<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>Vortacity Blog</title>
    <link>http://www.vortacity.com/vortacity-blog</link>
    <description>Expert cybersecurity insights, threat intelligence, and practical security guidance for associations, nonprofits, and small businesses. Stay ahead of evolving cyber threats with Vortacity.</description>
    <language>en</language>
    <pubDate>Mon, 22 Jun 2026 21:20:33 GMT</pubDate>
    <dc:date>2026-06-22T21:20:33Z</dc:date>
    <dc:language>en</dc:language>
    <item>
      <title>Associations Need Better Visibility, Not More Cybersecurity Tools WordPress Excerpt - Vortacity</title>
      <link>http://www.vortacity.com/vortacity-blog/associations-need-better-visibility-not-more-cybersecurity-tools-wordpress-excerpt</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="http://www.vortacity.com/vortacity-blog/associations-need-better-visibility-not-more-cybersecurity-tools-wordpress-excerpt" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.vortacity.com/hubfs/Imported_Blog_Media/ChatGPT-Image-Jun-16-2026-04_10_49-PM.png" alt="Associations Need Better Visibility, Not More Cybersecurity Tools WordPress Excerpt - Vortacity" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p class="isSelectedEnd"&gt;Associations do not need more security dashboards. They need better visibility into what is happening across identity, email, cloud systems, and member-facing platforms.&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="http://www.vortacity.com/vortacity-blog/associations-need-better-visibility-not-more-cybersecurity-tools-wordpress-excerpt" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.vortacity.com/hubfs/Imported_Blog_Media/ChatGPT-Image-Jun-16-2026-04_10_49-PM.png" alt="Associations Need Better Visibility, Not More Cybersecurity Tools WordPress Excerpt - Vortacity" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p class="isSelectedEnd"&gt;Associations do not need more security dashboards. They need better visibility into what is happening across identity, email, cloud systems, and member-facing platforms.&lt;/p&gt;  
&lt;img src="https://track-na2.hubspot.com/__ptq.gif?a=46362935&amp;amp;k=14&amp;amp;r=http%3A%2F%2Fwww.vortacity.com%2Fvortacity-blog%2Fassociations-need-better-visibility-not-more-cybersecurity-tools-wordpress-excerpt&amp;amp;bu=http%253A%252F%252Fwww.vortacity.com%252Fvortacity-blog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Cybersecurity for Associations</category>
      <category>TrapLine</category>
      <category>Cybersecurity</category>
      <pubDate>Sun, 07 Jun 2026 20:02:40 GMT</pubDate>
      <guid>http://www.vortacity.com/vortacity-blog/associations-need-better-visibility-not-more-cybersecurity-tools-wordpress-excerpt</guid>
      <dc:date>2026-06-07T20:02:40Z</dc:date>
      <dc:creator>Ben Muscolino</dc:creator>
    </item>
    <item>
      <title>Associations Have a Bigger Attack Surface Than They Think - Vortacity</title>
      <link>http://www.vortacity.com/vortacity-blog/associations-have-a-bigger-attack-surface-than-they-think</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="http://www.vortacity.com/vortacity-blog/associations-have-a-bigger-attack-surface-than-they-think" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.vortacity.com/hubfs/Imported_Blog_Media/blog-image-June-26-attack-surface.png" alt="Associations Have a Bigger Attack Surface Than They Think - Vortacity" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Associations are built to be accessible.&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="http://www.vortacity.com/vortacity-blog/associations-have-a-bigger-attack-surface-than-they-think" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.vortacity.com/hubfs/Imported_Blog_Media/blog-image-June-26-attack-surface.png" alt="Associations Have a Bigger Attack Surface Than They Think - Vortacity" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Associations are built to be accessible.&lt;/p&gt;  
&lt;img src="https://track-na2.hubspot.com/__ptq.gif?a=46362935&amp;amp;k=14&amp;amp;r=http%3A%2F%2Fwww.vortacity.com%2Fvortacity-blog%2Fassociations-have-a-bigger-attack-surface-than-they-think&amp;amp;bu=http%253A%252F%252Fwww.vortacity.com%252Fvortacity-blog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>cyber</category>
      <category>cyber for associations</category>
      <category>Cybersecurity for Associations</category>
      <category>attack surface</category>
      <category>Vulnerability Management Services</category>
      <category>Vulnerability Assessment</category>
      <category>associations</category>
      <category>cyber scans</category>
      <category>Cybersecurity</category>
      <pubDate>Thu, 28 May 2026 15:48:37 GMT</pubDate>
      <guid>http://www.vortacity.com/vortacity-blog/associations-have-a-bigger-attack-surface-than-they-think</guid>
      <dc:date>2026-05-28T15:48:37Z</dc:date>
      <dc:creator>Ben Muscolino</dc:creator>
    </item>
    <item>
      <title>What Is a Pen Test? (And What It Actually Tells You) - Vortacity</title>
