Over the past decade, cybersecurity attacks have escalated at a troubling rate. Cybercriminals now cost the global economy trillions of dollars each year, and it's not just large, publicly traded corporations that are targeted.
Nonprofits and professional services firms of all sizes are attractive targets to cybercriminals for a variety of reasons, making it critical for organizations in these sectors to stay vigilant. Every cybersecurity incident offers valuable lessons other organizations can learn from.
This white paper reviews:
- Real-world cyber attacks on five nonprofit organizations and professional services firms, including how each incident impacted the business and how leadership responded
- The most common and costly missteps that surface across these cases, from delayed patching to social engineering scams
- Practical, insurance-backed guidance for reducing your organization's cyber risk and preparing for the aftermath of an incident, should one occur
Download the guide here or continue reading below.
Top Lessons Learned from Real-World Cyber Attacks
What Nonprofits and Professional Services Firms Can Take Away from These Cyber Attack Experiences
Over the past decade, cybersecurity attacks have escalated at a troubling rate. As of 2023, Cybersecurity Ventures estimated the global cost of cybercrime would reach $8 trillion that year, a figure that underscores how quickly this risk has grown.
It's not just large, publicly traded corporations that are targeted. Nonprofits and professional services firms of all sizes are attractive targets to cybercriminals for a variety of reasons, making it critical for organizations in these sectors to stay vigilant.
Every cybersecurity incident offers valuable lessons other organizations can learn from. With that in mind, this guide reviews real-world cyber attacks on several nonprofit organizations and professional services firms, how each incident impacted the business, and how those businesses responded. It also offers insights and practical guidance on how to reduce your organization's risk of a cybersecurity incident and avoid the high costs and other damaging consequences that can follow.
Why Cybercriminals Target Nonprofits and Professional Services Firms
First, let's examine why nonprofit and professional services firms are attractive targets to cybercriminals.
Nonprofits tend to store data on donors, who may be perceived as prime financial targets, along with vulnerable or at-risk populations such as children, the elderly, and low-income individuals and families. They often work with third-party vendors that may themselves be susceptible to a security breach. And many nonprofits lack the financial resources to invest significantly in cybersecurity measures, or may not perceive themselves as prime targets at all.
Professional services firms typically maintain sensitive, private, or confidential client data, so they are likely to feel pressure to pay to recover that data if it's locked by ransomware. Their employees often work remotely at client sites, requiring these firms to balance the need for access to documents, files, and data with the demand for security. Additionally, some lack the robust cybersecurity measures needed to thwart an attack, or the disaster recovery plans and procedures to restore operations quickly and effectively.
As a result, for both nonprofits and professional services firms, the consequences of a cyber attack can be far-reaching. Aside from the financial loss, an organization might suffer reputational harm, lose clients or donors, face penalties and fines from regulators, or have to devote time and resources to defending a liability lawsuit.
Five Cases, Five Different Experiences
Incidents like the following illustrate how easily nonprofit organizations and professional services firms can fall prey to a cyber attack, along with the damaging consequences that can result.
1. The Red Cross
Incident: The Red Cross was the target of a sophisticated cyber attack on its servers, which host personal data on more than 515,000 people. Per the organization's detailed FAQs, the hackers used tools that aren't widely available, along with techniques designed to hide and disguise their activities. The organization stated that the attack succeeded because it failed to apply an available security patch quickly enough.
Impact: The Red Cross was required to notify all impacted individuals whose personal information was potentially exposed. Given the size of the affected population, the organization described the notification process as complex and ongoing, involving phone calls, hotlines, public announcements, letters, and even travel to remote areas to inform people in person.
Response: The Red Cross relaunched its systems with several security enhancements, including two-factor authentication and advanced threat detection features.
2. Philabundance
Incident: Philabundance, a large regional hunger relief group, was the victim of a social engineering scam, losing nearly $1 million when it paid what it believed was a legitimate construction bill for a new facility built for its Community Kitchen program. The $923,000 invoice actually originated from fraudsters who had infiltrated the organization's systems and sent a mimicked email impersonating an employee, along with what appeared to be a real invoice from the construction company on the project. The email and invoice were both fake. The organization only realized it had been hacked when the contractor inquired about the late payment.
Impact: Philabundance stated that the incident didn't affect its day-to-day finances or its online donation system.
