{"id":86668,"date":"2023-01-23T08:00:00","date_gmt":"2023-01-23T08:00:00","guid":{"rendered":"https:\/\/cloudnewshub.com\/archives\/86668"},"modified":"2023-01-23T08:00:00","modified_gmt":"2023-01-23T08:00:00","slug":"ncsc-warning-over-cyber-risk-to-charity-sector","status":"publish","type":"post","link":"https:\/\/cloudnewshub.com\/?p=86668","title":{"rendered":"NCSC warning over cyber risk to charity sector"},"content":{"rendered":"<div><img decoding=\"async\" src=\"http:\/\/cloudnewshub.com\/wp-content\/uploads\/2023\/01\/ncsc-warning-over-cyber-risk-to-charity-sector.jpg\" class=\"ff-og-image-inserted\"><\/div>\n<p>Under-resourced <a href=\"https:\/\/www.computerweekly.com\/resources\/IT-for-charity-organisations\">charities<\/a> running services and fundraising activities online are increasingly seen as a soft touch by cyber criminals looking to make a quick buck, and are at risk of malicious actors taking advantage of public generosity during challenging times.<\/p>\n<p>In a&nbsp;<a href=\"https:\/\/www.ncsc.gov.uk\/collection\/charity\/cyber-threat-report-uk-charity-sector\">newly issued report<\/a>, the UK\u2019s <a href=\"https:\/\/www.ncsc.gov.uk\/\">National Cyber Security Centre<\/a> (NCSC) highlighted how besides launching cyber attacks against charities, cyber criminals are also \u201cinserting\u201d themselves into the third sector, masquerading as legitimate charities to siphon off bona fide donations from the public, as has been observed in numerous incidences relating to charity drives for Ukraine.<\/p>\n<p>The report also guides charity organisations towards bespoke sector advice, and encourages them to take advantage of the NCSC\u2019s free Active Cyber Defence (ACD) tools, such as Web Check, Mail Check, and the ever-popular<a href=\"https:\/\/www.computerweekly.com\/news\/252486036\/NCSC-launches-pen-testing-service-for-remote-workers\"> Exercise in a Box<\/a>. Some charitable organisations are also currently eligible for <a href=\"https:\/\/www.computerweekly.com\/news\/252528999\/Vulnerable-organisations-to-get-free-Cyber-Essentials-support\">free Cyber Essentials assessment and accreditation<\/a>.<\/p>\n<p>\u201cThe UK\u2019s charities are doing fantastic work every day, and digital services and online fundraising are now playing a crucial role in this,\u201d said NCSC CEO Lindy Cameron. \u201cWhile it is right that technology should play a part in helping charities, this does open up the possibility of cyber attacks and it is important they understand the risks.<\/p>\n<p>\u201cThe NCSC is here to help and I urge all charities to reduce their vulnerability by reading our latest report, following our guidance and making use of the tools available to them,\u201d she said.<\/p>\n<p>Helen Stephenson, chief executive of the <a href=\"https:\/\/www.gov.uk\/government\/organisations\/charity-commission\" target=\"_blank\" rel=\"noopener noreferrer\">Charity Commission for England and Wales<\/a>, added: \u201cCharities play a crucial role in our society and in every community \u2013 they save lives, and they provide many of the services that make life worth living. All charities ultimately rely on public trust and continued public generosity.<\/p>\n<p>\u201cSo the impact of any cyber attack on a charity can therefore be devastating, not just for the organisation and those who rely on its services, but also in undermining public confidence and support.<\/p>\n<p>\u201cTaking steps to stay secure online is not an optional extra for trustees, but a core part of good governance. We welcome this report and urge trustees to take early action to protect their charities from cyber harm,\u201d said Stephenson.<\/p>\n<p>There are many reasons why charities are quite so vulnerable to cyber attacks, said the NCSC, including a reluctance to expend limited funds and staff effort on basic security controls, a high-number of casual volunteers untrained in cyber security, and a reliance on bring-your-own-device policies. Many charities also have data on sensitive issues or vulnerable people, making them attractive targets for government-backed actors.<\/p>\n<p>It highlighted a number of recent incidents, including a <a href=\"https:\/\/www.computerweekly.com\/feature\/How-to-prepare-for-Ransomware\" target=\"_blank\" rel=\"noopener noreferrer\">ransomware attack<\/a> on the Edinburgh Festival Fringe Society and a <a href=\"https:\/\/www.techtarget.com\/searchsecurity\/news\/252522493\/Early-detection-crucial-in-stopping-BEC-scams\" target=\"_blank\" rel=\"noopener noreferrer\">business email compromise<\/a> (BEC) incident at a small, unnamed hospice in the West Midlands, both of which cost thousands of pounds to mitigate.<\/p>\n<p>In the first instance, the Fringe Society found systems and data had been encrypted by ransomware in January 2022. Despite a quick and effective response, and a higher-than-usual degree of preparedness \u2013 it had implemented system segregation so its attackers were not able to access everything \u2013 recovering from the attack cost \u00a395,000, of which insurance only covered \u00a325,000, forcing the arts charity, which cancelled the 2020 festival due to Covid-19, to dip into its reserves.<\/p>\n<p>The hospice charity, meanwhile, was attacked after a staff member received a phishing email that seemed to be from Microsoft, which asked them to change their password. Later, they received a second email saying this update had not worked, and to re-enter their original credentials.<\/p>\n<p>A day later, one of the hospice\u2019s donors rang to query a strange email they had received from the staff member. A flurry of other calls followed it, at which point the charity turned to its managed services provider (MSP), which found that cyber criminals had taken control of the staff member\u2019s email account and changed the email forwarding rules so that they could not see what their account was sending out. The staff member additionally had access to credit card data on 35,000 users.<\/p>\n<p>Fortunately, the attack was mitigated swiftly, no ransom demand was made, and there was no evidence that the card data was stolen or misused. However, the cost to the hospice was \u00a317,000, money that should have been spent on patient care.<\/p>\n<p>\u201cEven though we have to accept no organisation will ever be 100% secure, we can confidently tell all of our supporters, and those that we care for, that we take the security of their personal data very seriously and have taken every possible step to make our hospice as digitally secure as possible,\u201d said the charity\u2019s operations director<\/p>\n<p>\u201cThe reputational damage would have been far worse had we not been honest about a mistake made by a member of staff,\u201d they added.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Under-resourced charities running services and fundraising activities online are increasingly seen as a soft touch by cyber criminals looking to make a quick buck, and are at risk of malicious actors taking advantage of public generosity during challenging times. In a&nbsp;newly issued report, the UK\u2019s National Cyber Security Centre (NCSC) highlighted how besides launching cyber [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":86669,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[533],"tags":[],"class_list":["post-86668","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-it"],"_links":{"self":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts\/86668","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=86668"}],"version-history":[{"count":0,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts\/86668\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/media\/86669"}],"wp:attachment":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=86668"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=86668"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=86668"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}