Thread regarding Blackbaud Inc. layoffs

Any1 feel like BB was overly punished for the security incident?

feel like the number of requirements/systems/processes we've implemented, are currently implementing, or will implement in the future, as a result of that are starting to be a bit much

by
| 1161 views | | 8 replies (last March 31, 2025) | Reply
Post ID: @OP+1jq7zdec9

8 replies (most recent on top)

The punishment isn't the problem, it's how the securitah apparatus interprets it in the worst possible way every chance they get without any recourse.

by
| | Reply
Post ID: @13y+1jq7zdec9

To whoever posted this and is defending their post in the comments:

Just stop. Please. You sound ignorant and I question how qualified you are to even possess an opinion regarding Blackbaud's punishment or the cybersecurity changes Blackbaud is making.

Blackbaud deserves every bit of backlash and penalties they've faced from this incident. There are people who screamed from the mountaintops for years and warned their leadership team of the vulnerabilities in our software and infrastructure. There are people who warned leadership teams that we were spreading information to customers when we told customers that no sensitive information was accessible in the client databases. The entire leadership team should have been fired over this. They willfully disregarded critical cybersecurity risks and put millions of people at risk of having their identity stolen.

As far as Blackbaud's cybersecurity and infrastructure changes in response to this incident, they should have made these changes decades ago. They are not overreacting and phish resistant MFA is a bare-minimum. Do you even know what phish-resistant MFA is? Have you actually been paying attention to the mandatory cybersecurity trainings that CorpIT requires us to take every year?

We're talking about a company who hosts and manages DONOR and FINANCIAL DATA. If you think Blackbaud is "overreacting" to this incident, then maybe you shouldn't be at Blackbaud, or this industry for the matter.

The fact that this is coming from a tech employee in 2025 scares me and really sheds light for why Blackbaud is in its current situation.

Do better. The industry you serve deserves better.

by
| | Reply
Post ID: @ss+1jq7zdec9

maybe downvoted for being misunderstood. i am not talking about punishments related to leadership individuals at all

most of these are good practices that orgs are indeed doing today, but not all.. just one example off the top of my head is phish resistant MFA. almost like we're a guinea pig and being forced to buy a crapton of 3rd party software

by
| | Reply
Post ID: @j9+1jq7zdec9

Considering Support was basically told to lie to clients reaching out about it, no....no I don't think the punishment was too harsh.

by
| | Reply
Post ID: @gs+1jq7zdec9

Most of the actual requirements are good practices. It is BB's leadership that makes implementation painful for just about anything.

So many meetings. Lots of staff that are not hands-on with technical work. Too few people who can implement changes.

by
| | Reply
Post ID: @cc+1jq7zdec9
  • no. These are good best practices that most places are already doing.
by
| | Reply
Post ID: @c4+1jq7zdec9

If that makes you mad, just wait until you hear about the ELT’s disastrous M&A record. That is where we will be punished.

by
| | Reply
Post ID: @c2+1jq7zdec9

2022 wants this comment back

by
| | Reply
Post ID: @bs+1jq7zdec9

Post a reply

: