hem

LastPass Stores Passwords So Securely Users Cannot Access Them










hem

5 Data Security Risks for Nonprofits (and How to Fix Them)

 

Many nonprofits handle sensitive personal information belonging to community members — whether it's names or email addresses or payment information. But are you handling this data properly to prevent a data breach?

This post is by no means exhaustive — after all, every nonprofit handles different sorts of data, and each organization has different security needs. That said, these are some practical things to think about when you review your handling of sensitive personal information.

#1 Risk: Malware and Software Vulnerabilities

The Problem

This one may seem obvious, but with so many other security risks out there, it's easy to forget that malware still poses a major threat to your organization's data.

How You Can Mitigate It

To start, make sure you have antivirus software installed, and that it's up to date. In addition, you'll want to make sure your operating system and any software installed are also up to date, with all security patches installed.

Beyond that, be careful what you click on. Don't download and install software from sites you don't trust. Be careful of the email attachments and links you click on — even from people you know. If you aren't expecting a file or link, click with caution.

#2 Risk: Ransomware

The Problem

Ransomware is an especially insidious form of malware that holds your computer or data hostage unless you pay a sum of money to a criminal actor. Oftentimes, ransomware will encrypt your data, preventing you from accessing it. And according to Symantec's Director of Security Response Kevin Haley, some forms of ransomware will threaten to publicly release your data.

How You Can Mitigate It

Aside from up-to-date antivirus software and taking steps to avoid infection in the first place, there isn't a ton you can do to deal with a ransomware attack once your data's been encrypted.

In that case, according to Haley, keeping up-to-date backups of your data is your best bet. That way, you'll be able to get back up and running quickly with minimal data loss. (TechSoup offers backup and recovery solutions from Veritas.)

#3 Risk: Public Wi-Fi

The Problem

Public Wi-Fi is generally fine for some things, such as browsing cat videos on YouTube, or catching up on the headlines. However, for anything involving sensitive personal information, it's a security disaster waiting to happen. Bad actors could potentially eavesdrop on what you're doing while using public Wi-Fi, leaving your data and work open to prying eyes.

How You Can Mitigate It

First off, avoid using public, unsecured Wi-Fi when handling sensitive information — whether it's internal organizational data or your own personal banking information. Using a wireless hotspot, like those from Mobile Beacon (offered through TechSoup), instead of public Wi-Fi is an easy way to keep your data more secure.

If you can't avoid public Wi-Fi, a virtual private network (VPN) is a good option — VPNs secure data between your computer and the website you're visiting. Not all VPNs provide the same level of security, though, and you'll need to make sure your VPN of choice conforms to any data security regulations that your organization may be subject to. See our previous overview of VPNs for more.

#4 Risk: Inappropriate Sharing of Sensitive Information

The Problem

Sharing sensitive information via email, messaging apps, or similar means is a risky proposition.

Email is a notoriously insecure method of communication. Email accounts are often the target of data breaches and phishing attacks. (A phishing attack is where an attacker tries to steal your account information by tricking you to enter your account information on a phony login page.)

And whether it's through email or messaging app, it's all too easy to accidentally leak data by sharing it with the wrong person.

How You Can Mitigate It

Avoid sending sensitive information to colleagues via email. It's easier said than done, we know. Maybe you need to share a list of donor contact information with your marketing department, for example. Consider uploading it to a secure file server on your network that can only be accessed by others in the office.

If your organization uses a cloud storage service like Box, consider using that instead — so long as it meets your organization's security needs. These cloud storage services usually encrypt data you upload to prevent it from getting stolen. You may also want to consider using constituent relationship management (CRM) software, a tool designed specifically to store and manage your organization's contacts.

In addition, pay attention to access permissions. If you can, restrict access to sensitive information to only those who need it. Revisit your permissions settings regularly and update them as needed.

To prevent your user accounts from being compromised in the first place, practice good account security hygiene. Use strong passwords and require your staff to use two-factor authentication.