      <link>http://www.vortacity.com/vortacity-blog/what-is-a-pen-test-and-what-it-actually-tells-you</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="http://www.vortacity.com/vortacity-blog/what-is-a-pen-test-and-what-it-actually-tells-you" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.vortacity.com/hubfs/Imported_Blog_Media/what-is-a-pen-test.png" alt="What Is a Pen Test? (And What It Actually Tells You) - Vortacity" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;If you spend enough time around cybersecurity conversations, eventually someone says:&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="http://www.vortacity.com/vortacity-blog/what-is-a-pen-test-and-what-it-actually-tells-you" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.vortacity.com/hubfs/Imported_Blog_Media/what-is-a-pen-test.png" alt="What Is a Pen Test? (And What It Actually Tells You) - Vortacity" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;If you spend enough time around cybersecurity conversations, eventually someone says:&lt;/p&gt;  
&lt;img src="https://track-na2.hubspot.com/__ptq.gif?a=46362935&amp;amp;k=14&amp;amp;r=http%3A%2F%2Fwww.vortacity.com%2Fvortacity-blog%2Fwhat-is-a-pen-test-and-what-it-actually-tells-you&amp;amp;bu=http%253A%252F%252Fwww.vortacity.com%252Fvortacity-blog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>cyber for associations</category>
      <category>Cybersecurity for Associations</category>
      <category>Penetration Testing</category>
      <category>Cybersecurity</category>
      <pubDate>Sat, 16 May 2026 12:38:06 GMT</pubDate>
      <guid>http://www.vortacity.com/vortacity-blog/what-is-a-pen-test-and-what-it-actually-tells-you</guid>
      <dc:date>2026-05-16T12:38:06Z</dc:date>
      <dc:creator>Ben Muscolino</dc:creator>
    </item>
    <item>
      <title>The Phishing Epidemic: Why Associations and Nonprofits Are Prime Targets - Vortacity</title>
      <link>http://www.vortacity.com/vortacity-blog/the-phishing-epidemic-why-associations-and-nonprofits-are-prime-targets</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="http://www.vortacity.com/vortacity-blog/the-phishing-epidemic-why-associations-and-nonprofits-are-prime-targets" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.vortacity.com/hubfs/Imported_Blog_Media/ChatGPT-Image-May-7-2026-12_31_39-PM.png" alt="The Phishing Epidemic: Why Associations and Nonprofits Are Prime Targets - Vortacity" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt;  
&lt;div class="text-base my-auto mx-auto pb-10 [--thread-content-margin:var(--thread-content-margin-xs,calc(var(--spacing)*4))] @w-sm/main:[--thread-content-margin:var(--thread-content-margin-sm,calc(var(--spacing)*6))] @w-lg/main:[--thread-content-margin:var(--thread-content-margin-lg,calc(var(--spacing)*16))] px-(--thread-content-margin)"&gt; 
 &lt;div class="[--thread-content-max-width:40rem] @w-lg/main:[--thread-content-max-width:48rem] mx-auto max-w-(--thread-content-max-width) flex-1 group/turn-messages focus-visible:outline-hidden relative flex w-full min-w-0 flex-col agent-turn"&gt; 
  &lt;div class="flex max-w-full flex-col gap-4 grow"&gt; 
   &lt;div class="min-h-8 text-message relative flex w-full flex-col items-end gap-2 text-start break-words whitespace-normal outline-none keyboard-focused:focus-ring [.text-message+&amp;amp;]:mt-1"&gt; 
    &lt;div class="flex w-full flex-col gap-1 empty:hidden"&gt; 
     &lt;div class="markdown prose dark:prose-invert wrap-break-word w-full dark markdown-new-styling"&gt; 
      &lt;p&gt;In the association and nonprofit world, trust is foundational.&lt;/p&gt; 
      &lt;p&gt;Members trust your organization with personal information, payment data, certifications, continuing education records, donations, advocacy engagement, event registrations, and years of professional history. Boards trust leadership teams to protect sensitive communications and financial operations. Sponsors and partners trust the integrity of your brand.&lt;/p&gt; 
      &lt;p&gt;Attackers understand this.&lt;/p&gt; 
      &lt;p&gt;And that’s exactly why associations and nonprofits are increasingly being targeted by phishing campaigns designed to compromise identities, exploit trust, and gain access to cloud environments like Microsoft 365.&lt;/p&gt; 
      &lt;p&gt;This isn’t random.&lt;/p&gt; 
      &lt;p&gt;It’s patterned, scalable, and working.&lt;/p&gt; 
      &lt;h2&gt;Phishing Remains One of the Most Effective Attack Methods&lt;/h2&gt; 
      &lt;p&gt;Despite advances in cybersecurity technology, phishing continues to be one of the simplest and most successful ways for attackers to gain access to organizations.&lt;/p&gt; 
      &lt;p&gt;The Anti-Phishing Working Group reported more than 1 million phishing attacks in Q1 of 2025 alone, one of the highest quarterly totals in recent years. Meanwhile, the 2025 Verizon Data Breach Investigations Report found:&lt;/p&gt; 
      &lt;ul&gt; 
       &lt;li&gt;16% of breaches began with phishing&lt;/li&gt; 
       &lt;li&gt;22% involved stolen credentials&lt;/li&gt; 
       &lt;li&gt;60% involved the human element, including phishing, social engineering, and credential compromise&lt;/li&gt; 
      &lt;/ul&gt; 
      &lt;p&gt;For associations and nonprofits, these numbers are especially concerning because many organizations operate with:&lt;/p&gt; 
      &lt;ul&gt; 
       &lt;li&gt;Lean IT and security teams&lt;/li&gt; 
       &lt;li&gt;Distributed or hybrid staff&lt;/li&gt; 
       &lt;li&gt;Volunteer leadership and rotating committee members&lt;/li&gt; 
       &lt;li&gt;Multiple third-party platforms and vendors&lt;/li&gt; 
       &lt;li&gt;Complex Microsoft 365 collaboration environments&lt;/li&gt; 
       &lt;li&gt;High-trust communication cultures&lt;/li&gt; 
      &lt;/ul&gt; 
      &lt;p&gt;That combination creates an ideal environment for modern phishing attacks.&lt;/p&gt; 