Response: Philabundance enhanced its IT security systems and controls to safeguard the money it raises.
3. Accenture
Incident: Accenture, a global consulting and technology firm, was hit by a cyber attack in which a ransomware group gained access to more than six terabytes of data. The attackers threatened to publish the information unless they received a $50 million ransom.
Impact: Initially, Accenture publicly stated the incident had no impact on its operations. Months later, in a Securities and Exchange Commission (SEC) filing, Accenture reported that the attack did involve a data breach, that the criminals published some of the stolen data online, and that its clients "have experienced, and may in the future experience, breaches of systems and cloud-based services enabled by or provided by" the company.
Response: The firm's security controls enabled it to identify the suspicious activity, isolate the affected servers, and restore those servers from backups.
4. Cadwalader, Wickersham & Taft
Incident: This global law firm experienced a cyber breach that placed more than 90,000 clients' personal information at risk and rendered many of its internal systems unavailable for weeks, according to some reports.
Response: In notifying affected parties, the firm stated it took steps to halt the breach as soon as it was discovered, reported the incident to regulators and law enforcement officials, and implemented measures to strengthen its network. The firm advised clients to monitor their financial accounts closely and offered free identity theft protection services to those affected.
Impact: A class action lawsuit was later filed, claiming the firm "failed to prevent the data breach because it did not adhere to commonly accepted security standards and failed to detect that its databases were subject to a security breach."
5. A Large (Anonymous) Nonprofit
Incident: A nonprofit that provides financial advising services fell victim to a ransomware attack, with cybercriminals demanding $2 million to restore access to affected files. Through a speedy response, the organization was able to contain the damage and negotiate the ransom down from $2 million to $500,000, and eventually to zero.
Response: Under its recently purchased cyber insurance policy, the $1.2 million the organization had spent on forensic IT work, legal services, negotiation services, and proper notification was covered. Because the nonprofit had a history of strong service to its thousands of members, it avoided an avalanche of claims.
Impact: Other than the lost staff time required to respond to the attack, the nonprofit was well positioned to manage the breach through its cyber insurance coverage.
Insights From the Professionals
Brandon Newlands, Senior Vice President, Senior Director of Coverage and Claims at B. F. Saul Insurance, and David Katz, a shareholder with the law firm of Weissman Zucker Euster + Katz P.C., assessed these real-world cyber incidents to offer insights that other nonprofit organizations and professional services firms can learn from.
"In the nonprofit sector, organizations that experience a cyber attack often find their donors and other constituents, given the organization's larger mission and good works, will give them the benefit of the doubt as to why the breach occurred, the first time," Katz said.
"Generally, I think people understand that nonprofit dollars are focused on the charity's core mission and not necessarily data security. However, it is a major mistake for nonprofits not to focus on these risks. Most nonprofits must adhere to regulatory requirements for protecting private or confidential data, with stiff fines and penalties for noncompliance."
With or without regulatory requirements, the court of public opinion is always a factor in the aftermath of a cyber incident. "The tolerance for mistakes might be higher for a nonprofit, especially a charitable organization, but any organization's members, donors, clients, and other constituents will expect the organization to put the proper controls in place to avoid another cyber attack," Katz said.
Offering reparations can also help from a reputation standpoint. For example, the anonymous nonprofit referenced above offered every member a credit protection service for a period of time, which would have cost the organization in excess of $100,000 had it not had robust cyber insurance.
While some organizations struggle to appreciate the full extent of their cyber risk, the available data is becoming harder to dispute. "There are many reputable sources that document the incidence of cybersecurity claims by company size and industry," Newlands noted. Sharing those reports with senior leaders is a good first step toward increasing their awareness of the true level of risk.
Real-World Cyber Attacks Lessons Learned
Each of these cybersecurity incidents offers useful takeaways for any organization, especially nonprofits and professional services firms.
Size and Industry Are Irrelevant to Criminals
A bad actor doesn't care whether you employ a staff of 15 or 15,000. If they see a financial opportunity, they'll target your business. That's not just a function of the depth of your pockets. It's about the value of your data and its impact on your business. A nonprofit's donor information can be valuable to mine and sell, while a small accounting firm might find it difficult to operate for even a few days without its systems, making it a prime ransomware target.
