Ransomware attack - who pays the costs of notifying the affected supporters

As we are expected to contact anyone who may have had their details stolen during the, who pays the costs of notifying the affected supporters?

Blackbaud will need to compensate charities, as its going to be an extra cost to contact all the supporters affected.

Can someone give us that information please?


Thanks



 

 


Comments

  • This is a good question, and one that did not come up in the webcast today - they focused more on "most orgs will not need to notify" (but what about the ones that do?)


    I'm curious about the answer.
  • I got this answer


    We will honour our contractual obligations to your organisation.  Most of our customers will determine they are not required to notify their constituents.  If you determine you do need to notify your constituents and you believe this type of reimbursement is explicitly provided for in your contract, you can submit a request for review and consideration after you have concluded notification and paid your associated expenses. We will ask you to provide some information that you will only have after concluding your notifications. Please enter it in this form, https://hello.blackbaud.com/Request-for-Reimbursement.html


    What webcast was that?
  •  

    Thank you, Dawn Cox‍! 


    The webcast was in the Incident Resources link for those who have access - 

    live webinars with our Director of Privacy and Chief Information Security Officer

    Friday, July 17 10 a.m. ET

    Friday, July 17 4 p.m. ET

    Tuesday, July 21 10 a.m. ET

    Tuesday, July 21 4 p.m. ET

    Thursday, July 23 10 a.m. ET

  • More discussion over in the RE (non NXT) forum you may want to look at https://community.blackbaud.com/forums/viewtopic/147/51457. Hiding behind a "we aren't legally required" to notify is pretty bad in my opinion. Own up to it and the potential issues it causes.


    Brian Hoyt