. I work as a project manager in an enterprise project management office in a college and we rest. Inside the tech department, so just by virtue of that there’s usually tech involved, but we’re also doing organizational change projects we’re doing, you know, things that maybe only incidentally have tech, and a lot of what I’ve learned about project management, especially through the NTC goes back to work that I’ve done in my previous career in fundraising. So a fundraising appeal can be a project because it’s, you know, that appeal itself is a new thing that will end it goes into your operational flow of projects. So really anything, um, tech is, is just the, the, the hook here. Oh, that’s our, yeah, that’s our medium here. OK, cool, yeah, um, so let’s go. Into the tools. What, uh, what are they? All right, so the 5 tools that I brought, you know, they’re, they’re by no means the only tool I talked to a project manager. There’s hundreds, but the 5 that I think are, are a good head start for people who, you know, have, have not done this before and might apply to basically any project are the project charter, the stakeholder register, the communication plan, the meeting agenda, and the closing report. Um, and do you wanna go into reasons why I chose those, or yeah, yes, but would you say them one more time for me? Absolutely. The project charter, the stakeholder register, the meet, uh, communication plan, uh, meeting agenda. And a closing report. OK. Yeah, so let’s start with the project charter. Sure, uh, so the project charter is a document, you know, it can take a lot of forms. It’s less common in organizations that don’t have formal project management, um, but you can do it in a really lightweight way. It’s essentially a contract that sets out the basic terms of what are we doing, why are we doing it? Who has given us the authority, what kind of resources do we have, both financial and people and time, um. How will we know that we did it correctly? So, so like scope, like a, a, a scope of work, yep, it includes the scope of work. Um, it includes the, the mission and vision of the project. It includes, you know, the scope of work also crucially includes what’s out of scope, what are we not gonna do, um, and it also pulls together who is in the project team, who’s in the governance, who’s responsible for the project, budgeting as well as in here. The scope is gonna impact budget, obviously, clearly, OK. Um, all right, anything else on the, on the charter? I don’t wanna go through, I don’t wanna go through them too fast. I don’t want you to give short shrift to nonprofit radio listeners. No, I could tell you’re not doing that. The, the charter is one that’s really easy to skip because it seems intimidating, especially if you don’t have a project management office, so you’re not a project manager, but even just a single one page that says this is who said it’s OK to go ahead with this project. This is what we’re doing. This is what we’re not doing, and you know we have a budget. It came from this department or whatever, um, taking the time at the start of the project to have those discussions to identify so you don’t get six months into the project and realize, oh, turns out no one actually gave us permission for this, and now we’re getting a lot of pushback, that kind of thing or what we’re not clear what the budget, yeah, I can see. I mean, like a lot of things, the preparation and the planning are valuable even though they’re a time suck, but they’re gonna pay off in ways that you may never even learn through the, the remaining 44 tools, right? I mean you, you’re gonna get creep and uh yeah, accountability and authority issues and things like that that you’re gonna avoid if you’re intentional at the. Yeah, at the outset, OK, um, I, I got an interesting question from one of the participants, um, who was describing a situation where she’s, you know, new to a, a department in her Oregon is being tasked with picking up a project that has gone adrift because there was a lot of staff turnover. The people who were on it are no longer there. There’s uncertainty of what was done. Things are in some abandoned asana boards, and she was asking about what to do to move forward. And I really think that taking some time to write a new project charter and say like this is maybe the phase two of this project we’re starting over again we’re acknowledging what was done, but we’re not gonna be bound by like a contract that was maybe implicitly created even if it wasn’t written down by people who aren’t there anymore to carry out the terms of the contract, but that’s a proxy for the conversations that have to be had anyway and it’s the the the charter as a holder for that. And then the register, the stakeholder register, so you know, projects like operational work and anything else else we do in pro in nonprofits are actually all about people, you know, nothing is gonna happen. AI is, is not there yet. Um, I, I don’t think it ever will be, but that’s not our topic. Um, anything you do in a project involves people, and the lingo in project management for people is stakeholders. The formal definition of that is basically anyone who uh will be affected by your project’s outcomes or you know the the tech work it takes to do the project, um, anyone who can affect the project either affect the outcomes or affect the way that the project works, um, and anyone who can get in the way of the project or enable the project to move forward risks exactly. So, so some of your stakeholders are, are people who may be threats but also may be your greatest allies later. Uh, so the stakeholder register is really just a list of all those people, and I’ve provided a template that is, uh, you know, it’s a simple Google sheet that gives you some ideas of things that you wanna know about those people in order to get them to contribute as best they can to the project, hold yourself accountable to checking in with them. And um if they are people who may present threats or or be you know a potential challenge for your project, how to activate them and turn them into champions and assets for your project but it all comes down to in the first place you have to know who they are and that’s what the stakeholder register is all about. OK, OK, um. Yeah, the folks who are going to be impacted by the project, I mean, I hope they have influence in the project too, so it’s not foisted on them and, and assuring, you know, non-use. And that’s one of the things that is absolutely the responsibility of the project manager. It’s also the responsibility of everyone else in the project, but I, I see an important role of the project manager as being the communications hub for the project, the, the person who anyone can come to me and say, oh well, there’s this project going on. Adrianne’s involved. I’ll just ask her what’s going on, and then I give them all that. Information even if I already emailed them 3 times, I’m always happy to tell you again because the fact that you asked me matters but I’m also accountable, you know, if I had Tony on my list of users who’s gonna be affected by this change, I have to proactively reach out to you to understand, you know, if you’re, if you’re an core user to understand what your needs are, explain to you how things are gonna be changing. But even if you know you’re my user but you’re not in my org, you know, like I don’t know you, I have to understand as much as I can about you to be sensitive to that and so sometimes you might be on my list of stakeholders, you don’t even know the project is happening, but it matters to me that it happens in a way that works for you so all of these things, um, again it just comes back to knowing. Who we’re thinking about in these projects, I could see that’s an important part of your work because you’re, you’re a big university, well, college, whatever, but a big organization. I mean big enough that it has a project management team that you’re on, so you don’t know a lot of the people unless you made projects with them before, but throughout the college, you may not know a lot of the stakeholders because you, you work in a, you work in a project management team serving the whole college. So getting to know folks, buying, getting their buy-in. I mean, I would think that’s a big part of your work as a project management. Expert team member, absolutely. Anytime I’m starting up a new project, I’m, I’m just about 2 years into my current role, so I’m just now starting to get my feet under me and understanding where all the offices are and when people use acronyms, I think I know what that that is and. At this point now I’m starting new projects that that involve people that I knew before, but it’s still my first task to say, OK, what are all the offices and people that are gonna be involved? What are the groups of students that might be affected or faculty, sometimes community members outside the college, some of those, it’s groups, you know, so maybe it’s all of the students in one, you know, area of the academic area or sometimes it’s all of the staff members in, you know, the library. Um, and so I have that group, but then I start dialing in and saying how do I learn more about that group as individuals? And then when I have actual individuals, how do I use the networking tools that I have available to me inside the organization to say, hey, like I haven’t met Mike before. What can you tell me about him? How do I, how do I talk to him in a way that makes sense to him and then introduce myself as, as the project manager, um, and help them see how they can interact. Because I, you know, you never want a project to get too far along and end up being a surprise to somebody who needs to actually be involved. Yeah, yeah, that’s, yeah, that’s poor. That’s, that’s the, that’s the, uh, antithesis of. Smart project management. Uh, number 3 is your communications plan. All right, so like how are we gonna keep in touch with all these stakeholders that we identified in the, in the, uh, register? Absolutely, yeah, and that’s they, they go hand in hand and personally I actually like to use a single spreadsheet with multiple tabs, one for my stakeholder register and one for my communication plan. I can just tab back and forth and see, OK, for each of these stakeholders, some of them individuals sometimes groups, those are audiences that I need to communicate with what can I put on the communication plan as far as one on one conversations or, you know, road show presentations or, you know, email blasts or however I can communicate but then as I’m writing out the communication. And I think of other things that I might wish to communicate and think about the audience and then if that audience isn’t in the stakeholder register, I scurry back over to that tab and add new lines. Both of those are are living documents that keep going through the whole course of the project as I learn more about the project, I learn more about the needs and the people and build it together and then next time I do a project that’s similar, I can go back and sort of take some of that information and, and start, uh, the next project. OK. Go ahead with 4, our agenda meeting agenda. So this one is a meeting agenda meeting agenda, yeah, it’s, it’s, it’s the simplest one. I, I don’t belabor it in my presentation, but it’s so important and something that is so easy to ignore. Um, I’m not an anti-meetings person, you know. I think that meetings are an important communication tool. I put them on my communication plan. Um, you know, sometimes a, a week-long email chain could have been a meeting, um. But it’s a sort of a sacred trust to ask people to come to a meeting. You’re asking them for their time. You’re asking them to put themselves out there and hopefully feel that they’re actually contributing in this case to the project, and part of that is the agenda. You need to have a goal for the meeting. You need to understand who’s invited, who of your stakeholders are invited. You need to understand what are you, uh, attempting to discuss, accomplish, what decisions do you need. But also you need everyone who’s coming to the meeting to have access to that information up front. If I just call, you know, you and, and Amy and, and 3 other people into a meeting, but I don’t tell you what’s happening, you’re coming in puzzled, annoyed with me, not ready to engage. You might just like say no at the last minute. But if I send out the agenda and say like, here is the importance of this meeting, here’s why you, Tony, are coming. And if you can’t come, I need you to delegate somebody from your team because we need this decision. sharing that information up front helps to level the playing field, make sure we have everybody in line and really get value from that meeting. So what kind of meeting cadence do we need that varies by project and we have like an 18 month project. Yeah, um, that’s something that I like to negotiate with each project. Uh, very commonly I’ll have a core team that’s usually like, you know, between 4 and 6 people who are steering the project and maybe, you know, they’re doing hands on tech work and I’ll do a weekly check-in with them and we know it’ll be sometimes a half hour just to say here’s what we’re doing. Um, which we’re ready to cancel if nothing new has happened and so that’s a big part of the agenda is like check in a few days beforehand. Can we cancel this or do a asynchronous check-in. Then I like to do sometimes like either biweekly or monthly meeting with more of a steering committee that are people that have decision making authority or who are very, uh, concerned stakeholders but maybe not doing the actual work of the project. And then I’ll often, especially in a longer project like an 18 month or a 2 year project, I’ll have subareas within where we’ll have, you know, meetings once a week for 2 months for a sub team that’s working on something really heavily in that 2 months, but it’s only the people that are actually doing that heavy work like I, I had a project where we. We’re doing um some compliance uh regulatory changes that needed some technical updates but also needed quite a bit of um information sharing and communication to bring the whole college community along because it involves some somewhat significant business process changes to meet our new state regulations. So we had a communications subproject that involved doing a lot of website updates because you know for a large institution getting all the approvals to update the website and just the mechanical work of that is a lot so we had a, a little communications strike team of of 3 people and we were meeting once a month or once a week for a short period of time while the overall project team was meeting at a different cadence. OK, so it’s uh that’s part of setting up the agenda is if it’s a recurring meeting, getting everyone to agree on the cadence and then revisiting that. I, I also like to revisit a meeting cadence about every 6 months and say, or in, in higher ed I’ll do it on a semester basis like, so you know, for spring semester we met this regularly. Do we need to do that for the summer? And on our closing report, so the closing report, you know, it’s, um, brings us back to that definition of a project that by definition it’s a temporary endeavor that means it has to end, but this is a thing that really trips a lot of us up, especially those of us that don’t, you know, currently I, I work in a place that has very defined policies around closing projects for budgetary reasons, but at my previous roles, um, it is very common, and I know a lot of people that this is very common that a project will just keep going. You know, maybe you weren’t able to accomplish what you thought you were going to or you had some staff turnover and no one’s quite sure what’s happening or like, you know, a grant got pulled so you had to put it on the back burner but you didn’t actually close it because maybe that’s admitting defeat or you’re not quite ready to declare victory and it’s just there. And then it becomes a major, you know, psychic and time weight on everyone who was involved with it because even if you’re not working on it day to day it’s in the back of your brain and you remember, oh yeah, you know that that refresh on the website that we decided not to do. I’m still gonna think about it every couple of weeks and so having a way to close a project, um, by, you know, policy and will of your organization but also a practice and a template to do that. Whether it’s because you finished the project successfully and you’re gonna celebrate it, it’s wonderful, or we’re acknowledging, you know what, having this project open no longer meets our needs, so we’re gonna just close it down and we’ll have lessons learned, no blame, it’s just, it’s OK. Um, having a template ready to go that you know at the start of the project, um, you know, would help you sort of write your charter to say how will we know that we’re done preparing yourself to then close it, I think can help lessen that pressure of just having these projects that just don’t stop. It’s uh yeah it’s a boundary like we know this is completed good hopefully not bad let’s say just good or indifferent it’s it’s wrapped up you know we’re all moving on. OK, it’s time absolutely and then the report itself can live in your organizational files if you have a PMO. It lives in your PMO, but then it’s there for re, uh sorry, project management organization, and that’s the group that I that I work in. Um, but there are organizations that have what they call a PMO, but it’s just one person who holds all the templates and the records that, that can be a PMO. But your, your way of doing projects, and maybe it’s just a file in your OneDrive, um, but if you have those records of all these past projects, then when you do a new project and you’re gonna charter a new project that’s somewhat similar, pull out the closing report from the old ones that were similar and say, what do we learn on this project about how we operate. Great things we did that ended up not being productive for us, things that were really great, um, you know, and that will make your next charter and your next set of meetings and everything else much easier and, and better for the next time. Where do we document changes, uh, uh, process changes, maybe staff changes that are that have been made? We’ve been doing it this way at the college for many, many years and now that the. Our project has closed. Uh, Business processes have changed. Maybe reporting responsibility or who’s responsible for different things that changed? Where do we document all these these organizational changes? Oh, that’s a really good point. So that’s part of the closing report is. Acknowledging that you did the handover to operations and so the closing report should document the decisions that you made, the changes that you made, but just because it’s in the closing report of a project doesn’t mean it actually happened I think is what you’re, you’re, uh, implying, uh, or or alluding to and so, um, that’s where the like projects shaking hands with operations really comes in is you’re saying OK, this project made this happen. But then some team, you know, some operational team or department or person has to take responsibility for that, so you can’t actually close the project until you’ve done the handover. So, you know, oh, I’m, I’m, you know, did this project where I, you know, helped you implement your new scheduling system for your, uh, podcast guests, um, until I hand it over and you say, OK, I acknowledge that I have this new process and it’s, it’s in my area. I can’t say my project is done because you didn’t actually take it on and agree to do it. Um, do we have a ceremony or what is there a ribbon cutting? I mean, if it’s a physical project that could, but still, even so, that’s ceremony, that’s not operational continuation. Mhm, um, yeah, so you can have, I, I highly recommend having, you know, a, uh, some sort of a ceremony to close the project, a final meeting or a pizza party or something, but that sort of that handover of the new. Things I like the idea of it having to be some sort of a pomp or circumstance to make it happen um but the recording of the new policies should be done in whatever way you are recording your policies so like however you had it written before you change and put it in now if the project was to set up a change in tracking system for your things then you’ll have it. OK interesting all right um what else, what else did you talk about in your session that we haven’t talked about with our listeners. So one of the things, and, and you know I can share with you the link to the templates, um, yeah, actually, would you do that you email me the link and then I’ll include it in the show notes. Absolutely I can do that and, and I really encourage anyone to, to take a look. They’re all um. You know, the just Google Docs and Google Sheets. Anybody can download them, brand them yourself, use them, you know, fully free. I have a little CCB license on it, but really I assume you’re gonna be changing them enough that it’s your own work if you use it, so it’s my interest to get it out there. But in each of those, um, areas. As people who work in nonprofits and mission based institutions, I think each of these tools is an opportunity for us to like express and forward our values, um, so in the project charter you should be writing your project vision or project mission in line with your vision and mission of your organization. You should be expressing your values in your stakeholder registry. You should be expressing your values based on who you are targeting as your stakeholders that you know it’s not just like you. Googled and saw, OK, who should be a stakeholder for a website change it’s, you know, your people and your people who matter to you on a deep level as an organization, go for that. Um, there are some really useful things around accessibility that you can do in a stakeholder register. You can note, you know, are there people who have specific accessibility needs like do they need a wheelchair accessible meeting room, um, so you make sure that you have that for them or you have live. Optioning so that you don’t have to keep asking people the same questions in order to make sure that they are able to be in the room with you. Same thing with your communications every project communication you send out should be an expression of your organizational values, um, and that’s gonna play out differently depending on the project, but, um, I, I think if we keep this in mind and make sure that, you know, we’re, we’re not ignoring that aspect of it just to drive a project through we’re all gonna end up with better outcomes in the end. That’s a great place to end. That’s perfect and with values. Absolutely. Adrian Figgis, project manager at Madison College, Madison, Wisconsin, thanks very much. Thank you for sharing. Well, thank you, Tony. This has been lovely. Thanks and thank you for being with Tony Martignetti nonprofit radio coverage of the 2026 nonprofit Technology conference. It’s time for a break. We are sponsored by the Bridge Conference, produced by AFP DC and DMAW July 29 to 31 at the Gaylord National Resort and Convention Center in National Harbor, Maryland. More than 2400 professionals will gather at bridge. Tony will be with them. The question is, will you? Thought leaders from nonprofits, associations, foundations, hospitals, higher ed, faith-based, and mission-driven causes across the country come to Bridge to discover new ideas, solve real challenges, and connect with smart people shaping the future of our industry. From 125+ educational sessions and hands-on pre-conference workshops to bridge tech, the faith and fundraising forum. And inspiring keynote speakers, Bridge offers something for every mission and every role. The conversations happening at Bridge will shape strategies, careers, and organizations long after the conference ends. Don’t hear about it afterward. Be in the room. Register at bridge.org. Now it’s time for cybersecurity on a shoestring. Welcome back to Tony Martignetti Nonprofit Radio coverage of the 26 NTC. That’s the 2026 nonprofit Technology Conference where we are all gathered together in technology community in Detroit. My guests now are Edward Wilson, principal at Arch Tech, and Ellen Samuel, COO at Just Tech. Edward, Ellen, welcome to Nonprofit Radio. Thank you for having us. I’m very glad you’re with us. Your topic is cybersecurity on a shoestring, safeguarding nonprofits in the age of AI. Um, Ellen, could you do, uh, just give us a 30,000 ft view of the topic before we go into the details? Sure. So we wanted to make sure that nonprofits understand the importance of, uh, cybersecurity and securing their technology and their. Staff and the client information and data and we went through how we can do this, uh, affordably or as affordably as we can. So, um, we went through the importance of why, why, um, nonprofits are at risk and how they are attacked and then, uh, some, uh, list of things that nonprofits can do. Relatively cheaply in order to maintain their security. And then we had a bit of a dive into business and compromise and wrap things up at the end with some amazing questions from the audience. OK, well, we’re, we’re gonna talk about all that and uh maybe even some of the questions. We’ll see. So we’re gonna, we’re gonna go into some details. So thank you very much for uh giving a high level view. Um, why are we, uh, Edward, let’s turn to you. Why are we, uh, nonprofits at risk? How are we at risk? That’s a great question. One of the things that we run into with most of our nonprofits is that there is more demand for their service than there is budget to help them meet that demand, and that leads to a lot of difficult decisions along the way. Nonprofits are actually the number 2 target these days for cyber criminals because they’re aware that there’s some weakness in that area where we haven’t strengthened the whole picture. We underinvest in cybersecurity because we’re more devoted to mission and programs. Yes, and sometimes I think there’s that, again, it’s an education thing, right? So we’ve seen nonprofits who have spent a lot of money potentially covering one small space of what they need to work on. But leaving other picked areas of the business not covered. And so our goal was to help them get that 360 degree coverage for less than they might spend on one fancy tool on a shoestring, or cybersecurity on a shoestring. By the way, I love we have like some symmetry. Edward Nellen, Archtech Just Tech, uh, it all, it all seems to fit together very well. I wish he had the same. I wish you had the same initials, your last initial. Maybe you could change your name to Samuel. Edward, maybe you could change your name to Samuel. Yeah, Samuel’s, yeah, Ellen Samuel. It’s cool, like Ellen Samuel, Edward Samuel, Arch Tech, Just Tech. OK, we’ll, we’ll, we’ll work with, work with what we have, you know, it doesn’t say he’s, he’s, he’s open to the idea, but he’s not about to run out and do it, so change his name. So, all right. Yeah, all right, all right. So we’ll stick with the, uh, I like the architectch just tech. All right. Um, so, I don’t know, should we just do like do ping pong? Like you have 10 essential, oh, let me, uh, I do have a threshold question, um, from your session description, 10 essential security measures every nonprofit IT team can implement right now, do we have to have an IT team? To do a lot of these 10 essential security measures, or can we do it if we don’t have an IT team? Maybe would outsource IT vendor helping us. Is that OK? Or do we need to have an internal team? Absolutely we understand that most, a lot of nonprofits don’t have probably most our listeners are small and mid-sized nonprofits. We’re the other 95, we’re the other 95%. So exactly. So we have one person who is the IT team and they’re not trained in that. Um, that’s one of the services that we as new service providers provide more affordably to nonprofits is we can give them those services and that expertise without having to hire a full time. OK, OK, so we can still take advantage. Of the 10 essential security measures that every nonprofit can implement right now without breaking the bank, we can still take advantage of these. Absolutely. Otherwise the mics are going off and we’re done. We’re done in fewer than 5 minutes. All right, that’s good. Whether they have an in-house team or they’re using an external team, that list of top 10 items is a great checklist to walk through. And say, am I covering all of these things with our in-house or external team? So for decision makers, really important. All right, let’s get into the, let’s get into the 10s, kick us off. Give us numbers 1 and 2 because we’re not going to go 1 Samuel, I mean 1 Edward, 2 Ellen, Edward, Ellen, Edward. So let’s do like 2 or 3 at a time. Edward, give us our top 2. Sure, the first thing we say is that you need to identify where all of your information systems actually are. People store information in a lot more places than they think. They may think a server or an email system, but you’ve got your accounting platforms, your HR platforms, your telecommunication platforms, your backup platforms, backup email, online giving, making sure that you understand all the places that you need to protect, controlling what we call the information system boundary. And then we want to protect access to that by protecting the users who access it with things like MFA passwords, and so on, and even protecting the devices that access that where we can. OK, is that 1 and 2? That is 1 and 2. OK, so number 2 is the protection of the data once you identify where it all is, protecting that access. Absolutely. OK, protecting access. All right. Ellen, it’s your turn. So one of the highest ROI things that police can do or organizations can do is implement MFA multi-factor authentication. And this, for anyone who doesn’t know, is a way of logging into systems. Using both a password and something else. So a token, um, a text message, we all know about this using from our bank, um, other systems. It is one of the the best ways that you can protect your users from being Attacked or or people giving up their credentials to your system and it’s usually free or easily to easy to implement and uh we see a surprising amount of organizations that just don’t have it turned on. They just haven’t checked the button and we need to do it. OK, so number 3 is do MFA.A. It’s just, it’s just an extra step. I mean. Uh, I, I think initially maybe it was annoying, but now it seems like it’s just, OK, I’ll, I’ll get the text. I don’t know. Maybe this is true on Android phones. I know on iPhones you get the text and you don’t even have to put the numbers in. If you’re on, if you’re on the phone, it just says use, use from text. Put the numbers, yes, tap that and it fills in the 5 or 6 numbers. So you don’t even have 5 or 6 keystrokes that you have to do, key taps, I should say. So, all right, do MFA number 3. All right, what else? What else for? Talk about also changing your default credentials to your hardware that you get. So you get um a camera that comes with uh default credentials that are open and available. That information’s on the internet. And anybody can come in and log into those systems and do kind of nefarious things with those. And it’s really easy and cheap. It’s free to go in and change that information on your routers, on your Internet of things devices. Just go in and change those things so that people can’t come in and look at your video or get into your system because they’re because they’re standard format defaults, right? It’s like, yeah, I just right. I just learned one, you know, on WordPress, the admin, the admin URL is standard like WordPress slash admin hyphenWP or something like that, or WP hyphen admin like, so everybody knows that and, and it’s easy for a bot to, to. To exploit it, OK. And that also, that, that also applies at home, like your, your ring, your ring system, your refrigerator, whatever, you know, whatever, like you, you mentioned the internet of things. I’m just, I’m just drilling down. Whatever you’ve got, it came with some default admin password. Your, your home, well, home as well as office, um. Um, internet access, Internet, right? It’s like Ocean 307 is your Spectrum router default, yeah, change, yeah, Ocean 307. That’s not mine, right? That’s not mine. That’s not mine. That’s not mine. Yeah, mine is 307 Ocean. I’m very savvy about, I’m very savvy about passwords. Yeah, yeah, that’s it. No, no, don’t do that. That’s bad advice. Don’t follow that. Don’t, I don’t want anybody saying I did that, and he said it was a good idea. All right. All right, so number 4, change your default configurations on all your devices. OK. All right, Edward. Edward Wilson is up. I like the next one. Update your infrastructure. So I’ve actually got a story about this one from yesterday. One of the things we do is free security and incident response for nonprofits. They can just call us and we’ll help them out if they run into a security incident. And our most recent call came in yesterday from somebody who had had their router hacked, and they were using an old Ocean Ocean’s 307. It works. It works. You use that everywhere. That they were using a Cisco router that had been installed in 2014 and had gone end of life in 2020 with no additional security updates, and the interesting thing was as we got into this and we looked at it, the last time that it had been updated, the firmware on that was in 2014. Well, they hadn’t even done the updates from 2014 to 2020 we’re 12 years behind on updates for this, and that’s one example of just needing to keep that infrastructure up to date. On our laptops it’s our Windows OS updates. It’s our third party software patching, which a lot of people don’t think about. The browsers that we run, Adobe, keeping all those other programs that are on our computers up to date, so you just click the automatic, just tap the automatic updates option. A lot of times that’s going to take care of Windows, but it might not take care of everything else, so IT teams want to be conscious of that. OK, OK. Update the infrastructures. All right, that’s incredible. So they even, I mean, so the, right, the product had been no longer um supported since 2020. But even before that, from 2014 to 2020, they hadn’t done any updates. Missing six years of so, yeah, right, like 2015, it was out of date for the, and, and, OK, that’s a bad situation. Honestly, we were a little surprised it took so long for them to get hacked given that you’ve been lucky all these years and you should be, you should be thankful. But we do these um technical assessments, both our organizations do where we’ll go in and we’ll look at organizations and one of my very favorite standards for us to look at is the HIPAA compliance standard, the HICP that the government publishes and puts out there for free. And the smallest one that’s designed for physicians’ offices of less than 10 physicians, the average score on that is about 50%. So this is common in the nonprofit world. All right, you have one more, Edward. We’re doing 2 at a time. Got it. I like using the firewall, making sure that we’ve got that set up. We used to be very complex in our firewall setups, and now that we’re more cloud-based, that becomes less important. We want to secure the user and device no matter where they are. But firewalls still have great tools to help protect us at the office. And so just making sure that we’ve implemented many of our vendor best practices. It’s the same among most brands, not using some of those default configurations, making sure that the admin access to the firewalls is MFA protected, goes back to the story I just told. Change that default, make sure you change the default admin on the firewall. Yeah, but firewalls are so annoying. Yeah, they’re going to prevent content from, they’re going to prevent pop-up windows. Sometimes I need the pop-up window because I do want to subscribe to the, to the, to the nonprofits newsletters. I want the. The firewalls are radio programs and podcasts. We don’t have, we don’t use pop-up. Yeah, we don’t even, we don’t even pop, we’re not even that sophisticated. But no, all right, so how do I overcome the objection in the firewall, uh, it’s so annoying. I have to load the content directly or I’m, I’m missing out on pop-ups. I’m getting warnings from some