1. Understand common online risks

Understanding Common Online Risks

The internet provides many opportunities for committees and community groups to connect with their communities, promote events, and share information. However, using digital tools and social media also brings risks that can affect individuals, organisations, and the people they work with. Understanding these risks is the first step towards staying safe online and protecting your organisation's reputation, information, and resources.

Online risks can affect anyone, regardless of their level of experience or technical ability. By learning how to recognise common threats and adopting safe online practices, committees can reduce the likelihood of becoming victims of cybercrime or online misuse. 


Why Online Safety Matters

Many community organisations now use:

  • Email and cloud storage.
  • Social media accounts.
  • Online banking.
  • Digital membership records.
  • Video conferencing platforms.
  • Online surveys and engagement tools. 

If these platforms are not managed securely, organisations may experience financial loss, reputational damage, loss of information, or disruption to their activities.


Phishing Scams

Phishing is one of the most common online threats.

A phishing attempt may arrive as an email, text message, social media message, or website that appears legitimate but is designed to:

  • Steal passwords.
  • Obtain personal information.
  • Trick users into sending money.
  • Install malicious software. 

Warning signs include:

  • Urgent requests for action.
  • Unexpected attachments.
  • Requests for passwords or banking details.
  • Suspicious links.
  • Poor spelling or unusual language. 

Always verify requests before responding or clicking on links.


Weak Passwords and Unauthorised Access

Using weak or reused passwords increases the risk of accounts being compromised.

Good password practice includes:

  • Using strong, unique passwords.
  • Enabling two-factor authentication (2FA).
  • Avoiding password sharing.
  • Updating passwords when access changes.

Committees should ensure that multiple trusted individuals can access key organisational accounts without compromising security.


Social Media Risks

Social media can be a valuable communication tool, but it also presents risks.

Examples include:

  • Inappropriate or offensive posts.
  • Fake accounts impersonating an organisation.
  • Online harassment or abuse.
  • Misinformation.
  • Accidental sharing of confidential information. 

Having clear social media guidelines and designated account administrators can help reduce these risks.


Malware and Ransomware

Malware is harmful software designed to damage, disrupt, or gain unauthorised access to devices and systems.

Examples include:

  • Viruses.
  • Spyware.
  • Ransomware.

Ransomware can lock access to files and demand payment for their release. Malware often spreads through suspicious links, attachments, or compromised websites.

Keeping software updated and avoiding unknown downloads can reduce the risk.


Protecting Personal Information

Many committees collect information about members, volunteers, or service users.

Examples may include:

  • Names and contact details.
  • Membership records.
  • Volunteer information.
  • Event registrations.

This information should be stored securely and only accessed by authorised individuals. Organisations should take appropriate steps to protect personal data and avoid accidental disclosures. 


Online Meeting Risks

Video conferencing and online meetings have become increasingly common.

Potential risks include:

  • Unauthorised attendees.
  • Sharing confidential information.
  • Weak meeting security settings.
  • Recording meetings without permission. 

Meeting organisers should use secure settings and ensure participants understand any ground rules.


Creating Good Cyber Habits

Simple actions can significantly improve online safety:

  • Think before clicking links.
  • Keep devices updated.
  • Use strong passwords and 2FA.
  • Back up important files.
  • Be cautious about sharing personal information online.
  • Report suspicious messages or activity promptly.

Cyber security is everyone's responsibility, not just that of one committee member.


Reflection Activity

Think about your organisation's online activities.

  1. What online accounts does your committee currently use?
  2. Who has access to them?
  3. How are passwords managed?
  4. Could a phishing email be easily recognised by committee members?
  5. What steps could be taken to improve online security?

Write down three actions your organisation could implement to improve its cyber resilience.


Further Reading and Resources

CyberScotland

Scotland's national cyber resilience hub, providing advice, guidance, training, and resources for individuals, community groups, and organisations.


National Cyber Security Centre (NCSC)

UK Government guidance on staying safe online, spotting scams, securing accounts, and responding to cyber incidents.


Scottish Government: Cyber Advice and Support

Information on cyber resilience, reporting incidents, and accessing trusted support and guidance in Scotland.


Information Commissioner's Office (ICO)

Guidance on data protection, information security, passwords, cyber security, and protecting personal information.


Get Safe Online

Free practical advice on online safety, scams, privacy, and protecting devices for individuals and organisations.


Key Message

Online risks are a normal part of using digital technology, but many can be avoided through awareness and good security practices. By understanding common threats such as phishing, weak passwords, malware, and data breaches, committees can use online tools with greater confidence and help keep their organisation and community safe