Morison Cogen LLP

Accounting, Audit & Tax Services

Client Portal | Secure Upload267.440.3000

  • Home
  • About Us
    • What We Do
    • Why Choose Us
    • Partners
    • Managers
    • Partners Emeritus
  • Services
    • Accounting
    • Audit
    • Tax
    • Financial Management
  • News and Posts
    • Business
    • Employer
    • ETRA
    • Federal Tax Posts
    • Individual Tax
    • Not for Profit
    • Small Business Tax
    • Featured
  • Contact Us Today
    • Join Our Mailing List
  • Morison Global

December 1, 2022

Protecting your nonprofit from data breaches

By now, all organizations — for-profit and not-for-profit — know about the risk of cyberattacks. Why then, would any nonprofit fail to secure its network and digital assets? One reason is cost. Cybersecurity can be expensive. Yet according to IBM’s “2022 Cost of a Data Breach Report,” a data breach in the United States leads to an average $9.44 million loss. Obviously, the average is skewed by cyberattacks on large companies. But it’s possible for nonprofits to lose more than they can afford.

Phishing evolves

Most attacks are made via phishing schemes, where cybercriminals use email to dupe victims into providing personal information, including login credentials. Phishing emails generally include links or attachments that, when clicked, infect computers with malware that enables fraudsters to access your systems.

Increasingly, cybercriminals are using phishing emails to perpetrate ransomware attacks. They gain control of an organization’s network and data and lock legitimate users out. They then hold the data hostage until the victim organization pays a ransom. The criminals might leak some confidential information to the public or on the “dark web” to show they’re serious and to encourage quick payment. Ransomware perpetrators usually release the data after they receive a ransom — but not always.

Acting proactively

Criminals have hacked everything from government agencies to hospitals to large charities, so it’s critical that all nonprofits act defensively and provide training to staffers. Training should cover various phishing schemes and include testing so employees can see how easy it is to fall for scams. Other ways to contain potential cyberthreats are:

Look for emails flying red flags. Everyone in your organization should look out for suspicious emails, including messages with a sense of urgency, such as a subject line that says, “Respond ASAP.” Phishing subject lines might also include references to upcoming meeting agendas, payroll questions and password verifications. They may appear to come from HR, tech support or your executive director.

Phishing messages frequently are peppered with bad grammar and misspelled words. They may use numbers and special characters that look like letters to dodge anti-phishing software and include URLs that are close, but not identical, to the addresses of legitimate sites.

Use password managers. Your organization should consider using password managers. A surprising number of employees still use easily hacked passwords such as 1234 and PASSWORD. Password managers generate complex passwords and store them for users. At the very least, require employees to come up with difficult passwords and change them frequently. For greater security, implement two-factor authentication. This requires users to log in normally and then confirm their identity via text or phone.

Stay current. Implement hardware and software updates on a timely basis and stop using programs that are no longer updated and supported by their makers.

No excuse

There are plenty of affordable (if not free) cybersecurity tools available to nonprofits. So there’s no excuse for you to simply hope your organization won’t be hacked. Contact us for more information about protecting your assets.

© 2022


Filed Under: Featured, Not for Profit

Recent News and Posts

Renting to a relative? Watch out for tax traps

2023 tax calendar

5 benefits of outsourcing your accounting needs

Tips to help prevent accounting and tax errors

Update on remote auditing

News and Posts by Category

  • Business
  • Employer
  • ETRA
  • Featured
  • Federal Tax Posts
  • Individual Tax
  • Not for Profit
  • Small Business Tax
  • tax
  • Tax Tips

Items of Interest

Merger Announced!

Morison Global Press Release

Tax Planning Guide

Global Tax Insights

Peer Review Letter

CPA-USA Association

Join Our Mailing List

About Morison Cogen

Morison Cogen LLP is a full-service certified public accounting, tax, and business consulting firm serving private and public companies, not-for-profit organizations, and the personal accounting needs of individuals in the U.S. and around the world....read more

Get Connected

Morison Cogen LLP
484 Norristown Road, Suite 100
Blue Bell, PA 19422

P: 267.440.3000
F: 267.440.3001
E: info@morisoncogen.com

Copyright © 2023 Morison Cogen LLP