Cybersecurity for HOAs 101: What Your Association Needs to Know – Part 2

HOA Cybersecurity 101 | All Property Management

Are you a landlord or a property manager? There’s a special version of this post just for you: Cybersecurity for Landlords 101

HOA Cybersecurity 101

In last week’s post, we examined the top HOA cybersecurity risks: from common misconceptions that hurt associations’ security, to the biggest threats that demand our attention in 2017.

This week, we’ll lay out a step-by-step HOA cybersecurity plan for each component of your association. Have a notebook and pen handy–you’ll want to take notes!

HOA Cybersecurity Tip #1:

Formalize Your Cybersecurity Policies & Emergency Plans

As you read through the following sections, each of which delves into bolstering your HOA cybersecurity in a specific area, keep the following questions in mind:

  1. How will your HOA cybersecurity policies be enforced, and by who?
  2. How will potential security breaches be dealt with?
  3. Who should employees and board members contact with questions and concerns?
  4. How will current and future employees and board members be trained?

HOA Cybersecurity Tip #2:

Improve Your Password Practices

1. Create stronger passwords:

    • You may have heard the term “passphrase”–this is a lengthy password that may consist of a short, memorable sentence (including spaces) instead of a single word. (e.g. “i love chocolate cake”)
    • You should also incorporate as many letters, numbers, and symbols as each site or app allows. (e.g. “1 l0v3 ch0c0l@73 c4k3!”)
    • Don’t use any dictionary words or names unless they’re part of a lengthy passphrase; use a mix of capital and lowercase letters. (e.g. “1 L0v3 Ch0c0l@73 C4k3!”)
    • Be sure that you’re not using one of these?common passwords.
    • Keep in mind that hackers are using password cracking software to run through thousands of possible passwords each second. You can check how long it would take a password cracker to guess your password here: How Secure is My Password?
    • I also recommend reading this article: How I’d Hack Your Weak Passwords

2. Don’t reuse passwords. This is a step that everyone knows, but few people heed–to their detriment. We know it’s tedious, but it’s also the single most important step you can take when it comes to HOA cybersecurity. As we discussed above, when hackers gain access to one of your passwords, they have software that allows them to test it across all of your accounts–potentially enabling them to gain access to all of your information in one fell swoop.

3. Use password management software. This is the key to using different passwords across all sites and apps. A good password manager (our security expert recommends 1Password) will help you to create incredibly secure passwords and store them for use across all of your accounts, along with usernames, account numbers, and other pertinent information. All of my important accounts now have extremely long, gibberish passwords that no human could remember–but now, I don’t have to!

4. Create & enforce a password policy. Train all employees and board members on how to create strong passwords. Make it perfectly clear that your HOA cybersecurity (and, consequently, its financial standing and reputation) could be compromised by one person’s negligence. Passwords are the first line of defense when it comes to HOA cybersecurity, so be sure that your employees and board members understand that your security is in their hands. Here’s a sample policy from SANS Institute that you’re welcome to adapt.

HOA Cybersecurity Tip #3:

Bolster Your Software Security

1. Update your software regularly across all devices that you, your employees, and your board members own. It can be tempting to put off updates when you’re busy, but keep in mind that new software versions often patch holes in their security. By saying “remind me later,” you’re choosing to continue using a weaker version, creating vulnerabilities in your HOA cybersecurity. This applies across your laptop, phone, tablet, and even your router.

2. Invest in an anti-virus solution. There are free options like Avast and AVG for personal use; but our security expert recommends investing in a full security suite for data breach prevention within your business. He suggests Trend Micro, Bitdefender, Sophos, Symantec, and McAfee.

HOA Cybersecurity Tip #4:

Lock Down Your Data

1. Decide who gets access to sensitive data, and who should be given administrative privileges. Our security expert’s advice is to grant access to as few people as possible, and to have a plan in place to remove those privileges the moment that someone leaves their job or the board.

2. Don’t hold on to records any longer than you’re legally required to. This significantly minimizes what could be stolen in the event of a breach.

