Showing posts with label Convio. Show all posts
Showing posts with label Convio. Show all posts

Tuesday, August 5

Convio decides not to take company public

I've been told that Gene Austin at Convio sent out an email to clients this morning explaining that they "have chosen not to remain on file with the Securities and Exchange Commission to become a public company. Simply put, good companies don't go public in bad markets."

He also points out that Convio "processed $377 million in online donations on behalf of clients during the first half of 2008."

That's a lot of money.

For those of you that remember, I issued a friendly challenge to Austin earlier this year that if Convio "can process over $820 million for their clients in 2008, I will reveal my secret blogger identity."

Friday, July 18

Four CRM case studies

Reed over at the AFP blog pointed out a great article yesterday by Anthony Pisapia and Brett Bonfield from Idealware:

"Managing Constituent Relationships: Four Case Studies" tries to explain how four organizations have implemented CRM and what their experiences can offer others. The authors take a complete look at the product, the cost, the implementation, the challenges, and the words of advice.

The examples they cite are the NY-NJ Trail Conference, which used a database software called ebase; Hispanics in Philanthropy selected Microsoft CRM 3.0; Washington Toxics Coalition recently migrated from ebase to Salesforce and finally, Easter Seals uses a combination of Convio and Team Approach.

The rest of the article is on the TechSoup website.

Wednesday, June 18

Convio uses Akido to redirect attacks

Rather than me posting yet another entry about Convio, I decided to lift this message that Robert L. Weiner from the Strategic Technology Advisors to Nonprofit and Educational Institutions posted to a fundraising listserve yesterday:


Convio just announced that they will be releasing a donor database, code-named Akido, on the SalesForce.com platform. This will be a separate product from their online Constituent Relationship Management suite -- you don't have to be a Convio CRM client to use the database. They also say it's not simply a new template for SalesForce, but a product built from the ground up. Info is at: http://www.convio.com/signup/crm-system.html

As of now, the database is only available through what they're calling their Charter Program (which I read as beta testers). The program announcement includes a FAQ (at the bottom of the page) about the database and the program, plus some promotional videos:
http://www.convio.com/convio/news/charter-media-room.html

And if you want more, Gene Austin, their CEO, is blogging about the new database here:
http://tinyurl.com/5uldng

They plan to release the product in the 2nd half of this year. They haven't announced pricing.
For those of you that are curious, Akido is a form of martial arts that combines sport, philosophy, and religious beliefs. The irony for me is that Akido is known for "blending with the motion of the attacker and redirecting the force of the attack rather than opposing it head-on." It can also be categorized under the general umbrella of "grappling arts."
Too funny.

From the stories I've heard of people who have tried to integrate online and offline data from their eCRM provider... it sounds like they picked the perfect name to redirect one of their biggest criticism into a new business opportunity.

Tuesday, June 10

Bloggers challenge Gene Austin from Convio to announce his over/under goal for the year

On June 5th of last week, Tom over at The Agitator posted this article:

Courtesy of Don’t Tell the Donor blog, I just saw Convio’s reaction to Blackbaud’s purchase of rival Kintera. In it, Convio CEO Gene Austin comments that in April alone, Convio processed over $41 million in online contributions for its clients.

So here’s my question for you, Gene…

Are you ready to predict a $500,000,000 (that’s a half-billion for you creatives) online fundraising year for Convio clients? That’s getting to be big money!
Even though it was this site that originally posted the number, Austin must have decided not to post to Don't Tell the Donor directly. Instead, Austin posted this challenge to a bet on the comment thread at the Agitator:
Gene Austin on June 5th, 2008 10:53 am
As we all know there is a fair amount of seasonality in fundraising (Spring, October and the end of year), but I actually think $550M is achievable this year. Remember that this is only actual online giving and many of our clients will testify that their offline results are significantly impacted by their online communications and strategy.