sites. How do I overcome? How do we, how do you two at, uh, Just Tech and Arch Tech overcome these? Naysayer objections. I think that leads nicely into one of our other top 10s, which is to train your users and explain why we’re doing these things, why they’re important, what the risks are, and what these systems do. We find that our organizations really do not put the time and effort into training the people at the organization. About how to use their technology safely and efficiently and effectively and a lot of those concerns, a lot of those issues you can handle in those trainings and talking and explaining, yeah, this might make it a little more difficult for you to do your day to day work, but it’s important because we don’t want other people getting into our system. We have really important client information that we are protecting, so. You need to make sure that you’re training, training people on technology and safety and security. OK, can we call that number 7 then? Training, training in it. OK, training, train the users. You get another one. Go ahead, Ellen. OK. Another really important thing is that when people leave your organization, you need to make sure that you are completely off boarding a lot of. Organizations just kind of missed this step. They don’t lock people out of systems. They don’t clear their computers. They, um, they don’t make sure that people don’t have access to their systems anymore, and it is a huge security risk regardless of who it is. If it’s an intern or volunteers in particular, you know, they just kind of set up. Forget about them, but people can do a lot of damage and the systems can be opened and hacked if people are not properly. OK, so it’s more than just taking back the ID card. There might be a code for entry. They might have a personal code for entry into the office. You got to disable that code. You don’t want these people coming back. You just, you just perp walk them out. Let’s not have them come back on Saturday. Using their their personal code to enter the building. Another thing that we recommend is using a password manager because a lot of our organizations, even though they shouldn’t share passwords among their staff, and for example, we do use a, we, um, work with a lot of law firms and sometimes there’s court passwords and court system passwords that you have to. Share, um, and giving those out to people and having them save them themselves is really a risk. So having that in a company provided password manager that can better protect that information as well so that when somebody leaves they don’t have access to that. Oh, that’s interesting. OK, so there are some that have to be shared. OK, yeah, Edward, one that would be really interesting, I think, for your users is to realize that when they’re on that company device and they’re saving passwords to their browser, we’ve seen people do things like log in with their personal Gmail account. Not only is this problematic in terms of saving their passwords to their personal Gmail account, but when they leave the organization and they give the laptop back to IT, there’s the potential to get in and access that information. And this will lead users to support the adoption of company password managers. Highly recommended. OK, Edward, thank you. That’s a good one. That reminds me of a story I heard. The organization provided company phones. But uh I recently. Dismissed employee. Didn’t use the company phone. All her personal info was on her own phone, and all her company info was on her own personal phone. They took the personal phone, or, or maybe it was the other way around. She, she had all her personal info on the company phone. That’s what it was. She lost all her contacts because they took back, that’s what it was. She had everything on the company phone, they took back the company phone. They took it. She lost, like she had to ask for permission, you know, can I call my husband to let her, let him know that I, I don’t, I’m not employed anymore. Um, yeah, I mean, she lost everything, all her, all her personal contacts gone because it was on the company phone. Big mistake. If your company’s giving you a phone, you gotta, you gotta use it just for company info because if, even if you’re, you know, you don’t necessarily have to be perp walked out. You might, you might resign. You might go to another job when you’re surrendering your company phone, you’re surrendering everything that’s on it. Very risky, very risky. All right, that’s a good one. OK, so off board completely, that was kind of we spun off from offboard completely. So I think we have 2 left. Is that, does that sound right? One of my favorites is to separate admin and user accounts, and this goes out to the IT staff who are logging in as an administrator every day on their systems. If you’re logged in as an administrator and somebody compromises you, then they are the administrator, right? And so it’s really important that we have a daily use account and that we keep those admin credentials separate for only admin purposes. Don’t don’t share the admin credentials because it’s easier. OK, just use this, just use this and you’ll be able to change your desktop. Never. Share admin credentials, but also if I’m an IT administrator, I need to have an account that I’m using for daily work that does not have administrative privileges. The only nonprofit I’ve ever seen truly go under from a cybersecurity personally that I’ve seen go under from a cybersecurity incident happened because the IT director was just using their admin account for regular work all day long. They hit the wrong link. They ransomware the entire organization. I see. Oh, using, OK, using their admin account for day to day. All right, now I see the implication because now the attacker had admin privilege, had admin, right, right, right. They hacked the admin account, not just the user level account. OK, that’s an excellent one. You love these. I can tell you, Edward, Edward’s like smiling. He loves all these. I mean, Ellen is smiling too, but Edward’s OK, gleeful. Edward’s like gleeful. Ellen is just smiling. All right, passionate about making affordable cybersecurity a reality for folks because sometimes these are things we don’t work, work through or think about. All right, that’s why we’re cybersecurity on the shoestring here. All right, you have one more left. Are you? Deferring to Ellen for the final. OK, OK, because by right this would be Edwards because we’re doing 2 by 2, but he’s surrendering. Chivalry is not dead. Chivalry has not died. It’s, it’s embodied here in this seat. That’s right. So it’s a trade-off. Yeah, yeah. OK, go. So another thing that organizations really need to do is have a disaster recovery and business continuity. We see again organizations this is something that you don’t need to hire somebody for, uh, but you can, um, but you need to make sure that you have a plan in place if and when you are compromised um a lot of times we hear it’s not uh a matter of if you’re gonna be compromised, it’s when, and a lot of places actually don’t even know that they are currently compromised. And there’s people in their systems you can if you get ransomware then you get locked out of your system that’s not the time you wanna figure out what are we, who am I supposed to contact? Who’s our cybersecurity insurance provider? Who are my IT people? What is the cell phone number of the IT person, right? Like these things that you need to have worked on, have written out. I even recommend printing them out like old. School having a physical printed copy because when you’re locked out of your systems, you’re not going to be able to get in there and look at the documents. You’re the, you’re the second guest here at NTC to say print your disaster recovery. She, she and I were talking about disaster recovery and incident recovery, and she was making a distinction between the two, but she and, and the business continuity plan have these things printed because when you’re locked out of the cloud. You’re locked out, so you can’t get the, you can’t get the IT cell number, so print the things and keep them in your office and and keep them at home too, keep them at home too, because a disaster might be in your office. You might have a fire or flood or some emergency that you’re not allowed in. So you go back home and there’s your printed plan and do practice runs. Because, you know, you, you don’t know where your weaknesses are, you don’t know how it’s gonna go until you’ve practiced and gone through the information with everybody on the team who needs to know that information. So do it a few times a year. It’s, it’s always more things that people have to do, but it really is gonna save you time and money and the safety of your information when you get hit. Awesome. I love this. The uh Ellen Edward show. Ellen and Edward show. We have our own Arch Tech, just architectch, Just Tech, Edward Ellen. OK. Um, so there’s our 10. We’ve, we’ve, uh, enumerated our 10 and gone into some detail on each. You mentioned business email, something about business email. Don’t hold back. You talked about it in your session. You got to share it with nonprofit radio listeners. What is it about business email that we need to know? So we’ve been doing free security and incident response for nonprofits for about 5 years now, and we’ve only seen one incident that wasn’t compromised email in some way or another, and there are two main categories of that. The first is financial compromise, and it’s not an IT item. It’s actually for the finance team. Never change a payment method or process without picking up the phone and calling somebody. We’ve seen vendors get hacked and the vendor submits an invoice and says, please pay this invoice over here, and it looks completely authentic. They pay the invoice only to find out that they paid to the wrong account, the wrong person. That money is no longer recoverable. That’s a finance issue. But even on the IT side, there’s a lot that we can do in order to protect email. And in our session we went through how to get that number to close to 0. All right, let’s do it. We’re not just going to talk about what we talked about in the session. We’re going to talk about the substance here. Excellent. What do we do? There are front end and back end protections in email. OK. Front-end protections involve products like Proofpoint, Mimcast. They scan our incoming email to find bad things and make sure you don’t click those. You can actually do a lot of this for free in Google and 365 without even using those products, and I don’t know how to tell our listeners to download things, but if you put our contact info in, they can reach out. We distributed a step by step how-to for all of the attendees to harden those email systems, and I’m happy to send that out to. OK, what you should do is give me the URL. For where that where that is, and I’ll include the URL in the show notes. Perfect. OK, we’ve got you got to make sure you do it. Somebody has to email me and then when your show is going to be aired in your episodes show notes, I’ll include the URL. Excellent. OK, OK, so we can get we’ve got several downloads in there for you. All right, all right, but we’re going to walk them through how to protect that email account and get the odds of their being compromised as close to zero as we possibly can in this technical environment, and a lot of it involves backend protection. Eventually, no matter how good your front end protections are, an email is going to get through. The user is going to click a link. They’re going to enter in their credentials, their MFA, and they’re going to give that MFA token that access to a threat actor who now has access to the email account, and our ability to detect that, respond, and to shut them out automatically becomes key. OK, OK, Ellen, is there more we can talk about around? Business email safeguards. Just to echo what Edward said, nearly every attack that we’ve seen has come in through email and somebody giving away their credentials. So you’ve got the email issue, right? If those emails never come in, that’s great. But then you also, again, have MFA. That’s if, if an email does come through and somebody tries to give away their credentials, that MFA can stop the, the bad actor from getting it. All right. Business email, very, very common method of exploiting. Nonprofits, I would guess it’s in the 99%. You said everyone, everyone, everyone except one, yeah, in a, in a test that you did or in our experience where we have nonprofits calling us and saying we’ve been compromised. What do we do, right? And we try to help them through that process along the way. It’s been email every time but one, in the last 5 years. All right, I’ll tell you what, Edward, you’re so gleeful about this, passionate, I’m passionate about it. Why don’t you take us out since Ellen gave us the overview. You could take us out with, uh, you know, inspiration and empowerment, why cybersecurity on a shoestring is so important. I want to emphasize to our audience that we want to solve the problem with one expensive fancy tool, but usually that only covers a small amount of our attack surface. We want to look 360 degrees at the whole picture, and there are two open source sources that I would like to refer people to that are free and available online. One is the HIPAA standard, the HICP. They can start with Volume One. It is simple. It is approachable. It is designed for mom and pop doctors’ offices with less than 10 physicians. It’s written in clear, clean language and we’ll give them a checklist to start walking through. OK, so it’s valuable for nonprofits even though we’re not a doctor’s office, even though you’re not a doctor’s office. Every time it says PHI, protected health information, just insert my sensitive and protected information. And you’ll be fine. Excellent. OK. And number 2, number 2 are the CIS controls, the Critical Information Security controls, and that also is open source. It’s available to everyone. I prefer the HICP because I think it’s more approachable and a bunch of really smart people sat down at the table and said, how are we actually being compromised and wrote a list on that. To protect healthcare providers and number 1 is email. All right. And the second resource was CIS, the CIS controls. And what does CIS stand for? Critical Information Security Controls. But somebody may have to test me on that acronym later. CIS controls. The CIS controls version 8. If you Google it, it’ll come right up at the top. OK, but your preferred is the H. The HIC HICP, and this is actually HIPAA, yeah, it’s put out by the Department of Health and Human Services. It’s available online. It’s a free download, HICP Volume One. Outstanding. That’s Edward Wilson, principal at Arch Tech. It’s named Arch Tech because they’re in Missouri. The Arch. Ellen told me that before. It actually was supposed to have a play on the word architecture because we believe good design can solve most of your problems in advance. OK, I thought about that possibility, but then when she said it’s arch tech, it’s not, it’s not architect. So is it, is it architect or architect? To be fair, how do you want to say? How do you want it said? We call it Arch Tech. I started pronouncing it Arc Tech, but we’re in St. Louis, so the point applies. About 6 months in, I realized it was going to be Arch Tech forever because of the St. Louis Arch. I see. All right, so it’s, it’s evolved into it is Arch Tech, so I said it correctly. All right. Can you say? I think that is pretty easy to say. Yeah, just. Just, just tech. J U S T T E C H. That’s Ellen Samuel. She’s the COO at J U S T T E C H. Just tech with a hyphen in between. Well, if you’re typing it, you, you don’t want me to say just hyphen tech. The company is just hyphen tech. No. Oh, well, all right, well, they, they’re gonna Google Ellen Samuel too, uh, but the website does have a hyphen if, if you need that. OK. Edward, Ellen, thank you very much. Great fun and value. Thank you. Thank you for the value. Thank you for sharing. Thank you. Thank you, and thank you, listener, for being with Tony Martignetti nonprofit radio coverage of the 2026 nonprofit Technology Conference. It’s time for Tony’s take 2. Thank you, Kate. Thank you and 10. This is our final show from the 2026 nonprofit Technology conference where we were all together, as you, as you hear, episode after episode in uh Detroit, Michigan. I’m just grateful for the partnership. They take good care of us. They appreciate the value that we bring to the conference, promoting it for months after the conference. Amplifying their speakers to our, our complete audience, way beyond just the folks who attend the conference. So, and I appreciate the, the value that they bring. They give us, Accessibility and, and exposure for the show. And I appreciate the, the partnership and the collaboration for N10 year after year. This year was our 13th. Next year, I’m already looking forward to it. It’s in Portland, Oregon. It’s in March of 2027, and we’ll be there for our 14th. NTC So, looking forward to that. Thank you very much again, and 10. I’m grateful. Listeners, again, I apologize about the audio. It was. It was your lackluster host. I’ll make sure, uh, well, I mean, I’ll do everything I can to make sure it doesn’t happen again. Thanks, thanks for understanding. Kate, Are we coming up on episode 800? We most certainly are. This is episode number 798. 0, 2 more. Absolutely. We’ve got just about a buttload more time. Here is make confident tech decisions, finishing our 26 NTC coverage. Welcome back to Tony Martignetti nonprofit radio coverage of the 2026 nonprofit Technology Conference. We’re all gathered in Detroit, Michigan. This is the final day. With me today is Simone Carvalho, with me right now today, Simone Carvalho and Rebecca Kaplan. Simone is principal consultant at Skeleton Key. strategies and Rebecca Kaplan is senior director of member grants strategy and operations. That’s member grants strategy, not member grants, strategy and operations. She only has two things, not 3. Rebecca Kaplan is senior director of member grants strategy and operations, so operations modifies the grant strategy and the member modifies the grant strategy. So it’s a member grant strategy and operation. No, it’s quite simple. No, no, member grant strategy. And operations at Feeding America. OK. Welcome. Welcome, Simone, Rebecca. Thank you. Good to have you both. Thanks for having us. Pleasure. It’s a pleasure. Simone, would you do an overview? Give us like a, you know, a high level view of the topic to kick us off, please? Sure. Um, so Becca’s here with me today, and we’re at non, uh, the nonprofit tech conference to talk about competent tech decisions, um, and we specifically talked about the tech assessment framework. So a technology assessment, um, is a structured evaluation of an organization’s current technology, the underlying processes, and the capacity, um, within it. Um, and we walked through, and I’ll probably we’re going to do it here, yeah, yeah, yeah, I’ll walk through in detail. We’re not going to just talk about the session here. We’re going to talk about the topic here, yeah, um, the phases of the tech assessment, when to like anticipate or when you should really consider having your own tech assessment, whether or not you should involve consultants, um, and then ultimately like what are the potential outcomes on the benefits of conducting a tech assessment. OK, thank you, and I should have said that the topic is. Assess, don’t guess, a framework for confident tech decisions. All right, all right, so thank you very much, Simone, for getting us started. You can take off your little uh Mini Mike. OK, so we have uh the the opening threshold question. Let’s turn to you, uh, do you go Rebecca or Becca, do you prefer? Either Either is fine. You go by Becca, can I call you Becca? Is that all right? OK, OK. And then at the end I’ll say Rebecca Kaplan again, keep it formal for people who want to connect with you on LinkedIn. OK, Becca. So how do we know whether we should or we are ripe for an audit, an assessment of our uh tech stack? Yeah, so I can talk about Feeding America’s experiences. We think about it as internal triggers that might indicate your needs, something like this, or external triggers. Um, so that’s when you hear people say things like, oh, I’d rather look at this in my spreadsheet, or there’s workarounds, right? So those are some common links. And for us, um, we were deep in the workaround. So, for example, I do grant making, so getting funds out to a few things. And in order to pay our grants, we needed to download payments from our grants management system, reformat them in Excel, email multiple spreadsheets, when appropriate opportunity to our finance department for finance to upload in their system. OK, like it’s 45 different steps, and a lot of it manual or it’s all manual, right? And then we had no good record of our payments. They were in email, they were in spreadsheets. Finance had them, but they weren’t connected to our brands. So that was his workaround, his back side. The other was staff morale. So our system was a legacy system. I’ve been using it over 10 years. For close to 10 years rather, and it was slow. We had permits issues and staff morale was suffering and we knew that formally from our engagement survey. OK, OK. Things look bad and lots of, lots of multi-step processes that humans are involved in and employee satisfaction was low or mediocre. We were just frustrated by the technology and so are our grantees and so when it was also affecting our network partners, that was another trigger. OK, uh, Simone, sound like, looked like you may want to add something. Yeah, yeah, I can talk about, uh, so when Becca mentioned like external and internal triggers and goals, I’m borrowing that framework actually from change management. So change, uh, management theory often talks about like organizations change basically when they’re forced to, um, and External triggers. So Becca talked about like the specific scenario of Feeding America that initiated her tech assessment, but other organizations might hear whispers of a hedge fund has purchased your product and you’re gonna be sunsetting it, or, you know, they’re going to suddenly hike up the prices. So there’s external factors that are pushing you. Um, or perhaps like an external, that would be an external trigger. An external goal would be something like we want to aspirationally just be better serving our clients. We’re expanding our geographies internal, same thing, there’s internal triggers and internal goals where it’s coming from inside the house. Um, perhaps there’s a change in leadership, like employee dissatisfaction. Employee dissatisfaction was a great one. Um, that was like super interesting to learn that it came up in like her employee surveys, um. It could be the change in leadership or you could just simply find that like the processing is taking 3 days and 6 months. OK, all right, these are troubling symptoms, but, uh, but we have a, we have a therapy, we have a treatment. It’s a, it’s a tech, tech audit. Uh, I’m going to tick through some. I, I think these are your, your, your, your phases or your processes. I want to make sure for an audit that you’re looking at there’s a discovery, analysis, prioritization, and a roadmap. OK, and you’re including your people processes and your strategy. OK, let’s talk through these. That’s, that’s a great overview, but that’s all I can do, uh, like tick through. Let’s let’s talk about who the, who the folks are and what the processes are that should be involved in your, in your, your tech audit. Um, so, taking like one step back really quickly, uh, the reason why our tech assessments aren’t just about the technology is that, um, we often think about Technology as like one leg of a three-legged stool where it’s technology, people, and process all supporting strategy. So if one of the legs of the stool is a little bit wobbly, you know, you could potentially top it over. So our tech assessments aren’t just looking at purely the technologies and the systems itself. We always in our discovery and all these phases think about the underlying processes and the capacity and the folks. So, the first phase discovery is pretty self-explanatory. It’s lots of interviews, group discussions. It’s trying to glean as much information as possible. Um, and we often Uh, are pulled in because consultants don’t always have to be involved in it, but can be helpful when you find that perhaps you don’t have the internal trust or buy-in from folks and they need like an objective third party because I think that’s the thing consultants can bring more than experience is there’s a neutral third party that folks might feel uncomfortable discussing their, you know, system secrets with, uh, so that’s discovery. You’re gleaning as much information as possible and perhaps you would have a survey in there. Um, I should also say before all of these phases, there is scope definition. Um, the one thing that I think we really pressed upon was the like the essential need to document and define the scope of the tech assessment, um, because we often find folks are really not lied about what is a tech assessment and what’s included in the tech assessment, and scope creep like just explodes, yeah. Um, so knowing definitively because we want to go deep rather than wide explicitly what systems or departments or processes are involved or are not. Let’s just turn to Becca for a second. So more than 1 2nd, even more than 1 2nd. Becca. So what was the experience at this phase for Feeding America, discovery phase? Like, were there people who wanted to participate, who shouldn’t be, or people who didn’t want to, who should be involved, and you know, how did that discovery phase go for Feeding America? Great question. So Skelton Key did probably over 50. Interviews with stakeholders across many departments. So if you think about grant making, it’s touching finance, it’s touching development, it’s touching the teams that are, um, programmatically overseeing the grants. So we were lucky that folks are really invested and interested. Helping us define the processes of understandings and responsibilities. So the discovery was exciting for us because we had a lot of feelings about our system, um, and the mostly negative. Mostly and also dreams but about potential too, good feelings about potential, but frustration in the in the moment. Exactly. So we’re excited to come through like it would be really cool if those sorts of ideas, um. So I think there’s a lot of buying in the discovery of this in America. Yeah, cool. All right, all right, um. Should we, can we move to analysis? Is that all right? So we’re in our analysis phase. Analysis is taking the blobs of information and doing something with it. So, that’s when we start like actually combing through what we’ve collected through documentation and interviews and discussions, surveys, and we’ve compiled. There’s a couple of different outputs. It ultimately depends on like, you know, back in the discovery phase and when you’re defining your scope and the, the thing that has to be clearly defined is like what question are we trying to answer for Feeding America, I’ll let Becca speak to that, but there was some big questions. So, Some of the key outputs of this um analysis is developing user stories. So these are like human centric requirements. Um, so as Becca mentioned, it was like very future facing and aspirational. As a grants manager, I wanted to XYZ in order to fulfill a specific business, uh, objective. There’s process maps, so visualizations beyond the grants of managers, the grantees, right? I’m sure you interviewed some grantees among those 50. And the aspirations for them. Oh my God, these emails that I get from Feeding America, I mean, I love having their support, but my goodness, it’s enough, enough is too much. It’s too much already. These are, these are Becca’s emails coming that they’re commenting on, but yeah, but among the grantees, right? Yeah, OK, OK. Um, and then there’s process mapping, which again is typically like aspirational and future facing and folks really like that because we are daydreaming about like what I want my pieces to look like in the future. Um, and then, as I mentioned, you just get lots of information and not all of that information is like specific to the technology and especially with New America, we just started compiling what we called a process improvements inventory because there was lots of things outside of the GMS, the grants management system, like ownership struggles, everyone owning a thing. that also needed to be addressed before we talked about the actual technology systems. OK, so there’s the processes, the people, and the technology as well. All right, cool. It sounds like you really need an outside. Facilitator, coordinator of this kind of audit, I mean, I don’t know, can an internal IT team do it now? You have to be, I’m asking you to be objective, Simone. I do actually do think so. The key question to ask or for someone to determine whether or not they can do it. Internally, there’s a couple of things. I think the first thing is capacity, because it’s, it can be done internally. It ultimately depends on what is your timeline. So if it’s an external trigger like, hey, we’re going to be sunsetting your system, you might not have the internal capacity and velocity to get it done in 6 weeks in the way you need to. Um, there is also just that, that question I raised earlier, which is, are your stakeholders going to be honest with you? Sometimes there’s like the benefit of relationships, or, I’ll say more to an outside consultant than I will to a colleague in the IT department. Sometimes we’re the therapist, the data department, yeah, OK, OK. For us it’s also leadership buy in. So we, one of the reasons we brought in a consultant was that in order to have the business case to invest in the system. They wanted the confidence that consultant. Ask members to make that decision. OK. Leadership buy-in is important for a project like this, right? Everybody’s got to be participating, uh, and that encouragement comes from the top, plus there’s the budget, the budget. Uh, I was thinking of conflict. I don’t know why I’m focused on conflict, like people who don’t want to participate that should, or I said people who should participate, don’t want to, I don’t know why I’m focused on the negative, uh, but there’s also, you know, there can be decisions to be made, like about the scope, which is going to impact the budget, the scope of the audit is going to determine how much we’re spending on this, this venture, right, OK. Yes, leadership buy-in. Thanks, Becca. Excellent. OK, um, prioritizing. Becca, can you lead with prioritizing? OK, let’s mix it up a little bit. Yeah, yeah, so we had a long list. OK, from the analysis phase, yes, right, from the analysis. Ths of the things that we wanted to do and accomplish through this transition and we used, um, Simone mentioned it, but, uh, basically a uh prioritization framework that allowed us to think about what was the effort and what was the. Where we’re going to be. Um, and we picked a mix of things on our prioritization list, some that would be the That we can actually confidently accomplish some that were going to be really difficult and really important and then some in the middle so it was a realistic mix it had to be everything, um, and that framework really helped us. You can actually accomplish. OK, you want to talk to the framework, Simone? Yeah, um, so it was a pretty simple one for Feeding America because they did have a really long list, and I think the thing I would emphasize here is, um, and as we talk about roadmap, there’s the low hanging fruit, but there was also things that needed to be immediately addressed regardless of the system. Um, that were pain points that like had to be addressed regardless of how long it took to go to from existing. OK. You might also be looking for maybe low lift and high impact or it affects a lot of people and this one is not going to be difficult to do. Boom, that’s obviously a top priority confidence and buy in into like, oh, this was worthwhile, right, like versus the other quadrant, the, the quadrant opposite that one which is high lift and low return. You probably had some of those. OK, so what happens to those? Do they, I mean, realistically, do they never get done? I mean, I hope, but that brings us to the roadmap roadmap and also the scope. I mean, there’s only so much, there’s only so much we can do together. There’s only so much Feeding America is willing to pay for, so some of these things are not going to get done this, like this year as part of this process. OK, I’m sorry, that brings us to what you say, the road mapping. OK. Oh well, well, even the lackluster host can provide a decent segue. OK, good. What’s the roadmap? Yeah, so it’s, you know, you. Collect all this information, we’ve analyzed it. You have all these artifacts, you have this list of prioritized things, but now it’s about putting it down on paper, assigning ownership and like actually planning some scenarios, allocating a budget, and putting it on. And we got asked this question a couple of times, but like, what, how big is a roadmap? Um, we tend to do like two versions of the roadmap. There’s the immediate needs roadmap, right? Like we mentioned, there’s typically things that are like immediate pain points that have to be addressed in order to like, help people and their morale while migrations take time. Um, so, you know, between choosing and actually migrating to a system that could be a little easier. And so there are things that just have to be addressed in that year. So, we usually do like a short version of the, the roadmap. So, it’s gonna be like 3 months, the next 3 months, you know, the immediate things you guys can do based on how much capacity or budget you have. And oftentimes, we’re actually not doing these activities, we’re giving it back to the client, um, and they can decide things. I know the key thing here is ownership, because nothing is, nothing’s going to get done if nobody owns it. Exactly. And nothing is more disappointing than like spending all this time and investment in a tech assessment, and it lands in a room full of people who have lots of opinions, but then there’s no one. To act on it, um, so that’s pretty critical. And then depending on again the size and the scope of the organization and the tech assessment and what they’re going through, it’s anywhere from like a 12 month roadmap to a 36 month road. And this also includes total cost of ownership as well, which is what does that mean, yeah, that, um, total cost of ownership. So in Feeding America’s scenario, I’ll let you speak to that, Becca, but like oftentimes the tech assessment comes on the heels of some external factor like we have to move off of the system. And leadership wants to know, OK, but going to this new system, scenario A, how much is it actually going to cost us? So it’s not just the licensing, you know, ongoing licensing, it’s the implementation and data migration, the training, the backfill of staff, the consultants, and then the ongoing costs like you’re going to have to change your staffing model and hire a new admin to help you support this product. So that’s the total cost of ownership. OK, that’s great, Rebecca Kaplan. Senior director of Member grants strategy and operations at Feeding America, and Simone Carvalho, principal consultant at Skeleton Key Strategies. Thank you very much, Simone, Rebecca, thanks very much for sharing. Thank you so much for having us. My pleasure and thank you for being with Tony Martignetti nonprofit radio coverage of the 2026 nonprofit Technology Conference. Next week, a wide ranging AI conversation with 3 experts. If you missed any part of this week’s show, I beseech you, find it at Tony Martignetti.com. We are sponsored by the Bridge Conference. Tony will be with more than 2400 nonprofit professionals at Bridge, July 29 to 31 in National Harbor, Maryland. Info and registration at bridge.org. Our creative producer is Claire Meyerhoff. I’m your associate producer Kate Martinetti. The show’s social media is by Susan Chavez. Mark Silverman is our web guy, and this music is by Scott Stein. Thank you for that affirmation, Scotty. Be with us next week for nonprofit radio. Big nonprofit ideas for the other 95%. Go out and be great.