A Cyber Response Is Complex and Costly
Unless you've experienced one firsthand, it can be difficult to appreciate how multi-faceted, complicated, and expensive it is to respond to a cyber attack. Investigating the cause is just one important and costly piece of the puzzle. As these examples illustrate, a proper response also involves mitigating the damage, restoring access to files and data, and developing and implementing a notification plan. The notification requirements alone can be expensive to comply with, and the cost of a thorough response, including forensic IT work and media experts to help mitigate reputational harm, could threaten the survival of a small company.
Cyber Insurance Is Just the Start
Despite common misconceptions, proper cyber insurance isn't just for companies in the tech sector. As case after case shows, cyber coverage can be essential for any business, especially a professional services firm or nonprofit. However, limiting your protection to insurance alone is a reactive approach. In addition to budgeting for the proper coverage, it's prudent to allocate funds toward proactive and preventive measures, such as assessing your system and network vulnerabilities and implementing stronger controls to fill gaps and address weaknesses.
The Insurance Requirements Are Not Trivial
Most cyber insurance carriers require the insured to have certain protective measures in place, and these requirements are becoming more stringent over time. For instance, many carriers require companies to use multi-factor authentication to verify identity. You'll find these requirements in the policy application as well as the warranties section of the policy document. Some may be costly to comply with, but if you fail to meet the stated warranties and later experience a cyber incident, the carrier could deny coverage.
The Regulatory Requirements Vary
A growing number of states require companies that fit certain criteria to assess how well they safeguard the data they gather, process, and store, and to take steps to improve their controls where needed. More states are likely to follow suit in the coming years. In turn, carriers may begin requiring companies to demonstrate they're meeting relevant state regulatory requirements for assessments and other measures.
The Notification Requirements Are Considerable
The detailed FAQs published on the Red Cross website serve as a strong example of a well-developed notification plan. The organization took a direct approach and used many channels to ensure it reached everyone who needed to know, even making in-person visits for people who were otherwise hard to reach. Consider how daunting the notification requirements can be for a nonprofit that serves tens of thousands of members, or a mature services firm with decades of records. To help ensure proper notification, it's helpful to work with an attorney experienced in advising businesses in the wake of a cyber incident. Most cyber insurance policies include these legal costs as part of the coverage offered.
The Liability Risk Can Be Significant
"While a nonprofit's members aren't likely to bring a class action lawsuit after a cyber breach, that may not be the case with a professional services firm that serves clients," Newlands said. For legal and professional services firms, failure to safeguard data can trigger an errors and omissions (E&O) and/or directors and officers (D&O) claim. Publicly traded companies are even more likely to see a class action lawsuit post-breach, especially if the incident negatively impacts the stock price.
It Pays to Develop a Response Plan Proactively
In the immediate aftermath of a cyber attack, emotions run high. That's why it's essential to develop a thorough, well-documented cyber response plan before trouble strikes. Following an established playbook can help your organization respond thoughtfully and strategically after a cyber incident. The process of developing the plan also helps an organization think through key issues in advance, such as the chain of notification, how to comply with regulatory and carrier requirements, and which qualified vendors to call on for help.
Staying Cool Under Pressure Is Vital
"When a cyber incident occurs, the immediate reaction is to panic," Newlands said. But reacting emotionally or impulsively can make matters worse. "Knowing what to do and maintaining coolness under fire can make a big difference," Katz said, noting that a poor response can create additional exposure. Working with an attorney or an independent broker can help an organization slow down, think critically, and follow the incident response and communication plan it has, ideally, developed during calmer times.
Your Response Is Only as Good as Your Third-Party Vendors
Given the highly technical nature of the cybersecurity field, it's important to thoroughly vet and approve any vendors you choose to work with to investigate the cause of an attack and help restore data and operations. Look closely at each vendor's credentials and make sure you have full confidence in the experts you're relying on.
Ongoing Cyber Training Is Essential
In the case of Philabundance, an employee's response to a fraudulent email opened the door to the breach. Many organizations are caught off guard when this happens, but human error remains the most common cause of cyber attacks, which makes ongoing training and education essential. Many carriers periodically test an insured's employees to see whether they fall victim to a simulated phishing attempt, then require anyone who fails the test to complete additional training. With or without such a service, making cybersecurity training a priority, and budgeting for it, is critical.