#5 Risk: Handling Credit Card Data

The Problem

A breach involving credit card data can be embarrassing for your organization, but it could wreak financial havoc on your members and supporters. All it takes is for hackers to grab a few pieces of information to rack up credit card debt in your supporters' names.

How You Can Mitigate It

Securing credit card information is important, but you don't have to make it up as you go. Make sure your organization conforms to payment card security standards. The Payment Card Industry Security Standards Council, as well as banks and credit card issuers, provide guidelines on how to best handle credit card information to prevent breaches.

Has your nonprofit recently encountered any other notable risks? Tell us about it in the comments!




hem

EU approves €385 million renewable energy scheme for Lithuania

The European Commission has approved a €385 million (US$429.7 million) renewable energy scheme to support renewables generation in Lithuania, including hydroelectric power.




hem

EU corporates want renewable energy but bureaucracy and regulations are holding them back

This week energy developer BayWa r.e. published its Energy Report 2019, which surveyed 1,200 European corporations about their attitudes toward renewable energy.




hem

E.ON Pilots Efficiency Funding Scheme for UK Consumers

Integrated energy company E.ON and BNP Paribas Personal Finance are piloting a new energy efficiency financing scheme for UK consumers.




hem

EU corporates want renewable energy but bureaucracy and regulations are holding them back

This week energy developer BayWa r.e. published its Energy Report 2019, which surveyed 1,200 European corporations about their attitudes toward renewable energy.




hem

Sumitomo Chemical to buy Botanical Resources Australia

Japanese chemical giant Sumitomo Chemical group has spent approximately ¥15 billion (A$177 million) on Botanical Resources Australia, a Tasmanian pyrethrum business.




hem

EU corporates want renewable energy but bureaucracy and regulations are holding them back

This week energy developer BayWa r.e. published its Energy Report 2019, which surveyed 1,200 European corporations about their attitudes toward renewable energy.




hem

EU corporates want renewable energy but bureaucracy and regulations are holding them back

This week energy developer BayWa r.e. published its Energy Report 2019, which surveyed 1,200 European corporations about their attitudes toward renewable energy.




hem

Show me the Money! - The SFC Moves to Regulate Depositaries of SFC-authorised Collective Investment Schemes

The SFC Moves to Regulate Depositaries of SFC-authorised Collective Investment Schemes In September 2019, the Securities and Futures Commission of Hong Kong (the “SFC”) issued a Consultation Paper (available here) setting out its proposa...




hem

New court pilot scheme for unopposed lease renewals

...




hem

Coronavirus - New Guidance: Government update on the Coronavirus Job Retention Scheme - UK

On Friday 20 March 2020, the Chancellor announced a new “Coronavirus Job Retention Scheme” (the Scheme) to help pay people’s wages. Updated Guidance on the Scheme was issued on 4 April 2020 (the Updated Guidance). This Alert seeks ...




hem

Coronavirus - Further guidance on Coronavirus Job Retention Scheme - UK

In previous Alerts (here and Full Article



hem

Coronavirus: Hong Kong Government provides more details on the Employment Support Scheme - Hong Kong

We previously reported on the Hong Kong government’s Employment Support Scheme (“ESS”) to help employers defray salary costs and maintain employment. Earlier today on 17 April 2020, the government published more...




hem

Coronavirus - Final details emerge as the Coronavirus Job Retention Scheme is now live - UK

On Friday evening, 17 April, further revisions were made to the guidance for employers and employees regarding the operation of the Coronavirus Job Retention Scheme (the Scheme). This time also, the guidance changes were accompanied b...




hem

Coronavirus – Job retention scheme - UK

On Friday 20 March 2020, the Chancellor announced a new “Coronavirus Job Retention Scheme” (the Scheme) to help pay people’s wages. Importantly, to aid understanding of the Scheme and how it operates, we now have: Full Article



hem

Coronavirus: Further conditions imposed on the Hong Kong Government’s Employment Support Scheme - Hong Kong