If you are a “betting man” Tom we could put a little wager together on $550M. If we don’t hit it, I will fly you to our Summit and pay for your registration….now what do I get if we beat it?

When I read the bet Austin was making, I couldn't wait to offer my own Vegas-style lines on what Convio's expected donation processing total will be for 2008. At first I thought the SEC might be supisicous if I was to publicly comment on how many donations I thought would be a reasonable over/under... but my urge to gamble made me get involved.

I assume the first stated over/under number of $500 million was determined because Tom multiplied $41 million from April by 12 months (that would be $492 million for you math geeks). So, part of me thinks if Gene's bravado is ready to drop a number like $550 million as an even higher over/under... that means he's holding back his real estimate.

But how much higher should the real over/under be?

First, we need to set some realistic benchmarks:

I know a couple organizations that raise 5% of their total online revenue during the month of April. That means their total annual revenue is 20 times the amount raised in the month of April. If we apply those metrics to this bet, the over/under should be $820 million. That would be an impressive accomplishment.

So, I'll tell you what. If Convio can process over $820 million for their clients in 2008, I will reveal my secret blogger identity on the Agitator's blog. Live. What do you think about that challenge Gene?

Monday, June 2

Convio responds to Blackbaud acquisition of Kintera

Gene Austin, the CEO of Convio, sent out his response this morning to last Thursday's announcement that Blackbaud would be acquiring Kintera.

No doubt you have now heard the news about Blackbaud's proposed acquisition of Kintera. This is certainly an interesting, but not entirely unexpected, development in our rapidly evolving market.

The Software as a Service approach we have led in the industry has driven tremendous success for organizations like yours, and we believe this approach causes challenges for legacy software providers. Blackbaud now faces the task of addressing the well-publicized operational challenges at Kintera, while rationalizing a roadmap that includes multiple eCRM and donor management products from four companies (Blackbaud, Target Analytics, eTapestry and Kintera). It will be interesting to watch this integration play out over the coming quarters and years.

My hope is that this acquisition will convince Blackbaud to listen and respond to the growing demand from nonprofits for interoperability and an open approach to integration. We would like to see Blackbaud make their APIs freely available, following Convio and other leading vendors who have worked with clients and the market to drive improved results. Better data integration benefits the nonprofit market.

We are increasingly excited about the success our clients are achieving and the growth in our business. We processed over $41M in online gifts for our clients in April alone — making this our largest month ever. Our business remains strong, with over 30% revenue growth in Q1 2008 compared to the same quarter in 2007 (on a proforma basis including our acquisition of GetActive). You will also see announcements from us in the coming months that highlight our continued investment in providing solutions that help you get more value from every constituent relationship.

We remain committed to your success — keep up the great work!

Regards,
Gene Austin

A lot of that stuff sounds like spin to me... but you have to admit, it takes a certain of amount of chutzpah from Austin to give Blackbaud pointers on the need for them to "rationalize a roadmap" to integrate multiple eCRM and donor management platforms.

Make no mistakes, this is high stakes poker. Austin's use of this communique response to call on Blackbaud to "make their APIs freely available" seems designed to position Convio as an advocate on behalf of nonprofits against the newly created Blackbaud monster.

Thursday, May 29

Blackbaud announces acquisition of Kintera

...and then there were two.

In news just hitting the wires... Blackbaud announced today they are buying Kintera as an all-cash tender offer for all of the shares at a price of $1.12 per share.

Tim Williams, Blackbaud's Senior Vice President and Chief Financial Officer, stated, "In addition to the strategic reasons supporting the acquisition of Kintera, we believe the acquisition is attractive from a financial perspective as well. Subscription revenue was already the fastest growing source of revenue at Blackbaud and it was expected to become larger than license revenue at some point in the second half of 2008. With the acquisition of Kintera, this will become a certainty as we will add another significant source of subscription-based revenue from an on-demand service offering. The evolution of Blackbaud’s business model toward new revenue sources with ratable revenue recognition has been a significant and positive development over the past several years, and it complements the very strong cash flow profile of the Company.”
While the press release seems almost giddy, I'm not so sure nonprofits will be thrilled that their viable options for major providers continues to shrink. If I was a shareholder in BLKB, I would be concerned that $46 million is too much to pay for a provider that seemed destined to go out of business anyway.