      &lt;h2&gt;Why Associations Are Attractive Targets&lt;/h2&gt; 
      &lt;p&gt;Associations and nonprofits often manage a unique blend of sensitive operational and identity data, including:&lt;/p&gt; 
      &lt;ul&gt; 
       &lt;li&gt;Member directories&lt;/li&gt; 
       &lt;li&gt;Payment and donation systems&lt;/li&gt; 
       &lt;li&gt;Board communications&lt;/li&gt; 
       &lt;li&gt;Education and certification platforms&lt;/li&gt; 
       &lt;li&gt;Sponsor and donor relationships&lt;/li&gt; 
       &lt;li&gt;Event registration systems&lt;/li&gt; 
       &lt;li&gt;Advocacy and engagement data&lt;/li&gt; 
      &lt;/ul&gt; 
      &lt;p&gt;To attackers, these environments represent more than just data.&lt;/p&gt; 
      &lt;p&gt;They represent trust-based ecosystems where compromising a single identity can open the door to financial fraud, executive impersonation, business email compromise (BEC), and long-term access to organizational systems.&lt;/p&gt; 
      &lt;p&gt;A compromised Microsoft 365 account can quickly lead to:&lt;/p&gt; 
      &lt;ul&gt; 
       &lt;li&gt;Fraudulent wire or ACH requests&lt;/li&gt; 
       &lt;li&gt;Executive impersonation emails&lt;/li&gt; 
       &lt;li&gt;Exposure of sensitive board communications&lt;/li&gt; 
       &lt;li&gt;Theft of membership or donor data&lt;/li&gt; 
       &lt;li&gt;Access to shared files and collaboration platforms&lt;/li&gt; 
       &lt;li&gt;Persistence inside cloud identity systems&lt;/li&gt; 
      &lt;/ul&gt; 
      &lt;p&gt;And in many cases, organizations don’t realize the extent of the compromise until well after the initial phishing email is discovered.&lt;/p&gt; 
      &lt;h2&gt;Modern Phishing Is About Identity, Not Just Malware&lt;/h2&gt; 
      &lt;p&gt;Many people still think of phishing as a malicious attachment or infected link designed to install malware.&lt;/p&gt; 
      &lt;p&gt;Today’s attacks are often much quieter.&lt;/p&gt; 
      &lt;p&gt;Modern phishing campaigns frequently focus on stealing credentials and abusing identity platforms rather than deploying traditional malware. Attackers create convincing Microsoft 365 login pages, impersonate trusted vendors or executives, and use social engineering tactics designed to trigger urgency or familiarity.&lt;/p&gt; 
      &lt;p&gt;Once attackers gain access to an account, they may not act immediately.&lt;/p&gt; 
      &lt;p&gt;Instead, they often spend time learning how the organization operates:&lt;/p&gt; 
      &lt;ul&gt; 
       &lt;li&gt;Reviewing communications&lt;/li&gt; 
       &lt;li&gt;Mapping relationships&lt;/li&gt; 
       &lt;li&gt;Monitoring payment workflows&lt;/li&gt; 
       &lt;li&gt;Identifying privileged users&lt;/li&gt; 
       &lt;li&gt;Enumerating shared files and groups&lt;/li&gt; 
      &lt;/ul&gt; 
      &lt;p&gt;The goal is rarely just access.&lt;/p&gt; 
      &lt;p&gt;The goal is persistence and opportunity.&lt;/p&gt; 
      &lt;h2&gt;The Real Risk Begins After the Click&lt;/h2&gt; 
      &lt;p&gt;One of the biggest misconceptions organizations have is believing the incident ends once the phishing email is identified and the password is reset.&lt;/p&gt; 
      &lt;p&gt;In reality, that may only address the initial compromise.&lt;/p&gt; 
      &lt;p&gt;Modern attackers often establish persistence inside Microsoft 365 environments by:&lt;/p&gt; 
      &lt;ul&gt; 
       &lt;li&gt;Registering rogue MFA methods&lt;/li&gt; 
       &lt;li&gt;Creating hidden inbox forwarding rules&lt;/li&gt; 
       &lt;li&gt;Abusing OAuth application consent&lt;/li&gt; 
       &lt;li&gt;Manipulating permissions and privileged roles&lt;/li&gt; 
       &lt;li&gt;Maintaining access through trusted cloud services&lt;/li&gt; 
      &lt;/ul&gt; 
      &lt;p&gt;These techniques allow attackers to remain inside environments quietly, sometimes for weeks or months.&lt;/p&gt; 
      &lt;p&gt;Most organizations focus on the login.&lt;/p&gt; 
      &lt;p&gt;Attackers focus on keeping access.&lt;/p&gt; 
      &lt;h2&gt;Associations Need to Think Beyond Prevention&lt;/h2&gt; 
      &lt;p&gt;Security awareness training and multi-factor authentication are critical. But prevention alone is no longer enough.&lt;/p&gt; 
      &lt;p&gt;Associations and nonprofits need visibility into:&lt;/p&gt; 
      &lt;ul&gt; 
       &lt;li&gt;How identities are being used&lt;/li&gt; 
       &lt;li&gt;What changes are occurring inside Microsoft 365&lt;/li&gt; 
       &lt;li&gt;Whether persistence mechanisms exist&lt;/li&gt; 
       &lt;li&gt;How attacker behavior can be detected early&lt;/li&gt; 
      &lt;/ul&gt; 
      &lt;p&gt;This requires a shift in mindset from simply “blocking attacks” to understanding how modern compromises actually unfold.&lt;/p&gt; 
      &lt;p&gt;Because phishing today is rarely just about one email.&lt;/p&gt; 
      &lt;p&gt;It’s about what attackers can do once trust is compromised.&lt;/p&gt; 
      &lt;h2&gt;Building a More Resilient Organization&lt;/h2&gt; 
      &lt;p&gt;The good news is that organizations can significantly reduce risk by strengthening identity security, improving visibility, and validating their environments regularly.&lt;/p&gt; 
      &lt;p&gt;That includes:&lt;/p&gt; 
      &lt;ul&gt; 
       &lt;li&gt;Reviewing Microsoft 365 security configurations&lt;/li&gt; 
       &lt;li&gt;Monitoring identity activity and privileged access&lt;/li&gt; 
       &lt;li&gt;Validating MFA enrollment policies&lt;/li&gt; 