A Proper Post-Mortem Can Help
If your organization experiences a cyber attack, conducting a thorough post-mortem can help minimize the odds of a future incident. Bring together key people to discuss what could have been done differently, where changes are needed to address vulnerabilities, and whether outside resources are needed to help. It's easy to grow fatigued after completing the initial response and revert quickly to business as usual, but staying focused on preventing another attack or breach is essential.
Turn to an Independent Broker Like B. F. Saul Insurance
When it comes to protecting your organization against complex risks like cybersecurity, having an independent broker on your side can make a meaningful difference.
The financial lines specialists at B. F. Saul Insurance have helped organizations approach cyber risk with proper insurance coverage and proactive risk management measures. We also stay close to the evolving cyber landscape to help you stay ahead of emerging risks.
To discuss how to protect your organization against the growing threat of cyber incidents, schedule a call with the cybersecurity specialists at B. F. Saul Insurance.
For legal advice and insightful best practices for risk assessments, incident response planning and responding to cyber attacks, contact David Katz at dkatz@wzlegal.com.
Frequently Asked Questions
Q: Why do cybercriminals target nonprofits and professional services firms?
A: Nonprofits often hold valuable donor and beneficiary data but may lack cybersecurity resources, while professional services firms manage sensitive client information and face pressure to pay ransoms quickly. Both sectors can be attractive, lower-resistance targets for cybercriminals seeking financial gain or valuable data.
Q: What does a cyber response typically involve after an attack?
A: A cyber response can include investigating the cause of the breach, mitigating damage, restoring files and systems, and developing a notification plan for affected individuals. These steps often require forensic IT specialists, legal counsel, and sometimes media experts, making a thorough response both complex and costly.
Q: Is cyber insurance necessary for small nonprofits and professional services firms?
A: Size doesn't determine risk. Cybercriminals often target organizations based on data value and operational vulnerability rather than budget. Cyber insurance can help cover costs like forensic investigation, legal fees, and notification expenses that could otherwise be financially devastating for a smaller organization.
Q: What requirements do cyber insurance carriers typically expect policyholders to meet?
A: Many carriers require safeguards such as multi-factor authentication as a condition of coverage, often outlined in the policy application and warranties section. Failing to meet these stated requirements could result in a denied claim if a cyber incident occurs, so it's important to understand and maintain them.
Q: How can an organization prepare for a potential cyber attack before one happens?
A: Developing a documented incident response plan in advance can help an organization act quickly and strategically rather than react emotionally under pressure. This includes establishing a notification chain, vetting trusted vendors, and working with an experienced broker or attorney to align the plan with regulatory and carrier requirements.
Have Questions? Get In Touch With An Expert.
Brandon Newlands brings over 20 years of litigation experience to his role as SVP and Senior Director of Coverage and Claims at B. F. Saul Insurance. Brandon supports clients in the event of a claim or coverage issue, and specializes in coverage disputes, claims evaluation/valuation, and risk analysis. He leverages his expertise to guide clients in making informed decisions that align with their unique circumstances.
Any advice, information, data, communication, proposal and/or document transmitted to you in or in connection with this blog (including, without limitation, any past or future written or oral communications in connection with this blog or its subject matter, and any replies to or forwarded messages in connection with this blog) (collectively, this “Communication”) shall not be deemed legal advice and are not a substitute for the guidance of your legal, tax, financial or other professional advisors. The information contained in this Communication is based on the information made known to B.F. Saul Insurance, Inc. (“BFSI”), at the time this Communication is transmitted to you. If any of the information provided to or relied on by BFSI is inaccurate or changes before insurance coverage is bound then the terms and conditions, premiums, or even availability of such coverage may be subject to change. This Communication does not constitute a contract for insurance and, the terms and conditions of any current or future policy(ies) of insurance shall supersede and prevail over this Communication. This Communication and any information disclosed to you in connection with this Communication at any time (whether orally or in writing) are provided to you in confidence, are the proprietary and confidential information of BFSI, and shall not be disclosed to any third party (except to legal, tax, financial or other professional advisors for the sole purpose of enabling and only to the extent necessary to enable them to provide their services to you in such capacity(ies)), reproduced or used for any other purpose without the express written consent of BFSI.
All requests to place, change or terminate coverage must be confirmed in writing and are subject to the terms and conditions of your insurance policy(ies). Coverage shall not be considered and cannot be bound, changed or terminated unless you have received written confirmation of such from a licensed agent pursuant to the terms and conditions of your insurance policy(ies).
