SnickersDOM · M
Why did they keep historic data anyway?
Well, I Googled for you, since you weren't curious enough to do it yourself, and it's fairly obvious in retrospect:
- Re-engagement: Past donors are the best targets to start giving again during special campaigns.
- Trend Analysis: Charities study old data to see when and why supporters stop giving.
- Legal Rules: Tax laws and financial rules require groups to keep donation records for a set number of years.
- Legacy and Trust: Knowing a family's history helps the charity build trust with next-generation givers or estate planners.
I think the bigger question is why was the CRM system these charities were using so vulnerable to attack.
peterlee · M
@SnickersDOM And it makes a lot of us vulnerable.
Best to give items, like food to a food bank. It cuts out accountants.
Best to give items, like food to a food bank. It cuts out accountants.
FreestyleArt · 36-40, M
Yep...and King Charles the Fart thinks digital identification is the way to go. F this world.
View 7 more replies »
ArishMell · 70-79, M
@FreestyleArt Making childish insults about foreign nations while showing you know nothing about them, only demeans you.
ArishMell · 70-79, M
The question should be, why do they keep the data on insecure systems accessible via the Internet?
If that total is correct it suggests to me either -
- they were all taken in by some accounting-software company far better at selling its products than making them,and taking no responsibility for its efficiency and security. (Remind me again, which well-known Japanese company wrote the Post Office's disastrous 'Horizon' system....?)
- they were all using standard MS Office on computers linked to directly to the Internet, with no digital or physical barriers and other precautions. (Microsoft's virtual world-wide monopoly makes life easy for the attackers.)
I do wonder if we will see a drift back to using paper records, or at least physically-portable storage like CDs and solid-state memories, with all critical information kept on computers not connected to the outside world.
If that total is correct it suggests to me either -
- they were all taken in by some accounting-software company far better at selling its products than making them,and taking no responsibility for its efficiency and security. (Remind me again, which well-known Japanese company wrote the Post Office's disastrous 'Horizon' system....?)
- they were all using standard MS Office on computers linked to directly to the Internet, with no digital or physical barriers and other precautions. (Microsoft's virtual world-wide monopoly makes life easy for the attackers.)
I do wonder if we will see a drift back to using paper records, or at least physically-portable storage like CDs and solid-state memories, with all critical information kept on computers not connected to the outside world.
SnickersDOM · M
@ArishMell they were using Beacon CRM (other alternatives would include Salesforce and Blackbaud)
For non-profits in particular I'm not sure how realistic it is to expect each one of them to roll their own in-house, air-gapped historical data warehousing solution, particularly if most staff may even be volunteers, perhaps modestly skilled / non-tech-savvy volunteers (especially if it's already difficult to ask donors to fund even just the charity's core mission, never mind its "administrative overhead", which people tend to balk at, and charities subequently get penalized for on charity rating sites if too much of the donations go toward overhead), as opoosed to for-profit businesses being more able to hire developers / DBA's (never mind don't have to explain to every last investor why they're hiring devs / need to hire devs) ... hence they usually rely on SaaS vendors
For non-profits in particular I'm not sure how realistic it is to expect each one of them to roll their own in-house, air-gapped historical data warehousing solution, particularly if most staff may even be volunteers, perhaps modestly skilled / non-tech-savvy volunteers (especially if it's already difficult to ask donors to fund even just the charity's core mission, never mind its "administrative overhead", which people tend to balk at, and charities subequently get penalized for on charity rating sites if too much of the donations go toward overhead), as opoosed to for-profit businesses being more able to hire developers / DBA's (never mind don't have to explain to every last investor why they're hiring devs / need to hire devs) ... hence they usually rely on SaaS vendors
ArishMell · 70-79, M
@SnickersDOM Many charities do not have warehouses but the larger ones at least do have professional managers, and it is their responsibility to ensure their systems are safe, especially given as you say that the "shop floor" staff are not especially highly IT-skilled.
ShenaniganFoodie · 41-45, M
Bet it was Harry
Why keep historic data???
Why wouldn't they??? Makes sense that if they get donations once, they're going to try hitting that source up again. Just like MP's do...
Why wouldn't they??? Makes sense that if they get donations once, they're going to try hitting that source up again. Just like MP's do...
val70 · 56-60
More than 90% (!) of successful cyber attacks start with a phishing email or involve human error and social engineering. That's the most important issue on this, I think.
HumanEarth · F
Its the government secretly attacking the charities
peterlee · M
@HumanEarth No, but it begs the question. why keep data on us when we are no longer giving.
And let’s face it no data is safe from the likes of Putin and Kim.
And let’s face it no data is safe from the likes of Putin and Kim.
FreddieUK · 70-79, M
TheOneyouwerewarnedabout · 46-50, MVIP
im calling bullshit straght up.. they deleting evidence..
ArishMell · 70-79, M
@TheOneyouwerewarnedabout Your are the one writing "buls**t.
The crime was by the attackers, so whom do you imagine is deleting what evidence, of what?
The crime was by the attackers, so whom do you imagine is deleting what evidence, of what?