We have previously reported on the initial details of the Hong Kong Government’s Employment Support Scheme (“ESS”) on 17 April 2020. Funding for the ESS has now bee...




hem

Lawbite: Tenancy deposit scheme and pre-2007 tenancies

Charalambous and another v Ng and another [2014] EWCA Civ 1604 The courts continue to produce surprising decisions in relation to the tenancy deposit scheme introduced by the Housing Act 2004, applying it in certain respects to tenancies granted bef...




hem

Education Procurement Briefing: Supreme Court dismisses Edenred's challenge to the government's decision not to tender for the administration of a new childcare scheme

In Edenred (UK Group) Ltd v (1) Her Majesty’s Treasury (2) Her Majesty’s Commissioners for Revenue and Customs (HMRC) (3) National Savings and Investments [2015] UKSC 45, the Supreme Court unanimously dismissed Edenred’s challenge ...




hem

Supreme Court dismisses Edenred’s challenge to the government’s decision not to tender for the administration of a new childcare scheme

In Edenred (UK Group) Ltd v (1) Her Majesty’s Treasury (2) Her Majesty’s Commissioners for Revenue and Customs (3) National Savings and Investments [2015] UKSC 45, the Supreme Court unanimously dismissed Edenred’s challenge to Her ...




hem

Reverters and how to spot them

This webinar will provide delegates with an introduction to the rights of reverter, which may result in unexpected consequences where land ceases to be used for certain educational purposes....




hem

Trust-based pension schemes: trustee and employer responsibilities

Pension trustees are required by law to be familiar with pensions and trust law, scheme funding and investment principles and their scheme’s governing documentation. This course is designed to give those with responsibility for trust-based pension ...




hem

Cyber security and pension schemes

The Pensions Regulator has issued guidance on cyber security, highlighting the need for trustees to be aware of their “responsibilities in respect of cyber resilience” and to “receive regular training and have access to skills and expertise to under...




hem

IHC HR e-briefing 98: vetting and barring scheme guidance

Last Friday, the Home Office issued comprehensive guidance to assist employers and volunteer organisations in properly implementing the vetting and barring scheme. October 2009 saw the introduction of barred lists (which replaced t...




hem

IHC HR e-briefing 110 - Vetting and barring scheme implementation halted

This morning, the Home Secretary, Theresa May, announced that the new vetting and barring scheme for people who work with children or vulnerable adults is to be "brought to a halt" pending review. The scheme, the scope of which is defined by the Saf...




hem

China’s government has tamed dragon investors and harnessed them to ride for the state

As originally published in React News Beijing is determined all outgoing investment will align with China’s strategic goals Stockholm - home of ABBA and fermented herring. A fish so pongy, the Swedes o...




hem

Lawbite: The Lease Renewal Pilot Scheme in practice

Eventuate Capital Ltd v Grosvenor Estate Belgravia (E02CL652) The County Court and First-tier Tribunal Unopposed Business Lease Renewal Pilot Scheme has been in place for over 2 years but very few cases have, as yet, proceeded to trial. In one of th...




hem

More updates needed to your scheme’s statement of investment principles

Unexpectedly, the Government has issued regulations which will require trustees to make further changes to their Statement of Investment Principles (SIP) from 1 October 2020. They will also require additional disclosures in relation to investment pr...




hem

What do pension schemes need to say about ESG, climate change and stewardship?

Trustees and providers of pension schemes face ever increasing and changing legal duties to have policies on and disclose how they deal with stewardship and environmental, social and governance (ESG) issues. This article pulls the new rules together...




hem

Spruce up your scheme

...




hem

Speedbrief: The Pension Schemes Bill – was it worth the wait?

