If we need to do a data breach notification...

Preemptively, I'd like to flag that we should connect around strategy if it's appropriate for all WordFly-based orgs to reach out to our patrons about the ransomware data breach.

I have absolutely nothing deeper than that to say yet, but it occurred to me earlier today that, should we need to do this, a good number of tri-state area people may suddenly be on the receiving end of dozens of alarming notifications and make the issue feel even larger. A coordinated notification may be a better approach.

Should today's Town Hall reveal that we ought to pursue this, we'll spin up an initial Zoom or something along those lines.

Please go ahead and use this thread to note ideas or even just interest.

CC: to the NJ folks, and

  • Hi - 

    The majority of you presumably just got an email notification via the Event Invite functionality, but to connect this to that: https://community.tessituranetwork.com/local_tessitura_user_groups/greaternyc/c/e/1037#

    Also, should anyone not be to participate directly but do have leeway to indicate whether their organization intends to communicate with patrons, if that info is anonymized/shared only as part of a total count, I'm happy to try to figure out how we play by the rules while getting some clear indication of expected activity. (No subterfuge meant here, sorry for any sinister vibe I didn't manage to edit out--I simply know I value a statement like 30 orgs are opting not to notify and 10 haven't decided as much, if not more so, than Theater A is doing X, Theater B is doing Y, etc. I don't currently know what accomplishes this, but I promise to be as confidential as anyone requires.)

  • I appreciate the contribution, David, and like this new option of a note rather than a dedicated communication--always the best strategy to try to identify all the permutations something could take rather than assuming there's only a binary.

  • July 25 Zoom Recap:

    • We had 18 attendees representing about 12 organizations. (Possibly represents ~25% of area WordFly users.)
    • The unanimous view of all present is that we are still in a holding pattern re: any constituent communication.
      • No one present has concluded that the known data in question requires notification, and is not currently inclined to message about this. 
      • Without access to reconfirm our data fields within WordFly, it's hard to verify more.
      • Most/all present have not yet pursued any alternative email platform, so it also makes sense to allow for more time/knowledge while we don't have a ready way to communicate anyway.
      • We may want to reconvene in a week / when we have a more complete set of info.
    • There was, however, also a group consensus that a coordinated approach feels key, should things change. While we may (likely) will need to send independently, we'll want to collaborate to ensure that our patrons do not receive similar but varied explanations from us, as that's potentially very confusing.
    • Segmentation of who to notify, should notification become the plan, will be an important consideration. It could likely make sense to focus on those with a particular field of uploaded data, rather than all records.NYTUG WordFly Meeting Notes 7.25.22.docx.pdf

    A longer, more transcript-like set of notes is attached. Thanks to Lauren Cartelli for keeping up with conversation on her keyboard.

  • Good morning -

    Let's re-poll our community preferences around sending notifications out to constituents, as we had good news from WordFly and have at least a bit more concrete information than we previously did.

    https://forms.gle/FXw1aUVv1jJLeB4YA

    I've included new response choices to indicate having already sent something out, as well as an option to "decline to answer." I am hoping the latter allows representatives of more organizations to indicate they're following the conversation, even if they can't share plans--it's helpful to know how many of us are represented.

    Also, acknowledging: Many/most of us are expecting to keep evaluating as we learn more about who is or isn't doing a patron notification. Please consider this baked into the response you give now, ie preference/plan only as the landscape stands right now.

    I'll figure out a way to share a graph of the results here.

    Last quick note: This is a log of web links to notifications that have gone out (none local at the moment). If you have others to add to this reference, please send me the web link at jobrien@new42.org and I'll add them in.

  • Hi all, and happy return of WordFly day.

    To echo an email I just sent out to some people directly, it seems like the scale is starting to tip towards more patron notifications. As such, I'll convene a conversation space for an effort to have joint/coordinated communications.

    As a first step, I'm running a Doodle to determine which time slot works for the most people/organizations. If you'd like to actively participate in this planning, feel free to weigh in about time via the Doodle. Once confirmed, the appointment and Zoom info will go out via this forum.

  • Pre-Monday morning quick note:

    There are enough Mon afternoon and Tues morning indications of availability that we will be able to use one of those times instead of first thing Mon. I can’t edit the Doodle to remove it though.

    I’ll finalize the actual time on Monday morning—add your reply before 11am please, if you’d like to weigh in on preference.

  • Good morning - 

    The next round of conversation is now available for registration at https://community.tessituranetwork.com/local_tessitura_user_groups/greaternyc/c/e/1042 . This time slot slightly edged out the rest. If you/your org isn't able to attend, we'll get some notes shared out.

  • Hello all,

    I am interested in understanding what legal advice the assorted internal legal teams have been providing. It would be helpful to learn that during our call. 

    Susan

  • Good afternoon -

    Here are the notes from this morning's call. Agenda & Notes _ Greater NYC Community_ Pooled Data Exfiltration Notification Conversation (Aug 2).pdf

    Given our discussion has revolved around how many notifications could go out, I'm going to find it helpful to have a current reference as to who is not planning a notification and yesterday was a major change to earlier equations. So, since I assume I'm not the only one interested and hopefully for the last time, here's a quick poll. As the other have had, there are answer choices of 'do not know' and 'decline to respond' (which helps show community participation in the conversation, if no other detail).

    The poll response graph will be visible here once there's data flowing into it.