EVENTS INTERFACE
WITH S. DAVID RAMIREZ, CFEE
CYBER RISK IS EVENT RISK:
A
TEN CYBERSECURITY CHECKS FOR EVENT ORGANIZATIONS
I has changed the threat landscape in a fundamental way. Anyone with bad intentions and an internet connection can now execute a cyberattack. Technical expertise is no longer a barrier to entry. The question is no longer whether your organization is a target. It is whether you have made yourself a harder one than the next organization on the list. Organizations in our own industry have been phished. Not small, disorganized operations. Well-run shops with experienced staff who clicked something that looked legitimate. One credential. One moment of distraction. That is all it takes. Most cyberattacks succeed because of basic, preventable failures. These 10 action items address the most common ones.
storing them in a spreadsheet or notes app. There have been instances where people have broken into offices and, in addition to stealing items, also gained access to software. Implementing an organization-wide password management tool solves a lot of headaches. These tools will generate strong unique passwords, store them securely, and allow passwords to be shared safely among team members. There’s always some inertia in implementing a tool like this, but the goal is to have lower friction and higher security with your passwords. Introductory tools like Bitwarden have free tiers and scale relatively inexpensively. 1Password and LastPass have stronger centralized control for bigger teams. You should also encourage staff to use a password manager in their day-to-day life. People frequently use the same password across professional and personal accounts. Someone gaining access to your work email should also not be given access to your water bill. Some of these password tools allow for a personal folder and a professional folder, which means you can also increase the security of your staff outside of the office.
1. Phishing Training Phishing is a type of social engineering attack that we’ve increasingly seen target event organizations. Criminals will impersonate trusted organizations or individuals to trick victims into clicking on links, revealing sensitive information, or providing direct access to systems and credentials. This type of attack can be hard to protect against because it relies on human trust rather than the exploitation of technical vulnerabilities. There are multiple types of common phishing tactics including email phishing where an operator sends fraudulent emails with malicious links or attachments, smishing where the activities are conducted by SMS or text message, vishing where attackers call people directly, or spear phishing where a specific high-value target like an executive director receives customized messaging to gain access to their credentials or systems. There are simple ways to protect yourself: always verify an email’s sender, never click links without ensuring they go to expected URLs, and turn on multifactor authentication. At an organizational level, phishing training should happen annually if not quarterly. There are free and low-cost starting points like Google’s phishing quiz. If you have budget to allocate to this, KnowBe4 and Proofpoint (or similar products) can be deployed across an organization. Larger-scale municipalities and organizations may want to explore products like Ninjio for more intensive training and tracking. IT departments may also want to send out test emails to see if people are clicking or downloading things that they are not supposed to. This shouldn’t be for a gotcha moment. This is about building muscle memory around cybersecurity resilience.
3. Two-Factor Authentication and Multifactor Authentication (2FA/MFA) Multifactor authentication adds an additional step to gain access to a system. Most of us are familiar with two-factor authentication that uses a text message code. There are also authenticator apps, like Google Authenticator, which can be faster and more secure than text messages, especially if teams are remote and may not have consistent access to SMS messages. Larger organizations may want to look into something like Duo, which is a phone app that sends a push notification as the second factor. That push notification is also logged centrally, so an administrator could see if a push approval is routed through a location where that staff member is not actually present. Any tool containing personally identifiable information, or any tool whose loss of access would be majorly disruptive, should be the first place to implement 2FA. This includes email, financial platforms, registration and ticketing systems, CRMs, and anything touching payment or attendee data. MFA/2FA is an additional step that can sometimes be inconvenient. But that inconvenience is minor compared to a data breach.
2. Password Management I get it. Events require an entire constellation of software systems and tools to effectively operate. Each one of them has a separate login and password. Some require monthly password updates and keeping all those passwords in your head feels like an impossible task. But effective password management is vital when so much of our operational capacity is tied to the use of these tools. Password hygiene is important. Teams should not be reusing passwords, storing them on sticky notes or in notebooks, or
4. Vendor Access and Offboarding Event organizations often share access with a rotating cast of contractors, volunteers, and vendors. That is a normal part of the current event staffing landscape. The danger happens when these organizations do not manage who retains access to systems after the event ends. An access audit should be conducted annually, if not after every major event. Create a list of everyone with login credentials to your systems and determine whether they still need them. If you
40
IFEA’s ie: the business of international events
Fall 2026