Skip to main content

✨Na Technology Forum

responsibility to identify/report especially tech ...
searchSearch
Search

We have a 'Tech Help Hour' every week staffed by volunteer residents who help other residents with technology issues. If others have a similar program, what do you instruct volunteers to do when they interact with someone that they feel is especially vulnerable to scamming because of diminished cognition/judgment?

This is a sensitive issue. A lot depends on the community culture, and the degree to which the community is caring vs. transactional. I'll assume that the hypothetical resident is in the unregulated independent living end of the continuum of care. The management has no authority to proactively intervene. Your volunteers probably are not professionals, and not qualified to assess the cognitive or psychological capacites of another resident. So you shouldn't intervene.


That said, your CCRC probably has professional social workers. If you are concerned, you might discreetly give them a heads up. Express your concern and let them decide a proper course of action. Typically, they will be aware of the person in question, and they may reach out to the relatives, power of attorney, or other proxy who has standing to give support.


I'm working on a handout about secure technology and practices, but here's the essence of what it will say:


--------------------------------------------------------------------------------------------------------

Technology Can Help Protect People Who Are More Vulnerable to Scams

People who are experiencing cognitive, emotional, or other difficulties may be more vulnerable to scams even when they have used computers confidently for years. In these situations, scam prevention should not depend entirely on recognizing every suspicious email, phone call, pop-up, or website.

A better approach is to build technical guardrails around the person’s computer, communications, and finances.

The goal is not to eliminate independence. It is to make the most dangerous actions—such as installing remote-access software, opening risky applications, visiting malicious sites, or transferring large sums of money—more difficult or impossible without help from a trusted person.

Hardened Windows Computers

A Windows computer can be made considerably safer by giving the vulnerable user a Standard account rather than an Administrator account. The administrator password can be kept by a family member, friend, or other trusted helper.

This can prevent or interrupt one of the most common scam sequences:

“Call this number, go to this website, download this program, and let me connect to your computer.”

Programs such as AnyDesk, TeamViewer, ScreenConnect, and similar remote-support tools are frequently misused by scammers. If the user cannot install software without an administrator password, this avenue of attack becomes much harder.

Additional protections can include Microsoft Defender, SmartScreen, reputation-based application controls, and restrictions on which applications may be installed.

For people who primarily use email and the web, Windows 11 in S mode may offer an additional layer of protection because software installations are limited to applications available through the Microsoft Store.

A hardened Windows computer can therefore preserve the familiar Windows environment while placing important limits on what the user can change or install.

Chromebooks

A Chromebook may offer an even simpler protective environment for someone whose needs are primarily email, web browsing, documents, video calls, and online services.

ChromeOS already limits many of the ways ordinary Windows malware operates. With supervision and appropriate settings, access can also be restricted to approved applications, browser extensions, and websites.

At the most restrictive level, the user could have access only to approved sites such as:

  • email
  • the resident community website
  • newspapers
  • medical portals
  • banking
  • YouTube
  • selected shopping or information sites

A scammer could send a link, but the computer could simply refuse to open a website that had not been approved.

This type of whitelisting is one of the strongest protections available because it does not require the user to decide whether every unfamiliar site is safe.

iPad and Assistive Access

The iPad is another strong option because ordinary Windows-style programs cannot simply be downloaded and run.

Apple also offers Assistive Access, a simplified interface intended for people with cognitive disabilities. A trusted supporter can decide which applications and features are available and simplify how they appear.

Combined with restrictions on installing apps, changing accounts, or modifying settings, an iPad can provide access to email, FaceTime, photographs, websites, banking, and other useful services while reducing opportunities for scammers to manipulate the device.

GrandPad

GrandPad takes a different approach.

Rather than making a conventional computer safer, it creates a much more controlled communications environment. A trusted Family Administrator can manage contacts, applications, and features.

Its strongest protection is that communication can largely be confined to approved people.

That changes the scam problem fundamentally:

If strangers cannot easily reach the user, many scams never begin.

Internet access can also be limited to approved websites.

The tradeoff is independence. Someone accustomed to ordinary web browsing, online shopping, and installing applications may find GrandPad restrictive. For a person whose vulnerability has reached the point where unsolicited communications themselves are dangerous, however, those restrictions may be exactly what is needed.

Protect More Than the Computer

The device is only one part of the solution.

A scam-resistant environment should also consider telephone calls, text messages, email, and financial accounts.

Possible protections include filtering unknown callers, aggressive spam filtering, limiting communications to known contacts where appropriate, transaction alerts to a trusted person, lower transfer limits, separate accounts with limited balances, and credit freezes.

These protections are especially important because a scammer does not necessarily need to infect a computer. A persuasive caller may simply convince someone to transfer money, buy gift cards, disclose credentials, or visit a bank.

Protection Can Be Increased Gradually

It may be useful to think in terms of four levels of protection.