Eighteen months ago, the Government published a white paper on protecting DB pension schemes.  This was followed by consultations on a variety of matters, including a stronger Pensions Regulator, the introduction of collective defined contribut...




hem

Coronavirus Job Retention Scheme: key pensions issues - UK

On Thursday 27 March, the UK Government released fuller details of the new Coronavirus Job Retention Scheme (or “Furlough Scheme”) first announced on Friday 20 March, with guidance being published for both employers and Full Article



hem

Authorised contractual schemes and PAIFs - SDLT

The Chancellor’s Autumn Statement contained the following stamp duty land tax announcement regarding the tax-free ...






hem

R&D-to-Sales Ratio of Most Korean Petrochem Companies Below 1%

Despite the record-high results, the R&D investment level of the nation's petrochemical industry is still miserably low. According to industry sources on August 28, the amount of R&D investment of Lotte Chemical, which achieved a record-high sales revenue of 7,849.4 billion won in the first half, fell short of 44.5 billion won. This is only 0.57 percent of the total sales. Even last year when the company posted the highest operating profit (2,547.8 billion won) among all petrochemical...




hem

SK E&C Wins $210 Mil. Petrochem Plant Project in Thailand by Outbidding Japanese Consortium

SK Engineering & Construction has won a large-scale petrochemical plant project in Thailand. The company said on August 29 that it clinched a deal worth US$210 million to build polyol plant within the Hemaraj industrial zone in Thailand's Rayong. This followed news that the company signed a $1.6-billion project to modernize an oil refinery in Iran earlier this month. The plant, located 150 kilometers southeast of Thailand's capital Bangkok, is commissioned jointly by PTT Global Chemical, ...




hem

Hanwha Chemical an Unexpected Beneficiary of Coal Price Hike

As international coal prices are on the rise, Hanwha Chemical's prospect is getting brighter. That's because the Korean company uses naphtha to produce polyvinyl chloride (PVC) while its rivals in China are largely based on coal, which will make it more price competitive vis-a-vis the Chinese chemical producers. According to Korea Resources Corp. and chemical industry sources on September 10, the freight-on-board (FOB) price of bituminous coal out of the Chinese port of Qinhuangdao was US$95....




hem

Petrochem Industry to Invest 10 Tril. Won in Daesan Industrial Complex

The Daesan petrochemical industrial zone in Seosan, South Chungcheong Province, will transform into an advanced chemical industrial complex. The nation's major petrochemical companies may invest up to 10 trillion won in this area. On September 14, S-Oil, Lotte Chemical, Hanwha Total, South Chungcheong provincial government, and Seosan city gathered in Lotte World Tower and signed a memorandum to create a Daesan specialized industrial complex. Currently the area is home to large petrochemical ...




hem

Age discrimination: impact on employee share schemes

...




hem

Covid 19 coronavirus: Police worry there will be mayhem on the streets at alert level 2

Police fear bars will be "swamped" when the country finally drops to level 2.On Monday, Prime Minister Jacinda Ardern will reveal when New Zealand will drop a level in its Covid-19 warning system – with the move potentially coming...




hem

Energy Saving Opportunity Scheme: A new mandatory energy assessment scheme for large undertakings

What is the Energy Saving Opportunities Scheme ("ESOS")? ESOS is the UK Government’s implementation of a particular requirement of the Energy Efficiency Directive regarding energy audits.  It requires energy assessments (including the ide...




hem

Cyber liability: how can businesses protect themselves against underestimated cyber risks?

Cyber risk is the risk of financial loss, disruption, or damage to reputation as a result of  breaches of data security, including unauthorised disclosure of data, and compromise or failures of IT systems.  Specific examples include: ...




hem

Local Government Briefing Note 1 of 2013 - December 2012 UK Government Announces Future Changes to the CRC Energy Efficiency Scheme (“CRC Scheme”)

Many in local government will already be familiar with the CRC Scheme. This is the UK’s mandatory emissions trading scheme aimed at improving energy efficiency and cutting carbon dioxide emissions in large public and privat...