Nonprofit Radio for April 27, 2026: Disaster Recovery & Incident Response For Accidental Techies

 

Amanda Bache: Disaster Recovery & Incident Response For Accidental Techies

Our conversations from the 2026 Nonprofit Technology Conference continue with your DR & IR plan. Cyberattacks, hardware failure or human error can cause big problems, but get minimized when you have the right plan in place. Amanda Bache helps you keep calm when everything crashes, by working ahead of time to identify your critical systems; create actionable response steps; test your plan; and maintain resilience. She’s with Paths For Families.

Listen to the podcast

Get Nonprofit Radio insider alerts

 

Apple Podcast button

 

 

We’re the #1 Podcast for Nonprofits, With 13,000+ Weekly Listeners

Board relations. Fundraising. Volunteer management. Prospect research. Legal compliance. Accounting. Finance. Investments. Donor relations. Public relations. Marketing. Technology. Social media.

Every nonprofit struggles with these issues. Big nonprofits hire experts. The other 95% listen to Tony Martignetti Nonprofit Radio. Trusted experts and leading thinkers join me each week to tackle the tough issues. If you have big dreams but a small budget, you have a home at Tony Martignetti Nonprofit Radio.
View Full Transcript

And welcome to Tony Martignetti Nonprofit Radio. Big nonprofit ideas for the other 95%. I’m your aptly named host and the pod father of your favorite Hebdomadal podcast. I’m traveling for several weeks, so my audio is not gonna sound as good as it usually does on the road with my laptop. But the, uh, the quality is still there. It’s just that, the, the, the substance, of course, still high quality. It’s just the sound quality, not so good. Oh, I’m glad you’re with us. I’d suffer the effects of urethral incontinence if I had to leak the idea that you missed this week’s show. Here’s our associate producer, Kate, with what’s up this week. Hey Tony, here’s what’s up. Disaster recovery and incident response for accidental techies. Our conversations from the 2026 nonprofit Technology conference continue with your DR and IR plan. Cyberattacks, hardware failure, or human error can cause big problems, but get minimized when you have the right plan in place. Amanda Bach helps you keep calm when everything crashes by working ahead of time to identify your critical systems, create actionable response steps, test your plan, and maintain resilience. She’s with Paths for Families. On Tony’s take too. Under pressure. Here is disaster recovery and incident response for accidental techies. Welcome to Tony Martignetti nonprofit radio coverage of the 2026 nonprofit Technology conference. We’re wrapping up our day two coverage with Amanda Beach. Amanda is IT support and operations specialist at Paths for Families. Amanda, welcome to nonprofit Radio. Thank you for having me. I’m glad you’re with us. Your topic is disaster recovery and incident response essentials for accidental techies. Oh, that’s great. So you obviously do not need to be a tech person to understand what to do in case of disaster or bad incidents. Could you just give us an overview before we get into it deeper? Um, of incident response and disaster recovery, you wanna be prepared for anything from, um, floods, fires, anything that can happen to your agency or your house, um, and also incident response like cybersecurity and ransomware, um, so you wanna be prepared for either of those incidents and have a policy so you’re not making the decisions on the fly and in the panic. OK, you want, you want us to keep calm during these. All right, thank you. Thanks for that. Look, it’s like 30,000 ft overview. So let’s, uh, let’s dive in a little bit. Um, yeah, so it’s not all bad actors, like you said, floods, fires, right? Uh, technology fails. You may have heard rumors about that from time to time. Hardware fails. OK, OK. Uh, but it could also be bad actors. Yes, that will the cybersecurity, that’s we’re gonna tie that into bad actors with cybersecurity and then the incident response. OK, OK, um, would you like to talk about the, the cybersecurity first? Is that, is that the best way? Or we can tell the disaster recovery and then um there’s other plan called business continuity. Um, business continuity is kind of where you want to keep all of your business essentials in one place and basically I call it a table of contents of any incident policies you may have and you wanna just think about like your what what you’re gonna do in a disaster, what you’re gonna do in an incident response, and then what you need to do to get back online. OK, OK, so let’s start with disasters. I don’t know, we wake up, uh, and there’s a flood, right? I mean it happens, uh, there’s a fire. Um, all right, so what do we need to be thinking about in our. Disaster recovery plan so that we’re not Panicked and we are well we’re still gonna be a little panicked with a fire or a flood, but we’re not as panicked as we would be if we had no plan. You want the first thing you wanna think about is how you’re gonna communicate with other staff and how you’re gonna make sure everybody’s safe. That’s the biggest thing is we wanna make sure they’re safe. Um, if obviously we’re gonna call people or email them, but it might be the Internet’s might be down like wireless communications could be down, um, in which case you can create like a meeting spot. And we, so we have two offices in Maryland and we created a park or uh designated a park in between the two offices and within a certain time frame after that incident we all go and meet at the park in person in order to make sure we’re actually all physically safe and to see if anybody needs any support. Um, another piece of advice I give everybody is buddy system. So if you have somebody that lives near you, go check on them. Like, does anything, you know, do they need anything? Are they physically OK? And then the last piece is we have to um have two forms of communication like um emergency contacts for somebody and this is also good for our remote workers who might work in another state and let’s say a hurricane has hit Texas before and we have a worker in Texas we couldn’t reach her because she was out of power so we were able to. That family that she had in the area and they were able to confirm that she was OK she just had lost power so it’s a way to also include remote employees who are not physically in the state that you are in OK and those forms of contact and that includes other people. I thought you were taking like sell an email, yeah, but like sell an email might be down so then you got to think of an alternative way to make sure everybody. is safe. OK, so there’s an alternative contact person for everybody on the team. OK, OK, um, and who’s managing our, our plan, our disaster recovery and incident recovery plan? The plans are made for the people. Like they help avoid confusion and panic, but the point we like the basically the agency will develop the plan. Um, the IT team, like our IT team is developing the plan, but we’re help, like especially disaster recovery, we’re including everybody else’s feedback because we wanna make sure like what do you think you might need in a disaster? Like what do you think would help you? So disaster recovery we are including like other staff people and their feedback because we wanna make sure like. What do you need and what can we do to help you because part of it, well, you just talk about safety and communications. How can we make sure you’re safe and how can we get in touch with you? Yeah, and that’s the other thing is how do we keep people safe, not only how do we communicate with people, but how do we keep people safe, um, so one of the things that we talk about is like if there’s an incident in an office location or your home. Um, evacuate if you need to and then shelter in place. People don’t think about that, so we actually lay it out in the plan and so like shelter in place, turn off any like white lights, any, uh, music producing or, you know, noise producing things, and like if you can move heavy furniture in front of a door to protect yourself, not necessarily for like an active shooter, but it could be fire, it could be anything else. Um, and then the other thing we wanna think about is also sending emergency alerts out. So if you’re, you’re in an office and let’s say there’s something going on in the office, you wanna alert somebody who might be coming in to that location. And say hey there’s a fire in the office. Don’t everybody stay away from this location because somebody just could come into that office and not know. How do you do that? Um, emergency communication sometimes via email or you could do like group text or like WhatsApp text or Teams, um, if you have that, um, information, um, sometimes like we’ve had somebody. Call somebody else and be like I can’t talk. I can’t send this out can you alert the other staff that this is going on? It was just a power outage we had a power outage in the office and obviously she couldn’t get anything out because everything died on her and so like can you let everybody know don’t come in because we have a power outage, um, and then we also say follow local law enforcement instructions so if they’re on scene they take priority and they’re gonna be the ones that help do that do you practice these? Um, we haven’t, but we are going to start. Um, I call them like fire drills. Yeah, yeah, we walk in and there’s all of a sudden there’s, you’re, you’re just, you came into a fire and you were just told to evacuate. All right, so do it and let’s carry out the plan. Yeah, that’s the same thing we used to do in elementary school, like fire drills because you thought we never know. Yeah, and then the next thing we talk about in disaster recovery is how do we return to work? How do we do the work we do if something might be going on. Um, so we always tell everybody to be flexible, like understand, and if we can get a message out to clients, just explain to them like, hey, there’s been a fire, our staff is affected. If we can’t, then we’ll just like maybe we’re re remote work. Everybody just shifts to all remote work, or they, we can work from an alternative location. So if your office has been like had a fire, you can maybe go to a local library. And work at your library in order to um get the work done and then you always wanna have have your leadership obviously they they know they know what’s going on and ensure that they have um clear communication out to the staff what to expect like everybody can remote work, OK. The uh the the office is gonna be reopening. Everybody can come back and so it’s just making sure that everybody can do that safely, OK. Do you have people for each of these communications? Like even the emergency communications, like, is there somebody designated and then there’s a secondary, or it’s we haven’t thought about that, but that’s a really great idea. But if whoever’s in the office, if there is something going on like primary person might not be there, yeah, so it’s like if there was a fire in the office and there’s a person there, then obviously they’re the point of contact to like get the information out, yeah, um, I was thinking more like routine like coordinate communicating with the staff. The, the office is going to reopen in 3 days. Yeah, that would typically. be like the senior leadership and like the CEO like I know our CEO like when we have recently had a snowstorm, an ice storm, we actually did shut down for a while and she was communicating out via emails, hey, we’re gonna be closed for 2 days hey everybody can take a 2 hour delay so she was kind of the one that was like leading the charge and letting everybody know about that. OK, yeah, um, what else besides safety communications, what else belongs in this disaster recovery plan? Um, it’s just everybody just has to remain flexible and remain calm. And the more you can do that, the better everything will be, um, and then like just every just take your time getting back to normal to be safe about it if you don’t feel comfortable coming back yet just communicate with that and I feel like at that point everything is great. Um, the only other thing I recommend is with all of your policies like this disaster recovery and incident response, make hard copies for all of your offices and all of like your IT and leadership have printed copies in their homes in case the Internet goes down and we can’t get to it. We’re, yeah, then we’re in big trouble like, oh what do we do? Well, I don’t know, it’s in SharePoint, yeah, it’s the plan in the cloud and we can’t get to the cloud, yeah. OK, excellent. I was thinking of something, but uh uh it’s escaped me. I will, I’ll think of it, um. All right, thanks. What, uh, so, so, so distinguish this again between disaster recovery now and incident response. Yes, so the way that this disaster is like you’re recovering from a disruption, a major disruption that has happened with your agency. The incident response plan is now something has happened. Now how are we gonna fix it, and that’s gonna be a lot more involved than disaster recovery, um. So the first thing you want to think about, I’m sorry, before we get to incident response, I thought of the thing I was thinking about disaster recovery, um, we’re, we’re gonna be remote maybe for a week. We had a fire, flood, whatever. What if everybody doesn’t have the tech at home that they need. To to do the work remotely and their laptop was in the flood. Yeah, I mean it’s something we’ll definitely work with staff on um thankfully our like our office we all have laptops and we all work from home, but if need be like we would make sure they have what they needed to. Get you know the work done like again if you’re if you have a buddy system or like if there’s a way we can like FedEx you something if you live like externally but you’re like something happened and you need us to send you a new laptop because you’re burned up or something we can obviously FedEx and get you what we need. It’s time for Tony’s take 2. Thank you, Kate. I’m feeling under pressure with my book. The editor is the next step, and she needs enough time with it. Before we get it to the graphic designer who also needs time with it. And this is, this, this is all just feeling, uh, a little stressful. A little, uh, you know, like deadlines are imminent. I’ve got, I’ve got to finish my part within the next like 788 days or so. And there’s still a fair amount to do, so. That’s why I say feeling under pressure like the uh. Queen and David Bowie song from 1981 Under Press. Uh, that’s all I’m saying. Uh, trust me. So just uh sharing that, you know, book. Publishing, self-publishing is uh still fun. And I’m enjoying it. Uh, it, it’s, it’s a challenge, but I’m up to it. Just uh feeling. Under pressure for the next week or so. And that’s Tony’s take too. Kate. Well, if singing doesn’t work out, at least you’ll have a book. Singing is not likely to work out, so the book better do very, very, very well. We’ve got just about a buttload more time. Here’s the rest of disaster recovery and incident response for accidental techies with Amanda Beach. Incident response, um, it’s like what are you gonna do when something happens, um, so the first thing I like to lay out in my incident response plan is identify what your three tiers are for your, your, um, software. So tier one would be the most critical software and that can’t go down like you can’t function as an agency if it goes down. And so our, our example would be email, our website, um, like our phone system, things like that because we need to be able to get in the clients and get the support out. Tier two would be something that can go down for a like small amount of time for a small disruption. But has to come up in order for us to function a little bit, um, so our example would be like Zoom and Teams because that’s how we do like our video calls and our trainings and then tier three is some like things that can go down but they don’t need to come up right away and you can find workarounds so such as like. FedEx.com stamps.com. Like if we need to send something out we can just get in our car and take it to there. So you want to start by thinking about what are the most critical things first so when you do have an incident or a disaster, you know what you need to bring online 1st, 2nd, and 3rd, yeah. So with an incident response, yeah, so you wanna think about the first thing you want to think about is who is going to be on the team you have to have an incident response team like who is going to. Be on the team to help run the plan when something goes wrong, um, so, yeah, great question. So that that you could, it can vary depending on the agency and who wants to know. See, on ours we have about 5 people, but you could have up to like 67, or 8 people. So one instance is the IT manager and IT lead. They’re gonna be the person. That kind of liaisons between all of the members of the team kind of making sure everything’s getting done we’re on track with things, things like that you can have your IT support and uh IT vendors so like we use a managed service provider and we also have an MDR vendor so we would include them because they need to know what’s going on uh. Oh, I can’t remember right now, so, so they, they monitor all of the, the back end like the, uh, vendors and stuff and all of our, um, security. Um, that’s, that’s blanking on me right now. All right, they, they manage your back end. They, they, they watch your butt, yeah, and like they’ll alert us if like somebody is logging in from like Sweden or something, so they just kind of help monitor our logins and like what’s going on, um, and then you, if you have, um, communications and PR team, so if you need to get anything out to the media, you wanna have somebody on your team if you need to do that. You wanna have legal counsel so in case there is law enforcement involved or anything we wanna have legal involved in case you need legal advice. Um, you’ll have HR in case there’s any staff or personnel issues that are going on, and then the biggest thing is cybersecurity insurance, a vendor, so just a little caveat, I highly recommend everybody has cybersecurity insurance because they will help you along the way. And like we did have an incident 3 years ago but we we we didn’t know what to do so yeah so somebody clicked an email signed in and then they got their credentials and they were able to log in as that person and I caught it. I called the person I’m like, did you send this email? and they were like, no, I’m at my son’s karate practice. I’m like, oh, so I called my managed service provider. I’m like, we have a problem. What do we do? And they were like, OK, well let’s call the cybersecurity insurance company. So and we did. They helped us hire. A forensic investigator, they helped craft the message that we sent out to the clients, help with like the client’s credit reports like credit monitoring. They crafted what we needed to put out for social media and thankfully it was just a small fee deductible that we had to pay. And that was it. But if the agency does not have cybersecurity insurance, they could go bankrupt paying for all of that. And like I said in my session, I probably wouldn’t be here if we didn’t have cybersecurity insurance. So always include them in the team too, because they like they took off running and they did it all, and which was great because we didn’t know what we were doing. Also the rescue reputation to risk your, your public communications, they helped you craft. Oh, it was perfect like. They they kind of did everything, um, but it was like we just kind of went from, but I highly recommend like you’re gonna take one thing away, have cybersecurity insurance because without them it’s gonna cost tens of thousands if not hundreds of thousands of dollars to recover from something, yeah, uh, more on the incident response, yes, yes, so the, um, you wanna establish clear communication, um, so again, essential communication is key. Um, depending on the urgency, so like when we had our incident, I picked up the phone and called, which is not our norm these days to actually physically call somebody, and but if I had sent her an email she may not have seen it until the next day and the bad actor could have been like in the system for even longer than it was so like think about that as well and then you also kind of wanna think about documentation. So that’s the next biggest thing I wanna say about any type of plan and policy if you ever have a disaster or an incident response, you want to document everything so think about how you’re gonna document and like how you’re gonna report how you’re gonna train staff to report an incident. And like set up blogs like it could be a Word document or an Excel and they could just be like like the who, the what the when the where the why just like Tina Smith reported a phishing email and she’s not sure if it’s a real thing or not so we’re just gonna document it. It’s better to have it documented than not sure. Um, which kind of leads us into the next stage of the what I call the life cycle of an incident response plan. Um, it kind of goes in a circle, but then it can kind of jump around the circle a little bit which I’ll talk about, um, so the first thing you wanna do is preparation which is creating your incident response plan, creating the team, getting those documentation ready, those logs ready like. Um, and then explained it’s trained to staff like what phishing emails look like, do the cybersecurity training with staff so they understand what they’re looking at and how to report it, and you also wanna tell them who to report it to like in our incident like you’re gonna report it. Like me and my boss, like we have a little form and then we’ll take it from there and then we’ll, we’ll contact you and then we’ll see if it’s a real incident or not. So that’s part of the preparation is like training everybody, um, and I always say at that point you’re gonna hope and pray you don’t go any further than that, um, but then the next stage is what I call detection and analysis so we’ve gotten. An alert from somebody that they think there’s an incident we’re gonna investigate everything whether it’s like oh I’ve got a phishing email I’m not sure what it is or hey there’s somebody it’s locked my computer out and I ransomware so we’re at that point we’re going to investigate it we’re gonna document the call or the end like the um report. And then we’re gonna like take a look and see like OK this is just a phishing email. Thanks for not clicking this great job to tight you know and then at that point we’ll go back, yeah, exactly, gold star and then at that point we’re gonna go back to the preparation so it’s kind of like like a. Bouncing around a circle and then if at that point if we realize it’s an actual incident like like this we had hacked and we had bad actor in her email we at that point it’s detection and it’s containment eradication and recovery so there’s 3 steps in that part of the plan containment we wanna contain that incident. So like we wanna make sure like the bad actor is getting getting out of that person’s email so we like reset the password reset multi-factor, and we were like looking at how this could happen plus you have a team or or a vendor who can help with forensics exactly and then the back out yeah see where they’ve been and then the back end. You’re like, OK, we know this happened, but how did this happen? So again we had the forensic investigator they like looked into how it happened and then so that’s containment and then eradication is how we’re gonna fix this, um, so it could be like patch on a software when you’re since your computer’s screwy like somebody got in. So, um, eradication is maybe we need to reimage the computer, maybe we need to start from scratch, maybe we just need to remove the software and then once we’ve done all of that recovery is we wanna make sure that everything is working as it should, but we also wanna make sure other staff. Are not experiencing that same incident so like it was an email that got sent out to everybody. I was like this looks weird, but we wanted to make sure that other people didn’t click that same email that caused that. So we were like, is everybody OK? Did you, you know, everybody’s doing everything and that’s, you know, you should be doing, um. And then from that it’s like it’s a full blown incident we’ve contacted everybody we’ve done the plans and now everything’s hopefully back to normal and then what you wanna do is you wanna have a post incident recovery meeting. So once after the incident has completed you’re gonna get your incident response team together and you’re gonna have like a follow up meeting about it and my biggest advice is that we’re here to learn what what happened from beginning to end but we’re not here to blame. Anybody for what they did or what they clicked or you know they didn’t do something right we’re here to learn about the process whether it worked or not so in that meeting you’ll wanna talk about like the timeline from beginning to end like all right like this person caught it we reported it then we did this then we did that um and given that also you wanna also review review all the documentation logs that we have so who did what when. There who talked to whom and like we want to make sure everything is like the I’s are dotted, the I’s are dotted and the T’s are crossed because if law enforcement has us have to get involved they’re gonna want our logs so they would want to know what happened from A to Z and all the details in between, um, and then you want to figure out what worked well, what didn’t work well, um, and then you kind of wanna like go back and review the plan and like. From what went well and didn’t, yeah, like what is this working as it should and then if it didn’t go back and tweak the plan, just start small. That’s like my old big advice is start small even if you have a one page incident response plan, start small and then go from there, as you know, you kind of not to hope that anybody has to go through with it, but just start small with one page and then kind of build on that and figure out what’s needed at that point. OK, OK, um, you had wanted to talk a little about the business. Continuity, yeah, so business continuity is I call that the umbrella of the all the um disaster recovery and incident response plans, um, in there I talk about like the tiers that I mentioned earlier about the software system 123 yeah and like and you also wanna lay out what disasters you’re actually gonna, you’re gonna like cover or what incidents you wanna cover in the disaster recovery and incident response so it’s like the umbrella term. So like are we gonna cover we’re gonna cover natural disasters, active shooters like really be linear about everything that we wanna cover and have policies for because so that way somebody knows like oh if there’s an active shooter in our office, OK, that’s in the disaster recovery plan so it’s kind of like your table of contents of like where do we find this where like if there’s an incident or there’s a disaster where do I go? So it’s like that’s your umbrella and holds all the other information on there, um. The other thing that I get questions about a lot is how do we get buy-in from leadership and board about needing these plans? um, the best way to describe that and get the buy-in from them is explaining the risks like what could happen if we don’t have this plan. And the answer is you are making decisions on the fly in a panic and crisis mode and they may not be the most ethical and like responsible thing you’re just like running around with a chicken with its head cut off because you don’t know what to do and. You also wanna explain to them what’s gonna happen without it because it’s it’s gonna be a hot mess and so that’s a big question that I get all the time is like how do I, how do I get buy in because nobody’s like we don’t need these. I’m like yeah we really do and so we didn’t have a plan when we had our incident and leadership was like oh we were OK we we survived and. You know, everything went fine. I’m like, no, it didn’t really tiny incident. Yeah, you’re talking about the one that you caught that you reported, yeah, yeah, that was pretty small in the scale of disasters and incidents, yeah, and but it was like they don’t need a plan. I’m like it was, it was a little crazy because I didn’t know who to call. I didn’t know what to do. We had to call a forensics like they, we call mat. It was a little crazy and so we were like no I was a little panicked like and if I had had a plan I would’ve been like OK open the book all this I do this OK you do that so it’s really helpful to have like how are we gonna keep our business running when there’s a problem yeah that’s a good way to stop I think. How are we gonna continue business because there are people counting on. Well, people, animals, the environment, whatever, whatever, whatever our work is, there’s, there’s someone or something counting on us. We gotta continue. Amanda Beach, IT support and operations specialist at Paths for Families. Where’s Paths for Families? Oh, we are located in Maryland, DC, and Virginia. OK, yeah, thank you very much. Thank you for having me. I really appreciate it. You’re welcome. Thank you. And thank you for being with Tony Martignetti nonprofit radio coverage of the 2026 nonprofit Technology conference in Denver. Next week, more from 26 NTC with, branding you’re giving programs, and donor retention. If you missed any part of this week’s show, I beseech you, find it at Tony Martignetti.com. Our creative producer is Claire Meyerhoff. I’m your associate producer, Kate Martinetti. The show’s social media is by Susan Chavez. Mark Silverman is our web guide, and this music is by Scott Stein. Thank you for that affirmation, Scotty. Be with us next week for nonprofit Radio. Big nonprofit ideas for the other 95%. Go out and be great

Nonprofit Radio for March 9, 2018: Risk Management & Your Disaster Recovery Plan

I love our sponsors!

Do you want to find more prospects & raise more money? Pursuant is a full-service fundraising agency, leveraging data & technology.

WegnerCPAs. Guiding you. Beyond the numbers.

Credit & debit card processing by telos. Payment processing is now passive revenue for your org.

