Reading materials - Click here to Start!
1. Understand common online risks
Understanding Common Online Risks
The internet provides many opportunities for committees and community groups to connect with their communities, promote events, and share information. However, using digital tools and social media also brings risks that can affect individuals, organisations, and the people they work with. Understanding these risks is the first step towards staying safe online and protecting your organisation's reputation, information, and resources.
Online risks can affect anyone, regardless of their level of experience or technical ability. By learning how to recognise common threats and adopting safe online practices, committees can reduce the likelihood of becoming victims of cybercrime or online misuse.
Why Online Safety Matters
Many community organisations now use:
- Email and cloud storage.
- Social media accounts.
- Online banking.
- Digital membership records.
- Video conferencing platforms.
- Online surveys and engagement tools.
If these platforms are not managed securely, organisations may experience financial loss, reputational damage, loss of information, or disruption to their activities.
Phishing Scams
Phishing is one of the most common online threats.
A phishing attempt may arrive as an email, text message, social media message, or website that appears legitimate but is designed to:
- Steal passwords.
- Obtain personal information.
- Trick users into sending money.
- Install malicious software.
Warning signs include:
- Urgent requests for action.
- Unexpected attachments.
- Requests for passwords or banking details.
- Suspicious links.
- Poor spelling or unusual language.
Always verify requests before responding or clicking on links.
Weak Passwords and Unauthorised Access
Using weak or reused passwords increases the risk of accounts being compromised.
Good password practice includes:
- Using strong, unique passwords.
- Enabling two-factor authentication (2FA).
- Avoiding password sharing.
- Updating passwords when access changes.
Committees should ensure that multiple trusted individuals can access key organisational accounts without compromising security.
Social Media Risks
Social media can be a valuable communication tool, but it also presents risks.
Examples include:
- Inappropriate or offensive posts.
- Fake accounts impersonating an organisation.
- Online harassment or abuse.
- Misinformation.
- Accidental sharing of confidential information.
Having clear social media guidelines and designated account administrators can help reduce these risks.
Malware and Ransomware
Malware is harmful software designed to damage, disrupt, or gain unauthorised access to devices and systems.
Examples include:
- Viruses.
- Spyware.
- Ransomware.
Ransomware can lock access to files and demand payment for their release. Malware often spreads through suspicious links, attachments, or compromised websites.
Keeping software updated and avoiding unknown downloads can reduce the risk.
Protecting Personal Information
Many committees collect information about members, volunteers, or service users.
Examples may include:
- Names and contact details.
- Membership records.
- Volunteer information.
- Event registrations.
This information should be stored securely and only accessed by authorised individuals. Organisations should take appropriate steps to protect personal data and avoid accidental disclosures.
Online Meeting Risks
Video conferencing and online meetings have become increasingly common.
Potential risks include:
- Unauthorised attendees.
- Sharing confidential information.
- Weak meeting security settings.
- Recording meetings without permission.
Meeting organisers should use secure settings and ensure participants understand any ground rules.
Creating Good Cyber Habits
Simple actions can significantly improve online safety:
- Think before clicking links.
- Keep devices updated.
- Use strong passwords and 2FA.
- Back up important files.
- Be cautious about sharing personal information online.
- Report suspicious messages or activity promptly.
Cyber security is everyone's responsibility, not just that of one committee member.
Reflection Activity
Think about your organisation's online activities.
- What online accounts does your committee currently use?
- Who has access to them?
- How are passwords managed?
- Could a phishing email be easily recognised by committee members?
- What steps could be taken to improve online security?
Write down three actions your organisation could implement to improve its cyber resilience.
Further Reading and Resources
CyberScotland
Scotland's national cyber resilience hub, providing advice, guidance, training, and resources for individuals, community groups, and organisations.
-
Individuals & Families Resources:
Individuals & Families - Cyber Scotland
National Cyber Security Centre (NCSC)
UK Government guidance on staying safe online, spotting scams, securing accounts, and responding to cyber incidents.
-
The National Cyber Security Centre | National Cyber Security Centre
-
Phishing Scams Guidance:
Phishing | National Cyber Security Centre
Scottish Government: Cyber Advice and Support
Information on cyber resilience, reporting incidents, and accessing trusted support and guidance in Scotland.
Information Commissioner's Office (ICO)
Guidance on data protection, information security, passwords, cyber security, and protecting personal information.
Get Safe Online
Free practical advice on online safety, scams, privacy, and protecting devices for individuals and organisations.
Key Message
Online risks are a normal part of using digital technology, but many can be avoided through awareness and good security practices. By understanding common threats such as phishing, weak passwords, malware, and data breaches, committees can use online tools with greater confidence and help keep their organisation and community safe