Page Properties | ||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ||||||||||||||||
|
The below will appear on the Refined page at What trustees need to know about cyber security
Excerpt | ||
---|---|---|
| ||
We share the questions that Trustees need to ask to stay on top of their charity’s cyber security Trustees act as board members and play a very important role in governing the charities they support. The role comes with significant responsibilities, not least of which is ensuring the charity they represent manages their risks around cyber security to a good standard. Cyber security is, of course, a highly specialised area that is also very high profile. Many Trustees do not have professional cyber security experience, so how do they ensure their charities are conforming to best practice, investing in the right areas, and making best use of technologies at their disposal? In this guidance article, IASME team up with one of our Certification Bodies, Smartdesc, who specialise in providing IT Services for non-profits. We share practical advice for Trustees on what questions to raise with their Boards and explore how the core standards of the Cyber Essentials framework can be applied in your organisation. We are a charity, why would someone attack us? It is not so much that a criminal would deliberately attack a specific charity (although they might), it is that they randomly attack many thousands of organisations in one go, with no regard to who they are. Cyber criminals use readily available tools that require next to no skill and work by tricking people to give away their security credentials or by finding weak spots in their IT systems to gain access. If your charity uses digital technology, you are a potential victim of cyber crime. A good cyber security posture is often as simple as getting the basics right, to make you less attractive than the next organisation; attackers will always go for the lowest hanging fruit. Surely, I can leave cyber security for the IT manager to worry about? Cyber security is everyone’s responsibility, including Trustees. If you are lucky enough to have internal IT resource, they cannot be expected to be experts in everything. A cyber security incident will affect the whole organisation – not just the IT department. It may impact or halt your services, damage your reputation and contractual relationships, put sensitive client and donor information in the public domain and result in legal or regulatory action. Regardless of who is taking care of the IT, if something went badly wrong, the responsibility for the cyber security controls, the passwords, the accounts, and the potential data breach would lie with the senior management. Trustees themselves don’t need to be technical experts, but you should be having constructive discussions with key staff to ensure you are confident that cyber risk is being appropriately managed. If this is an area that you feel very uncertain about, could you introduce an IT consultant or cyber security professional to review your organisations’ cyber maturity? This would ensure that your charity is being proactive in aligning to industry standards and is often done on an annual basis. What are the key questions we should be asking?
Where can I find more information? If you are a small charity, the NCSC’s Small Charity Guide can help you nail the basics. If you are a larger charity, the NCSC’s 10 Steps to Cyber Security will help you to identify what to do within a more complex infrastructure. The NCSC has also created an Introduction to cyber security for board members. Cyber Essentials is an effective, government backed baseline scheme that will help you to protect your charity, whatever its size against a whole range of the most common cyber attacks including ransomware. It is a great way to check that you have implemented the five key controls adequately, without overlooking something. Many charities report that the process of certifying acts like a check list and gives them huge peace of mind. Smartdesc are a licensed Cyber Essentials Certification Body, and have helped dozens of charities achieve Cyber Essentials and Cyber Essentials Plus at affordable rates. Could this be the year to take the extra step and show your clients and sources of funding that you have prioritised cyber security and have the certification to show for it?Charity Cyber Essentials Fortnight runs between 6th and 17th November. IASME will be working closely with the National Cyber Security Centre and Charity Digital to educate and support charities about the cyber threat they face and inform them about the benefits of Cyber Essentials. There will be a discount to the price of certification and plenty of cyber security guidance tailored towards the charity sector. Look out for more information by visiting the Charities Cyber Essentials webpage. If you need help getting started on your Cyber Essentials journey, you can access the free Cyber Essentials Readiness Tool, developed on behalf of the NCSC by IASME. The Readiness Tool is a free, online tool accessible in the form of a set of interactive questions on our website. The process of working through the questions will inform you about your organisation’s level of cyber security and what aspects you need to improve. Based on your answers, you will be directed towards relevant guidance and a tailored action plan for your next steps towards certification. Where do I start? Adam Monks, Chief Executive of Smartdesc, advises Trustees who are unsure where to start when bringing their organisation’s cyber security up to speed to consider the next steps as a starting point.
|