Get Nonprofit Radio insider alerts!

Listen Live or Archive:

 

My Guests:

Ted Bilich: Risk Management

“Not all risks are bad,” says Ted Bilich. He’ll help you identify the good and bad ones and get them into your risk inventory. He’s CEO of Risk Alternatives, LLC.

 

 

 

Dar Veverka: Your Disaster Recovery Plan

An IT disaster is one of the bad risks. What belongs in your DR plan? Dar Veverka is from LIFT and she’ll help you sort it out. (Originally aired 5/1/15)

 

 


Top Trends. Sound Advice. Lively Conversation.

Board relations. Fundraising. Volunteer management. Prospect research. Legal compliance. Accounting. Finance. Investments. Donor relations. Public relations. Marketing. Technology. Social media.

Every nonprofit struggles with these issues. Big nonprofits hire experts. The other 95% listen to Tony Martignetti Nonprofit Radio. Trusted experts and leading thinkers join me each week to tackle the tough issues. If you have big dreams but a small budget, you have a home at Tony Martignetti Nonprofit Radio.

Get Nonprofit Radio insider alerts!

Sponsored by:


View Full Transcript

Transcript for 380_tony_martignetti_nonprofit_radio_20180309.mp3

Processed on: 2018-11-11T23:48:42.880Z
S3 bucket containing transcription results: transcript.results
Link to bucket: s3.console.aws.amazon.com/s3/buckets/transcript.results
Path to JSON: 2018…03…380_tony_martignetti_nonprofit_radio_20180309.mp3.621106110.json
Path to text: transcripts/2018/03/380_tony_martignetti_nonprofit_radio_20180309.txt

Buy-in hello and welcome to tony martignetti non-profit radio big non-profit ideas for the other ninety five percent. I’m your aptly named host. Oh, i’m glad you’re with me. I’d break out with cering go sista noma, if you made me sweat with the idea that you missed today’s show risk management, not all risk is bad, says ted village. We’ll walk you through why you should care about the good and bad and how to get going with your risk inventory he’s ceo of risk-alternatives and your disaster recovery plan one bad risk is you’re going to put ignore it at your own peril. What belongs in your d our plan darva arika is from lift that originally aired on may fifth twenty fifteen i’ll take two charity registration and plan giving podcasts responsive by pursuant full service fund-raising data driven and technology enabled tony dahna slash pursuant radio and by weinger cps guiding you beyond the numbers regular cps dot com tell us turning credit card processing into your passive revenue stream. Tony dot, m a slash tony tell us it’s my pleasure to welcome ted village. He is ceo of risk-alternatives llc, providing risk management and process improvement. Solutions for non-profits and start ups he used to practice law and has served on the boards of numerous organizations. Ted has written about risk management and process improvement in stanford social innovation review, where you can also hear this show. Corporate responsibility magazine. This show is not on corporate sponsors. What magazine and risk management magazine were also not there. He’s at t bilich and the company is at risk. Hyphen alternatives dot com welcome to non-profit radio. Ted. Tony it’s. Great to be here. I hope you’re doing well. Thank you. I am. And how are you? I have to ask. I’m doing great. Thanks. I’m glad. Everybody’s. Good today. All right. Um all right. You’ve been in some magazines that non-profits are most likely not reading responsability magazine. Corpse. Sorry. Corporate responsibility magazine risk management magazine. I’m sure you’re not unfamiliar with this risk management sounds boring. Why either boring or scary? Alright. And if this was not on some affiliate stations, i might use stronger language. I might put it. Put an adjective on before the word for before the word boring. Oh, my god. Why should we be paying attention to this? You know you. Hit on one of the most important issues that i face, which is when people think about risk management, they think about either the fact that it’s one more obligation for them or that they don’t wanna lift up rocks because they’re afraid of what what’s under them and and, you know, what i say to people time and time again is that risk management is a critical part of your business because especially if you’re a non-profit you are dealing with more risks than almost any other organization you could possibly think of, you know, think of the non-profit business model, toni it’s, your taking money from strangers in order to deal with intractable problems. And if you do your job really well, your business should go out of business that’s a risky model, so it really pays to pay attention to risk management, and we could get into sort of what that means if you’d like, yeah, we’re going to, um you do say that not all risk is bad. That’s exactly right? Flush it out. Yeah. Yeah, sure. You know, one of the one of the issues in risk management is what do you mean by rich? And risk matt necessarily mean bad things risk. So i always tell people, when you’re talking about risk talking about uncertainty management, you could have bad risk that could go go, go wrong, and we call those threats. He could also have good rick, you know, opportunities either opportunities for improvement of your current processes or opportunities in the sense of new initiatives, and all of that is within the framework of a good risk management process. Okay, so i like the idea of we don’t know what’s going to happen next. It’s. Just it’s something we don’t know, right? So it does not. Of course, it does not have to be bad. It could be fantastic, right? Okay, absolutely. You know, it could be that that that there is a new donor who is waiting to not give you money if you expand your programs in a new direction, but simply wants to give you money to do mohr of what you’re doing now. And you believe that this is important for non-profit sustainability? Oh, gosh, yes, if you don’t, if you don’t have a risk management process, tony, then let’s say, you’re thinking about having a strategic plan or you have a strategic plan, how can you possibly have confidence that that strategic plan is going to accomplish its its objective if you don’t have a really strong awareness of what your current capabilities are, including what the threats and opportunities are that face your organization? So there’s this thing out there called a swot tte or swat analysis? Um s w o t the o’s opportunities in the tear threats i forget with the what do you what’s the s and the w its strength and weak she’s. So weak threat. Thank you. All right. Yeah. And and people use that sometime during strategic planning process. Okay, so this is s so we’re calling altum positive risks or good risks. That that’s the opportunity. That’s, right? Those are opportunities there. Potential opportunities? Ok. Yes, exactly. And one of the things that i talk to people about when when they talk about a swat analysis, is that swat analysis tends to be a static once every couple of years, activity done during strategic planning. One way to think about risk took that slot and alan and you operationalized it so that you were as a matter of routine, looking at your strengths and weaknesses and opportunities and threats. That’s one way to think about a risk management structure is it’s taking the swat process and making it something that is ongoing over time. I think it should be swope i think it’s a long hour, i know not to quibble, but i think it’s, of course, equivalent, but i think it’s a long oh, i think so long, so might be, but i don’t think that negates anything that you just said, i don’t know listeners thinking that all right, so so an ongoing process. Now you you have this cool article. Stanford social innovation review called a call for non-profit risk management, you make very clear in that, and we have about a minute before first break make very clear that that this is not really appropriate for start ups. If you start up basically, your your argument is you can cover this most of your problems or potential risks with insurance. But so when when should we start doing formalized risk analysis? You know, a good signal for that, tony and briefly before break good signal is when you start doing, when you start having regular audit, um, that usually happens when a non-profit is going into growth phase, and at that point, it’s useful to start having a risk management process because after all, you’re becoming a grown up organization. Okay, so when you start when you start having going through an audit process with your right when you and then that usually in love that you know, depending on the state seven hundred fifty thousand dollars to a million dollars of annual revenue, okay, let’s, take our first break pursuant, their newest paper demystifying the donor journey. You need to be intentional, deliberate about stuart in your donors, we’re talking about being delivered today, assessing risk. You also need to be deliberate about stewarding your donors so you don’t lose them. Pursue it will help you create and fine tune your donorsearch stewardship plan. Keep your donors with you so you don’t have to replace them each year. Demystifying the donor journey it’s at tony dot m a slash pursuant, radio let’s, go back to ted village and let’s continue our talk about risk management thiss ongoing assessment process so all right, so we know when we should begin. Um, what shall we begin with? Is it? Is it the risk inventory? That’s exactly right, tony the first step still, this good risk management process is too take stock of where you are now because you can’t start prioritizing if you don’t have awareness of what your current threats and opportunities are so there’s a process risk-alternatives hq inventory it’s simply a structured exercise that you take your staff through to help them identify threats and opportunities not just within operations, but operations and finance that i t and a talent management and development and all those different functions within the non-profit and it usually takes about, you know, two or three hours of work total for your staff to do something like this spread out over a couple of weeks, and at the end of it, you have a really good idea of the threats and opportunities you currently face, really only two to three hours for each put threespot actually not that hard of a process in fact, your listeners could go to our website, risk-alternatives risk-alternatives dot com and download a little report that shows you how to do it on your own when we do it as a facilitated manner. It takes about an hour to train people about risk management, and then they go off on their own and each person takes about forty minutes to use an online tool toe identify these threats and opportunity. So it’s really not a long involved process. I love the online resource. Thank you for that. So again, risk hyphen alternatives dot com let’s say i want to flush this risk inventory a little bit. So who should be involved in this process? First of all? Well, when when we advise customers to do it, we always say you should have your c sweet team. I’m assuming that that you have a small, that this is a fairly small organization were small. There were small to midsize non-profits here, however you think one point five, two million dollars to five million dollars in revenues, you probably have a ceo cfo, a head of development in in some form or another, and probably someone in charge of programs. You would want to have those people, but we also also always advised get one person who’s simply a staff member right on the front line and have them do it along with the senior team because they’re no thing that that the senior staff don’t have any id dea is going on. Yeah, i know that there. That could be very eye opening on ly one person, though, from from down in the trenches. Well, on in your initial risk inventory, tony wanna balance thoroughness with efficiency. And so with this initial inventory, i think it’s good to have one person from the trenches. But this is mostly going to be a bottom down identification process. His first run through the idea behind it, though, is that risk management is not a one and done thing. You do an inventory, you prioritize, you respond to those you assess and improve, and then you do another inventory and so on and so forth. And as as you grow this within your organization, you would want to make sure that mohr and more people are involved in that risk identification process. All right, so i see we’ve got an interpretive process. Let’s, go back to our initial one now. All right, so we’ve got this were basically creating a committee, that’s going to meet a couple of times, you said over, like two or three weeks. We’re creating a committee. A risk risk assessment committee is not going to scare people like we think committee, right? Okay, that sounds like when, when, when people below the c suite start hearing there’s, a risk assessment committee being formed. That sounds like they’re going to firings, coming, eyes firing or they know about. They know about the seven deadly plagues that are ten deadly plagues, depending on which version bible you read. There’s, locusts and blood and darkness coming on dh, what else we got flies really was that part of the buy-in frogs, frogs that was the effort, the other fellow. So this sounds a little scary to me if i’m not on the committee, no that’s exactly right, which is why one of the things that we advise the senior staff to do when they decide to go through this sort of exercise is to send in all staff e mail out saying, you know, we’re doing this process so that we can dip our toe in the in the waters of risk management. It’s not a matter of something to worry about. In fact, the idea over time is to get everyone in the organization involved in this process, okay? So yeah, and we’re actually trying to do is reduce worry by identifying what’s out there that we don’t know. So we’re identifying are known unknowns. What about our unknown unknowns? Can we get to them? They’re always going to be things that are unknowable, you know, there’s, a wonderful book by, uh, well, it’s called the black swan. Have you read it, tony? You know, i think i saw a movie called black swan, but i don’t i don’t think it’s very different now a very different from what i’m talking about, okay, this book is about how, no matter how well you might try to predict the future, there are always going to be significant jolt of one sort or another that you can’t possibly predict beforehand. And so you know, i again, i always tell people, risk management is not a crystal ball. The better analogy is risk management is a flashlight in the dark, it allows you to see things you might not otherwise see. It makes the path a little safer because you can see some of the things that that might be bad along the way and some of the things that might be good, that can help you, but it also gives you a healthy sense of maybe we shouldn’t be running too fast, because if we run too fast, we’re not going to see the things that could trip let’s. Let’s, go back to our to our initial committee now. So so how do we ah wei, is that there’s a risk assessment committee? Yeah. Can we call that? Okay, managing committee, risk inventory shoretz are risking our r i c were first our first rick. So way get the group together. What do we do? How do we get the process started? If we don’t, we don’t have the luxury of the of a professional facilitator, right? Well, if i were doing it and i didn’t want to bring my company or some other company and it’s, what i would do is i would cheat in the following way, i would go get that that report that that we have on our website and i would download that and it says, ah, this is how you do it. These air, the various different functions that you want to look at, and it lists eleven different functions of the organization, and it says what you ought to do is you hot auto, have each team member within each function, identify three things that could go wrong, and one thing that could go right in the near future either because it’s a new process that we could adopt, or a new initiative or a process that we could tweak in some way. So each one of the people goes off and does and and they identify three threats and one opportunity in each function of the organization. Okay, then they do it, but they do it, tony, even if it’s not their function oh, you’re going all right. Well, let’s, take one step at a time. First of all, just just name a couple of the functions. You know, talent management. Okay. Hiring, developing and if necessary, firing people that’s one funky reputation management, you know, how do you influence what? What people think about your organization. Um, fernand is another function. How do you account for the money that flows through the the organization? Just give us one. Give us one more. We don’t want to eleven. Because because there are available on the title is the big ones. You know, how do you use elektronik technology in order to enhance the services you provide? Why’re we waited three, three potential bad and one potential. Good. Why can’t we be? Do equalize it out two and two. You could do it that way. I’ve found just over time that people are going to be very, very, um, free with identifying things that could go wrong. People have lots of worries, especially during an initial risk inventory. They like to dump a lot of stuff out on on the table it the reason why we emphasize identifying at least one opportunity is that we want them to be balanced in their presentation to some extent. Nevertheless, it always is that people are going to identify more threats than opportunities, and so we’ve set it up as a rubric of three to one to at least get the one in each because really not balance it’s tze, twenty five percent good and seventy five percent bad, but but you see, people are thinking mohr negatively, people thinking more about the bad risks that’s, right? And and also when when you know, when we reconvene after after having people look at those things out on their own. One thing that that happens is that the team the committee that you’ve developed is going to find that they identified it ah lot of the same risk, so you might get a list of one hundred risks, but really it’s going to end up with about sixty sixty to seventy risks and and a lot of those things that they identify as bad things aren’t going to stand up to the light of day one person might be worried, but another person has a full explanation, and so it will simply go away. You’ll end up with about forty or fifty for challenge either positive challenges or negative challenges, and and at the end of that process, i can almost guarantee that someone who does this will be aware of two or three things that are low hanging fruit, that they can pick very rapidly in order to help their organization thrives. Now, are we allowed to come back to the committee then with mohr than the four that you challenged us with? And then the committee and the committee flushes them out to get down to this forty or fifty? Is that the way it works? Yes, if someone wants to identify more than three threats and one opportunity, i would never say, no, you can’t, but but on the other hand, you don’t want someone, for instance, to focus so much on this that they become, you know, all engrossed in in their potential worries rather than doing their job. So you wanted to be somewhat manageable, all right? We’re in the details of this, which is where i want to be. So so our first meeting is introductory. And then we give some homework second meeting you’re coming back in a week or maybe give him ten days. All right, maybe it’s a it was a long weekend in there, so e-giving e-giving ten days you’re coming back with your your analysis of threats and opportunities with the understanding that we’re going to narrow, we as a committee are going to narrow it down to three, three and one for each functional area, okay? No, no, no, that that i think i misled you on that one. Well, you’re going to narrow it down to a certain number of risks. It may be that there are that that the committee ends up saying, yeah, there really are seventeen risks in the development function. And they all are really rich. Each person would have identified only three. But, you know, maybe maybe it ended up that that you had ah, fifteen at least, um, legitimate risks threats that were identified, that is, you don’t limit it artificially as far as the total number of risk that could be identified within a function. Okay, i think you did mislead me, but that’s all right? You know, character. So listeners going go back, listen to what ted originally set the record will now pass that’s, right? I think it’ll show that i’m correct, but, um, so all right, so and you had also said that people can identify threats and opportunities outside their their own functional area, so a cfo can comment on it, and i can’t comment on hr and talent development, et cetera. Okay, um, that’s our second meeting, what happens after that? Now, we’ve now we’ve got our core of forty to fifty yeah, you’ve got your core of forty to fifty. The next step in that in the process would be to prioritize along those risks, because if you have forty two, fifty two, sixty risks and you think they’re all equally important, well, you’re just going to be frozen in inaction. So the next step is to use whatever tool you wish to use to prioritize those risks down to the most important ones that your organization face. And when i’m advising r our clients, i say the simpler the better, as far as prioritization, use a simple, you know, ah, point system, where each person on the team gets a certain number of points and they can allocate those points, however they wish among the fifty or sixty rhys so that if you want to push him all of your chips on toe one risk because you think that’s really important and should be really high priority for the organization, you could do that. Um, and and by doing that, you end up with your top ten or fifteen risk that got the most points and those become your first prioritized punch list of high value items that your organization should focus on during the coming period of time. You could do this like a poker game. You could all be you could buy everybody a stack of chips and okay, number one, we’re going to go through all forty or fifty. Number one who wants to throw is number one throwing your chips. But when you have a chip on that one that you exactly right, good bet judiciously, because when you’re out of chips, then you’re silent. There’s no taking chips back. Alright, right? Yeah. And? And what is happening is that people will take different different approaches to deciding what you know what their priority risks are and and the reason why. I say it needs to be a simple process is that deciding priority really is a judgment call? It has something to do with how dangerous or how good is this opportunity of its opportunity? How, how, how big is the risk if it comes about, how likely is it to come about? And if it comes about, how much lead time are we going to get before it manifest? Seldman now, you know, if you’re a multi billion dollar corporation, you khun create huge financial models to make those sorts of decision, but for the average non-profit you have to rely on people’s considered judgment, and so having a simple prioritization process where people are told, you know, consider those three factors and then put your chips the way they should. It ends up being a pretty powerful system for identifying the core risk organization and say those three three factors again, yes, it is it’s, the magnitude of the risk if it comes about the likelihood of the risk coming about and how much lead time you’re going tohave once the risk manifests itself before the full impact hit, okay, that third one could be it could be a day or so? I mean, that could be short term and they could on the end. And that might mean that you would get several rank that risk hyre because you don’t get that much lead. On the other hand, if you’re talking about a legislative change, you might have not in front. Okay? Yes, exactly. Yeah. So you’re aware, of course, weighing the factors, it might be low, like a low, low, low probability, but xero lead time and great magnitude you’re going to rank that thing. Hyre okay. All right, all right. So now we’ve got our ten. We’ve got our top ten. Yeah. Now, do we continue in just the committee and dealing with these? Or do we start to open it up in, like, meeting three or four guard to open it up? Ok, start opening up when you, when you boil that tend the risks down to your poor wrist, then you start opening it up to the rest of your staff by bringing those the list of those risks to your staff meetings and talking about those with your staff asking, ah, you know, for for their reactions tow those risks. Signing those. Risks, too. Particular people tto be dealt with a signing check in dates for when when you’re going to check back, you know that that list of core risks, which is second big tool that risk managers use, they call it a risk register. But that prioritized list becomes the operational judge document that you share with your staff in all staff meetings and and other staff meetings. You also share that up to your board of directors because those are the core risk that the organisation face and the board may want to weigh in on some of those risks. Excellent. Ted. We’re gonna leave it there. That’s a perfect place to ah overviewing on dh, of course, there’s get you could get thie get the format at risk. Hyphen alternatives dot com. You could follow ted at t bilich b i l i c h ted village. Thank you so much for sharing. Uh, tony was great to be here. Thank you so much for having me on my pleasure. We need to take a break. Wittner, cps, anek cerp from the latest testimonial quote, they’re accessible. They care about their clients. End quote, can you say that about your accounting and audit firm? This is another way that wagner goes beyond the numbers remember all the guides and the templates you heard me rattle on about, but they’re valuable. So it’s rattling and it’s valuable rattle. Yes, it was very it was a high tone rattle, good tone, so there’s that but then there’s also they’re accessible. They care let’s make it personal. Talk to eat. Which tomb he’s. The guy you want to talk to? Check out wagner, cpas, dot com he’s a very good guy. Now time for tony’s take two two people have me on their podcasts, it’s their lives joe correct, and i talked about charity registration. Now, first of all, i have to apologize to joe correct, who i’ve always called joe garrick, including what he was on the show. Why he didn’t correct me, i guess. It’s too polite. I don’t know. I think i take notes. Well, as long as they’re not from my wife, i think i’m open so i would. Appreciate it, but joe correct did not. So i have to correct, correct and eso yes, joe, correct, and i did charity registration and i did, launching a planned e-giving program with heather yan tao. Those are my two tricks to trick pony that’s what i know, plan giving and charity registration heimans lots of people say they feel passionate, passionate about their their work you need i love you. The twitter bios air are actually pretty interesting there’s a lot of passion out there, they’re passionate about whatever they do. I don’t know, i like it. I like playing giving i like charity registration let’s just leave it at that let’s not get carried away about passion. Um, so those are the two things i talked about. So the plan the plan giving with heather watching apollo program? Not surprisingly, i talked about charitable bequests that is the place to begin your plan giving program, as you know, and it could be the place to stop. If you’re a smaller, maybe even midsize shop, you don’t want to invest in more and more like infrastructure and further expertise or something it’s not necessary, you can have a very respectable program with charitable bequests start and stop there so you’ll hear that message. And then, of course, we’re going to more detail about starting a plan giving program against marketing tips that i shared with heather et cetera and for charity registration that was the one with job. Correct? Um, you know, the biggest hook with that is your donate. Now button, if you have a donate now button on your website, you’re accepting gifts on your site. That thing is a solicitation in lots of states the day that it goes live, and it doesn’t matter whether anybody in montana ever clicks on it. I don’t know if montana is one states you gotta register is like ten or twelve states where you don’t but let’s just don’t don’t fight the hypothetical, um, it’s it’s a solicitation in a lot of states, the moment it goes live because people in those states can see it so that’s a big hook you donate now button and just generally, of course, charity registration. You need to be registered in each state where you solicit donations, and joe and i went into some of the generalities about registration because it’s a morass. But there are some generalizations you could draw about what the states require in terms of timing and forms and fees, things like that when you get into the weeds of charity registration, then that’s where it’s it’s a morass because every state has its own let’s be polite and say video sync christie’s that they’re their own personalities that must emerge through the charity registration channel so you can’t make a lot of you can’t go into a lot of detail and, you know, like a forty minute podcast, but there are generalizations you can draw, and so we talk about exemptions also exemptions or key, you know, once you find a state that you need to register in because, you know you’re soliciting in that state, the first thing you want to do is look at the exemptions in that state. What do those look like? Because you might very well be exempt. Then, of course, drill down to the details of exemptions and that’s where the morass comes in is in a state where you apply for the exemption or the state, and you have to be approved for the exemption. Or is it a state where? You could just walk away, throw up your hands and go to the next state because you just deem yourself exempt, right? So joe, correct, and i talked about the exemption, of course, too, because, you know, you could save a lot of time if you find that you are exempt. All right. So carrie restoration job, correct planned e-giving beginning of launching a plant e-giving program that’s with heather, you, lando and i’ve got links to those two podcasts, of course, there’s. My video. I have to have my own personality and nuances. So my video, with the links to the those two podcasts where i was a guest, is that tony martignetti dot com live. Listen, love it’s got to come now, pre recorded today, but the love goes out the life, the live the love goes out, the live love is out. If you’re listening live, you’re getting the love that’s the key. So live listeners so glad you are with us. Love goes out to you thanks for being with us and the podcast pleasantries you expected me to say the word heels, didn’t you? And you were waiting for heels on the heels off, but your ah your hopes are dashed. I’m not going to say the word heels today. Podcast pleasantries today over twelve thousand listening whenever wherever, whatever device the bulk of our audience the podcast dorian’s so glad you’re with us. Thank you very much and the affiliate affections on the heels of the podcast pleasantries has to come. The affiliate affections our am and fm station listeners throughout the country affections to you. I’m grateful that you listen that your station carries us whatever time, whatever day thanks for being with us. Thanks to your station for carrying us affiliate affections that’s the liveliest or love the podcast pleasantries and the affiliate affections. Now let’s, go to darby, barca and your disaster recovery plan. Welcome to tony martignetti non-profit radio coverage of ntc twenty fifteen the non-profit technology conference were in day two. We’re in austin, texas, at the convention center and my guest is dar vivir ca she’s vice president of technology for lift a lefty and her workshop topic is avoiding disaster a practical guide for backup systems and disaster recovery planning. Dar welcome, thank you very much. Good to be here. It’s a pleasure to have you this day two we’re highlighting one swag item at ntc per for interview and, uh, i have a double chip biscotti from ah sputnik moment the hashtag is hashtag is sputnik smiles and i’m told that the glasses go with the biscotti, so this is essential. This is this interview’s swag moment. Thank you very much. Sputnik smiles and it goes into the goes into the swag collection. There it is. Okay, door. Um, we need to know some ah, little basic turn. Well, you know what? Before we even get into why is disaster recovery and the related and included back-up so i don’t know if it’s just for gotten ignored, not done well, what inspired the session is a organization i used to work for. We were required by auditors to do a disaster recovery plans. So when it came time for the annual audit, i got out the current disaster recovery plan and went all right, i’m going to go ahead and update this and when i discovered when i read the plan was there were servers, there were eight years old gone for the last eight years server and reading the planet was very clear that what the previous person had done was simply change the date and update the plan for auditors. And as i thought about it and talk to other people, i found that that actually happens a lot people it’s d r is sort of that thing they don’t have time for because no one ever thinks it’ll happen to them, so you push it off and you push it off, and you either just download the template, you know, a template off the internet, and you slap a date on it and basically fill it out just for the auditors. But a lot of organizations never actually think through their disaster recovery, they don’t get into the details, they don’t worry about it, and then when a disaster actually happens to them, they’re sort of stuck. You don’t have a plan that i don’t have a functioning crush on, they’ve never tried it out, so that was what inspired the session and as we dug into it. We we tried to give the thirty thousand foot view because disaster it cover, you know, there’s an entire industry, the deals with technology, disaster recovery. You can spend days on this topic, and obviously we didn’t have days. We had a ninety minute session, so we tried to give the thirty thousand foot view of the practical items you need to pay attention to if you’re not confident in your organisation’s d our plan, if you don’t have a d our plan or if you do and you really don’t, you know, you think it really needs an overhaul that sort of the top ten of items of what you should really be looking at when you’re dealing with disaster recovering backups. And we tried to give some several practical examples myself and the other speaker and andrew, who could not make it this morning of disasters we’ve had to deal with as well as other well known ones. Yeah, okay, do we need some basic language? Miree before we get into the d r disaster recovery topic short jr is one of them. Disaster recovers, often referred to his d r it’s often spoken about in terms of business continuity or bc, which is sort of the larger plan for the entire organisation should’ve disaster strike there’s the others very d are specific things such as our poet recovery point objective that we could talk about your rto, which is recovery time objective there’s very specific language like that for disasters. It’s usually just revert to de ours. So whenever we say d arts disaster recovery okay, we’ll see if we get into those eyes and i could explain to ms wick. Okay, um, all right? So clearly we should have a disaster recovery written, just recovery plan. Even if we’re an organization that small enough that doesn’t have an annual audit, we still should have something in place. Yes. Okay. What belongs in our day? Our plan top ten things. You need a contact list for your team. So if you have a top ten of the d r i do of what should your plan d our plan? You know, it could be anything from a five page outline that just covers the basics. And in in our sessions slides, which i’ve posted in the ntc library gives it some good resource is for doing andy. Our plan, or it could be a, you know, a huge hundred page document, it covers absolutely every aspect of business continuity or something in between it’s going very by organization, and the reality is, if you’re a small organisation with a small team, you might only be able to do the five page outline but that’s better than nothing that’s better than no d our plan or a d r plan that realistically hasn’t been updated in the last ten years, but i would say, you know, the top ten you really should have in your day. Our plan is number one, a contact list for your team members. What is the contact for your team, folks, your business continuity folks, if you normally would get that out of your email and you’re in a disastrous situation, you know you can’t get to your email or, you know, like we’re ever going through, and i want listeners to know that she’s doing this without notes, i it seems very confident that she’s got the hopefully i’ve ever altum in-kind get seven out of seven or eight ten will be ecstatic, but so continue. Oh, but i want to say yeah, as we’re going through, consider two organizations that may not have someone devoted to it. Correct, that is, our listeners are small and midsize non-profits right? They very, very well just all be outsourced or it falls on the executive director’s desk. Excellent point. Would you cover that in the session? So t finish at the top ten contactless three team members contact list for your vendors, a call tree and some sort of communications. How do you tell your organization in your members that you’ve had a disaster? Either your servers have gone down your parts of burst and your communications air underwater? How do you do that? What is your network look like? So? Network diagram process outline how you’re actually going to do your disaster recovery a timeline? How long do you expect these activities to take before you? Khun b live again, a list of systems and applications that you’re going to recover if you’re a large enough or gore, you can afford a hot site what’s called a hot or warm site where you can immediately switch over two other equipment. You know information about that, you’d need that to start your recovery and then also information about your backups. You know, who’s got your back ups? What system are you using? How do you, you know? Get those back. So those air sort of like the top ten things or d our plan should have. Alright, let’s dive intothe process. Ok a bit, because that intrigues me. And hopefully listeners. I think so. I think i have a fare beat on what’s. Interesting. I hope i do. Um, yeah. What? How do we start to think about what our dear process should be? First, you have to think about what all could be a disaster for your organization. A lot of people think about things, you know, earthquakes, hurricane, sandy, hurricane katrina. But it could also be water pipes bursting in your building. That is one of the most common thing. If your server is not properly protected, which a lot aren’t a lot of stuck in closets. Ah, dripping pipe water. We call those water events and that seems to be the most common thing departments encounter is leaking pipes in the building or some sort of a flooding situation. But it could also be an elektronik. Disasters such i’ve worked at an organization that underwent what’s called a ddos attack, which is a distributed denial of service. It took out our entire web presence because malicious hacker hacker went after that’s where there’s millions of right the network and they just flood your network seconds you’re overloaded and yeah, and that’s a disaster situations. So one, why would they attack like that? Why wasn’t non-profit attack malicious? The cp dot organ are attacked out with avon marchenese travon martin decision. Folks attacked our our petition site way. We were able to get it back online, but for a couple of hours. Yeah, we were off line. And that could be considered a disaster situation. For sure. Yeah. How do you help us think through what potential disasters are not even identify them all i think about what could affect your or what you wear. You vulnerable? Some of the things we talked about in the session and we’ll think about it. How would you get back online if the’s various things happen to you are your are your services sort of in the cloud? Do you have servers on site and start there when thinking about your process is what would you have to recover if these various scenarios affected you or with these various scenarios. Scenarios affect you if your website is completely outsourced to a vendor that has de dos protection. Okay, that’s, not a scenario you have to worry about so kind of analyze it and every organs going to be different. You know, if you live on the west coast, you’re probably concerned more about earthquakes than other regions. So it’s it’s going to vary for each organization, what sort of disaster you’re going to be worried about? And then you start getting down into the practical nuts and bolts in terms of who are your disaster recovery people, who’s your team, if you’re really small lorry, that might just be you or as you mentioned before, if you’re using outsourced, manage service provider and your vendors responsible for that, make sure your vendor has a d our plan for you. Ah lot of folks just assume your vendors taking care of that, but when it comes right down to it, do they actually have d our experience? Can they recover your items? Actually sit down and have that conversation? Because so many of the small org’s as you pointed out, do youse outsourced thes days and there’s there’s a lot of manage service providers that specialize in non-profit, but you need to have that conversation. Don’t wait till you’re under a disaster scenario to discover that groups they don’t actually have that experience have that conversation ahead of time. What else belongs in our process? Outline in your process latto outline if you’ve got a another site either a cold, a warmer, hot site or if your stuff is based in the cloud, where would you recover to the hot side is some place you go to drink cold water or hot? Sure, a cold site would be where you’ve got another location let’s say you have a dozen servers at your location, and in the case of, you know, your building being inaccessible or underwater. A cold site would be where you’ve got another location you could go to, but you don’t really have any equipment stage there, but it is another location you can begin operations out if that’s a cold sight there’s nothing ready to go, but you’ve got a sight a warm site would be where you sort of have a skeletal equipment there it’s far less capacity than you’re currently at, but you’ve got something there it’s not live, but you got stuff ready to go that you can restore to and get going. And a hot site is where you can flip over immediately. Your live replicating to somewhere else, it’s ready to go? It might not be full capacity, so it might not have, you know, full blown data line size that you’re used to might not have your full range of service, but it is live and you could switch over near instantaneously. That’s a hot site, ok, eso you’d want that in your process, and you’re going to want to think about what are you restoring and that’s where we get into the backups? What comes first and that’s, where you start getting into terms such as recovery point, objective and recovery time objective those air to very common d our terms recovery time is how far back are you recovering, too? And what does that mean for each system? So if it’s your donorsearch system that’s probably fairly critical, you want a recent restore of that? If it’s a system that doesn’t change very much, maybe a week ago restores okay for that and sorry that’s recovery point objective recovery time objective is how long does it take you to get back online after a disaster? You know, ifyou’ve got to download your data from an external source. Has anyone thought about how long that’s going to take you to get the data back? Is it going to take you fifteen hours or three days? So it’s in a lot of folks don’t think about that ahead of time, they just go oh, you know, we’ll we’ll pull it back down if we have a disaster, but they don’t think about instead of their nice normal data communications, they’re going to be on a tiny d s l line trying to pull down one hundred fifty gigs of information and it’s going to take a week to get it back down. I have to say you’re very good about explaining terms and thank you, proper radio. We have jargon jail? Yes, we try not teo transcend. You haven’t transgressed cause your immediate about explaining exactly what recovery point river and recovery time objectives are. It could be very confusing, you know, if you don’t understand the terms in tech, you can be confusing what folks are talking about, and that was one of the the focus is of our station session is making it less confusing and being very practical, practical about what you can or cannot do. And if folks go and look at our slides, they’ll see on several of the items we did a good, better best, and we tried to talk about that all throughout the session because we realized again for a small ork or, you know, even a large order that just doesn’t have the resources to devote to it. You might not be able to do best practice, but you could at least try a good practice that would be better than nothing. And then so we do a good, better best for each each type of thing like what does a good d our plan look like? Versace best day our plan and at least try and get to that good, because at least you’ll have something and it could be a continuum where you try and improve it along the way. But you’ve got to start somewhere it’s better than just ignoring it, which is what happens. At a lot of places. Got to take a break. Tell us credit card and payment processing. You know these people check out the video at tony dot m a slash tony tello’s that will start to explain to you the long tail of revenue that you can earn from. Tell us when you get companies to look att tello’s. Let tell us look at their processing fees. Then they switch to tell us you get fifty percent of the revenue forever. Tony dahna slash tony. Tell us now back to your disaster recovery plan with dar do we need to prioritize what what’s mission critical. And, yes, we can work with out for a time. Yes. How do we determine that? Definitely. We talk about that in terms of its not just a knight each decision either because we may think that the emails the most critical thing out there, but development may see the donor system as the most critical out there program might think that the case management system is the most critical out there. So you finance wants their account. They want their accounting system up. Obviously you’ve got to have an order in which you bring these things up. You’re probably not gonna have enough staff for bandwith or, you know, equipment to bring everything back online, so there needs to be and hopefully your executive team would be involved in deciding for the organization what is most critical in what order are you going to bring those things up? And that needs to be part of your d r plan? Because otherwise, if you’re in a disaster scenario, you’re not going to know where to start and there’s going to be a lot of disagreement of who starts where so you guys need to decide on the order, okay, we still have a few minutes left, but what more can we say about d r and related back-up that’s not going to wait till i’m back up because i think we could do a little bit in terms of d r i would say the key points on backups are check them because a lot of time, yes, monthly or quarterly, at least is anyone looking at your back-up back-up work-life one of the scenarios that we talked about that actually happened to my co speaker, andrew, was that their server room flooded and it hit their razor’s edge server, which is their entire c, m, s, c r, e, m and donorsearch system, and they thought it was backing up, but no one had actually check the backups in the last two months, and it was on, and it was not s o in terms of back-up just typical, you know, pay attention to the maintenance. What do you backing up? Has anyone checked it? And again, if you’re using a manage service provider, make sure if they’re responsible for for looking at your backups of managing them, make sure they’re doing that, you know, double check and make sure that they understand that your backups are critical and they can’t just ignore the alerts about your backups. You know, you don’t want to be in the unpleasant situation of three of our servers just got flooded. We need the data and discover nobody was backing it up. It ain’t exactly okay. All right. Anything else? You wanna leave people about back-up before we go to the broader diar? No, i think that’s. Good for those were the highlights for it. All right. So back to the disaster recovery. What more can we say about that. There are going to be a lot of watches if you’re in a large d our situation and so one of things we stress is one getting down into the details of your d our plan before disaster hits, you see, if you’ve never thought about how you’re actually going to do the restores air, actually, how you’re going to be rebuild those servers, you need two ahead of time. A lot of folks never practice have a fire drill. I hate fire drill, but and you don’t have a live fire drills in this case, it might be a live fire drill. You don’t want to have that, so you should make some effort to practice, even if it’s just something small, you know, trying to restore one server. I mentioned in this session that i was put in a situation years ago at johns hopkins university, where we were required to have verification of live tr practice. So i was put in a room that had a table, a telephone, a server, and we were carrying two laptops, and we couldn’t come out of the room, and so we had completely restored our domain. We had a set. Of backups on the thumb drive and added the second laptop to that domain improve that we had restored the domain, and an independent person that was not connected to our department was monitoring to make sure we had done it and we had to prove it, and that was an eye opening experience is as experienced as i was doing that i’d never done it live, and it took me three tries to do it so that’s, right? Encourage folks to really try and practice this stuff ahead of time and get down into the you know, the weeds on there on their d our planet on also to think about it. You weren’t fired because way, john no, no, no. I actually like too much john soft. No, we did complete it within the time frame, but we were a little startled when we discovered that we thought we knew how to do it first time out. And we kept making little mistakes. There were two of us and they’re doing it. And we were surprised ourselves that we thought, oh, of course we know this. This is not a problem, but no, we were making little mistakes. Because we didn’t have the documentation down, a specific is it needed to be, and so that was a very eye opening experience. There’s a couple of their d r gotchas we talked about, which is crossed, people don’t think about the cost ahead of time. How much is going to cost to get you that data? Back in the instance of my co presenter who had the damaged drives, they weren’t expecting a near ten thousand dollars cost to recover those drives, but that’s what happened when they didn’t have the backups? They had to take those hard drives to a data recovery place, and the price tag was nearly ten thousand dollars. Dealing with insurance is another big one that people don’t think about having to account for all of the equipment that was lost, and dealing with that insurance morass often gets dumped on the auntie department in a small organization. There’s not, you know, a legal department that’s going to deal with that it’s going to be you so to, you know, kind of talk to your insurance provider ahead of time and see what all you have to deal with in a disaster situation, so you don’t get an unpleasant surprise if you’re ever, in one a cz well, on the insurance topic, just are you covered? Exactly what what, exactly, is your equipment covered, and what do you have to do with that? In terms of accounting for it, if you suffer a disaster and you know the gooch is, we get so a couple of minutes, if if oh, about conscious. Trying to think about somebody we don’t hold back on provoc video, i think some of the other ones that we covered in their thick wit mint again to the cost, how much is it going to cost you? Two gets new equipment and did you account for that when you were doing your d our plan and a time to recover? A lot of folks don’t understand how long it may take them to do a recovery and also deciding what is important and what is not important, not just in terms of what should be restored in what order, but in terms of practical things, do you really need to restore your domain? Er, or could you just start over from scratch if your domain only contains maybe fifty accounts and doesn’t have any associated servers faster for you to just start over and just recreate the domain immediately? Especially if a lot of your emails in office three, sixty five or google maps, you could reconnect it very quickly. So, you know, thinking about more practical gotsch is like that that you should think about have time, you know, obviously it’s that’s the best practice to think? Of all these details, and he realized folks may not be able to, so we provided someone sheets and some samples of them of just quick, yes or no questions and thinking this through and things to think about and where will we that is not notice provoc radio has a professional sound i don’t know about ntcdinosaur ten, but that was a way over there. They’re on their own. They can come to us for expertise if they if they need to. But, uh uh, now i messed myself up because i ask you about something. What were you just talking about? How much? How long will actually take you to recover things? And whether or not you should practically skipped recovering something because it might be faster to rebuild it. Okay, i have a follow up to that my smart ass humor, maybe lose it. All right, so why did you leave us with one take away? Dror back-up the session was a little bit misnamed because technically, you’re not going to avoid a disaster you really can’t in many cases, you’re not gonna avoid the flood. You’re not going to avoid the earthquake if you’re in that. Region so you need to plan on how to deal with it. So it’s more like avoiding avoiding your d are becoming the disaster because you’re not going to avoid the disaster itself, so you might as well plan for it. Outstanding. Thank you very much. Door. Thank you much. Darby america vice president of technology for lift. This is tony martignetti non-profit radio coverage of ntc non-profit technology conference two thousand fifteen. Thank you so much for being with us. Thank you. Next week date your donor’s returns with jonah helper. If you missed any part of today’s show, i beseech you, find it on tony martignetti dot com were supported by pursuing online tools for small and midsize non-profits data driven and technology enabled. Tony dahna slash pursuant radio wagner c p a’s guiding you beyond the numbers regular cps dot com and tell us credit card and payment processing your passive revenue stream tony dot m a slash tony tell us our creative producers claire meyerhoff family boots is the line producer show social media is by sirs and chavez and this great music is by scott stein with me next week for non-profit radio big non-profit ideas for the odd. They’re ninety five percent go out and be great. Kayman you’re listening to the talking, alternate network, waiting to get you thinking. Nothing. Cubine are you stuck in a rut? Negative thoughts, feelings and conversations got you down. Hi, i’m nor ing. Sometimes the potentiality tune in every tuesday line to ten eastern time and listen for new ideas on my show. Beyond potential live life your way on talk radio dot n y c. Me, are you feeling unhappy with your body, shape or size? Ever feel out of control with food? I’m elizabeth from nourish the soul, and on this show you will uncover the route to these imbalances and discover a permanent solution toe having a healthy relationship to food and your body. Join us every thursday morning at eleven a, m eastern time on talk radio dot buy-in. Hey, all you crazy listeners looking to boost your business? Why not advertise on talking alternative with very reasonable rates? Interested simply email at info at talking alternative dot com. Yeah. Are you into comics, movies and pop culture at large? What about music and tv? Then you’re in for a treat. This is michael dulled, your host on talking alternative dot com. I’ve been professionally writing comic books, screenplays and music articles from fifteen years. Catch my show secrets of the sire at its new prime time slot. Wednesdays, eight p m eastern time, and get the inside scoop on the pop culture universe you love to talk about. For more info, go to secrets of the sire dot com dahna. You’re listening to talking alt-right network at www. Dot talking alternative dot com, now broadcasting twenty four hours a day. Are you a conscious co creator? Are you on a quest to raise your vibration and your consciousness? Sam liebowitz, your conscious consultant, and on my show, that conscious consultant, our awakening humanity. We will touch upon all these topics and more. Listen, live at our new time on thursdays at twelve noon eastern time. That’s, the conscious consultant, our awakening humanity, thursday’s twelve, noon on talk radio dot. You’re listening to the talking alternative network. Napor