3. Encrypt all digital data, and never share files containing PII via unencrypted email.

4. Back up your data to an offsite location in case your network is compromised. Keep in mind that if you back it up to the cloud, you need to take cloud security into consideration, utilizing the suggestions for vendor contracts that we include toward the end of this post.

HOA Cybersecurity Tip #5:

Secure Your Networks

93% of the time, attackers take just minutes (or less) to compromise a system; and intruders are in your network for an average of 200 days before they’re noticed. This makes it critically important to follow these steps as part of your data breach prevention strategy:

1. Restrict access to your wireless network. Limit the number of people who know your office’s Wi-Fi password. Visitors should be restricted to a separate guest network.

2. Decide which sites employees can access, restricting their ability to visit risky or inappropriate sites.

3. Change the default password on your router. This is a surprisingly common oversight, but it’s incredibly dangerous–you’re essentially letting anyone access your network who bothers to test it.

4. In the event of a data breach, be prepared to shut down your networks immediately to keep an intrusion from spreading.

HOA Cybersecurity Tip #6:

Manage Mobile Devices

Will you allow employees and board members to use their personal smartphones, tablets, and laptops for association business; or should they acquire a second set of devices strictly for business use? Here are the considerations:

Pros of BYOD

Pros of BYOD: On one hand, using personal devices (an increasingly popular movement known as bring-your-own-device, or BYOD) can increase productivity by allowing employees and board members to bring work and communication tools with them everywhere they go. In addition, it saves you the expense of buying a second set of devices.

Cons of BYOD

On the other hand, allowing sensitive data to live alongside personal files and apps is a significant risk. Employees and board members will have to use their devices in a certain way, such as always using a six-digit passcode to unlock their phones.

HOA Cybersecurity Tip #7:

Defend Your Email

Don’t get caught up in the common misconception that your inbox doesn’t contain anything sensitive. As we discussed in last week’s Cybersecurity 101 post, personally identifiable information (PII) like email addresses, full names, and billing addresses are extremely attractive to hackers! Here are the steps that you need to take to protect your messages from cybercriminals:

1. Require extra-strong email passwords among your employees and board members. According to our security expert, your email tends to be the center of all of your accounts–if it’s breached, the rest of your accounts are at risk. Use the password tips that we recommended in the previous section to the max.

2. Learn how to recognize phishing scams:

    • Never click on a link or open a file in an unsolicited email from an unknown sender.
    • Be suspicious of emails that end in a foreign extension (e.g. ‘.co.uk’) rather than .com or .gov.
    • Don’t open files that end in .exe, .bat, or .pif unless you’re expecting the file from someone that you know. Keep in mind that even files from people that you know could be viruses if their device has been compromised, so always check with them before opening unexpected files.
    • Hover over any links before clicking on them to see where they will actually direct you.
    • Be skeptical of links that don’t begin with ‘https,’ which signifies that a site has been authenticated and is encrypted to protect your data.
    • Be suspicious of odd grammatical mistakes, poor graphic quality, or offers that seem too good to be true.
    • Don’t trust emails that say, “Your account will be suspended unless you log in now”–and don’t click on that link or enter any account information! Go directly to the company’s website instead.
    • If you do open a suspicious link by accident, shut down the device immediately.

3. Educate your employees & board members. A number of companies (including Duo & Wombat) now enable you to send simulated phishing emails to groups of employees to see how they respond, then train them accordingly. It’s particularly critical to train anyone involved in your finances–they’ll be the most common targets of these attacks, as cybercriminals aim to hijack your financial information and gain access to your funds.

HOA Cybersecurity Tip #8:

Bring in Experts

Hire IT & security staff, whether full-time or as contractors. They’ll review any existing HOA cybersecurity measures that you have in place, make recommendations for how to improve your standing, and make any necessary upgrades that you can’t take care of yourself. It’s important to admit where your expertise may fall short when it comes to HOA cybersecurity. Investing in cybersecurity efforts costs far less in the long-term than crossing your fingers and hoping for the best.