       &lt;li&gt;Reviewing OAuth and application consent activity&lt;/li&gt; 
       &lt;li&gt;Conducting post-compromise assessments when suspicious activity occurs&lt;/li&gt; 
       &lt;li&gt;Improving incident response readiness&lt;/li&gt; 
      &lt;/ul&gt; 
      &lt;p&gt;Most importantly, organizations need partners who understand how attackers operate inside modern cloud environments, not just how to deploy tools.&lt;/p&gt; 
      &lt;h2&gt;Looking Ahead&lt;/h2&gt; 
      &lt;p&gt;In the next post in this series, we’ll examine what actually happens after an attacker gains access to a Microsoft 365 environment, including the techniques used to maintain persistence, manipulate communications, and quietly expand access across an organization.&lt;/p&gt; 
      &lt;p&gt;Because phishing isn’t the breach.&lt;/p&gt; 
      &lt;p&gt;It’s the beginning.&lt;/p&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div class="z-0 flex min-h-[46px] justify-start"&gt;&lt;/div&gt; 
  &lt;div class="mt-3 w-full empty:hidden"&gt; 
   &lt;div class="text-center"&gt;&lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
&lt;/div&gt;  
&lt;div class="pointer-events-none -mt-px h-px translate-y-[calc(var(--scroll-root-safe-area-inset-bottom)-14*var(--spacing))]"&gt;&lt;/div&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="http://www.vortacity.com/vortacity-blog/the-phishing-epidemic-why-associations-and-nonprofits-are-prime-targets" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.vortacity.com/hubfs/Imported_Blog_Media/ChatGPT-Image-May-7-2026-12_31_39-PM.png" alt="The Phishing Epidemic: Why Associations and Nonprofits Are Prime Targets - Vortacity" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt;  
&lt;div class="text-base my-auto mx-auto pb-10 [--thread-content-margin:var(--thread-content-margin-xs,calc(var(--spacing)*4))] @w-sm/main:[--thread-content-margin:var(--thread-content-margin-sm,calc(var(--spacing)*6))] @w-lg/main:[--thread-content-margin:var(--thread-content-margin-lg,calc(var(--spacing)*16))] px-(--thread-content-margin)"&gt; 
 &lt;div class="[--thread-content-max-width:40rem] @w-lg/main:[--thread-content-max-width:48rem] mx-auto max-w-(--thread-content-max-width) flex-1 group/turn-messages focus-visible:outline-hidden relative flex w-full min-w-0 flex-col agent-turn"&gt; 
  &lt;div class="flex max-w-full flex-col gap-4 grow"&gt; 
   &lt;div class="min-h-8 text-message relative flex w-full flex-col items-end gap-2 text-start break-words whitespace-normal outline-none keyboard-focused:focus-ring [.text-message+&amp;amp;]:mt-1"&gt; 
    &lt;div class="flex w-full flex-col gap-1 empty:hidden"&gt; 
     &lt;div class="markdown prose dark:prose-invert wrap-break-word w-full dark markdown-new-styling"&gt; 
      &lt;p&gt;In the association and nonprofit world, trust is foundational.&lt;/p&gt; 
      &lt;p&gt;Members trust your organization with personal information, payment data, certifications, continuing education records, donations, advocacy engagement, event registrations, and years of professional history. Boards trust leadership teams to protect sensitive communications and financial operations. Sponsors and partners trust the integrity of your brand.&lt;/p&gt; 
      &lt;p&gt;Attackers understand this.&lt;/p&gt; 
      &lt;p&gt;And that’s exactly why associations and nonprofits are increasingly being targeted by phishing campaigns designed to compromise identities, exploit trust, and gain access to cloud environments like Microsoft 365.&lt;/p&gt; 
      &lt;p&gt;This isn’t random.&lt;/p&gt; 
      &lt;p&gt;It’s patterned, scalable, and working.&lt;/p&gt; 
      &lt;h2&gt;Phishing Remains One of the Most Effective Attack Methods&lt;/h2&gt; 
      &lt;p&gt;Despite advances in cybersecurity technology, phishing continues to be one of the simplest and most successful ways for attackers to gain access to organizations.&lt;/p&gt; 
      &lt;p&gt;The Anti-Phishing Working Group reported more than 1 million phishing attacks in Q1 of 2025 alone, one of the highest quarterly totals in recent years. Meanwhile, the 2025 Verizon Data Breach Investigations Report found:&lt;/p&gt; 
      &lt;ul&gt; 
       &lt;li&gt;16% of breaches began with phishing&lt;/li&gt; 
       &lt;li&gt;22% involved stolen credentials&lt;/li&gt; 
       &lt;li&gt;60% involved the human element, including phishing, social engineering, and credential compromise&lt;/li&gt; 
      &lt;/ul&gt; 
      &lt;p&gt;For associations and nonprofits, these numbers are especially concerning because many organizations operate with:&lt;/p&gt; 
      &lt;ul&gt; 
       &lt;li&gt;Lean IT and security teams&lt;/li&gt; 
       &lt;li&gt;Distributed or hybrid staff&lt;/li&gt; 
       &lt;li&gt;Volunteer leadership and rotating committee members&lt;/li&gt; 
       &lt;li&gt;Multiple third-party platforms and vendors&lt;/li&gt; 
       &lt;li&gt;Complex Microsoft 365 collaboration environments&lt;/li&gt; 
       &lt;li&gt;High-trust communication cultures&lt;/li&gt; 
      &lt;/ul&gt; 
      &lt;p&gt;That combination creates an ideal environment for modern phishing attacks.&lt;/p&gt; 
      &lt;h2&gt;Why Associations Are Attractive Targets&lt;/h2&gt; 
      &lt;p&gt;Associations and nonprofits often manage a unique blend of sensitive operational and identity data, including:&lt;/p&gt; 
      &lt;ul&gt; 
       &lt;li&gt;Member directories&lt;/li&gt; 
       &lt;li&gt;Payment and donation systems&lt;/li&gt; 
