Articles

Cybersecurity Awareness Month: Protecting Housing Associations from Digital Threats

As Cybersecurity Awareness Month rolls around this October, the Cybersecurity and Infrastructure Security Agency (CISA) is proud to work with NAHRO to remind housing associations to focus on the increasingly critical issue of cybersecurity. With more associations managing large volumes of sensitive data, such as residents’ personal information, financial records, and property management systems, they are becoming prime targets for cybercriminals.  

Whether you’re a small redevelopment authority, or a large public housing community, the threats, and how to mitigate them, is essential to protecting your organization, your employees, and residents you serve. We have seen firsthand how housing authorities have been scammed by fake vendor invoices and have been victims of ransomware attacks. Vulnerable residents are victims too, as hackers have stolen personal data, and can also be subject to personal cyber attacks that impact their families.   

Secure Our World during Cybersecurity Awareness Month 

Cybersecurity Awareness Month (CAM) is an annual initiative that takes place every October. Since 2004, the President of the United States and Congress have declared the month of October to be Cybersecurity Awareness Month, a dedicated month for the public and private sectors to work together to emphasize the importance of cybersecurity.  

The purpose of this month-long campaign, led by CISA, is to raise awareness cyber threats, and the importance of cybersecurity. Throughout the month, CISA provides resources and information to help individuals and organizations stay safe online. The theme of Cybersecurity Awareness Month is CISA’s Secure Our World program. The overarching goal of the Secure Our World program is to create a culture of cybersecurity awareness and to ensure that good cybersecurity practices become, and remains, a natural part of everyone’s daily digital life. Being safe online is a year-round habit we should all develop. 

The Growing Importance of Cybersecurity in Assisted Housing 

Public Housing Agencies (PHAs) and other community development organizations provide crucial support to some of our most vulnerable populations. You manage a wide array of sensitive data, such as tenant financial records, personal information, internal documents, and communications of the organization. This makes PHAs attractive targets for hackers looking to exploit vulnerabilities for financial gain or data theft. Additionally, as more PHAs adopt digital management systems, online tenant portals, and cloud storage, the risk of cyber related attacks increases. PHAs invest in residents but they don’t always have sufficient resources to build a strong cybersecurity organization. That amplifies the potential for attacks. 

A successful cyberattack could not only compromise tenant privacy but also the operational functionality of the organization. Could you imagine what would happen if an PHA lost access to property management systems or tenant data due to a ransomware attack? Rent collections, maintenance requests, and even tenant safety could be jeopardized. 

Common Cybersecurity Threats to Housing Authorities and Assisted Housing Organizations 

  1. Ransomware Attacks: Hackers may encrypt an organization’s systems, demanding payment to restore access. This can lead to delays in rent collection, tenant communication, and maintenance scheduling, all of which could disrupt services. 
  1. Phishing Scams: Cybercriminals often target employees and board members with emails that appear legitimate but contains malicious links. Clicking these links can provide hackers with access to sensitive systems or allow them to steal login credentials. 
  1. Data Breaches: Housing associations store a vast amount of personally identifiable information (PII), such as tenant names, addresses, and financial details. A cybersecurity breach can lead to identity theft or financial fraud, severely damaging trust with residents. 
  1. Weak Passwords: Employees may reuse passwords across multiple platforms, making it easier for hackers to gain access to systems. Without security measures such as password managers or multifactor authentication, unauthorized individuals can infiltrate internal systems. 
  1. Business Email Compromise: These attacks gain access to email accounts and send messages impersonating the account holder to try to convince the target to make a fraudulent transaction. Payroll or purchasing departments are often targets where the scammers try, for example, to change employee direct deposit information, or send fake invoices for services that look legitimate. They may try to request a change to bank account details or payment methods. 

Why Cybersecurity Matters for Housing Associations 

  1. Resident Trust: Residents trust housing authorities with their personal and financial data. A data breach can severely damage that trust, potentially leading to resident dissatisfaction and even legal actions such as lawsuits. 
  1. Regulatory Compliance: Housing organizations are subject to regulations around data protection. Non-compliance due to a security breach can result in significant fines and legal repercussions. 
  1. Operational Continuity: Cyberattacks can disrupt housing operations, disabling everything from communication to property maintenance. For many associations, the ability to function seamlessly is vital to the quality of life for residents. 

CISA’s Secure Our World Program 

In 2023, CISA launched its newly founded cybersecurity awareness program, Secure Our World, which is the enduring theme for all future Cybersecurity Awareness Months. This theme recognizes the importance of taking daily action every day to reduce risks when online and connected to devices. Housing authorities, community development organizations, and associations such as NAHRO can use CISA’s Secure Our World theme and resources when planning for the 2024 and future Cybersecurity Awareness Month campaigns.   

Below are the simple actions we should all take not only during October, but every day throughout the year to stay safe online.  

Key Strategies to Strengthen Cybersecurity 

  1. Implement Strong Password Policies and Utilize Password Managers: Encourage the use of strong, random and unique passwords and ensure that employees don’t use the same passwords for different systems. Better yet, institute a password manager, or single sign-on authentication to reduce password fatigue.  
  1. Turn on Multifactor Authentication: Utilizing multi-factor authentication (MFA) for system logins can significantly reduce unauthorized access and add an extra layer of security. Phishing resistant MFA, like a biometric requirement or password key makes MFA event stronger. 
  1. Update Software: Ensure that all software, including property management systems and tenant portals, is updated regularly to address vulnerabilities. Outdated software can be a major entry point for hackers. Enable automatic updates for all organization devices. 
  1. Recognize and Report Phishing and Scams: If you suspect phishing or that you are being scammed or tricked, resist any temptation to click on links or attachments. Instead, report the phish to protect yourself and others.  

All the principles of these four actions can also be used by residents and we encourage housing authorities to share resources that help resident project themselves. CISA’s Secure Our World resources are useful guides for online safety for employees, vendors and residents alike.