A story we hear too often
The Giving Tuesday the donor database asked for a ransom
the executive director of a 25-person food bank
Grace runs a food bank on the West Side with 25 staff, four hundred volunteers and a donor database that goes back to 1994. Giving Tuesday is a third of the year’s individual gifts, and the email goes out at 6 a.m.
At 6:40 the development director cannot open the donor system. The screen says the files are encrypted and lists the names of three major donors as proof. Somewhere in the last week, a volunteer’s shared login, still active from the spring gala, was used to install something on the fundraising PC.
The version that goes badly: the gifts that day land on a page that no longer works, the donor list is posted online with giving histories, the board learns from a reporter, and a foundation pauses a grant pending a security review nobody can pass.
In Grace’s version, the protection agent quarantined the fundraising PC at 2:12 a.m. and the engineer on watch restored the donor database from the offline copy before staff arrived. The 6 a.m. email goes out at 6. The only thing Grace changes that day is the volunteer account policy, and she changes it by nine.
The screen says the files are encrypted and lists the names of three major donors as proof.
What changes the ending
- No shared or volunteer logins that outlive the event, and MFA on every account (CIS Control 5, Account Management)
- Offline, tested backups of the donor database and the finance system (CIS Control 11, Data Recovery)
- Endpoint protection on the fundraising and finance PCs, with someone watching overnight (CIS Controls 10 and 13)