Although, the only people who will suffer more than nonprofits looking for competition in the marketplace will be the folks at Convio who must be shitting themselves.
Kintera will continue to be led by its current President and CEO, Richard LaBarbera. The company is expected to formally launch the tender sometime next week and close on or around July 2.

UPDATE: 1232AM = Steve MacLaughlin at Blackbaud's Connections blog points out that:

Because both Blackbaud and Kintera are publicly traded companies there are very specific Federal Trade Commission rules about what can be said and done until the deal officially closes. This may take as many as 30 days and until then both companies will perform as separate units, competing with each other as they did prior to this announcement.
He goes on to say:

* Blackbaud becomes the leading provider of online solutions and services to the nonprofit industry with over 4,500 clients

* Both
Kintera Sphere and Blackbaud NetCommunity are strong Internet solutions that largely serve very different segments, including The Raiser’s Edge, Team Approach, eTapestry, and non-Raiser’s Edge customers.

* Blackbaud plans to continue to support and invest in both products.

* Kintera’s other offerings, FundWare, P!N and certain capabilities within Sphere (e.g., Friends Asking Friends) are well-recognized and respected in the marketplace.
Hmmmmmm. Interesting.

Thursday, May 15

MPower announces "database connector" with Convio

I got an email press release today about how Convio and a company called MPower announced the availability of a "Database Connector" to integrate Convio's online constituent relationship management (eCRM) suite and content management system (CMS) with MPower's offline donor management solution.

This isn't the first time the two companies have worked together. Back in 2005 they announced a partnership to do basically the same thing... although back then it wasn't called "database connector" it was called "Optimizing Online and Offline Data Integration for Joint Customers."

Back then MPower bragged that they had "more than 225 leading Christian organizations, including Insight for Living with Chuck Swindoll, Walk Thru the Bible, and Habitat for Humanity Orange County." MPower also listed Fellowship of Christian Athletes, Mothers of Preschoolers, East-West Ministries and Voice of the Martyrs as clients at that time and the press release from 2005 said that Turning Point Ministries was a joint customer of Convio & MPower as well.

MPower's website says that they have "hundreds of nonprofits of all sizes with diverse missions and constituencies, including some of the world's largest and most sophisticated direct marketers." Although they don't carry offer a client list on their website. If any readers know of any nonprofits that use their system, let us know in the comment section.

I saw that MPower's CEO, Randy McCabe, runs his own blog called "Freedom to Fundraise." It looks like a decent site... although he doesn't post that often. I recommend this post about how the stock prices of vendors to charities are getting battered.

Wednesday, November 28

Four weeks too late

It's hard to get a lot of respect as an anonymous blogger. I understand that. Why would you trust someone who writes a blog without the accountability of their own personal reputation? That's one of the reasons, I got myself an intern to kick around.

But, come on. That doesn't mean you can simply ignore anonymous blogs altogether and wait for the mainstream media to deliver the news you need.

The security breach at Convio is a perfect case in point. Those of you that read this blog regularly knew back on November 4th that Convio had confirmed the fact that hackers stole password information. During the days that followed, I published no less than 13 entries, I kept in contact with the folks at Convio to ask questions and get official comments, I even posted a detailed analysis on what 6 groups did to notify their members.

I'm not trying to toot my own horn. However, I am shocked by the amount of email I received today from folks who only read about the security breach yesterday in the New York Times. One email was even titled, "BREAKING NEWS" and begged me to notify readers immediately?

Seriously? If anything bad happened, the risk was four weeks ago when the breach occurred.