Nonprofit Radio for June 23, 2017: Don’t Be The Founder From Hell & Your DR Plan

I love our sponsors!

Do you want to find more prospects & raise more money? Pursuant is a full-service fundraising agency, leveraging data & technology.

It’s not your 7th grade spelling bee! We Bee Spelling produces charity fundraiser spelling bees with stand-up comedy, live music & dance. It’s all in the video!

Get Nonprofit Radio insider alerts!

Listen Live or Archive:

 

My Guests:

Jim Nowak: Don’t Be The Founder From Hell

Jim Nowak heads fundraising for the dZi Foundation, which he founded. How did he and the Foundation manage his transition from executive director to chief fundraiser? He talks candidly about the board, job descriptions, ego and more. (We talked at Opportunity Collaboration 2015 & this originally aired 10/30/15.)

 

 

Dar Veverka: Your DR Plan

Disaster recovery: Ignore it at your own peril. What belongs in your DR plan? Dar Veverka is vice president of technology for LIFT. (This originally aired 5/1/15 and is from the 2015 Nonprofit Technology Conference.)

 

 


Top Trends. Sound Advice. Lively Conversation.

Board relations. Fundraising. Volunteer management. Prospect research. Legal compliance. Accounting. Finance. Investments. Donor relations. Public relations. Marketing. Technology. Social media.

Every nonprofit struggles with these issues. Big nonprofits hire experts. The other 95% listen to Tony Martignetti Nonprofit Radio. Trusted experts and leading thinkers join me each week to tackle the tough issues. If you have big dreams but a small budget, you have a home at Tony Martignetti Nonprofit Radio.

Get Nonprofit Radio insider alerts!

Sponsored by:

Vertical_Color
View Full Transcript

Transcript for 345_tony_martignetti_nonprofit_radio_20170623.mp3

Processed on: 2018-11-11T23:41:08.514Z
S3 bucket containing transcription results: transcript.results
Link to bucket: s3.console.aws.amazon.com/s3/buckets/transcript.results
Path to JSON: 2017…06…345_tony_martignetti_nonprofit_radio_20170623.mp3.178031979.json
Path to text: transcripts/2017/06/345_tony_martignetti_nonprofit_radio_20170623.txt