       &lt;li&gt;Board communications&lt;/li&gt; 
       &lt;li&gt;Education and certification platforms&lt;/li&gt; 
       &lt;li&gt;Sponsor and donor relationships&lt;/li&gt; 
       &lt;li&gt;Event registration systems&lt;/li&gt; 
       &lt;li&gt;Advocacy and engagement data&lt;/li&gt; 
      &lt;/ul&gt; 
      &lt;p&gt;To attackers, these environments represent more than just data.&lt;/p&gt; 
      &lt;p&gt;They represent trust-based ecosystems where compromising a single identity can open the door to financial fraud, executive impersonation, business email compromise (BEC), and long-term access to organizational systems.&lt;/p&gt; 
      &lt;p&gt;A compromised Microsoft 365 account can quickly lead to:&lt;/p&gt; 
      &lt;ul&gt; 
       &lt;li&gt;Fraudulent wire or ACH requests&lt;/li&gt; 
       &lt;li&gt;Executive impersonation emails&lt;/li&gt; 
       &lt;li&gt;Exposure of sensitive board communications&lt;/li&gt; 
       &lt;li&gt;Theft of membership or donor data&lt;/li&gt; 
       &lt;li&gt;Access to shared files and collaboration platforms&lt;/li&gt; 
       &lt;li&gt;Persistence inside cloud identity systems&lt;/li&gt; 
      &lt;/ul&gt; 
      &lt;p&gt;And in many cases, organizations don’t realize the extent of the compromise until well after the initial phishing email is discovered.&lt;/p&gt; 
      &lt;h2&gt;Modern Phishing Is About Identity, Not Just Malware&lt;/h2&gt; 
      &lt;p&gt;Many people still think of phishing as a malicious attachment or infected link designed to install malware.&lt;/p&gt; 
      &lt;p&gt;Today’s attacks are often much quieter.&lt;/p&gt; 
      &lt;p&gt;Modern phishing campaigns frequently focus on stealing credentials and abusing identity platforms rather than deploying traditional malware. Attackers create convincing Microsoft 365 login pages, impersonate trusted vendors or executives, and use social engineering tactics designed to trigger urgency or familiarity.&lt;/p&gt; 
      &lt;p&gt;Once attackers gain access to an account, they may not act immediately.&lt;/p&gt; 
      &lt;p&gt;Instead, they often spend time learning how the organization operates:&lt;/p&gt; 
      &lt;ul&gt; 
       &lt;li&gt;Reviewing communications&lt;/li&gt; 
       &lt;li&gt;Mapping relationships&lt;/li&gt; 
       &lt;li&gt;Monitoring payment workflows&lt;/li&gt; 
       &lt;li&gt;Identifying privileged users&lt;/li&gt; 
       &lt;li&gt;Enumerating shared files and groups&lt;/li&gt; 
      &lt;/ul&gt; 
      &lt;p&gt;The goal is rarely just access.&lt;/p&gt; 
      &lt;p&gt;The goal is persistence and opportunity.&lt;/p&gt; 
      &lt;h2&gt;The Real Risk Begins After the Click&lt;/h2&gt; 
      &lt;p&gt;One of the biggest misconceptions organizations have is believing the incident ends once the phishing email is identified and the password is reset.&lt;/p&gt; 
      &lt;p&gt;In reality, that may only address the initial compromise.&lt;/p&gt; 
      &lt;p&gt;Modern attackers often establish persistence inside Microsoft 365 environments by:&lt;/p&gt; 
      &lt;ul&gt; 
       &lt;li&gt;Registering rogue MFA methods&lt;/li&gt; 
       &lt;li&gt;Creating hidden inbox forwarding rules&lt;/li&gt; 
       &lt;li&gt;Abusing OAuth application consent&lt;/li&gt; 
       &lt;li&gt;Manipulating permissions and privileged roles&lt;/li&gt; 
       &lt;li&gt;Maintaining access through trusted cloud services&lt;/li&gt; 
      &lt;/ul&gt; 
      &lt;p&gt;These techniques allow attackers to remain inside environments quietly, sometimes for weeks or months.&lt;/p&gt; 
      &lt;p&gt;Most organizations focus on the login.&lt;/p&gt; 
      &lt;p&gt;Attackers focus on keeping access.&lt;/p&gt; 
      &lt;h2&gt;Associations Need to Think Beyond Prevention&lt;/h2&gt; 
      &lt;p&gt;Security awareness training and multi-factor authentication are critical. But prevention alone is no longer enough.&lt;/p&gt; 
      &lt;p&gt;Associations and nonprofits need visibility into:&lt;/p&gt; 
      &lt;ul&gt; 
       &lt;li&gt;How identities are being used&lt;/li&gt; 
       &lt;li&gt;What changes are occurring inside Microsoft 365&lt;/li&gt; 
       &lt;li&gt;Whether persistence mechanisms exist&lt;/li&gt; 
       &lt;li&gt;How attacker behavior can be detected early&lt;/li&gt; 
      &lt;/ul&gt; 
      &lt;p&gt;This requires a shift in mindset from simply “blocking attacks” to understanding how modern compromises actually unfold.&lt;/p&gt; 
      &lt;p&gt;Because phishing today is rarely just about one email.&lt;/p&gt; 
      &lt;p&gt;It’s about what attackers can do once trust is compromised.&lt;/p&gt; 
      &lt;h2&gt;Building a More Resilient Organization&lt;/h2&gt; 
      &lt;p&gt;The good news is that organizations can significantly reduce risk by strengthening identity security, improving visibility, and validating their environments regularly.&lt;/p&gt; 
      &lt;p&gt;That includes:&lt;/p&gt; 
      &lt;ul&gt; 
       &lt;li&gt;Reviewing Microsoft 365 security configurations&lt;/li&gt; 
       &lt;li&gt;Monitoring identity activity and privileged access&lt;/li&gt; 
       &lt;li&gt;Validating MFA enrollment policies&lt;/li&gt; 
       &lt;li&gt;Reviewing OAuth and application consent activity&lt;/li&gt; 
       &lt;li&gt;Conducting post-compromise assessments when suspicious activity occurs&lt;/li&gt; 
       &lt;li&gt;Improving incident response readiness&lt;/li&gt; 
      &lt;/ul&gt; 
      &lt;p&gt;Most importantly, organizations need partners who understand how attackers operate inside modern cloud environments, not just how to deploy tools.&lt;/p&gt; 
