“Be comfortable with the messiness”: how one charity built a cybersecurity policy alongside its frontline workers

The Islamic Family & Social Services Association’s cybersecurity policy breaks cybersecurity threats down into accessible language, while also inviting other community organizations to copy and adapt the policy to their own needs.

Why It Matters

Frontline staff are increasingly using social media and smartphones in their work with communities — particularly while on the move. Co-creating a cybersecurity policy with communities can reduce or remove the need for technical experts, as well as making cybersecurity everybody’s responsibility in an organization.

cybersecurity policy

Image courtesy of Islamic Family

This independent journalism on data, digital transformation and technology for social impact is made possible by the Future of Good editorial fellowship on digital transformation, supported by Mastercard Changeworks™. Read our editorial ethics and standards here

TORONTO/TREATY 13 – What happens when technology is framed as an opportunity for joy, optimism and curiosity? That was the question posed by the Islamic Family & Social Services Association (IFSSA) when it started developing its cybersecurity policy last year. 

The Edmonton-based organization collaborated with the Digital Governance Council, formerly known as the CIO Strategy Council, to overcome the trepidation cybersecurity and other technical undertakings often generate in non-profit organizations. They began with the basics in mid-2022: renewing the association’s insurance policy and acknowledging cybersecurity may have been one of their blind spots. 

The end result, known as the model cybersecurity policy, was officially launched this year.

The organization’s executive director Omar Yaqub says the cybersecurity policies of many social purpose organizations – or frameworks that social purpose organizations are encouraged to follow – are “fear-based and reductionist.” 

“Most of the policies aren’t policies – they are more like essays about things to be fearful of,” he says. “There are few substantive things in the policies about what staff can do.”

For example, if a frontline worker goes through three levels of security to send a text message to a community member, they might feel frustrated by the process or afraid of sending messages at all. 

Earlier this year, the Canadian Centre for Nonprofit Digital Resilience released a report outlining the unique constraints non-profits face when maintaining robust cybersecurity infrastructure. Not only do staff and volunteers in many organizations fall victim to phishing and ransomware attacks, but those on the receiving end of low-cost or donated hardware might find their computers are no longer receiving adequate security updates, putting them at an increased risk of cybersecurity attacks. 

Existing cybersecurity policies don’t always work for community organizations

Cybersecurity policies, both within and outside the sector, often assume organizations have fully-fledged IT departments at their disposal, Yaqub says. “That is not a reality for most organizations in the sector, not even the most well-resourced organizations.” 

But the IFSSA team treated their lack of an IT department as an opportunity rather than a constraint. Each member of the existing team has specific responsibilities for managing the overall digital security of the organization. Not only has that removed the need for a dedicated IT team, it also ensures everybody in the organization understands cybersecurity is a collective responsibility. 

“The language of IT can overwhelm and confuse people,” Yaqub says. “A lot of people might not know what phishing is and how to look out for it. They might not know what can practically be done.” 

To change that, IFSSA upended traditional cybersecurity policies they were seeing in their research and started building one from scratch. Everything was up for change, from the structure of the policy to the language it used. The team identified three types of assets that affect the organization’s cybersecurity. 

The first is data and managed assets, such as client or donor data and internal financial systems. The second is owned assets, such as physical devices and office spaces. And the third is external risks like misinformation on social media or technology vendors that have experienced data breaches. 

Yaqub says it was a “eureka moment” when the team realized assets could be broken down into three categories. The next step was implementing preventative measures, as well as reactive measures in case an attack occurs. Staff responsibilities were also clearly defined for each digital asset.

Under the new policy, the operations team is responsible for the security of all physical devices. In order to prevent cybersecurity attacks the team is also encouraged to apply security updates within 14 days, install mobile device management software so devices can be accessed remotely, and share monthly updates on the status of all staff devices within the organization. The operations team is also responsible for remotely deleting all data from any device reported missing to prevent data breaches, also known as wiping a device. 

Instead of thinking about what was difficult to control – which was more likely to lead to inertia or paralysis – IFSSA turned its focus to what was within its reach. The team asked a number of what-if questions covering a variety of scenarios — what happens if a member of staff leaves and a new person is hired? What happens when a member of staff doesn’t answer their phone? What happens if you lose a device with sensitive client data on it?