Dahna hello and welcome to tony martignetti non-profit radio big non-profit ideas for the idler ninety five percent. I’m your aptly named host. Oh, i’m glad you’re with me. I’d suffer the effects of black ophelia if you tried to sugar coat the idea that you missed today’s show, don’t be the founder from hell, jim no ac heads fund-raising for the d c i foundation, which he founded. How did he and the foundation manage his transition from executive director to chief fundraiser? He talks candidly about the board, job descriptions, ego and more. We talked that opportunity collaboration twenty fifteen miss originally aired october thirtieth, twenty fifteen and your d our plan disaster recovery ignore it at your own peril. What belongs in your d our plan dahna geever ca is vice president of technology for lift. This originally aired on may first, twenty fifteen and is from the twenty fifteen non-profit technology conference on tony’s take two the charleston principles we’re sponsored by pursuant full service fund-raising data driven and technology enabled, you’ll raise more money pursuant dot com and by we be spelling super cool spelling bee fundraisers we be e spelling dot com here is gym no ac with don’t be the founder from hell. Welcome to tony martignetti non-profit radio coverage of opportunity collaboration twenty fifteen were on the beach in x top of mexico. My guest is jim no ac. He is president and co founder of zi foundation. They’re at dc i that’s deltas delta zulu, india from my air force days dot org’s dc i dot org’s and we’re talking about avoiding being the founder from hell. Jim is not that jim. Welcome. Thanks, tony for having me on the show. Appreciate it. It’s a pleasure. I’m glad we got together rubs what? Two days ago, right? I think we’re connected. And, um all right, you’re not the founder from hell, and we are going. We’re gonna take this way only have one side of the story, so i don’t have justin you because one of your board to collaborate to corroborate your your side. But you’re doing a session here. Yeah, i presume you’ve been. You’ve been vetted. Yeah, i’ve done done the session for the six years i’ve been coming. Job pretending collaboration. I keep offering. You know i don’t need to do the session, but it seems as i always say nobody ends up in that session by mistake, you know, people and it’s been interesting people, aaron really tough situations, very emotional, you know, that the social sector is a tough space to be in, and people are very passionate and it can be really charged, but we do our best to try to give people some tools, maybe walk through these these these difficult situations, all right? And in the six years i’ve been doing, you’ve never been challenged by anyone who said, no, that guy is the ceo. That guy he’s the founder from hell, no never had that challenge, but having no, but there, you know, again, i would say i only have one perspective to bring to it there are people that have different perspectives and say that would never work that are absolutely, and i’ve had some of them as guests, but but we’re getting the founders perspective, which i haven’t had before. Yeah, let’s, start with your history with the organization. I’m the cofounder, and now i sit is president we started are working. Paul. Seventeen years ago, it was around an expedition that had been climbing in the fall for a number of years and small expedition to climb. Memoria twenty three thousand four hundred foot what’s. The name of it from maury fremery three miles to the west of everest, on the nepal tibet border. Doing a new route has never been climbed. I was on there and eighty nine now back in ninety eight and in ninety eight found out about small girls home that was financially failing. Raised money in my local community to help bail this girl’s home out. That was the genesis of our work. Where’s. Your community. Where were you living then? I was living the vail, colorado, that and shortly after that moved to where were based now in ridgeway, colorado, southwest corner of colorado. Down by tell you right now. Okay. And how long have you not been the executive director? I was executive director for the first thirteen years. Okay? And then we started into a process of identifying we wanted to shift from there and bring someone in with better financial skills than than myself. But and it was early, early on, it was identified by my board that they want me to say connected to the organization i carried the history carried a lot of the donors carried those relationships on. They want me to become the development director. Okay, i’m going to get to the details of how that all played out. That’s that’s, critical part. But so it was for you, it’s been four years now since you were executive director. Is that right? Correct. Okay. And there is a new executive director. Hired and same person have been in the position for years. Yeah, we feel like we we did a really thorough an extensive search. Get a job and he’s still on the job saying individual okay. Okay, so, he’s uh, he’s executive director. Um correct, mark. Mark. And you won’t get a shot at mark. Yeah. Mark rikers, mark rikers. And you’re the president. Correct. Okay. Let’s, um, let’s start with the board’s role in this what i think is really interesting eyes that it was the board recommendation that you stay it wasn’t you as founder dictating. I want to stay with this organization. The impetus for having you remain came from the board. And also the impetus toe hyre an executive director came from the board, so it was to phase it was like we need to. And as my board affectionately refers to jim, if you get hit by a bus, this organization could potentially go down in flames. So the impetus came from some very skilled and wise board members that had experience in the nonprofit world. Had experiences change management leaders. We’re just very savvy and saying let’s, make our organization more sustainable and increase our bench bench strength. There had to be a lot of trust, a cross, you and the board, i mean, you had to believe that the board actually wanted you two remain and in the capacity that you ultimately became president and which is chief fundraiser for right, you have put a lot of faith in you’re in your board members telling you that believing what they were telling you. Yeah, and this is a really an emotional space for founder’s teo walk into because you could certainly believed that you were in a situation where you were being replaced, you and i that certainly took ah, was it took a while for me? Because that was my first reaction. I don’t think it was an unusual one. Hyre this changing roles and organizations is really tough work, i think it’s exceptionally tough if you’re the founder, if you were the very first person working on your own, you know, from monstrous hours and generating the organization, but pardon parcel of that is that i always had the belief that eventually, you know, in organizations everyone leaves eventually, and i always had in the back of my mind that the most important thing was that this organization lived on beyond me. And this was certainly a major stepping stone to that. What about the, uh, the composition of the board you mentioned? You had some change management people on your board talk about the importance of having the right skill set on your board. Help this transition? Yeah. I mean, it’s it’s, kind of like who’s. Do you have the right people on the bus? You know, and early on in our evolution, you know, i was way had a lot of people that knew a lot about paul, and that was great. But they were all foreigners, you know? And they had great skill, great passion and that but the evolution has been to bring in people with sound non-profit experience people who were changed management leaders that basically had their own consulting firms that actually helped corporal eaters and non-profit lee just walk through these really challenging transitions in the evolution of the nor is a t had that expertise. Oh, yeah, we have that three people that change management expertise. Yeah, that was that was really hughes. And then more than anything, maybe was that i had specifically two individuals that i trust implicitly, that they actually have my back. And that that boardmember board members that this was, you know, they had long non-profit experience, but that this was the way the organization could go and that i was not being, you know, put out to pasture and that that that this would be a very fascinating time for me to be able to find out what i really wanted to do instead of having to do everything you also had to trust that the board has the best interests of z in mind that and that their vision is at least, you know, parallel to yours. I mean, it may not be identical, but they yeah, they’ve got z in their in their hearts and and that that really, you know, one of the two individuals i trusted implicitly had been there at the first board meeting in my kitchen table, you know? And now we’re actually we have our board meetings at his board table on the fourteenth floor in denver office, you know? So i mean, that’s been a long evolution, but that had been fourteen years of that relationship, so yeah, i really knew that they had my had my back, a lot of trust ways, but not without a lot of emotion. And a lot of baggage, i’m sure is a tough, you know, you know, talk about the emotional, you know, you just just feel, is this the where am i actually going? What was actually going to happen to the organization, you know, what’s gonna happen to me because i really impassioned about this work and want to stay in this space, you know? So yeah, a lot, a lot of challenges and a lot of ups and downs, and i would say that that period tow walk through that and feel confident it took a couple months and they really took a couple months, and we laid out a very deliberate plan on the evolution of this after about a month into it. So i was starting to get on board a month of emotion. Yeah, the emotion continued, but then it started become irrational process. Yeah, because it started to develop and expand into what could be and i didn’t see that initially. Oi! All i saw was what what? What i thought was being replaced. Yeah, yeah, yeah, yeah. Initially that’s it. Yeah, yeah. All right. But you obviously overcame that. Yeah. Oh, and to add to that in this process and, you know, one thing that was really fascinating is that our entire board bought into the concept that as we moved into a new executive director, that the executive committee and myself would be the five people that would decide, and it would be unanimous on who we decide if we didn’t find them knives like your daddy way did not find that person, we would scrap it for six months and then come back okay, you’re tuned to non-profit radio tony martignetti also hosts a podcast for the chronicle of philanthropy fund-raising fundamentals is a quick ten minute burst of fund-raising insights published once a month. Tony’s guests are expert in crowdfunding, mobile giving event fund-raising direct mail and donor cultivation really all the fund-raising issues that make you wonder am i doing this right? Is there a better way there is? Find the fund-raising fundamentals archive it. Tony martignetti dot com that’s marketmesuite n e t t i remember there’s a g before the end, thousands of listeners have subscribed on itunes. You can also learn maura the chronicle website philanthropy dot com fund-raising fundamentals the better way dahna we’re going to get to the search. I spent more time on the board. You mentioned you had a lot of longevity on the board. Not not just the one. The one guy who started your kitchen table and now you’re in his fifteenth floor. Yeah, but you you yeah, you had other board members with long longevity. They understand the organization. They they have the best interests of z in their hearts to jury. I mean in our by-laws boardmember sze sit for three years, they have to be voted back on for another three years. They could walk away from the organization or immediately go to an advisory board that gets all the information doesn’t vote. After a year, they could be voted back on the board, but wave have everything we’ve had people that stayed a long time. We’ve had people that cycled and cycled out. I think that’s a really healthy for the cycle more than anything. New ideas, new energy, new vision. You know, new new things. Yeah. Onda connection disease work. Yeah, and and that that solid underpinning has always been that people have been there to anchorage, not just myself. Let’s, talk about the the search, the search process. You said it was the executive committee of the board for people and you. And did it have to be? You had to be unanimous. Vote on who the successor would be. Okay. He obviously had a lot of you have to be a lot of trust in that process. Yeah, from the rest of the board members. So well. And you too, you know. Yeah. Yeah, yeah. All five of you had to. Well, actually, the whole board had trust the process. Yeah, they had delegated the vote to the executive committee and you, but the whole board had trust this process. Yeah, they really did. And so there were some mechanisms that engaged staff engaged other board members, whether it was an opportunity for the three final candidates to be in our office and ridgeway and for people to come there and meet them and to sit in on a conference call with all the board members anyone that wanted to patch in, we actually had the three final candidates work with our financial officer for an hour and at ask questions around that they were in a closed room also with our the paul country director who was in country at that time. So they they all spent time with them. So it was really a deal where everyone had input. But there were five the executive committee and myself that were decided. Maybe a little detail. But i’m interested. What was the mechanism for staff to give feedback to the five people who are going to do the vote? It was basically threw the board chair. So they say the staff whether it was the financial officer in the whole country. Director they gave that him. Put directly back to the board chair on the board chair. Disseminated that to this election. Okay. Okay. Yeah. Um, was there a outside search consultant? No. No, we all did. With is completely just posted it publicly. Well, we posted it in all sorts of spaces, you know, on you threw the peace corps on on. Were located in a remote area in western colorado. So speak on the western slope. So we had lots of people in the denver area. Certainly. Um what we ended up through our network’s way ended up with sixty for paper applications. Now on dh. So that was what we started to wed our way through and pretty short. Or there were a third that it was really crystal clear they were, yeah, yeah, way too much of a stretch, and people asking to remove work remotely in new york for this job. So am i, and that was deal that we want people in the office, you know, you know, face-to-face on dh, so that was a real process, and and once we cold that list, then all of the board members were assigned. The executive committee search committee were assigned a certain amount of people to deal with, to make phone calls, too. There was a list of questions to be asked, and then that information was brought back to the search committee, and we started to, just with a little bit, whittle it down. Job the job descriptions, you’ve identified that as being critical, setting boundaries abound. What? What? You’re what you’re gonna be doing as president and not doing with the exec director is going to be doing let’s. Let’s flush that out job description. Yeah, that was that was really critical, you know, so to speak. What? You know, what was mark’s role? What was my role in what was our rule? You know, and how are we gonna work? Basically in the same office. And how is that going to make this kind of lateral move to be in charge of of all development, really focusing and digging into that, which is something i certainly had done, but i was doing a lot of different things, too. So that was just really critical and also having our executive committee really get into the weeds on that. And then, you know, it’s all about really owning that once it won once things transition about assuring mark who became executive director, but during the process, maybe at the point where he was offered the job or at some point he had to be reassured that this was not going to be a founder. Syndrome situation that he was stepping into. Yeah, what was that like? How did you well, we did that with all of our three final buy-in indefinite detail. And that was something that we put forth. This is how this out was, is how it’s changing. Okay? And, um, you know, i mean, this is probably a good time and, uh, it’s about somebody’s ego and, you know, what’s the what’s, the main driver, is it about you is about control, is it about not allowing the organization to grow past you and evolved past you? Or you’re going to keep a stranglehold on it on dh make things miserable for not only marked, but everybody else in the organization, so i want to double it more detail on how those three candidates got god assured that this was not going to be a disaster situation they’d be walking into mean, it had to be more than just the written job descriptions. Yeah. You know, i think one of the things that was really interesting is we weren’t, you know, quite often in this the executive director search or changes organization. What happens is it’s because the, you know, the staff’s upset programs are not being delivered properly, and financially, you’re you’re in dire straits. I mean, it was a kind of that’s, a standard, why you’re changing. We actually came from a really strong position, and we felt it was inappropriate time to make the shift financially. We were in good shape. Um, staff was quite happy with what they were doing, and programs were certainly evolving at that time. So, you know, nothing was perfect, but we certainly were not in the crisis mode. That’s quite often, what happened, so we were on the front end of this, but we were again realizing the vulnerability of of me is found, yeah. And they also had to be assured that you personally wood abide by the job description. Yeah, on everything that’s being said. I mean, you know, this is all in writing, and it all sounds good, but, you know, i was the new executive director could walk in and, you know, this guy jim is just blowing everything out of the water that we talked about, and now i’m in a bad spot. Yeah, yeah, yeah latto latto i had to trust you. Yeah, and that it’s a pretty standard situation. Yeah, you know, it’s pretty standard that it be negative. Yeah, is that demanded? And quite often, i do hear that people cycle through that know that first executive director didn’t work out. Now we’re into our second one, you know, we were fortunate and maybe i don’t know why, but i guess mark and the two other candidates believe me, you know, i mean, i really think it comes down to you know that and reassurance from the executive committee, no more trust, yeah was allowed to rest there’s a lot of stress. Yeah, we’re taking a big step here. Like i said, the paper documents are fine. But in the end, they could be end up being meaningless. It comes down to a human connection and right and trust. Yeah. Yeah, ego. You mentioned it before. So let’s, explore that it’s mostly your ego that you had keep in check for the for the good of z. Yeah, i think so. I mean, i’m no, no expert trust me, but i guess at the core of this is i’ve always held a belief of doing your best to hyre smart people than yourself on that doesn’t intimidate me. It makes us a stronger organization. So that’s a core belief of mine. Mine. Um, i why would i not try to bring the best and the brightest board members to the board, the best and brightest staff to the board? Um, that’s. Just a core belief of mind that that’s what’s going to make a sustainable organization, you know, that’s where the oil starts for me. All right, you know, and, um, hyre, you know, again, that core belief that my biggest responsibilities, this organization, lives on beyond me. Yeah. It’s bigger than you. It is much bigger than me. And then you, you know, from one person operation tow for people in colorado in twenty five in the fall. And, you know, fourteen girls is where we started serving over. Thirty thousand people now it’s way beyond me. I play an inter call roll i have in trickle power because i am the founder, but i’m on ly a piece of the puzzle and that’s that’s a healthy place for nor ization obviously there was a transition period where you had a share, a lot of corporate knowledge, with mark as the new executive director. Absolutely. You know, one of the things that was interesting way we’re in an office situation where we had two basic office rooms, and initially mark and i were going to work in the same room, and i just was, like, that’s not gonna work. We took the office next door. We’re connected by a door, but we can be close and have our own private space that i didn’t want him to feel that i was looking over his shoulder. Yeah, ever, you know, but there was institutional knowledge, you know, of our organization and what we done and our relationships and our funding and our partners and how we did things and where we worked and all that stuff that had to be transferred over and that takes time. That’s just a constant process of answering those questions mark was incredibly quick study, but i mean, i can’t imagine i’m thinking back out for years now, but, you know, he was really getting it after four months, six months a year, you know, it takes time and it’s, you know, and transferring those relationships, introducing him to those relationships is key and again, taking that letter will move away from that, you know, so that’s, what an and in a way, we also identified that it was an opportunity for me to become maur engaged in the board on dh i now sit on the board, i had never sat on the board. First of all, no, there was not in exhibition zoho ous founder, no, no one i was fonder, i said as the executive director, but i did not sit on the board and you don’t have a vote now. I didn’t have a vote that i don’t have a way out or not right now you’re on the board, but you don’t have a vote, correct. So i’m basically straddled the board on the kind of clutch between the staff from the boy. Why that decision to not have a vote i already have enough power is what the board felt, and i think that that’s the accurate, that definitely was another risk situation for me where i was like, wow, i’m losing control. Yeah, but founders have immense historical knowledge, respond relationships, they have immense power with organizations. And although that did feel uncomfortable, it was the right decision, you know, and quite a lot, itjust wass, you know, a lot of this feels like it has to be the right people. I mean, here you’re you’re you’re saying, you know, you struggled with not getting a vote being on the board, but not having a vote, but in order for this to work and for the board to be comfortable, you had teo swallow that you had to accept that and, you know, another person might not have been able to yeah, a lot of this, yeah, trust and and the personalities that people have to be right now, if it’s not the right people, then you’re not gonna have the trust and and we’re gonna end up with what i’ve had guests on the show say that which is when the founder leaves the leadership role here. She has got a several ties. Yeah, that’s really the default, right? But it sounds like if you arrive the right personalities, you don’t have to you don’t. Except the default. Well, i think there’s a couple things that play into that one is most times when people are shifting executive directors, it is a crisis situation, and maybe the management wasn’t very strong for so that’s that’s a pretty standard situation. I mean, for us, we were coming from ah, solid footing and the thing that was the constant phrase that we we used in our search was we need to find somebody with correct emotional intelligence to come in and not gutsy, but to build on pond what we’ve already created. And so that was it was really the baseline kind of tag line that way worked off the position as president created opportunities for you that you didn’t have as dahna in the leadership relies founder yeah, let’s talk a little about that because i think it was important for you to recognize that there was opportunity for you and the board was making that clear in the new president role. Yeah, and there i think the opportunity around it was too deep in my relationship with board members. And as i say, be that clutch between what’s happening in our work on the paul what’s happening with staff and that but a zai moved into the development roll exclusively. Really? What happened is at a time. I mean, i had time to follow some more creative, creative things i mentioned there was a knopper to nitti where we were invited from a little town that’s less than a thousand people in ridgeway, colorado, to create enter an event in italy and in france, where there’s a charity cycling about where it’s it’s basically a fancy camp for cyclists that i mean, they have massages and right insane amounts. That was three days of riding with over twenty five thousand feet of climbing racing. And so basically, we were able to bring in individuals who had financial capacity to commit to raising a significant amount of money for the foundation. Through this, this leverage point through their friends, and you would not have been able to pursue this no way and found a rolling no on and much band with way too much band with and then what happened out there that is we actually then deepened our relationships in london in the uk and we were a register as a charity in the uk. So now there’s the zi foundation uk and we have a board of trustees over there and they basically carried the work of the zi foundation in the uk raise funds for the paul that money flows through the u s and then in the fall so that basically become a whole new revenue stream that we never had nor would they have had anywhere near the bandwidth to take something like that on so it’s all those opportunities you know and looking around the corner what’s next and being very creative about it and that’s been very, very rewarding for me simple question in in the wrap up why the title president instead of director of development or institutional advancement? I think the board really wanted to honor my legacy with the organization, you know? And instead of just director of della development, they just wanted to honor my title is cofounder present your morning thank you for sharing means really some personal stuff talking about trust and ego and you know, being the right personality, so i want to thank you very much for for sharing. Yeah, thanks. I’m happy to share with anybody. It’s it’s, i think one of the things that happens is in these non-profits u u you changed from being student sometimes teacher, and i’ve been able to share this with a lot of people. It’s tough work at that level and i’m happy to share with anyone. So thank you for having me on pleasure you’ll find him at xero foundation dot org’s, it’s dc i foundation dot org’s tony martignetti non-profit radio coverage at the opportunity collaboration twenty fifteen on the beach i know you hear the waves breaking in its top of mexico. Thanks so much for being with us. Your d our plan with dar viv arika coming up first. Pursuant they’re content paper. They want you to know about its breakthrough fund-raising like all their content it’s free and this one is going to train you on break through thinking where you will learn how to solve the challenges facing your office, how to set a breakthrough outcome and what that means and how to create a culture of breakthrough thinking. In your office breakthrough, you can do it. There’s good ideas in here. The paper is breakthrough fund-raising and you get it at pursuing dot com click resource is and then click content papers. We’ll be spelling spelling bees that raise money. It’s a fun night out at a local place and it’s not your seventh grade spelling bee. You need to raise more money. I know you do. You can do it. We be e spelling dot com. We’ll help you. We’ll be spelling now. Time for tony’s take two the charleston principles this is something that relates to charity registration, which talked about love three weeks ago or so roughly three, four weeks ago was the video on that charity registration morass. Now i’ve got one on the charleston principles. They were created in charleston, south carolina, and they have very good suggestions for states it za recommended body of laws for states to adopt around charity registration to try to standardize things. Trouble is ah, lots of states haven’t adopted them. It’s not too clear where they’re adopted. Eso it’s not really all that standardized, but they’re good ideas and they are in some states the charleston principles. Check out the video at tony martignetti dot com it will help you with charity registration. And as always, i can if can you help with that, too? That is tony’s take two here’s darby barca with your disaster recovery plan welcome to tony martignetti non-profit radio coverage of ntc twenty fifteen the non-profit technology conference were in day two. We’re in austin, texas, at the convention center and my guest is dar vivir ca she’s vice president of technology for lift a lefty, and her workshop topic is avoiding disaster. A practical guide for backup systems and disaster recovery planning you’re welcome. Thank you very much. Good to be here. It’s! A pleasure to have you ah, this day two we’re highlighting one swag item at and ntc her for interview. And, uh, i have a double chip biscotti from a sputnik moment. The hashtag is hashtag is sputnik smiles and i’m told that the glasses go with the biscotti so this is essential. This is this interview’s swag moment. Thank you very much. Sputnik smiles and it goes into the goes into the swag collection. There it is. Okay, door. Um we need to know some. Ah little basic turn. Well, you know what, before we even get into why is disaster recovery and the related and included back-up so i don’t know if it’s just for gotten ignored, not done. Well, what inspired the session is a organization i used to work for. We were required by auditors to do a disaster recovery plans. So when it came time for the annual audit, i got out the current disaster recovery plan. It went all right, i’m going to go ahead and update this, and when i discovered, when i read the plan was there were servers that were eight years gone for last eight years server and reading the planet was very clear that what the previous person had done was simply change the date and update the plan for auditors. And as i thought about it and talk to other people, i found that that actually happens a lot people. It’s, d r is sort of that thing they don’t have time for because no one ever thinks it’ll happen to them, so you push it off, you push it off, and you either just download the template, you know, a template off the internet. And you slap a date on it and basically fill it out just for the auditors. But a lot of organizations never actually think through their disaster recovery, they don’t get into the details, they don’t worry about it, and then when a disaster actually happens to them, they’re sort of stuck. You don’t have a plan that i don’t have a functioning christian, and they’ve never tried it out. So that was what inspired the session, and as we dug into it, we we tried to give the thirty thousand foot view because disaster it cover, you know, there’s an entire industry, the deals with technology, disaster recovery. You can spend days on this topic, and obviously we didn’t have days we had a ninety minute session, so we tried to give the thirty thousand foot view of the practical items you need to pay attention to if you’re not confident in your organisation’s d our plan, if you i don’t have a d our plan or if you do and you really don’t, you know, you think it really needs an overhaul that sort of the top ten of items of what you should really be looking at. When you’re dealing with disaster recovering backups and we tried to give some several practical examples myself and the other speaker and andrew, who could not make it this morning of disasters we’ve had to deal with as well as other well known ones. Yeah, okay, do we need some basic language? Wait, get into the d r disaster recovery topic short jr is one of them disaster recovers, often referred to his d r it’s often spoken about in terms of business continuity or bc, which is sort of the larger plan for the entire organisation. Should’ve disaster strike there’s you know, there’s very d are specific things such as our poet recovery point objective that we could talk about your rto, which is recovery time objective there’s very specific language like that for disasters. It’s usually just referred to d ours. So whenever we say d arts disaster recovery okay, we’ll see if we get into those eyes and i could explain this week. Okay, um, all right, so clearly we should have a disaster recovery written just recovery plan. Even if we’re an organization that small enough that doesn’t have an annual audit, we still should have. Something in place? Yes. Okay. What belongs in our day? Our plan top ten things. You need a contact list for your team. So if you have a top ten of the d r i do of what should your plan d our plan? You know, it could be anything from a five page outline that just covers the basics. And in in our sessions slides, which i’ve posted in the ntc library gives it some good resource is for doing a d our plan or it could be a, you know, a huge hundred page document. It covers absolutely every aspect of business continuity or something in between. It’s going very by organization. And the reality is, if you’re a small organisation with a small team, you might only be able to do the five page outline. But that’s better than nothing. That’s better than no d our plan or a d r plan that realistically hasn’t been updated in the last ten years. But i would say, you know, the top ten you really should have in your day. Our plan is number one. A contact list for your team members. You know what is the contact for? Your team, folks, your business continuity folks, if you normally would get that out of your email and you’re in a disastrous situation, you know you can’t get to your email or, you know, like we’re ever going through. And i want listeners to know that she’s doing this without notes, i it seems very confident that she’s got the and hopefully i remember altum in-kind get seven out of seven or eight of ten will be ecstatic, but so continue. Oh, but i want to say, yeah, as we’re going through, consider two organizations that may not have someone devoted to it correctly. This is our listeners are small and midsize non-profits right? They very, very well just all be outsourced, or it falls on the executive director’s desk. Excellent point. Would you cover that in the session? So t finish at the top ten contactless three team members contact list for your vendors, a call tree and some sort of communications. How do you tell your organization in your members that you’ve had a disaster? Either your servers have gone down your parts of burst and your communications air underwater. How do you do that? What is your? Network look like so. Network diagram process. Outline how you’re actually going to do your disaster recovery. A timeline? How long do you expect these activities to take before you, khun b live again? A list of systems and applications that you’re going to recover. If you’re a large enough or gore, you can afford a hot site was called a hot or warm site where you can immediately switch over two other equipment. You know, information about that. You’d need that to start your recovery. And then also information about your backups. You know, who’s got your back ups? What system are you using? How do you, you know? Get those back. So those air sort of like the top ten things or d our plan should have alright, let’s dive into the the process. Okay? A bit is that intrigues me, bond. Hopefully listeners? I think so. I think i have a fare beat on what’s. Interesting. I hope i do. Um, yeah. What? How do we start to think about what our dear process should be? But first, i have to think about what all could be a disaster for your organization. A lot of people think. About things you know, earthquakes, hurricane, sandy, hurricane katrina, but it could also be water pipes bursting in your building. That is one of the most common thing if your server is not properly protected. Which a lot of a lot of stuck in closets ah, dripping pipe water. We call those water events and that seems to be the most common thing departments encounter is leaking pipes in the building or some sort of a flooding situation, but it could also be an elektronik disaster. Such, i’ve worked at an organization that underwent what’s called a ddos attack, which is a distributed denial of service. It took out our entire web presence because malicious hacker hacker went after that’s where there’s millions of right network and they just flood your network seconds you’re overloaded and yeah, and that’s a disaster situation. So one why would they attack like that? Why wasn’t non-profit attack malicious? The cp dot organ are attacked out with avon marchenese travon martin decision. Folks attacked our our petition site way. We were able to get it back online, but for a couple of hours yeah, we were off line and that could be considered a disaster situation for sure. Yeah? How do you help us think through what potential disasters are not even identify them all i think about what could affect your or what you wear, you vulnerable? Some of the things we talked about in the session where? Think about how would you get back online if the’s, various things happened to you are your are your services sort of in the cloud? Do you have servers on site and start there when thinking about your process is what would you have to recover if these various scenarios affected you or with these various scenarios? Scenarios affect you. If your website is completely outsourced to a vendor that has de dos protection. Okay, that’s not a scenario you have to worry about so kind of analyze it and every organs going to be different. You know, if you live on the west coast, you’re probably concerned more about earthquakes than other regions. So it’s it’s going to vary for each organization, what sort of disaster you’re going to be worried about? And then you start getting down into the practical nuts and bolts in terms of who are your disaster recovery people, who’s. Your team, if you’re really small lorry, that might just be you or as you mentioned before, if you’re using outsourced, manage service provider and your vendors responsible for that, make sure your vendor has a d our plan for you? Ah lot of folks just assume your vendors taking care of that, but when it comes right down to it, do they actually have d our experience? Can they recover your items? Actually sit down and have that conversation? Because so many of the small org’s, as you pointed out, do use outsourced thes days? There’s yeah, there’s a lot of manage service providers that specialize in non-profit, but you need to have that conversation. Don’t wait till you’re under a disaster scenario to discover that groups they don’t actually have that experience have that conversation ahead of time. What else belongs in our process? Outlined in your process that outline? If you’ve got a another site, either a cold, a warmer, hot site or if your stuff is based in the cloud, where would you recover to? The hot side is some place you go to drink cold water or hot? Sure, a cold site would be where? You’ve got another location let’s say you have a dozen servers at your location and in the case of your building, being inaccessible or underwater, a cold site would be where you’ve got another location you could go to, but you don’t really have any equipment stage there, but it is another location you can begin operations out if that’s a cold sight there’s nothing ready to go, but you’ve got a sight a warm site would be where you sort of have a skeletal equipment there it’s far less capacity than you’re currently at, but you’ve got something there it’s not live, but you’ve got stuff ready to go that you can restore to and get going. And a hot site is where you can flip over immediately. Your live replicating to somewhere else, it’s ready to go? It might not be full capacity, so it might not have, you know, full blown data line size that you’re used to might not have your full range of service, but it is live and you could switch over near instantaneously. That’s a hot site, ok, eso you’d want that in your process and you’re going to want to think about what are you restoring and that’s, where we get into the backups? What comes first and that’s, where you start getting into terms such as recovery point objective and recovery time objective those air to very common d our terms recovery time is how far back are you recovering too? And what does that mean for each system? So if it’s your donorsearch system that’s probably fairly critical, you want a recent restore of that? If it’s a system that doesn’t change very much, maybe a week ago restores okay for that sorry that’s recovery point objective recovery time objective is how long does it take you to get back online after a disaster? You know, ifyou’ve got to download your data from an external source. Has anyone thought about how long that’s going to take you to get the data back? Is it going to take you fifteen hours or three days? So it’s in a lot of folks don’t think about that ahead of time, they just go oh, you know, we’ll we’ll pull it back down if we have a disaster, but they don’t think about instead of their nice normal data communications, they’re going to be on a tiny d s l line trying to pull down one hundred fifty gigs of information and it’s going to take a week to get it back down. I have to say you’re very good about explaining terms and thank you, proper radio. We have jargon jail? Yes, we try not to neo-sage transcend you haven’t transgressed cause your immediate about explaining exactly what recovery point river and recovery time objectives are. It could be very confusing. You know, if you don’t understand the terms in tech, you can be confusing what folks are talking about, and that was one of the the focus is of our station session is making it less confusing and being very practical, practical about what you can or cannot do, and if folks go and look at our slides, they’ll see on several of the items we did a good better best, and we tried to talk about that all throughout the session because we realized again for a small ork or, you know, even a large order that just doesn’t have the resources to devote to it. You might not be able to do best practice, but you could at least try. A good practice that would be better than nothing. And then so we do a good, better best for each. Each type of thing, like what does a good d our plan look like versus the best day our plan, and at least try and get to that. Good, because at least you’ll have something. And it could be a continuum where you try and improve it along the way. But you’ve got to start somewhere it’s. Better than just ignoring it, which is what happens at a lot of places. Like what you’re hearing a non-profit radio tony’s got more on youtube, you’ll find clips from stand up comedy tv spots and exclusive interviews catch guests like seth gordon. Craig newmark, the founder of craigslist marquis of eco enterprises, charles best from donors choose dot org’s aria finger do something that worked neo-sage levine from new york universities heimans center on philanthropy tony tweets to he finds the best content from the most knowledgeable, interesting people in and around non-profits to share on his stream. If you have valuable info, he wants to re tweet you during the show. You can join the conversation on twitter using hashtag non-profit radio twitter is an easy way to reach tony he’s at tony martignetti narasimhan t i g e n e t t i remember there’s a g before the end he hosts a podcast for the chronicle of philanthropy fund-raising fundamentals is a short monthly show devoted to getting over your fund-raising hartals just like non-profit radio, toni talks to leading thinkers, experts and cool people with great ideas. As one fan said, tony picks their brains and i don’t have to leave my office fund-raising fundamentals was recently dubbed the most helpful non-profit podcast you have ever heard. You can also join the conversation on facebook, where you can ask questions before or after the show. The guests were there, too. Get insider show alerts by email, tony tells you who’s on each week and always includes link so that you can contact guest directly. To sign up, visit the facebook page for tony martignetti dot com. Duitz i’m chuck longfield of blackbaud. And you’re listening to tony martignetti non-profit radio. Big non-profit ideas for the other ninety five percent. Do we need thio prioritize what’s mission critical and yes, we can work with out for a time. Yes, how do we determine that? Definitely we talk about that in terms of its not just a knight each decision either because we may think that the emails the most critical thing out there, but development may see the donor system as the most critical out there program might think that the case management system is the most critical out there, so you finance wants their account, they want their accounting system up. Obviously you’ve got to have an order in which you bring these things up. You’re probably not gonna have enough staff for bandwith or, you know, equipment to bring everything back online, so there needs to be and hopefully your executive team would be involved in deciding for the organization what is most critical in what order are you going to bring those things up? And that needs to be part of your d r plan? Because otherwise, if you’re in a disaster scenario, you’re not going to know where to start and there’s going to be a lot of disagreement of who starts where so you guys need to decide on the order, okay, we solve a few minutes left, but what more can we say about d r and related? Back-up that’s not going to wait till i’m back up because i think we could do a little bit in terms of d r i n st key points on backups are check them because a lot of time, yes, monthly or quarterly, at least is anyone looking at your back-up back-up work-life one of the scenarios that we talked about that actually happened to my co speaker, andrew, was that their server room flooded and it hit their razor’s edge server, which is their entire c, m, s, c r, e, m and donorsearch system, and they thought it was backing up, but no one had actually check the backups in the last two months, and it was on, and it was not s o in terms of back-up just typical, you know, pay attention to the maintenance. What do you backing up? Has anyone checked it? And again, if you’re using a manage service provider, make sure if they’re responsible for for looking at your backups of managing them, make sure they’re doing that. You know, double check and make sure that they understand that your backups are critical and they can’t just ignore the alerts about your backups. You know, you don’t want to be in the unpleasant situation of three of our servers just got flooded. We need the data and discover nobody was backing it up. It ain’t exactly okay, all right, anything else, you wanna leave people about back-up before we go to the broader diar? No, i think that’s good for those were the highlights for it. All right, so back to the disaster recovery. What more can we say about that? There are going to be a lot of watches if you’re in a large d our situation. And so one of things we stress is one getting down into the details of your d. Our plan. Before disaster hits. You see, if you’ve never thought about how you’re actually going to do the restores air, actually, how you’re going to be rebuild those servers. You need two ahead of time. A lot of folks never practiced have a fire drill. I hate fire drill, but and you don’t have a live fire drills in this case, it might be a live fire drill. You don’t want to have that, so you should make some effort to practice, even if it’s just something small, you know, trying to restore one server. I mentioned in this session that i was put in a situation years ago at johns hopkins university, where we were required to have verification of live tr practice, so i was put in a room that had a table, a telephone, a server, and we were carrying two laptops and we couldn’t come out of the room, and so we had completely restored our domain. We had a set of backups on the thumb drive and added the second laptop to that domain improve that we had restored the domain, and an independent person that was not connected to our department was monitoring to make sure we had done it, and we had to prove it, and that was an eye opening experience is as experienced as i was doing that i’d never done it live, and it took me three tries to do it so that’s, right? Encourage folks to really try and practice this stuff ahead of time and get down into the you know, the weeds on their on their d our plan and, uh and also to think about it, you weren’t fired because wayne johnson no, no, no, i actually like too much, john soft. No, we we did complete it within the time frame, but we were a little startled when we discovered that we thought we knew how to do it first time out, and we kept making little mistakes. There were two of us and they’re doing it, and we were surprised ourselves that we thought, oh, of course we know this. This is not a problem, but no, we were making little mistakes because we didn’t have the documentation down. A specific is it needed to be. And so that was a very eye opening experience. There’s a couple of their d r gotchas we talked about, which is crossed. People don’t think about the cost ahead of time. How much is going to cost to get you that data back in the instance of my co presenter who had the damaged drives, they weren’t expecting a near ten thousand dollars cost to recover those drives, but that’s what happened when they didn’t have the backups? They had to take those hard drives to a data recovery place, and the price tag was nearly ten thousand dollars. Dealing with insurance is another big one that people don’t think about having to account for all of the equipment that was lost, and dealing with that insurance morass often gets dumped on the auntie department in a small organization. There’s not, you know, a legal department that’s going to deal with that it’s going to be you so to, you know, kind of talk to your insurance provider ahead of time and see what all you have to deal with in a disaster situation. So you don’t get an unpleasant surprise if you’re ever in one a cz well on the insurance topic, just are you covered? Exactly what you think is your equipment covered? And what do you have to do with that? In terms of accounting for it? If you suffer a disaster, you know the gooch is we get so a couple of minutes, if if oh for days. About consciously trying to think about somebody we don’t hold back on non-profit video uh, i think some of the other ones that we covered in their thick wit mint again to the cost, how much is it going to cost you? Two gets new equipment and did you account for that when you were doing your d our plan and a time to recover? A lot of folks don’t understand how long it may take them to do a recovery and also deciding what is important and what is not important, not just in terms of what should be restored in what order, but in terms of practical things, do you really need to restore your domain? Er, or could you just start over from scratch if your domain only contains maybe fifty accounts and doesn’t have any associated servers faster for you to just start over and just recreate the domain immediately? Especially if a lot of your emails in office three, sixty five or google maps, you could reconnect it very quickly. So, you know, thinking about more practical gotsch is like that with that, you should think about have time, you know, obviously it’s that’s the best practice to think of all these details, and we realised folks may not be able to, so we provided someone sheets and some samples of them of just quick, yes or no questions and thinking this through and things to think about and where will we that is not notice provoc radio has a professional sound i don’t know about ntcdinosaur ten, but that was a way over there. They’re on their own. They can come to us for expertise if they if they need to, but, um, see, now i messed myself up because i ask you about something, but we were just talking about how much, how long will actually take you to recover things and whether or not you should practically skipped recovering something because it might be faster to rebuild it. Okay, i have a follow up to that my smart ass humor, maybe lose it. All right, so why did you leave us with one take away d, r or back-up the session was a little bit misnamed because technically, you’re not going to avoid a disaster. You really can’t. In many cases, you’re not gonna avoid the flood you’re not going to avoid. The earthquake if you’re in that region, so you need to plan on how to deal with it. So it’s more like avoiding avoiding your d are becoming the disaster because you’re not going to avoid the disaster itself, so you might as well plan for it. Outstanding. Thank you very much. Door. Thank you much. Darby america, vice president of technology for lift. This is tony martignetti non-profit radio coverage of ntc non-profit technology conference two thousand fifteen. Thank you so much for being with us. Thank you. Next week it will not be fermentation. If you missed any part of today’s show, i beseech you, find it on tony martignetti dot com. We’re sponsored by pursuing online tools for small and midsize non-profits data driven and technology enabled. And by we be spelling supercool spelling bee fundraisers we b e spelling dot com a creative producers. Claire miree off. Sam liebowitz is the line producer, but he mcardle is our am and fm outreach director. The show’s social media is by susan chavez. And this music is by scott stein be with me next week for non-profit radio big non-profit ideas for the odd learned ninety five percent go out and be great. What’s not to love about non-profit radio tony gets the best guests check this out from seth godin this’s the first revolution since tv nineteen fifty and henry ford nineteen twenty it’s the revolution of our lifetime here’s a smart, simple idea from craigslist founder craig newmark insights orn presentation or anything? People don’t really need the fancy stuff they need something which is simple and fast. When’s the best time to post on facebook facebook’s andrew noise nose at traffic is at an all time hyre on nine a m or eight pm so that’s when you should be posting your most meaningful posts here’s aria finger, ceo of do something dot or ge young people are not going to be involved in social change if it’s boring and they don’t see the impact of what they’re doing. So you got to make it fun and applicable to these young people look so otherwise a fifteen and sixteen year old they have better things to do if they have xbox, they have tv, they have their cell phones me dar is the founder of idealist took two or three years for foundation staff to sort of dane toe add an email address card. It was like it was phone. This email thing is right and that’s why should i give it away? Charles best founded donors choose dot or ge. Somehow they’ve gotten in touch kind of off line as it were. And, uh and and no two exchanges of brownies and visits and physical gift mark echo is the founder and ceo of eco enterprises. You may be wearing his hoodies and shirts. Tony talked to him. Yeah, you know, i just i’m a big believer that’s not what you make in life. It sze you know, tell you make people feel this is public radio host majora carter. Innovation is in the power of understanding that you don’t just do it. You put money on a situation expected to hell. You put money in a situation and invested and expected to grow and savvy advice for success from eric sabiston. What separates those who achieve from those who do not is in direct proportion to one’s ability to ask others for help. The smartest experts and leading thinkers air on tony martignetti non-profit radio big non-profit ideas for the other ninety five percent.