Level 1 — Cautious independence

A normal computer with automatic updates, security software, a password manager, multifactor authentication, and scam education.

Level 2 — Guardrails

A Standard Windows account, no administrator password, limits on installing applications, stronger browser protection, and a trusted person available to approve changes.

Level 3 — Controlled environment

A Chromebook or iPad with restricted applications, extensions, websites, and account changes.

Level 4 — Trusted-circle computing

A device such as GrandPad, where communications, websites, and features are largely limited to those approved by a trusted administrator.

This allows protection to increase gradually rather than waiting until someone must give up technology altogether.

One Particularly Valuable Safeguard

If families, resident associations, or senior communities develop technology-safety programs, one rule deserves special attention:

A person who is especially vulnerable to scams should not be able to install or authorize remote-control software without intervention by a trusted administrator.

That single safeguard could prevent a large number of tech-support, bank-impersonation, and computer-security scams.

The broader objective should be to preserve as much independence as possible while designing the technology so that a moment of confusion, fear, or misplaced trust does not lead to a catastrophic loss.


----------------------------------------------------------------------


What do you think? As my wife says, "Together we are a genius." Share your ideas here, and contribute to my handout.



Richmond Shreve

NaCCRA Board Member & VP

Forum Moderator

I'd like to share some information related to this subject. A few years ago a more technically savvy IL resident

asked our CFO if management was concerned about residents being scammed out of their nesteggs, thereby creating an inability to pay their monthly CCRC fees -- therefore creating the need to draw upon our Resident Benevolent Fund. This techy IL resident reported that he was being called upon to help neighbors with their computer problems and was VERY concerned about their vulnerability and lack of understanding. I was shocked to hear what the CFO said: that being scammed "might" be considered poor financial management ... and financial assistance couldn't be guaranteed because the contractual relationship between resident and the organization required a resident to exercise good financial management of their assets.


I was in this meeting and heard the above firsthand. I chose not to respond right then, but I sure thought, "Give me a break. You'd kick a resident to the curb because they got scammed out of their money? Doin that would make the 6:00 p.m. news locally and you'd never recover from the black eye."


Since I'd been attending national LeadingAge conventions for years, the next one I went to after hearing the above commentary (Denver) led me to stop at a vendor booth in the EXPO Hall -- one that specialized in providing individual technical services to seniors. They had contracts with management to provide educational sessions and on-site individual consultations and 24/7 help via phone. I grabbed their literature, taking a set to our newly-promoted Exec Dir. That went nowhere. Discouraged, I contacted this vendor and learned they were developing a resident-driven product -- where one could individually "enroll" with their services. I asked for references of communities who contracted for their community-based product and called them.... all were pleased with this compnay, but the on-going relationships had been affected by Covid. For example, I would ask the references (often it was the Exec Dir I contacted) why the management didn't just encourage their residents to use the retail services of The Geek Squad. Answer: Because those young people of the Geek Squad don't relate as well to seniors and assume seniors know more than they really do... more or less talking over them.


I continued to inquire of this vendor I'd met in Denver how they were faring with their individual product and learned that they weren't yet ready to expand into our part of the country (North Carolina). Soon, I got no responses at all, so I figured that they were a Covid casualty like some businesses were.


Cut to the latest vendor I located, thanks to a press release sent to me a year ago by the technically savvy resident I mentioned in the first paragraph above. I contacted them. Its services were very similar to the now-defunct vendor. Headquartered in CA, they had plans to expand eastward, going nation-wide. I made a point to visit their booth last November at LeadingAge Boston. The Marketing Person (whom I had corresponded with) was in the booth and was very welcoming. I asked how far east they'd come so far. Answer: Michigan and Indiana. Sorry folks, but I encouraged them to skip to the east coast, concentrating on PA, NC, and FL.


If anyone has read this far and would like to learn more about this 2nd vendor, you can contact me individually. Personally, I think there's a market for this kind of help for seniors who know of their vulnerability but don't know where to turn.


Jennifer Young

Thanks for sharing this experience. It is exactly the "transactional" culture that is replacing caring community culture. Fortunately the CEO and the administration don't dictate what IL residents can do for themselves. At Pennswood residents are educating other residents, and we treat scams as an emergency. Check out the Safety Forum for more ideas.


Richmond Shreve

NaCCRA Board Member & VP

Forum Moderator

We have ongoing scam  recognition education programs. We have had our corporate risk management team also provide programs which are taped and are available in our  on-demand video section of our portal. 

One of the themes that comes through is that you don’t have to be naïve and not tech savvy to be caught up in a scam because of the sophisticated social engineering that the scammers are now using. It can happen to anyone. 

We also have on site tech-support people who have been able to help people who may be caught up in a scam. There is a fee for that service. The key is education.


Ann MacKay

arrow_backReturn to Forum