      &lt;h2&gt;Looking Ahead&lt;/h2&gt; 
      &lt;p&gt;In the next post in this series, we’ll examine what actually happens after an attacker gains access to a Microsoft 365 environment, including the techniques used to maintain persistence, manipulate communications, and quietly expand access across an organization.&lt;/p&gt; 
      &lt;p&gt;Because phishing isn’t the breach.&lt;/p&gt; 
      &lt;p&gt;It’s the beginning.&lt;/p&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div class="z-0 flex min-h-[46px] justify-start"&gt;&lt;/div&gt; 
  &lt;div class="mt-3 w-full empty:hidden"&gt; 
   &lt;div class="text-center"&gt;&lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
&lt;/div&gt;  
&lt;div class="pointer-events-none -mt-px h-px translate-y-[calc(var(--scroll-root-safe-area-inset-bottom)-14*var(--spacing))]"&gt;&lt;/div&gt;  
&lt;img src="https://track-na2.hubspot.com/__ptq.gif?a=46362935&amp;amp;k=14&amp;amp;r=http%3A%2F%2Fwww.vortacity.com%2Fvortacity-blog%2Fthe-phishing-epidemic-why-associations-and-nonprofits-are-prime-targets&amp;amp;bu=http%253A%252F%252Fwww.vortacity.com%252Fvortacity-blog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Cybersecurity for Associations</category>
      <pubDate>Tue, 07 Apr 2026 01:00:12 GMT</pubDate>
      <guid>http://www.vortacity.com/vortacity-blog/the-phishing-epidemic-why-associations-and-nonprofits-are-prime-targets</guid>
      <dc:date>2026-04-07T01:00:12Z</dc:date>
      <dc:creator>Paige Anderson</dc:creator>
    </item>
    <item>
      <title>Why Associations Are the New Favorite Target for Cybercriminals - Vortacity</title>
      <link>http://www.vortacity.com/vortacity-blog/why-associations-are-the-new-favorite-target-for-cybercriminals</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="http://www.vortacity.com/vortacity-blog/why-associations-are-the-new-favorite-target-for-cybercriminals" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.vortacity.com/hubfs/Imported_Blog_Media/Cybercriminals-targeting-associations-online.png" alt="Why Associations Are the New Favorite Target for Cybercriminals - Vortacity" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;h2&gt;The Shift Toward Softer Targets&lt;/h2&gt; 
&lt;p&gt;Cybercriminals have changed their playbook. Instead of going after heavily fortified enterprises, attackers are increasingly targeting organizations that hold valuable data but invest less in defending it. Associations fit that profile perfectly.&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="http://www.vortacity.com/vortacity-blog/why-associations-are-the-new-favorite-target-for-cybercriminals" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.vortacity.com/hubfs/Imported_Blog_Media/Cybercriminals-targeting-associations-online.png" alt="Why Associations Are the New Favorite Target for Cybercriminals - Vortacity" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;h2&gt;The Shift Toward Softer Targets&lt;/h2&gt; 
&lt;p&gt;Cybercriminals have changed their playbook. Instead of going after heavily fortified enterprises, attackers are increasingly targeting organizations that hold valuable data but invest less in defending it. Associations fit that profile perfectly.&lt;/p&gt;  
&lt;img src="https://track-na2.hubspot.com/__ptq.gif?a=46362935&amp;amp;k=14&amp;amp;r=http%3A%2F%2Fwww.vortacity.com%2Fvortacity-blog%2Fwhy-associations-are-the-new-favorite-target-for-cybercriminals&amp;amp;bu=http%253A%252F%252Fwww.vortacity.com%252Fvortacity-blog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Cybersecurity for Associations</category>
      <pubDate>Thu, 05 Mar 2026 20:39:16 GMT</pubDate>
      <guid>http://www.vortacity.com/vortacity-blog/why-associations-are-the-new-favorite-target-for-cybercriminals</guid>
      <dc:date>2026-03-05T20:39:16Z</dc:date>
      <dc:creator>Paige Anderson</dc:creator>
    </item>
    <item>
      <title>Part 2: Business Email Compromise and Vendor Fraud: The Hidden Risk to Associations - Vortacity</title>
      <link>http://www.vortacity.com/vortacity-blog/part-2-business-email-compromise-and-vendor-fraud-the-hidden-risk-to-associations</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="http://www.vortacity.com/vortacity-blog/part-2-business-email-compromise-and-vendor-fraud-the-hidden-risk-to-associations" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.vortacity.com/hubfs/Imported_Blog_Media/blog-2-v-2.png" alt="Part 2: Business Email Compromise and Vendor Fraud: The Hidden Risk to Associations - Vortacity" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;While phishing opens the door, Business Email Compromise, or BEC, walks through it.&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="http://www.vortacity.com/vortacity-blog/part-2-business-email-compromise-and-vendor-fraud-the-hidden-risk-to-associations" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.vortacity.com/hubfs/Imported_Blog_Media/blog-2-v-2.png" alt="Part 2: Business Email Compromise and Vendor Fraud: The Hidden Risk to Associations - Vortacity" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;While phishing opens the door, Business Email Compromise, or BEC, walks through it.&lt;/p&gt;  
&lt;img src="https://track-na2.hubspot.com/__ptq.gif?a=46362935&amp;amp;k=14&amp;amp;r=http%3A%2F%2Fwww.vortacity.com%2Fvortacity-blog%2Fpart-2-business-email-compromise-and-vendor-fraud-the-hidden-risk-to-associations&amp;amp;bu=http%253A%252F%252Fwww.vortacity.com%252Fvortacity-blog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>cyber for associations</category>
