If we need to do a data breach notification...

Preemptively, I'd like to flag that we should connect around strategy if it's appropriate for all WordFly-based orgs to reach out to our patrons about the ransomware data breach.

I have absolutely nothing deeper than that to say yet, but it occurred to me earlier today that, should we need to do this, a good number of tri-state area people may suddenly be on the receiving end of dozens of alarming notifications and make the issue feel even larger. A coordinated notification may be a better approach.

Should today's Town Hall reveal that we ought to pursue this, we'll spin up an initial Zoom or something along those lines.

Please go ahead and use this thread to note ideas or even just interest.

CC: to the NJ folks, and

  • Co-sign this approach, Jean -- this is exactly what we've been talking about at Playwrights. IF we send a communication, we think it should be unified and led by -- and even sent from -- WordFly. We want to avoid patrons getting multiple messages from multiple orgs. 

  • Following and agreed! We would love to be involved in a unified notification, as suggested above. 

  • Chiming in to agree and wondering if anyone has heard anything new or if anyone has seen any org's sending out a communication. 

  • The Goodman Theater in Chicago sent out a notification.

  • After gathering information from three of Smithsonian’s units that uses Wordfly, our privacy council has met and is drafting language now for a message. Cooper Hewitt is the only NYC-based unit so I’ve been monitoring this group along with the Smithsonian conversations.


    Pamela Horn
    Lead Content Strategist  and
    Director of Cross-Platform Content
    Cooper Hewitt, Smithsonian Design Museum
    2 East 91st St.
    New York, NY 10128
    212.849.8361

    On Jul 21, 2022, at 12:59 PM, Kari Shaffer <bounce-karishaffer5692@tessituranetwork.com> wrote:

    
    External Email - Exercise Caution
    Tessitura_2D00_Network_2D00_logo_5F00_1500x421-png_2D00_150x42-png.png Update from Tessitura Network
    4U9MDYL4KXJU-jpg_2D00_70x70x2-jpg.jpg
    Kari Shaffer

    So did the Shed in NYC.

    View online

     

    You received this notification because you subscribed to the forum.  To unsubscribe from only this thread, go here.

    Flag this post as spam/abuse.

  • Hi everyone - 

    With the little burst of activity in this thread, I thought I'd pop quickly in to do a (non)update.

    I'm back at regular operations after two days on jury duty, so I can get back to facilitating a real-time space for us before the end of the day. I'm aiming for Mon or Tues (but generally haven't gotten much further in my brain).

    If you didn't do the earlier survey about your orgs current intentions or want to log an update, please do. 

    Also, I want to acknowledge/put it on everyone's radar that, for some orgs, anything with any question of a data breach (even when already commented on as not qualifying as one by external counsel) immediately moves the conversation away from those who participate in our forums and over to legal or security task forces. So, as you try to identify trends, I caution us all to remember that there are a lot of voices not represented here.

    More soon,

    Jamie

  • My understanding is that their email only went to a small segment of their audience, not the full list.

  • Jumping in from The Shed—we did send to all members and donors from the past 2 years yesterday, and plan to extend to more as our new IP continues warming.

  • Just wanted to report that about 36 people from a wide range of New England institutions met on a Zoom call yesterday afternoon. The general consensus seemed to lean toward a coordinated and somewhat low key announcement that organizations would include in a pre-existing monthly e-newsletter. A draft for coordinated language was discussed, and is now being revised. The suggested timeline was for orgs to send out with existing mailing(s) sometime between August 1 and August 12.  (Some orgs may be unable to do this if Wordfly isn't back up by then, so that remains an open question.) The general sense was that for almost everyone the information that could have been disclosed does not meet the standard that triggers legal requirements under Massachusetts law (which was home base for most of the orgs), but that it was still best practice to disclose what we know.

    There is some hope that by then Wordfly will have stood up a more subscriber-focused FAQ that we can link at the bottom of this announcement. If not, there was discussion of linking to their existing bulletin.

    Can continue to report on this and/or make connections if coordination between New York and New England orgs seems useful.