Employees at the Islamic family working on cybersecurity policy

Image courtesy of Islamic Family

Frontline staff involved in cybersecurity policy development

With frontline staff already overstretched, IFSSA wanted to motivate employees around the development and implementation of internal cybersecurity policies. To that end, the organization’s cybersecurity policy emphasizes, “maintaining the relationships, trust and integrity we have built with community requires us to treat the data we hold as a sacred trust, plan for continuity of service and reduce the impact of cyber incidents.” 

In other words, more technology and data in frontline work means each staff member is responsible for the security of the devices they use — and by extension — of the organization as a whole. 

For Yaqub, staff need to be involved in designing the cybersecurity policy because so many social workers now want to communicate via text and other social platforms. Some clients won’t respond to phone calls or prefer to be contacted on specific messaging platforms, he says.  

“We’re helping our frontline workers do the best work they can,” he says. “Our phones are fun, delightful devices that allow us to communicate with people – there is inherent joy in that.” 

However, he says, in co-creating a cybersecurity policy with frontline staff, it’s also vital to hold space for some of the concerns and technical limitations that they may be facing. For example, increasing cybersecurity software can also raise concerns about surveillance, which can undermine trust and work efficacy.

“Devices are personal,” Yaqub adds. “There isn’t a clear delineation between person lives and work lives anymore – someone could be using a personal device to text a colleague or shop in the middle of the work day.”

In order to address legitimate concerns around surveillance, IFSSA baked an ‘Honest Security’ approach into its policy. This includes making sure teams feel safe and supported, and clearly outlining that staff are not to feel like they are being “watched, confined or restricted,” the policy reads. 

The Honest Security guide also outlines ways organizations can end up abusing data collected through security activities – such as accessing an individual’s locations or files – as well preventative measures, including asking staff for informed consent and providing them with cybersecurity recommendations rather than negative or alarming alerts. 

How can community organizations and non-profits begin building their own cybersecurity policies and infrastructure?

“Listing our digital assets, thinking about preventative and reactive steps [to managing cybersecurity], and who would be in charge of it, was a really helpful framework,” Yaqub says. “It’s simple and any organization can apply it. You could spend an afternoon listing your assets and sources of client information.”

IFSSA’s policy is a publicly accessible document, which many internal cybersecurity policies often are not. And since the document is licensed under a Creative Commons Attribution-NonCommercial-ShareAlike license, it can be copied, redistributed and adapted into any medium or format that another organization sees fit. Instructions for how to do so are included in the policy itself, and those who do choose to copy and tweak IFSSA’s approach are encouraged to provide feedback. 

To Yaqub, it’s also important that other non-profit organizations seeking to build their own cybersecurity policies realize that IFSSA “made a ton of mistakes.” The current policy was far from the first draft, he adds. In fact, the team has intentionally chosen to leave some of the comments and feedback from the development process in the policy’s digital version, to show the “intentional mess” that occurred as the policy took shape. 

“We need to realize that most good policies are not written in stone, and most are living, breathing entities,” Yaqub says. “We’re excited to see what other organizations do with the policy and how it benefits them. We hope they can be comfortable with the messiness.”

Your job. Your mission. Your news.

With your support, the sector you're building gets the journalism it deserves, and you get a tax receipt. 

Author

Sharlene has been reporting on responsible business, environmental sustainability and technology in the UK and Canada since 2018. She has worked with various organizations during this time, including the Stanford Social Innovation Review, the Pentland Centre for Sustainability in Business at Lancaster University, AIGA Eye on Design, Social Enterprise UK and Nature is a Human Right. Sharlene moved to Toronto in early 2023 to join the Future of Good team, where she has been reporting at the intersections of technology, data and social purpose work. Her reporting has spanned several subject areas, including AI policy, cybersecurity, ethical data collection, and technology partnerships between the private, public and third sectors.

NO PAYWALLS HERE

Future of Good’s journalism is free. But we need your support to keep it that way. Sign up for our free newsletter to help!

Grab Your Copy Now

SIGN UP NOW

* indicates required
Close the CTA