Our security expert recommends forming a co-op with other associations or small businesses and jointly hiring a staff of experts to attend to your issues. In addition, your association manager can likely make helpful recommendations and referrals.

HOA Cybersecurity Tip #9:

Iron Out Your Vendor SLAs

What happens if a vendor that you work with has a security breach–and your association’s data is involved?

As a vital part of your HOA cybersecurity efforts, you should update all of your third party contracts to specify who’s responsible for protecting your association’s data. Just because a supplier is directly handling or storing your data does not mean that you’re off the hook in the event of a breach. You’re the one who chose to place your owners’ and employees’ data in their hands–so they’ll go straight to you with their complaints.

Have these tough conversations about HOA cybersecurity before you sign on the dotted line. Have a lawyer review all contracts–those that you’ve already signed, as well as those that you’re considering. Have each supplier’s security practices audited to make sure that they’re actually following the protocol that your contract lays out. You’re not being nosy or accusatory–you’re protecting your association. If they don’t have strict cybersecurity measures in place, you should absolutely reconsider your relationship with them. After all, even if you’re not held liable for a data breach on their end, it’s your association whose name will be dragged through the mud.

Multifamily Executive advises:

“Contractual provisions that detail how your suppliers protect sensitive information and address data breaches should be strongly negotiated by both parties to ensure the agreements reflect the realities of today’s challenging cyber landscape. […] This can be achieved through a data security questionnaire or a formal [request for proposal] process that requires suppliers to provide specific information on these issues. Clients may also ask for any assessments the suppliers have conducted (and the results and mitigation plan) or certifications they may have. […] Firms should establish an internal review process to ensure that adequate protections are included in all supplier contracts that have the potential to deal with sensitive information. […] Your contract provisions should have explicit details on:

  • Data use approval and sharing obligations
  • Data security and privacy standards
  • Accountability and liability
  • Breach notification obligations and disclosures
  • Investigation cooperation expectations
  • Indemnification
  • Compliance audits
  • Cyber insurance requirements”

HOA Cybersecurity Tip #10:

Consider Cyber Liability Insurance

This is an area of insurance that is rapidly evolving to cover the risks of doing business in our hyper-connected world. Insurance companies can’t adapt to changing technologies at the pace that they need to, but some coverage in this area is likely better than nothing. General liability insurance typically won’t cover the impacts of a data breach on your association. The closest that standard policies come to covering these events is providing business interruption insurance, which still comes up short.

HOA cybersecurity is a topic worth discussing with your insurance provider. Experts advise that if the subject has never come up, it’s safe to say that you’re not covered for anything.

HOA Cybersecurity Tip #11:

Fight Data Breach Fatigue

We’ve all been inundated with headlines about cyberattacks in recent years; and it’s simultaneously made us paranoid and complacent about our own security. There’s a phenomenon known as “breach fatigue” that describes the way that our reactions to data breaches shift over time, gradually devolving from outright panic to apathy. We all have to consciously fight this instinct–because, as Consumer Affairs reminds us:

“Such an attitude only benefits the hackers. It’s one thing to deal with breach fatigue by deciding ‘To heck with these hackable credit cards, I’ll just use cash,’ but another matter entirely to deal with it by deciding ‘I’ll continue using credit cards, but I can’t be bothered to check whether they’ve been breached or not.’ Various forms of ‘can’t be bothered’ fatigue is exactly what certain types of scammers count on to make their dishonest profits. […] Yes, you’re tired of all those reminders to inspect your credit card statements and look for fraudulent charges and change your account numbers and passwords every time a hacker might’ve seen the old ones. But hackers and scammers want you to feel this way. Their intention is to spy on or steal from you, and if you give in to breach fatigue, you’ll only make it easier for them to succeed.”

Robin Burinskiy is the Senior Content Writer and Managing Editor for the All Property Management Blog and Buildium Blog. She cut her teeth as a marketing copywriter at Wayfair and TechTarget, and she spends her free time perfecting her lifestyle blog, Feather & Flint. She holds degrees in psychology, sociology, and songwriting.