      <category>Cybersecurity for Associations</category>
      <category>Vulnerability Assessment</category>
      <category>Consulting</category>
      <category>Cybersecurity</category>
      <pubDate>Thu, 22 Jan 2026 18:54:37 GMT</pubDate>
      <guid>http://www.vortacity.com/vortacity-blog/part-2-business-email-compromise-and-vendor-fraud-the-hidden-risk-to-associations</guid>
      <dc:date>2026-01-22T18:54:37Z</dc:date>
      <dc:creator>Ben Muscolino</dc:creator>
    </item>
    <item>
      <title>Part 1: Bank Impersonation and Phishing Scams: Why Prevention Is No Longer Enough - Vortacity</title>
      <link>http://www.vortacity.com/vortacity-blog/part-1-bank-impersonation-and-phishing-scams-why-prevention-is-no-longer-enough</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="http://www.vortacity.com/vortacity-blog/part-1-bank-impersonation-and-phishing-scams-why-prevention-is-no-longer-enough" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.vortacity.com/hubfs/Imported_Blog_Media/blog-1-v-1.png" alt="Part 1: Bank Impersonation and Phishing Scams: Why Prevention Is No Longer Enough - Vortacity" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Financial institutions continue to warn businesses and individuals about rising bank impersonation and phishing scams. These attacks are not slowing down. They are becoming more convincing.&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="http://www.vortacity.com/vortacity-blog/part-1-bank-impersonation-and-phishing-scams-why-prevention-is-no-longer-enough" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.vortacity.com/hubfs/Imported_Blog_Media/blog-1-v-1.png" alt="Part 1: Bank Impersonation and Phishing Scams: Why Prevention Is No Longer Enough - Vortacity" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Financial institutions continue to warn businesses and individuals about rising bank impersonation and phishing scams. These attacks are not slowing down. They are becoming more convincing.&lt;/p&gt;  
&lt;img src="https://track-na2.hubspot.com/__ptq.gif?a=46362935&amp;amp;k=14&amp;amp;r=http%3A%2F%2Fwww.vortacity.com%2Fvortacity-blog%2Fpart-1-bank-impersonation-and-phishing-scams-why-prevention-is-no-longer-enough&amp;amp;bu=http%253A%252F%252Fwww.vortacity.com%252Fvortacity-blog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>cyber for associations</category>
      <category>Bank Scams</category>
      <category>Cybersecurity for Associations</category>
      <category>Vulnerability Management Services</category>
      <pubDate>Sun, 11 Jan 2026 17:00:54 GMT</pubDate>
      <guid>http://www.vortacity.com/vortacity-blog/part-1-bank-impersonation-and-phishing-scams-why-prevention-is-no-longer-enough</guid>
      <dc:date>2026-01-11T17:00:54Z</dc:date>
      <dc:creator>Ben Muscolino</dc:creator>
    </item>
    <item>
      <title>&#x1f384; A Very Secure Christmas &#x1f384; - Vortacity</title>
      <link>http://www.vortacity.com/vortacity-blog/-a-very-secure-christmas-</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="http://www.vortacity.com/vortacity-blog/-a-very-secure-christmas-" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.vortacity.com/hubfs/Imported_Blog_Media/v-holiday-social.png" alt="&#x1f384; A Very Secure Christmas &#x1f384; - Vortacity" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;On Christmas Eve, when houses were quiet and still,&lt;br&gt;Santa crept softly… for milk, cookies, and maybe a file or two to fill.&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="http://www.vortacity.com/vortacity-blog/-a-very-secure-christmas-" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.vortacity.com/hubfs/Imported_Blog_Media/v-holiday-social.png" alt="&#x1f384; A Very Secure Christmas &#x1f384; - Vortacity" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;On Christmas Eve, when houses were quiet and still,&lt;br&gt;Santa crept softly… for milk, cookies, and maybe a file or two to fill.&lt;/p&gt;  
&lt;img src="https://track-na2.hubspot.com/__ptq.gif?a=46362935&amp;amp;k=14&amp;amp;r=http%3A%2F%2Fwww.vortacity.com%2Fvortacity-blog%2F-a-very-secure-christmas-&amp;amp;bu=http%253A%252F%252Fwww.vortacity.com%252Fvortacity-blog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>cyber canaries</category>
      <category>a cyber safe holiday</category>
      <category>cyber for associations</category>
      <category>Cybersecurity for Associations</category>
      <category>Penetration Testing</category>
      <category>Cybersecurity</category>
      <pubDate>Tue, 23 Dec 2025 04:13:47 GMT</pubDate>
      <guid>http://www.vortacity.com/vortacity-blog/-a-very-secure-christmas-</guid>
      <dc:date>2025-12-23T04:13:47Z</dc:date>
      <dc:creator>Ben Muscolino</dc:creator>
    </item>
    <item>
      <title>Penetration Testing Explained: Internal vs External, Cloud Testing, and What Associations Really Need - Vortacity</title>