This isn't news. I'm not sure why the New York Times waited so long to publish their story... Stephanie Strom had to have known this was old news. So, either the timing of the publication is weird or the New York Times just proves once again how blogs have changed the speed of the information world.

Thursday, November 22

TechSoup's news - so old it's cold

A reader just forwarded me this email (dated Nov. 20th) from TechSoup, one of the leading edge techie types advising the nonprofit world. Why did it take them so long to notify subscribers?

TechSoup By the Cup - November 20, 2007
The Newsletter from TechSoup.org
"Technology served the way nonprofits need it."

***********************************************
CONVIO SUBSCRIBER ALERT:

Convio/GetActive - the service TechSoup uses to manage and distribute By the Cup - is warning subscribers to exercise caution after hackers broke into its systems and stole email addresses and passwords from 92 nonprofit clients.

While the vast majority of TechSoup email newsletter subscribers were unaffected, 3,000 TechSoup subscribers may have had the usernames and passwords they used to manage their email subscriptions stolen.

There is potential for misuse of this information should you use the same email address and password on other personal accounts (e.g, banking, PayPal,Amazon, Web-based email sites, etc.) Convio would like to advise you of important steps that you should take to prevent misuse of your personal information:

* If this email address and password are used together on any other accounts, it is recommended you change your password on those accounts immediately.

The email goes on to warn subscribers to be wary of emails asking for information. They also reassure folks that their privacy is taken seriously.

Yikes. Are they serious when they use words like "immediately" even though they waited almost three weeks to send out this notice? Maybe they should use warn us about the potential problems associated with Y2K?

Thursday, November 15

Coverage of Convio security breach varies

This blog covered the news of Convio's recent security breach closely. We noted that despite Convio's best efforts to notify all 92 nonprofits impacted by the hacker - it seems only a handful of nonprofits made the news public.

Today I came across three stories of the breach that told the story - all with a slightly different tone:

Roger Craver at The Agitator applauded Gene Austin, Convio's CEO for prompt and open recognition and acknowledgement of problems - saying that it was a critically important part of the process of building trust. Roger even thought Austin "deserved a raise."

Compare that to Allan Benamer over at the Non-Profit Tech Blog who was not so gracious in giving Convio a "C-".

Convio gets that “C-” for the late disclosure and for not doing due diligence properly on their GetActive acquisition. However, Dave Crooke did a decent job of answering technical questions regarding the breach despite the fact that he did it on an e-mail list when he should have done it on the Convio site itself. However, Tad Druart, Convio’s Director of Corporate Communications, did a good thing by not only alerting the press but also the blogosphere. It was a calculated decision to be sure, but Tad probably tamped down on the level of blogging cattiness by the likes of yours truly and others.
I have to think Allen is referring to me as one of the others who might have been catty if Tad had not reached out to me to answer questions and offer official statements.

Finally, I thought it was interesting how the brief story on page 32 of the November 15th Chronicle of Philanthropy gave Gene Austin an opportunity to give the money quote... blaming the problem solely on the ghost of GetActive.

Despite the fact that roughly half of Convio's 1300 clients use the GetActive software, Austin told the Chronicle that he thinks the attackers may have focused on GetActive because, in the past, "Convio has put more investment in security than GetActive."

Thursday, November 8

UConn Foundation issues statement on security breach

The University of Connecticut Foundation, Inc. apologized in a statement to friends, alumni and donors who were impacted by the breach at Convio. They published the most common inquiries that callers and e-mailers have asked the UConn Foundation since notification of the breach was sent.

UPDATE: I must admit, I've been overwhelmed by the number of emails I've received from folks over the past few days. A couple readers wanted to let me know that the Care2 community was discussing whether EarthJustice was affected. It also seems like The Five Moms Campaign sent out an email to their supporters as well (I know, who the heck are the 5 moms, right?)

