Planning for the worst
So yesterday I mentioned that a major subscription-based (paid) CRM for UK nonprofits recently had a security breach with complete data disclosure.
In other words, the full CRM data of all the nonprofits who were using that CRM was copied out by attackers, and could potentially be misused.
There's a great write-up about it on the CiviCRM blog, if you'd like to read more — including some thoughtful views on what this means for folks like you and me using open-source CRM solutions.
Beyond that, I think this is a good example of an important point:
No matter what system you decide to use, there's always some chance that the bad guys will find a way in.
It’s just as true as for our own personal security:
If my house gets robbed, I can't really prevent it happening again just by moving to a different house.
If my neighbor's house gets robbed, it doesn't necessarily mean that my house is any less at risk than his was.
Instead:
We do what we can to keep ourselves secure.
Meanwhile, we make a plan for how we'll handle it if something does go wrong.
Here’s the thing:
Life is full of risk, but that doesn't stop us from enjoying it as we go along.
Not in our own homes, nor in our work.
If you have questions about how to keep your constituents' data safe,
shoot me a reply and we can get into the details.
In the meantime, you might take a few minutes today to consider:
How would you and your constituents be affected if your CRM data were compromised?
How much damage could that cause to your mission?
How could you handle it, if it happened?
Uncomfortable as it might be, it’s worth some consideration.
These question can actually be answered.
And having the answers is a lot better
than not having them
when you really need them.
All the best,
A.