      <link>http://www.vortacity.com/vortacity-blog/penetration-testing-explained-internal-vs-external-cloud-testing-and-what-associations-really-need</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="http://www.vortacity.com/vortacity-blog/penetration-testing-explained-internal-vs-external-cloud-testing-and-what-associations-really-need" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.vortacity.com/hubfs/Imported_Blog_Media/ChatGPT-Image-Dec-17-2025-12_55_30-AM.png" alt="Penetration Testing Explained: Internal vs External, Cloud Testing, and What Associations Really Need - Vortacity" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Penetration testing is one of the most misunderstood security services in the market. Many organizations believe it is something they are required to do, while others assume it is the single best way to improve security. In reality, penetration testing is a powerful but very specific tool, and it is not always the first or most cost-effective step for every association.&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="http://www.vortacity.com/vortacity-blog/penetration-testing-explained-internal-vs-external-cloud-testing-and-what-associations-really-need" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.vortacity.com/hubfs/Imported_Blog_Media/ChatGPT-Image-Dec-17-2025-12_55_30-AM.png" alt="Penetration Testing Explained: Internal vs External, Cloud Testing, and What Associations Really Need - Vortacity" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Penetration testing is one of the most misunderstood security services in the market. Many organizations believe it is something they are required to do, while others assume it is the single best way to improve security. In reality, penetration testing is a powerful but very specific tool, and it is not always the first or most cost-effective step for every association.&lt;/p&gt;  
&lt;img src="https://track-na2.hubspot.com/__ptq.gif?a=46362935&amp;amp;k=14&amp;amp;r=http%3A%2F%2Fwww.vortacity.com%2Fvortacity-blog%2Fpenetration-testing-explained-internal-vs-external-cloud-testing-and-what-associations-really-need&amp;amp;bu=http%253A%252F%252Fwww.vortacity.com%252Fvortacity-blog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>cyber for associations</category>
      <category>Cybersecurity for Associations</category>
      <category>cloud scans</category>
      <category>Vulnerability Assessment</category>
      <category>association pen test</category>
      <category>Consulting</category>
      <category>Penetration Testing</category>
      <category>Cybersecurity</category>
      <pubDate>Wed, 17 Dec 2025 05:57:03 GMT</pubDate>
      <guid>http://www.vortacity.com/vortacity-blog/penetration-testing-explained-internal-vs-external-cloud-testing-and-what-associations-really-need</guid>
      <dc:date>2025-12-17T05:57:03Z</dc:date>
      <dc:creator>Ben Muscolino</dc:creator>
    </item>
    <item>
      <title>Understanding Post Compromise Security Assessments for Associations - Vortacity</title>
      <link>http://www.vortacity.com/vortacity-blog/understanding-post-compromise-security-assessments-for-associations</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="http://www.vortacity.com/vortacity-blog/understanding-post-compromise-security-assessments-for-associations" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.vortacity.com/hubfs/Imported_Blog_Media/ChatGPT-Image-Dec-17-2025-12_47_11-AM.png" alt="Understanding Post Compromise Security Assessments for Associations - Vortacity" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Account takeovers continue to be one of the most common and disruptive incidents affecting associations. A single compromised identity can create ripple effects across email, files, shared drives, committee workspaces, board communications, and member-facing systems. Even after passwords are reset, many organizations are left wondering what the attacker accessed, what configuration weaknesses made it possible, and what should change to prevent similar issues.&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="http://www.vortacity.com/vortacity-blog/understanding-post-compromise-security-assessments-for-associations" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.vortacity.com/hubfs/Imported_Blog_Media/ChatGPT-Image-Dec-17-2025-12_47_11-AM.png" alt="Understanding Post Compromise Security Assessments for Associations - Vortacity" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Account takeovers continue to be one of the most common and disruptive incidents affecting associations. A single compromised identity can create ripple effects across email, files, shared drives, committee workspaces, board communications, and member-facing systems. Even after passwords are reset, many organizations are left wondering what the attacker accessed, what configuration weaknesses made it possible, and what should change to prevent similar issues.&lt;/p&gt;  
&lt;img src="https://track-na2.hubspot.com/__ptq.gif?a=46362935&amp;amp;k=14&amp;amp;r=http%3A%2F%2Fwww.vortacity.com%2Fvortacity-blog%2Funderstanding-post-compromise-security-assessments-for-associations&amp;amp;bu=http%253A%252F%252Fwww.vortacity.com%252Fvortacity-blog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>cyber for associations</category>
      <category>Cybersecurity for Associations</category>
      <category>Vulnerability Assessment</category>
      <category>Consulting</category>
      <category>Penetration Testing</category>
      <category>Cybersecurity</category>
      <pubDate>Wed, 10 Dec 2025 05:41:40 GMT</pubDate>
      <guid>http://www.vortacity.com/vortacity-blog/understanding-post-compromise-security-assessments-for-associations</guid>
      <dc:date>2025-12-10T05:41:40Z</dc:date>
      <dc:creator>Ben Muscolino</dc:creator>
    </item>
  </channel>
</rss>