Nonprofit Radio for May 1, 2015: Multichannel Storytelling & Your DR Plan

Big Nonprofit Ideas for the Other 95%

Our Sponsor:

Opportunity Collaboration: This working meeting on poverty reduction is unlike any other event you have attended. No plenary speeches, no panels, no PowerPoints. I was there last year and I’m going this year. It will ruin you for every other conference! October 11-16, Ixtapa, Mexico.

Sign-up for show alerts!

Listen Live or Archive:

 

My Guests:

Jereme Bivens and Megan AnhaltMultichannel Storytelling

Once you have the best stories, make the most of them across the web, social media and email. Jereme Bivins is digital media manager for The Rockefeller Foundation and Megan Anhalt is strategy director at Purpose. We talked at the Nonprofit Technology Conference.

 

 

Dar Veverka: Your DR Plan

Disaster recovery: Ignore it at your own peril. What belongs in your DR plan? Dar Veverka is vice president of technology for LIFT. This is also from NTC.

 

 

 


Top Trends. Sound Advice. Lively Conversation.

You’re on the air and on target as I delve into the big issues facing your nonprofit—and your career.

If you have big dreams but an average budget, tune in to Tony Martignetti Nonprofit Radio.

I interview the best in the business on every topic from board relations, fundraising, social media and compliance, to technology, accounting, volunteer management, finance, marketing and beyond. Always with you in mind.

Sign-up for show alerts!

Sponsored by:

oc_wb_logo_banner-resized
View Full Transcript

Transcript for 238_tony_martignetti_nonprofit_radio_20150501.mp3

Processed on: 2018-11-11T23:19:00.251Z
S3 bucket containing transcription results: transcript.results
Link to bucket: s3.console.aws.amazon.com/s3/buckets/transcript.results
Path to JSON: 2015…05…238_tony_martignetti_nonprofit_radio_20150501.mp3.842471660.json
Path to text: transcripts/2015/05/238_tony_martignetti_nonprofit_radio_20150501.txt

Hello and welcome to tony martignetti non-profit radio big non-profit ideas for the other ninety five percent on your aptly named host oh, i’m glad you’re with me. I’d be stricken with ataxia telly inject asia if i inherited the mere notion that you missed today’s show multi-channel storytelling once you have the best stories, make the most of them across the web, social media and e mail. Jeremy bivens is digital media manager for the rockefeller foundation and meghan anhalt is strategy director at purpose. We talked at the non-profit technology conference and your d our plan disaster recovery. Ignore it at your own peril. What belongs in your d our plan darva barca is vice president of technology for lift that is also from on tony’s take two thank you, responsive by opportunity collaboration with working meeting on poverty reduction that will ruin you for every other conference. Here’s our first ntcdinosaur today’s show on multi-channel storytelling welcome to tony martignetti non-profit radio coverage of ntc twenty fifteen, the non-profit technology conference we are in austin, texas, at the austin convention center and my guests are jeremy bivens and meghan and halt they’re seminar topic is multi-channel storytelling for social impact, jeremy is the digital media manager for the rockefeller foundation, and megan and halt is strategy director purpose. Jeremy meghan, welcome. Thank you, let’s. Start with start with jeremy bivens. Why is storytelling so important? Storytelling is important because we have a lot of social sector organizations that are out in the field collecting stories from their impact working with communities around the world and storytelling helps catalyze people to action, to donate money, to volunteer, to help communities so it’s really important that we capture those stories, that we share them to maximize impact. And why your storytelling so much better than some other forms of content that we have a story telling storytelling interacts this in a different way. You had trouble with storytelling, interactive storytelling interacts with with us in a different way, it kind of tugs at the heartstrings and and inspires us to take action. It educates us, but it it really it motivates us to do more than just doing. Ah report let’s say an eighty page report full of statistics and fax is great, but if it doesn’t, if it doesnt make action that it’s not doing its job and stories can help help bridge that gap. Emotion. Yeah, you want anything? I mean, i think, like, what is really incredible powerful about stories is they do have that human connection they are able to cut through, you know, different very complicated con content or other types of content that are really hard to really connect with on be able to really tie into that emotional human connection. So being able to have that authentic experience where it really motivates you and inspires you to want to do something and that’s where for the work that we do around really driving impact and driving action, it could be a really powerful motivator. Call megan, remember to stay close to the mic when you’re when you’re talking ok? Yeah, no problem. All right, thank you, megan. How do we find the people to tell the stories that we recruit the right ones? Yeah. I mean, i think it goes down, teo really being clear and defining what your goals are for the impact that you want to have in the world and then identifying the people that can be really powerful storytellers for that, that goal. So an example, i talked about in our session yesterday is on this organization called the syria campaign identified this brilliant group of men on the ground in syria who were first responders in the syria crisis. Ah, and they called the white helmets, and they were really powerful story teller because they were sort of be able to bring this like, hopeful element to the work that was happening on the ground, and so it allows people to not feel overwhelmed or sad or feel like there’s, not a hope in what can you can accomplish, and so they’re become really strong advocates for the work that they’re doing so that you can really inspire people to want to take action and not feel like there’s nothing that can happen, teo, be able to have that impact, okay, but within our organization’s jeremy, how do we how do we find the right people? How do you find the right people? Tell story. All the stories you know, storytelling is really a collaborative effort. It’s not just the responsibility for the marketing of the communications team it’s, about everybody working together to define what those stories are. So people that are out in the field collecting photos, collecting quotes, it’s about bringing back things that tell a greater story arc the greater narrative of what your organization is trying to accomplish. So that’s really a joint effort? What if somebody’s good? You believe they have great stuff to share stories to share, but they’re they’re reluctant. I don’t want to be in front of a mike even if it’s audio only i certainly don’t want to do a camera. How do we get started to cajole them? Teo, help us out. So when it comes to storytelling, especially our reluctant storytellers a lot of times a laying that fear is maybe just in baby steps it’s working with them to produce blawg posts instead of going right on camera it’s working with them in media training, it’s working with them in speech development. But oftentimes those daunting task is sitting down and saying, share a story with me because it doesn’t give anybody charlie that place that’s not too helpful, right? Tell me a story exactly. About what? Why who’s listening, right? So instead, really the best way to go about it. Say you’re going to the field today? Can you bring back one quote? From one of the teachers that was helping a student in your in your tutoring center. Can you bring back one photo of the well that we helped dig in sub saharan africa? Something like that. So it really sets the stage say, oh, of course i could bring back one photo. Yeah, one quote, i can definitely get on board with that, and it helps ease them into the process of great stories, and then maybe they’ll be willing to provide some narrative for contacts to that photo or that quote, right once you bring them into the process and they feel like they’re a part of it, they feel like they’re owning it will get more comfortable sharing stories. Okay? Bacon you got any ideas for? Ah, people who are reluctant, uh, we’re reluctant contributors. Yeah, i mean, i think, like, really, as jeremy was saying, starting first by getting them to just ride out the different things that they think that are relevant to the work that you’re doing on being able to sort of break that down for them in a way. That’s really simple s o that they don’t necessarily have to go on camera. Or be sort of the actual microphone for the story itself. But as jamie was saying, being able to, like, break that down through photos to be able to tell the story, sort of on their behalf, okay, okay, how about, uh, once we’re in in production, whether it’s you handed them a iphone or you’re in a studio, maybe more formally, what advice do you have there? In what way? Buy-in coaching them in getting them? Well, presumably there already over there, their reluctance, but maybe now that maybe they stage fright, they were they were willing coming a driving in, they were fine and walking in the door, but now there’s a mike in front of them? Yeah, or in, you know, in coaching, yeah, how do we help them out? I think like one of the key element there is just staying authentic and being true to who you are in your own experience and not feeling sort of like that you have to be over coached or over polished because what we’ve seen in the work that we’ve done, purposes that people really connect with that authentic experience in that raw moment of being able to sort of share in your own voice, that experience that you’ve had, what what do you think is a good story? Maybe i should ask you that first we’ll get around, i get around the good questions. What, what? What? What makes a good story? I think, well, we’ve seen a lot of different elements that really drive really powerful stories, particularly ones that are really share a bowl and connect with a lot of people, so one of those elements is people really like to be surprised they like to hear something that they haven’t heard before. They also really like having that human connection. So as i said, that, like authentic, raw, human, honest moment could be really powerful, with people also being a little bit of paying attention to the right place and the right time, and i don’t mean that sort of by luck only, but also paying attention to what is happening in the news cycle, what people are already talking about events that are happening and sort of what’s already getting attention and being able tio leverage those moments as well, toe add a new element to it, that sort of hook news hook. Something talking about jeremy got more advice, anything you want, teo, that hits the nail on the head, being contextual and being relevant, somebody can identify with your story, they’re going to be more willing to share it. They’re going to be more willing to understand and they’re going to be more willing to take action. Okay, okay, and we’re going to move on because i don’t want to overlap too much with storytelling, storytelling, conversation i had with someone a panel on an earlier earlier spot, but you have some you have resource is that people can use sites non-profits can use to help make them better storyteller so maybe we could spend a good amount of time. We’re not near the end. I’m not i’m not trying to wrap up. We’re nowhere near the end, but i like to focus on something that you have to add to the previous conversation so we don’t do to that of the same let’s. Spend some time on these resource is sites aps whatever let’s get started. Yeah, so the rockefeller foundation has invested some time and resources into this and partnership with our lead grantee, hataway communications and plenty of other people who have provided us input and we wanted to know what what was the real challenge for organizations to telling great stories. And so we had done two things. The first thing we did was we created a report that just kind of let you analyze the landscape of the field what’s available out there for resource is what’s available out there for tools. What are people saying? What our organizations saying that there were issues are what they’re really succeeding? Well, with and from that report and from all of that feedback wave created a platform called hatch for good and hatch for good identifies those five those five areas strategy capacity, content platforms and evaluation, and it helps organizations go through each of those pieces step by step so you can identify what your strategy is. You can go through your audiences with sort of content you should be producing, how you measure that what platforms are out there and available to you, plus that it incorporates thought pieces from thought leaders in the in the space that are sharing excellent stories, how they answer those questions, the types of campaigns that they’re running things like that so it gives you some inspiration, and also a framework to go by is, uh, for the number four it’s fo r hatch fo r good dot or ge. Okay, you’re tuned to non-profit radio. Tony martignetti also hosts a podcast for the chronicle of philanthropy. Fund-raising fundamentals is a quick ten minute burst of fund-raising insights, published once a month. Tony’s guests are expert in crowdfunding, mobile giving event fund-raising direct mail and donor cultivation. Really, all the fund-raising issues that make you wonder, am i doing this right? Is there a better way there is? Find the fund-raising fundamentals archive it. Tony martignetti dot com that’s marketmesuite n e t t i remember there’s, a g before the end, thousands of listeners have subscribed on itunes. You can also learn maura, the chronicle website, philanthropy dot com fund-raising fundamentals the better way. Dahna that report that you mentioned that looked at what makes what keeps non-profits from being good storytellers, what lessons were there? Well, that was that was really focusing on those five pillows, and people were saying, you know, we don’t have the strategy behind it or we’re collecting a lot of stories, we’re sharing them, but we’re not getting a lot of feedback on them, so it was it was that mix of strategy capacity we don’t have enough people on staff, we don’t have the buy-in from our gdpr board, we don’t have the right content, that kind of thing, i say. All right, meghan another you have another resource that you can share? Well, i actually recently was involved in a purpose, the organization that i work for drafting a guide to digital to crafting digital stories, particularly with a lens for young people who are interested in sort of telling your story. You’re starting their own non-profits being able to bring sort of new perspectives to that on dh. That resource, which is an analog actually printed out guide that you can download it’s open source. You confined it purpose dot com okay. And what is going? To share a little more detail, what we’ll, what we’ll find there? Yeah, i mean it’s broken up into two parts, so the first part is really about identifying sort of the way to tell your story, really breaking down and thinking about the different elements of the story, which are very much in line with the resources that jeremy was talking about as well. S o thinking about things like goals, we talk a lot about a crisis, unity profess, which is really identifying a crisis that’s happening, but instead of sort of feeling overwhelmed and that you can’t there’s no hope coming out of that crisis, really turning that into an opportunity on being able to provide that hope in that story. So really thinking through that, and then it also talks about different platforms that you can use and how you can build those stories because a lot of times people think of stories justice being sort of full written out story. So blog’s are articles or sort of long form posts on, and we really think of stories as every little piece could be a story. So a facebook image that you post online with you know one sentence of content can be in a story and of its sound. Yeah, what are what are we talking about? His other platforms for storytelling before we get now, are there more resource is besides those two? Or there are there will be those of the crux, the resources you confined other other other places out there for block post that go through great detail. We were talking about this yesterday purpose has some fantastic campaigns to look at. Causevox has been doing some great stuff in storytelling big duck also has some resource is but a lot of what we’re doing now is taking what we see is the best of the best, and we’re trying to to get off their permission to put it up on hatch for good dot org’s so people can come and find one place where they confined all these great resources from all their best organizations that are doing the best storytelling. Let’s, let’s talk then, about some of the use of platforms. I mean, interesting that we can conceive of a picture in a sentence or two as storytelling nothing. Most people are thinking that way, so clearly is there? More that we should be thinking about more broadly on let’s just on facebook, let’s start there, is there? Yeah, i mean, i think there’s so many different ways you can tell a story on facebook these days. I mean, particularly with, like, you know, the native in beds of video now is getting really prioritized on facebook, so being able to create those videos, obviously there’s your stories now, you see a lot of those videos without the audio playing, so i think there’s a real opportunity there, as well as your people are scrolling through their news feed to be able to get that story without having the audio itself. But also, i mean, you see this a lot through images on facebook and there’s so many different types of images you can create that tell a story. I mean, a lot of people do like this or that, which is, you know, before and after cause and effect type of image, you also get really, like, thought provoking images, so people, images that really require people to think about an issue in a new way in one thing that you i’ve seen a lot particularly lately of on facebook is really just a photo or a snapshot of an individual on then really going behind the scenes to tell that person story. So it’s like here’s joe, who is an iraq war veteran, and then going into something related to the issue of veterans affairs. Ah, and so i think that is one element that could be really powerful was story time, okay? Anything else you want to add? Facebook? Jeremy, before we move off that platform, not not specifically to facebook? No, okay, we would like to go next. Well, i’m just thinking in terms of content like megan was saying photos and videos and different statistics and things like that a lot of times we received one piece or one piece of long form, like a publication or an essay or something like that has a whole bunch of different assets that are already too tied to it. So it’s about taking that piece of content and breaking it up so people have twenty ways into it instead of just posting your block post to facebook it’s about grabbing that photo and taking like a quote and saying, this is the quote, this is the photo and letting your audience engaged that that way, maybe there’s a link back to the block, maybe there’s a statistic that you khun tweet out with that video underneath it they’re different ways you can package that content that they comptel individual stories over the same narrative, the same longer narrative. Very interesting, alright repurpose ing dividing up helps helps increase your capacity, but it also helps give your story cem cem length, and it also makes sure that more people are consuming it. Then just package again into one giant report also also makes the storytelling craft less daunting. Yeah, you’ve got a couple of good stories that can be divided up. You could have you could end up with thirty or forty components across all the different channel. Exactly. Okay, excellent. Excellent. Should we wait? Talk specifically about twitter? You mean you know we’ve hit it sort of tangentially we haven’t named it but certainly could do what you just described on twitter anything mohr there’s now video on twitter anything mohr anyone add? Besides what has already been suggested twitter specific? Yeah, i mean, i think another thing twitter has done recently as well as images. So images are definitely king in the twitter feed these days, and so not just relying on that hundred forty characters but also being able to incorporate an image much like what worked really well on facebook. So being able to have these graphics that can have quotes or have the sort of bite-sized element that people can retweet and share, i think really thinking about like, what is that bite-sized element that could be easily consumable because we do that naturally, anyway, i mean, even if we’re scanning a long form content, we’re looking at the headlines were looking in the margins for sort of the key takeaways on twitter really allows you to pull out those key elements on and create bite-sized terrible content that’s, easily consumable and allows people to sort of share one keep perspective and on building on that, you could also you could also ask questions that on twitter and then build blackbaud post based on that feedback it’s a really quick way to the longer form content using short snippets or maybe a link to a survey if you want to ask more than just one question, yeah, if you could do a storify we actually recently the beginning of the year, we ask people with the what their big idea was for twenty fifteen what was the big social impact idea of twenty, fifteen? And so a handful of our staff leading up to it just tweeted our responses to that question, and then we embedded it into the blood post and people could comment back and say, this is my idea for twenty fifteen or they would respond over twitter and they would put that up there, and then we shared it on facebook and they would add it to the comments so they would reply directly back to twitter again on the comments on the block it takes again that one concept of an ideal what’s your big idea for twenty fifteen and it turns it into something that’s cross platform. Okay, well, we still have a few more minutes left together. What we could talk about some more platforms. We haven’t touched on instagram wherever you want to go, but what else will she got? I mean, in terms of the platforms, the platforms are you know, wherever your audience is, maybe if you’re dealing with youth, you don’t. Want to be on facebook anymore? Maybe you’re looking at snapchat how you, how you actually use that? Maybe there’s an entire generation of baby boomers that are now embracing facebook, so a lot of organizations that might do service baby boomers should be thinking about what’s our facebook strategy for our content. So the platform is really against whatever you set your goals to be again on your stories. Now, do you want to be talking to you? Let’s say little about snapchat? We don’t talk about that too much on show how much you use that for, for storytelling and again, this is this is for people or organizations that want to be talking to teenagers basically right? But if if that’s your objective, how could you be using snapchat wisely for stories? Yeah, you mean in snapchat? Because of the nature of the the disappearing nature of their work? It’s a great way to share things that might be kind of taboo i could see it being used for planned parenthood let’s say i could see them using it to great effect, convert convening ideas to a younger audience that maybe they would be too embarrassed to. Be looking up online themselves or to be looking at content that would stay on their phones. They have this is ah, it’d better information that you can see that disappears or a meeting date or time, things like that you can communicate directly out to your audience that’s temporary doesn’t have to be there for him. Okay, one example of an organization that i think used snapchat incredibly well, eyes do something dot or ge, they’ve been on it for quite some time now and do some really interesting things. So if anyone out there is really interested in seeing how you could engage teens in that in that snapchat way, they’re great organization to check out and you’re not the first guest in these two days to recommend recommend do something for talking, teo, i think they’re they’re targets like fifteen to twenty five thirteen to twenty five some like that when they do great work. Yeah, yeah, i’ve had aria finger on the show talking about do something and i’m also talking about t m i, uh, theo of their consulting spinoff? Yeah, i could do something about it also neo-sage let’s. See? Okay, we got still got a couple minutes where where would like to go with this? You you talked for ninety minutes on storytelling, so i know that i haven’t covered everything. What else more is more than a share. I mean, what else more is there to share about storytelling? I you know, i think a lot of organizations don’t think their storytelling organizations i think that a lot of people would probably listen to this and they would say, well, that’s, great, but that’s not for me, i don’t do that kind of work, and i think that that’s probably ninety nine percent of the time not even remotely true, that it just takes it takes a moment to step back and consider how your work is affecting people. So even if you’re not doing direct service, it’s, the work that you’re doing, how how, how you’re helping those organizations access it right? So it’s either on an individual level or an organizational level. How are you making people’s lives easier? How are you changing things for the better? And if you take a step back and identify what that is and start mapping out what that framework looks like, you’re going to find a place you can tell a story, you know, meghan, in your work, have you seen organizations that felt it wasn’t for them? It’s just they didn’t have anything t tell. Yeah, well, i think a lot of times people think that they don’t necessarily have they’re not, you know, maybe doing direct work on the ground or feel like they don’t have access to those stories that they traditionally think of as the ones that are incredibly powerful. But i mean, in the work that we do and particularly when you’re an organization seeking to have impact, one of the most powerful ways to show impact is through the stories of the impact that you’re having on, and that doesn’t always have to be work on the ground. I mean, it could be working with the siri’s of organizations, but i also have a social purpose and being able to help those organizations, maybe it’s, a young entrepreneur who just started a new organization, change the world coming out of school, being able to tell that story of how you were able to help that individual can also be really powerful. I mean, you see a lot. Of times who we do, you know, an annual reports are report backs for donors and that’s a storytelling i’m being able to find the right way, tio sure, that message can be key. So i think all of this applies for that that as well, yeah, ok, so do cement prospection. I mean, you’re a charity, you’re you have a charitable mission by design and definition. Who were you? Were you impacting? You got to be helping somebody and those somebody’s i can talk to you. Okay? Absolutely. I’m going to say it again myself. A couple more minutes share some more about whether we’ve even if we we’ve covered it, but maybe we didn’t cover enough detail here’s some more about stories. One of the points we went over in the session was this idea of the forty sixty rule that i borrowed from garth more from the one campaign and that’s about spending only forty percent of your time producing content and sixty percent of your time marketing it. So when you’re making that block post, no perfect is the enemy of good making sure that it’s good enough to go out, but thinking about who should see this block post who should see it and what do i want them to dio and then going to those places with, you know, whatever that content might be, because spending more time finding the right people that should be consuming it and should be sharing it and should be adding to it is ultimately more fruitful when you’re looking at your your analytics and your feedback. So you’re not just sending a story out into the wind and hoping that it catches on, you know, it’s got no value, then back in the morning it had anything to that? Yeah, i mean, i would say a lot of times, people sort of sometimes have quotas for certain number stories or start number of videos that they want to get out each year, and i think at the end of the day, the most important thing with any story they’re trying to tell is the story itself and that it’s compelling and that its strategic on and you’re creating that story for a reason and not just creating a video for videos sake on dh that’s really what’s going to drive the success of that piece of content in connecting with people is really having something powerful that people can connect with first on then thinking about sort of how you can use that to achieve your goals that you have for your organization on be able to build that impact. And then, as jeremy was saying earlier, be able to break that down into pieces and being able to use that story in a lot of different ways across different platforms to achieve your goals. Can we measure the r o i of storytelling? Absolutely. But you have to start with the strategy first, because maybe the roo i’ve storytelling is we want to raise more money, and we want our donors to being more involved. We want our board to be more involved. We need more volunteers. So, starting with your strategy and thinking about what your goals would be, why are we doing? Why are we still telling story exactly what i mean? What were we trying to do with these? Yeah. Okay. And then and then measure from there. Okay. Yeah. Purpose. We talk a lot about signaling and confirming that tricks. So a lot of times, people would be like, oh, great, this video got a million views? That was what that is, what we would consider a signaling metrics, so it shows the sort of a way of attention being brought to an issue, but it isn’t necessarily proving that doesn’t mean i can’t exactly uses worthless yeah, so you keep that in the category of could we keep that the category of, say, signaling metrics? But then you still have to pay attention to the broader change that you’re trying to have in the world and a million views on a video might be one thing, but a year from then, you might see some real impact on an issue that you’re sort of pushing through legislatively, and that video is all about that. And so that’s, where you’re able to sort of confirm that impact, ultimately it doesn’t happen right away. I mean, a lot of times when you’re tracking impact four stories, it takes a lot of time that speaks to a swell looking at the long form are the long tail of storytelling and that you don’t just want to produce that video, send it out there and hope open the best they need to start thinking about what’s. The game plan for this how we’re going to get this in front of the right people? Yeah, i mean, a classic example of this, of course, is in the marriage equality shift that has happened in the us over the past, you know, decades really on really that started with the power of stories. I mean, being able to connect with people on these universal issues of love, inequality on overtime, being able to sort of really connect with people on that issue and be ableto ultimately move the needle. All right? We’re gonna leave it there. Thank you very much. Thank you very much. All right. Jeremy bivens, digital media media manager for the rockefeller foundation and meghan and halt strategy director for purpose. My pleasure. This is tony martignetti non-profit radio coverage of and t c twenty fifteen the non-profit technology conference. Thank you so much for being with us. Tony’s. Take two and your d are planned coming up first opportunity collaboration. It’s a week long unconference in x top of mexico around poverty reduction throughout the world. This really is an amazing experience. There are no keynotes, there’s, no power points you’re always sitting in. Circles there’s lots of free time for making valuable friends let lasting connections new friends that can help you reduce eliminate poverty in whatever form you’re working it’s in october i was there last year. I’m going again this year if your work is at all related to poverty reduction, check it out. Opportunity collaboration, dot net, thank you for making it a double honor. I was honored last thursday, the twenty third at the hermandad gala and to make it a double honor. You were with me and i’m very grateful non-profit radio fans really stepped up and together we raised nearly five thousand dollars to save lives with water projects in rural dominican republic. The whole event raised over twenty five thousand dollars and i thank you. Thank you very much for being with me. My video thanks. Is that tony martignetti dot com that is tony’s take two for friday, first of may seventeenth show of the year here’s our next ntcdinosaur view on your disaster recovery plan with dar veverka welcome to tony martignetti non-profit radio coverage of ntc twenty fifteen the non-profit technology conference we’re in day two we’re in austin, texas, at the convention. Center and my guest is dar vivir ca she’s vice president of technology for lift a lefty, and her workshop topic is avoiding disaster, a practical guide for backup systems and disaster recovery planning. Dar welcome, thank you very much. Good to be here. It’s. A pleasure to have you this day two, we’re highlighting one swag item at and ntc per for interview and, uh, i have a double chip biscotti from a sputnik moment. The hashtag is hashtag is sputnik smiles and i’m told that the glasses go with the biscotti. So this is essential. This is this interview’s swag moment. Thank you very much. Sputnik smiles and it goes into the goes into the swag collection. There it is. Okay, door. Um, we need to know some ah, little basic turn. Well, you know what? Before we even get into why is disaster recovery and the related and included back-up so, um, i don’t know if it’s just for gotten ignored, not done. Well, what inspired the session is a organization i used to work for. We were required by auditors to do a disaster recovery plans. So when it came time for the annual audit, i got out the current disaster recovery plan. It went all right, i’m going to go ahead and update this, and when i discovered want to read the plan was there were servers that were eight years gone for last eight years server and reading the planet was very clear that what the previous person had done was simply changed the date and update the plan for auditors. And as i thought about it and talk to other people, i found that that actually happens a lot people. It’s d r is sort of that thing they don’t have time for because no one ever thinks it’ll happen to them, so you push it off and you push it off, and you either just download the template, you know, a template off the internet, and you slap a date on it and basically fill it out just for the auditors. But a lot of organizations never actually think through their disaster recovery, they don’t get into the details, they don’t worry about it, and then when a disaster actually happens to them, they’re sort of stuck. You don’t have a plan that i don’t have a functioning crush on, and they’ve never tried it out, so that was what inspired the session, and as we dug into it, we we tried to give the thirty thousand foot view because disaster it cover, you know, there’s an entire industry, the deals with technology, disaster recovery. You can spend days on this topic, and obviously we didn’t have days. We had a ninety minute session, so we tried to give the thirty thousand foot view of the practical items you need to pay attention to if you’re not confident in your organisation’s d our plan, if you don’t have a d r plan or if you do and you really don’t, you know, you think it really needs an overhaul that sort of the top ten of items of what you should really be looking at when you’re dealing with disaster recovering backups. And we tried to give some several practical examples myself and the other speaker and andrew, who could not make it this morning of disasters we’ve had to deal with as well as other well known ones. Yeah, okay. Do we need some basic language? All right. Before we get into the d r disaster recovery topic short jr is one of them disaster recovers, often referred to his d r it’s often spoken about in terms of business continuity or bc, which is sort of the larger plan for the entire organisation. Should’ve disaster strike there’s. You know, there’s very d are specific things such as our poet recovery point objective that we could talk about your rto, which is recovery time objective, there’s very specific language like that or disasters it’s usually just referred to d ours. So whenever we say d arts disaster recovery okay, we’ll see if we get into those eyes and i could explain this week. Okay, um, all right. So clearly we should have a disaster recovery written, just recovery plan. Even if we’re an organization that small enough that doesn’t have an annual audit. We still should have something in place. Yes. Okay. What belongs in our day? Our plan top ten things. You need a contact list for your team. So if you have a top ten of the d r i do. Of what should your plan d our plan. You know, it could be anything from a five page outline that just covers the basics and in in our sessions slides, which i’ve posted in the ntc library, gives it some good resource is for doing a d our plan or it could be a you know, a huge hundred page document covers absolutely every aspect of business continuity or something in between it’s going very by organization, and the reality is, if you’re a small organisation with a small team, you might only be able to do the five page outline but that’s better than nothing that’s better than no d our plan or a d r plan that realistically hasn’t been updated in the last ten years, but i would say, you know, the top ten you really should have in your day. Our plan is number one, a contact list for your team members. What is the contact for your team, folks, your business continuity folks, if you normally would get that out of your email and you’re in a disastrous situation, you know you can’t get to your email or, you know, like we’re ever going through, and i want listeners to know that she’s doing this without notes, i it seems very confident that she’s got hopefully i’ve ever altum in-kind get seven out. Of seven or eight of ten will be ecstatic, but so continue. Oh, but i want to say, yeah, as we’re going through, consider two organizations that may not have someone devoted to it correctly is our listeners are small and midsize non-profits right? They very, very well just all be outsourced or it falls on the executive director’s desk. Excellent point. Would you cover that in the session? So to finish at the top ten contact list, three team members contact list for your vendors, a call tree and some sort of communications. How do you tell your organization and your members that you’ve had a disaster? Either your servers have gone down, your pipes of burst and your communications are underwater? How do you do that? What is your network look like? So network diagram process? Outline how you’re actually going to do your disaster recovery a timeline? How long do you expect these activities to take before you? Khun b live again, a list of systems and applications that you’re going to recover if you’re a large enough or gore you can afford a hot site was called a hot or warm site where you can immediately. Switch over two other equipment. You know information about that. You’d need that to start your recovery. And then also information about your backups. You know, who’s got your back ups. What system are you using? How do you, you know? Get those back. So those air sort of like the top ten things or d our plan should have. Alright, let’s dive into the the process. Okay? A bit is that intrigues me, bond. Hopefully listeners? I think so. I think i have a fare beat on what’s. Interesting. I hope i do. Um, yeah. What? How do we start to think about what our dear process should be? First, you have to think about what all could be a disaster for your organization. A lot of people think about things, you know, earthquakes, hurricane, sandy, hurricane katrina. But it could also be water pipes bursting in your building. That is one of the most common thing if your server is not properly protected. Which a lot of a lot of stuck in closets. Ah, dripping pipe water. We call those water events. And that seems to be the most common thing. Departments encounter is leaking pipes in the building or some sort of a flooding situation. But it could also be an elektronik disaster. Such, i’ve worked at an organization that underwent what’s called a ddos attack, which is a distributed denial of service. It took out our entire web presence because malicious hacker hacker went after that’s where there’s millions of right network and they just flood your network seconds you’re overloaded and yeah, and that’s a disaster situation. So one why would they attack like that? Why wasn’t non-profit attack malicious? The cp dot organ are attacked out with avon marchenese travon martin decision. Folks attacked our petition site way. We were able to get it back online, but for a couple of hours. Yeah, we were off line. And that could be considered a disaster situation. For sure. Yeah. How do you help us think through what potential disasters are not even identify them all i think about what could affect your or what you wear. You vulnerable? Some of the things we talked about in the session and we’ll think about it. How would you get back online if the’s various things happen to you are your are your services sort of in the cloud do you have servers on site and start there when thinking about your process is, what would you have to recover if these various scenarios affected you or with these various scenarios? Scenarios affect you if your website is completely outsourced to a vendor that has de dos protection. Okay, that’s not a scenario you have to worry about so kind of analyze it and every organs going to be different. You know, if you live on the west coast, you’re probably concerned more about earthquakes than other regions. So it’s it’s going to vary for each organization, what sort of disaster you’re going to be worried about? And then you start getting down into the practical nuts and bolts in terms of who are your disaster recovery people, who’s your team, if you’re really small lorry, that might just be you or as you mentioned before, if you’re using outsourced, manage service provider and your vendors responsible for that, make sure your vendor has a d our plan for you. Ah lot of folks just assume your vendors taking care of that, but when it comes right down to it, do they actually have d our experience can they recover your items actually sit down and have that conversation because so many of the small org’s, as you pointed out, do youse outsourced thes days and there’s there’s a lot of manage service providers that specialized in non-profit, but you need to have that conversation. Don’t wait till you’re under a disaster scenario to discover that groups they don’t actually have that experience have that conversation ahead of time. What else belongs in our process? Outlined in your process? Latto outline if you’ve got a another site either a cold, a warmer hot site or if your stuff is based in the cloud, where would you recover to the outside is some place you go to a different drink, cold water or hot? Sure cold site would be where you’ve got another location. Let’s say you have a dozen sir servers at your location, and in the case of, you know, your building being inaccessible or underwater. A cold site would be where you’ve got another location you could go to, but you don’t really have any equipment stage there, but it is another location you can begin operations out if that’s a cold sight there’s nothing ready. To go, but you’ve got a sight ah, warm site would be where you sort of have a skeletal equipment there, it’s far less capacity than you’re currently at, but you’ve got something there it’s not live, but you got stuff ready to go that you can restore to and get going. And a hot site is where you can flip over immediately. Your live replicating to somewhere else, it’s ready to go? It might not be full capacity, so it might not have, you know, full blown data line size that you’re used to might not have your full range of service, but it is live and you could switch over near instantaneously. That’s a hot site, ok, eso you’d want that in your process and you’re going to want to think about what are you restoring and that’s where we get into the backups? What comes first and that’s, where you start getting into terms such as recovery point objective and recovery time objective those air to very common d our terms recovery time is how far back are you recovering too? And what does that mean for each system? So if it’s your donorsearch system that’s probably fairly critical. You want a recent restore of that? If it’s a system that doesn’t change very much, maybe a week ago restores okay for that sorry that’s recovery point objective recovery time objective is how long does it take you to get back online after a disaster? You know, ifyou’ve got to download your data from an external source. Has anyone thought about how long that’s going to take you to get the data back? Is it going to take you fifteen hours or three days? So it’s in a lot of folks don’t think about that ahead of time, they just go. Oh, you know, we’ll we’ll pull it back down if we have a disaster, but they don’t think about instead of their nice normal data communications, they’re going to be on a tiny d s l line trying to pull down one hundred fifty gigs of information and it’s going to take a week to get it back down. I have to say you’re very good about explaining terms and thank you, proper radio. We have jargon jail? Yes, we try not teo transcend. You haven’t transgressed cause your immediate about explaining exactly what recovery point. River and recovery time objectives are it could be very confusing. You know, if you don’t understand the terms in tech, you can be confusing what folks are talking about, and that was one of the focuses of our station session is making it less confusing and being very practical, practical about what you can or cannot do. And if folks go and look at our slides, they’ll see on several of the items we did a good better best, and we tried to talk about that all throughout the session because we realized again for a small ork or, you know, even a large order that just doesn’t have the resources to devote to it. You might not be able to do best practice, but you could at least try a good practice that would be better than nothing. And then so we do a good, better best for each each type of thing like what does a good d our plan look like? Versace best day our plan and at least try and get to that good, because at least you’ll have something and it could be a continuum where you try and improve it along the way. But you got to start somewhere. It’s. Better than just ignoring it, which is what happens at a lot of places. Like what you’re hearing a non-profit radio tony’s got more on youtube, you’ll find clips from stand up comedy tv spots and exclusive interviews catch guests like seth gordon, craig newmark, the founder of craigslist marquis of eco enterprises, charles best from donors choose dot org’s aria finger do something that worked and they only levine from new york universities heimans center on philantech tony tweets to he finds the best content from the most knowledgeable, interesting people in and around non-profits to share on his stream. If you have valuable info, he wants to re tweet you during the show. You can join the conversation on twitter using hashtag non-profit radio twitter is an easy way to reach tony he’s at tony martignetti narasimhan t i g e n e t t i remember there’s a g before the end he hosts a podcast for the chronicle of philanthropy fund-raising fundamentals is a short monthly show devoted to getting over your fund-raising hartals just like non-profit radio, toni talks to leading thinkers, experts and cool people with great ideas. As one fan said, tony picks their brains and i don’t have to leave my office fund-raising fundamentals was recently dubbed the most helpful non-profit podcast you have ever heard, you can also join the conversation on facebook, where you can ask questions before or after the show. The guests are there, too. Get insider show alerts by email, tony tells you who’s on each week and always includes link so that you can contact guests directly. To sign up, visit the facebook page for tony martignetti dot com. Lively conversation, top trends and sound advice. That’s. Tony martignetti non-profit radio. And i’m lawrence paige nani, author off the non-profit fund-raising solution. Oppcoll do we need to prioritize what what’s mission critical and, yes, we can work with out for a time? Yes, how do we determine that? Definitely we talk about that in terms of its not just a knight each decision either because we may think that the emails the most critical thing out there but development may see the donor system as the most critical out there program might think that the case management system is the most critical out there, so you finance wants their account, they want their accounting system up. Obviously you’ve got to have an order in which you bring these things up. You’re probably not gonna have enough staff for bandwith or, you know, equipment to bring everything back online, so there needs to be and hopefully your executive team would be involved in deciding for the organization what is most critical in what order are you going to bring those things up? And that needs to be part of your d r plan? Because otherwise, if you’re in a disaster scenario, you’re not going to know where to start and there’s going to be a lot of disagreement of who starts where so you guys need to decide on the order, okay, we solve a few minutes left, but what more? What about d r and related back-up that’s not going to wait till i’m back up because i think we could do a little bit in terms of d r i would say the key points on backups are check them because a lot of time, yes, monthly or quarterly, at least is anyone looking at your back-up back-up work-life one of the scenarios that we talked about that actually happened to my co speaker, andrew, was that their server room flooded and it hit their razor’s edge server, which is their entire c, m, s, c r, e, m and donorsearch system, and they thought it was backing up, but no one had actually check the backups in the last two months, and it was on, and it was not s o in terms of back-up just typical, you know, pay attention to the maintenance. What do you backing up? Has anyone checked it? And again, if you’re using a manage service provider, make sure if they’re responsible for for looking at your backups of managing them, make sure they’re doing that. You know, double check and make sure that they understand that your backups are critical and they can’t just ignore the alerts about your backups. You know, you don’t want to be in the unpleasant situation of three of our servers just got flooded. We need the data and discover nobody was backing it up. It ain’t exactly okay, all right, anything else, you wanna leave people about back-up before we go to the broader d r no, i think that’s good for those were the highlights for it. All right, so back to the disaster recovery. What more can we say about that? There are going to be a lot of watches if you’re in a large d our situation. And so one of things we stress is one getting down into the details of your d. Our plan before disaster hits. Because if you’ve never thought about how you’re actually going to do the restores air, actually, how you’re going to be rebuild those servers. You need two ahead of time. A lot of folks never practiced have a fire drill. I hate fire drill, but and you don’t have a live fire drills in this case, it might be a live fire drill. You don’t want to have that, so you should make some effort to practice, even if it’s just something small, you know, trying to restore one server. I mentioned in this session that i was put in a situation years ago at johns hopkins university, where we were choir, to have verification of live tr practice, so i was put in a room that had a table, a telephone, a server, and we were carrying two laptops and we couldn’t come out of the room, and so we had completely restored our domain. We had a set of backups on the thumb drive and added the second laptop to that domain improve that we had restored the domain, and an independent person that was not connected to our department was monitoring to make sure we had done it, and we had to prove it, and that was an eye opening experience is as experienced as i was doing that i’d never done it live, and it took me three tries to do it so that’s, right? Encourage folks to really try and practice this stuff ahead of time and get down into the you know, the weeds on their on their d our plan and, uh and also to think about it, you weren’t fired because way, john no, no, no. I actually like too much, john soft. No, we we did complete it within the time frame, but we were a little startled when we discovered that we thought we knew how to do it first time. And we kept making little mistakes. There were two of us and they’re doing it. And we were surprised ourselves that we thought, oh, of course we know this. This is not a problem, but no, we were making little mistakes because we didn’t have the documentation down. A specific is it needed to be. And so that was a very eye opening experience. There’s a couple of their d r gotchas we talked about, which is crossed. People don’t think about the cost ahead of time. How much is it gonna cost to get you that data back in the instance of my co presenter who had the damaged drives, they weren’t expecting a near ten thousand dollars cost to recover those drives, but that’s what happened when they didn’t have the backups? They had to take those hard drives to a data recovery place, and the price tag was nearly ten thousand dollars. Dealing with insurance is another big one that people don’t think about having to account for all of the equipment that was lost, and dealing with that insurance morass often gets dumped on the auntie department in a small organization. There’s not, you know, a legal department that’s going to deal with that it’s going to be you so to, you know, kind of talk to your insurance provider ahead of time and see what all you have to deal with in a disaster situation. So you don’t get an unpleasant surprise if you’re ever in one a cz well on the insurance topic, just are you covered? Exactly what i think is your equipment covered. And what do you have to to do with that in terms of accounting for it? If you suffer a disaster, you know the gooch is we get so ah, a couple of minutes, if if oh, for days about consciously trying to think about somebody we don’t hold back on non-profit video, i think some of the other ones that we covered in their thick wit mint again to the cost. How much is it going to cost you? Two gets new equipment and did you account for that when you were doing your d our plan and a time to recover? A lot of folks don’t understand how long it may take them to do a recovery and also deciding what is important and what is not important, not just in terms of what should be restored in what order, but in terms of practical things, do you really need to restore your domain? Er, or could you just start over from scratch? If your domain only contains maybe fifty accounts and doesn’t have any associated servers faster for you to just start over and just recreate the domain immediately? Especially if a lot of your emails in office three, sixty five or google maps, you could reconnect it very quickly. So, you know, thinking about more practical gotsch is like that that you should think about have time, you know, obviously it’s that’s the best. Practice to think of all these details and we realised folks may not be able to, so we provided someone sheets and some samples of them of just quick, yes or no questions and thinking this through and things to think about and where will we that is not notice provoc radio has a professional sound i don’t know about ntcdinosaur ten, but that was a way over there. They’re on their own. They can come to us for expertise if they if they need to, but, um, see, now i messed myself up because i ask you about something, but we were just talking about how much, how long will actually take you to recover things and whether or not you should practically skipped recovering something because it might be faster to rebuild it. Okay, i have a follow up to that it’s my smart ass humor, maybe lose it. All right, so why did you leave us with one take away d, r or back-up the session was a little bit misnamed because technically, you’re not going to avoid a disaster. You really can’t. In many cases, you’re not gonna avoid the, but you’re not going to avoid. The earthquake if you’re in that region so you need to plan on how to deal with it. So it’s more like avoiding avoiding your d are becoming the disaster cause you’re not going to avoid the disaster itself, so you might as well plan for it. Outstanding. Thank you very much. Door. Thank you much. Darby america, vice president of technology for lift. This is tony martignetti non-profit radio coverage of ntc non-profit technology conference two thousand fifteen. Thank you so much for being with us thinking thanks to everybody at and t, c and the non-profit technology network next week. What skills are most desirable in your board members? If you missed any part of today’s show, find it on tony martignetti dot com opportunity collaboration with world convenes for poverty reduction, you know, ruin you for every other conference opportunity collaboration dot net. Our creative producer is claire meyerhoff. Sam liebowitz is the line producer shows social media is by susan chavez susan chavez dot com on our music is by scott stein i love that yeah, he will be next week for non-profit radio big non-profit ideas for the other ninety five percent go out and be great. What’s not to love about non-profit radio tony gets the best guests check this out from seth godin this’s the first revolution since tv nineteen fifty and henry ford nineteen twenty it’s the revolution of our lifetime here’s a smart, simple idea from craigslist founder craig newmark yeah insights, orn presentation or anything? People don’t really need the fancy stuff they need something which is simple and fast. When’s the best time to post on facebook facebook’s andrew noise nose at traffic is at an all time hyre on nine a, m or p m so that’s when you should be posting your most meaningful post here’s aria finger ceo of do something dot or ge young people are not going to be involved in social change if it’s boring and they don’t see the impact of what they’re doing. So you got to make it fun and applicable to these young people look so otherwise a fifteen and sixteen year old they have better things to do if they have xbox, they have tv, they have their cell phones me dar is the founder of idealist took two or three years for foundation staff to sort of dane toe. Add an email address their card it was like it was phone. This email thing is fired-up that’s why should i give it away? Charles best founded donors choose dot or ge somehow they’ve gotten in touch kind of off line as it were on dno, two exchanges of brownies and visits and physical gift mark echo is the founder and ceo of eco enterprises. You may be wearing his hoodies and shirts. Tony talked to him. Yeah, you know, i just i’m a big believer that’s not what you make in life. It sze, you know, tell you make people feel this is public radio host majora carter. Innovation is in the power of understanding that you don’t just do it. You put money on a situation expected to hell. You put money in a situation and invested and expected to grow and savvy advice for success from eric sabiston. What separates those who achieve from those who do not is in direct proportion to one’s ability to ask others for help. The smartest experts and leading thinkers air on tony martignetti non-profit radio big non-profit ideas for the other ninety five percent.