Dear Abby: I have an acquaintance, “Tina,” who I believe is fraudulently using her GoFundMe fundraising webpage. A close friend of hers set it up a few years ago to assist with medical bills related to a rare form of cancer that will never fully go away. When the page began, Tina was soliciting donations on Facebook and sending text messages to remind everyone to donate. Later on, when she and her husband went out of town for surgery, they posted about it as if it were a vacation.
Recently, she has had some legal bills for an unrelated matter, and a year after her last medical donation, she received a hefty donation that matched the amount of her legal bills. I suspect the person who donated the money was duped into believing Tina had another large medical bill, but she used that donation for her legal expenses.
On top of this, Tina has opened a new fundraising page with a sob story…
IT & DATA SECURITY (MITIGATING THE “INSIDER THREAT”)
As seen in the TD Bank case, an employee with too much “access” can sell your customer data to syndicates.
- Principle of Least Privilege (PoLP): Employees should only have access to the specific folders and databases required for their current task.
- Access Revocation: Have a “Termination Checklist” that ensures all digital access (Email, VPN, Banking) is revoked within 60 minutes of an employee resigning or being dismissed.
- System Logs & Audit Trails: Enable “Read/Write Logging” on your server. If a customer’s data is leaked, you need to know exactly which login accessed that record and at what time.
- Encryption at Rest: Ensure that sensitive files (like your customer ID numbers or payroll spreadsheets) are encrypted so that if a staff member copies them to a USB, they cannot be read.
