RENXT Security / Anti-Hacking Measures

Hi everyone,

Following the news of a recent cyberattack on another CRM system (not Blackbaud, and not one we use), I started wondering about how protected RE NXT data would be in a similar scenario.

If an attacker were able to obtain a copy of a database backup, would Blackbaud's encrypted fields remain unreadable within that backup, or are there limitations to that protection?

Also, has this influenced what types of constituent or supporter information you do or don't store in RE NXT? I'd be really interested to hear how others are balancing usability with security and data minimisation.

Thanks!

Answers

  • Rachel Cavalier
    Rachel Cavalier Community All-Star
    Eighth Anniversary Kudos 5 2026 bbcon Attendee Badge August 2026 Monthly Challenge: Preparing for bbcon

    I was thinking about this because I'm a supporter of a couple of charities who use the CRM you're probably talking about, and I got their notification emails about the attack on Monday.

    I don't think this has influenced the type of information we store or how long we retain it in RE NXT any more than GDPR and other previous regulations and internal policies already had done so. I think some of my colleagues would love if we had more demographic information about our supporters, but it's just not something we've ever really collected so it's not in there.

    Additionally, the database for the people we serve is unconnected to RE - so the more sensitive data that could potentially be there is kept separate. The only "connection" is that someone checks our list of supporters who have passed away in the last week and updates the records of any that match in that database.

  • Suzie, good questions. You might find helpful the links in the 4th-6th bullets from this page of my website:

    image.png

    https://billconnors.com/resources

Categories