Security breach story continues to expand

Allan Benamer at the Non-Profit Tech Blog has been covering a couple angle's of the Convio security breach that - quite frankly - I don't understand all the technical issues. However, I know enough about security to be stunned by this exchange in Allan's comment field:

Anonymous "activist" wrote:
Convio’s multiple security failures here are elementary-level and simply inexcusable.

First, as mentioned before, there’s the unencrypted passwords issue.

But secondly, from what I’ve been reading about this, the GetActive and Convio network security was laughable. An employee was allowed to work from home, on a non-secure PC, without the latest spyware & malware protections? And this employee was someone with the priveleges to administratively access ALL 150 accounts that were affected or almost affected? Why does one employee need to be able to access 150 accounts? And this is at a company that is supposed to handle millions upon millions of records of data safely and securely?

A basic security audit would have pointed these vulnerabilities out — but I guess Convio didn’t want to bother with that.

I wonder how the potential of millions and millions of dollars of liabilities from this incident will affect Convio’s planned IPO

Allan responded by saying:
@activist — from what I can tell, the employee might have been phished so spyware and malware would not have helped. I’m more worried by the “download all the passwords” capability. That’s a bit nuts. It was like handing hackers the entire cookie jar. It was not a good kludge and all because they were too unwilling to do an open API. This is a great time to demand an SLA from Convio though. You couldn’t get it before but I’m sure there are lots of demands for SLAs right now coming at Convio.

Yikes. I hadn't read anything about the employee working from home who had access to so many records... and I certainly didn't think that this security breach could be tied to the new API developments that made headlines several weeks ago. Now I'm beginning to think we haven't heard the full story yet.

As always, I know the fact that I run this blog anonymously rubs some people the wrong way, but I continue to invite Convio to use the comments feature on this website if they choose to explain or refute any of this statements... after all, it seems like a better place than the progressive exchange list.

Wednesday, November 7

CARE notifies its donors of security breach

Jeff Herrity at RedBoots Digitial Rodeo shares his experience after getting an email from CARE and he makes the following observation:

Remember though, it it not their fault - but that of Convio who should be doing more to protect the data of it’s customers. A larger percentage of the bigger non-profits use Convio, so the problem could be wider than anticipated. And we could see a temporary increase in spam, and a decrease in overall responses over the next few weeks. (During this important year-end giving season).
Do you agree with Jeff that the timing of this breach could hurt year-end giving?

Tuesday, November 6

Nonprofit Times gets Austin to comment on Convio breach

Mark Hrywna at the Nonprofit Times got some more details from Convio:

“It was a very sophisticated attack. It took us longer than we would have liked to recognize,” said Convio CEO Gene Austin. Some of the tasks the intruder performed were routine, as if it was an administrator on the system, he said.

The intruder attempted to harm a donation page for a site “and that obviously is a nonstandard process very different from normal. Once that happened, we clearly knew something was wrong and caught them,” Austin said. The intruder began the attack by being routine, and now “we’re watching those standard routines much, much more closely,” he said.
Wow. A smart hacker, huh? But there is more:
“We immediately spent that night (Nov. 1), and most of the second, understanding the issues as well as eliminating any access points for further intrusion,” Austin said, and the rest of the weekend notifying clients. Each of the communications gave organizations tips on how to communicate and work with their constituents, including recommendations on changing their password and an 800-number to handle future questions.

Since the breach did not involve financial or personal information, it might not be a priority for the FBI, but Convio has submitted everything to authorities, as well as launching its own forensic investigation. “We’re starting to getting pieces of information this week, but we will not have a full picture for two or three weeks. We’ve installed additional monitoring, and doing a number of things to over-tighten the environment. The root cause will not be known until later this month,” he said.

“The most important thing for us now is to focus on clients and make sure they are on their feet as soon as possible,” Austin said. “Certainly we understand they trust us to manage this data. That trust has taken a little hit, and it’s important to regain and rebuild it.”
To read the full article, go here.

Was an employees login stolen?

