In October 2024, immediately after the above-referenced fraud was committed, SELF created a new policy with tighter internal controls in regard to ACH payments. The new policy requires multiple staff members to verify any banking information (in multiple ways) before any such payment can be initiated. The new policy was approved shortly thereafter by the organization’s board. SELF also contracted with a digital security company to train all employees about digital threat awareness including fraud and phishing attempts, specifically via email. As part of these new practices, all employees are required to participate in monthly training.