The Non-Profit Tech Blog published more details from Dave Crooke at Convio which was posted to the progressive exchange list:

The intruder obtained a login and password belonging to a Convio(GetActive) employee. It appears that their PC was compromised, but we are still investigating - we have sent that PC’s hard drive to a forensic lab for formal analysis. The operating system level integrity of the GetActive production systems was not affected.

The intruder logged in and downloaded a number of email addresses and passwords belonging to constituents of GetActive client non-profits.
So, will we need to wait for the forensic analysis before we learn more?

ACLU of Southern California notifies donors

A reader passed along an email to me this morning from the ACLU of Southern California:

This weekend we learned about a security breach atGetActive/Convio, the company that provides internet servicesfor our online Action Team. Your information has not been affected.

There was no breach of personally-identifiable information orcredit card data, but some email addresses and passwords mayhave been obtained by an unauthorized third party.

Because we take your privacy seriously, we want you to know whatwe are doing to protect it. Even though your information was notaffected, GetActive/Convio suggests the following steps foronline security:

1. Do not reuse the same password for your online services suchas banking or PayPal.
2. Pay careful attention to emails you may receive requestingpersonal and financial information, and only provide it when youcan confidently confirm that it has come from a trustedorganization.
3. Report any suspicious activity immediately to the accountprovider (bank, credit card, etc.) and to credit bureaus.
That must be an especially hard situation for the privacy folks at the ACLU.

Second group issues press release on Convio breach

The National Parks Conservation Association sent out an alert to online members regarding the potential impact of Convio's security breach. They reiterated that no credit card or other personally identifiable information was breached, however:

[It is] possible that the email addresses and passwords used by our online members for managing their NPCA email subscriptions were obtained by an unauthorized third-party as part of this breach. NPCA has taken appropriate counter measures, and has alerted our members accordingly.
The group then asks members to call or email them directly with questions.

Monday, November 5

More blog coverage of Convio's security breach

Allan Benamer at the Non-Profit Tech Blog picked up the story of the Convio security breach. He's got interesting discussion going on in the comments section, including comments from Eileen Bayers, VP of customer relations at Working Assets and Tad Bruart, Convio’s Director of Corporate Communications.

The scary silence that followed Convio's security breach

It seems like Convio has done their part by getting the information out to clients regarding the security breach. What seems extremely troubling to me is that not all of the organizations seem to have contacted their donors/constituents to notify them of the risk they may face.

Granted - no credit card details were compromised. But, am I the only dummy out here who uses the same password for multiple online sites. If a hacker got my password from a GetActive client that I supported... I would be a prime target for identify theft if that same hacker tried to access my Yahoo! or PayPal account.

That is the next (and scariest) phase of this story.

Convio can only lead their clients by providing draft emails... they can't make the clients actually send the email to their constituents. Should they be more proactive and contact the affected people themselves? Is Convio legally allowed to contact these constituents?


All too often I've seen nonprofits try to sweep bad news under the rug and hope that it goes away. This is not one of those cases.

If you lost a set of keys and those keys have your address printed on the keychain, don't you have an obligation to notify the people who you share that house, apartment, or office with? What would you do if that happened to you? Do you keep your mouth closed and hope no one breaks in? And if they do, would you continue to pretend the thief didn't get the key from you?

Act for Change tells donors about Convio breach

Working Assets members who participate in their Act for Change program received this email on Saturday explaining Convio's security breach.

We regret to inform you that the company we contract with to provide online services, Convio, has identified a breach of one of their internet security systems. There was no breach of personally-identifiable information or credit card data, but your email address and password for managing your Act For Change and Working For Change subscriptions were obtained by an unauthorized third party.

There is potential for misuse of this information should you use the same email address and password on other personal accounts (e.g, banking, PayPal, Amazon, etc.) Convio would like to advise you of important steps that you can and should take to prevent misuse of your personal information:
It goes on to explain some steps donors should take to protect themselves.