Posted on

Cybersecurity for Nonprofits: 6 Costly Gaps to Fix

Nonprofit staff reviewing cybersecurity settings on a laptop

Cybersecurity for nonprofits usually breaks at six predictable points: unpatched email accounts, shared logins, unmanaged volunteer devices, donor data spread across free tools, no backup you have tested, and no plan for the hour after a breach. None of these need a big budget to fix. They need attention, a short written policy, and a few settings turned on. Attackers target nonprofits because the data is valuable and the defenses are thin, not because the mission is small. Close these gaps in the order below and you remove most of the risk that actually causes harm.

Why Nonprofits Get Hit Harder Than Their Budgets Suggest

Nonprofits get attacked because they hold high-value data on lean, volunteer-heavy teams with almost no security spending. I have sat with development directors who assumed no one would bother a food bank or a youth program. The attacker does not see a mission. They see donor names, credit card records, grant details, and beneficiary files sitting behind a single password. That combination, valuable records plus thin defense, is exactly what automated attacks look for.

The money side makes it worse. Most nonprofits put every dollar toward the program, so security gets whatever is left, which is often nothing. Surveys of the sector keep finding that more than half of organizations have no line item for security at all, and most staff say they would not know what to do during an attack. We see the result every quarter: a wire-transfer scam that drains a grant, or a ransomware note on the one laptop that held the donor list.

Here are the five ideas this article comes back to:

  • The data you hold is the target, so protect the records first, not the hardware.
  • Free and built-in controls close most gaps before you spend a cent.
  • Volunteers and part-time staff need rules that survive turnover.
  • A tested backup is the difference between an incident and a shutdown.
  • A one-page response plan turns a panic into a checklist.

Gap 1: Email Accounts With No Second Lock

Nonprofit email is the front door for attackers, and most doors have only one lock. The single most common way we see a nonprofit get breached is a stolen password on a staff or board email account. Fix this first because it is free and it blocks the majority of account takeovers.

Turn on multi-factor authentication, the second step that asks for a code or app approval after the password, for every account in Microsoft 365 or Google Workspace. Both platforms include it at no extra cost, and both offer discounted or donated nonprofit licensing. Make it required, not optional, or busy people will skip it. Our team walks nonprofits through the same starting checklist we cover in our guide to cybersecurity best practices for smaller organizations, and multi-factor authentication is always step one.

The counterargument I hear is that codes slow volunteers down. That friction is real. It is also far cheaper than the wire fraud that follows a hijacked executive director account. Set it up once, add the phone app, and the daily cost drops to a two-second tap.

Gap 2: Shared Logins Nobody Can Trace

Shared logins remove the one thing you need after an incident: the ability to see who did what. Nonprofits love a single “info@” account or one password taped inside a desk drawer because it feels simple. It is simple right up to the moment a volunteer leaves, a password leaks, and you cannot tell which of nine people clicked the bad link.

Give every person their own account with their own password. Use a password manager, many offer free nonprofit tiers, so no one reuses the same weak phrase across the donation platform, the bank, and email. When someone leaves, you disable one account instead of changing a password that eight other people still need.

Some small teams argue that individual accounts are overkill for five people. In practice the opposite is true. Small teams have the highest turnover of volunteers and interns, so clean account handoffs matter more, not less. If you also handle regulated records, this ties directly into the donor-data duties we cover in IT compliance for nonprofits.

Gap 3: Volunteer Devices You Do Not Control

Personal volunteer laptops and phones are the part of your network you can see the least and trust the most. Volunteers log into your donor system from a home computer that may already carry malware, and you have no view into it. This gap grows every fundraising season when you add temporary help.

You do not need to buy everyone a device. You need three rules. First, no downloading of the full donor database onto a personal machine, work inside the cloud tool instead. Second, require a screen lock and current updates on any device that touches your systems. Third, remove access the day a volunteer finishes, using the individual accounts from Gap 2. Our managed cybersecurity services can enforce these rules automatically, but a written policy and a shared checklist get a small team most of the way for free.

The pushback is that strict device rules scare off volunteers who are donating their time. Frame it as protecting the people you serve, not policing the helper. Most volunteers accept a screen lock and a “work in the browser” rule once they know a leak would expose the families in your program.

Gap 4: Donor Data Scattered Across Free Tools

Donor data protection fails when records live in a dozen places no one is tracking. A typical nonprofit keeps donor details in a spreadsheet, an email inbox, a donation platform, a mailing tool, and a shared drive. Every extra copy is another place to breach, and most were never secured on purpose.

Start by writing down where donor and beneficiary data actually lives. That single inventory usually shocks the board. Then cut copies: keep the record in one primary system, restrict who can export it, and delete the stray spreadsheets. Encrypt the files that remain, which on Microsoft 365 and Google Workspace is a setting, not a purchase. If your work touches health, education, or payment data, mapping storage is also the first step toward cybersecurity compliance obligations you may already be under.

There is a fair objection that consolidating tools costs staff time you do not have. True, the cleanup takes a few afternoons. But scattered data is the reason a small breach becomes a full donor-list breach, and the cleanup is a one-time cost against an ongoing risk.

Gap 5: Backups You Have Never Actually Restored

A backup you have never restored is a hope, not a safety net. Nonprofits often assume the cloud tool “has a backup,” then learn during a ransomware event that the copy was incomplete, out of date, or encrypted along with everything else. The gap is not the absence of backups. It is the absence of a tested one.

Follow a simple rule: keep three copies of important data, on two different types of storage, with one copy offline or in a separate cloud account. Then, once a quarter, actually restore a file and confirm it opens. That test is the whole point. We keep a plain-language checklist for this in our cybersecurity resources library, and building the habit costs nothing but a recurring calendar reminder.

Some directors feel a backup review is a job for a big IT department. It is not. A volunteer with a checklist can run the quarterly restore test in an hour. The organizations that skip it are the ones we meet through our emergency cybersecurity response line, usually on the worst day of their year.

Gap 6: No Plan for the First Hour After a Breach

The first hour after a breach decides how bad it gets, and most nonprofits spend it guessing. Without a written plan, staff freeze, the wrong people get told last, and donors hear about it from the news instead of from you. A one-page plan removes the guessing.

Write down four things and tape them where staff can find them. Who to call first, an internal lead and an outside security contact. What to shut off, usually the affected accounts and any shared drives. Who must be notified, your board, your bank, affected donors, and any regulator that applies to your data. How you will communicate, with a short honest message ready to adapt. Then practice it once by talking through a fake phishing case for twenty minutes. Training the people is half the plan, which is why we walk nonprofits through running a staff security awareness session.

The common view is that only large organizations need an incident plan. The reverse holds. A large company has a security team to improvise with. A ten-person nonprofit has the plan on the wall or it has chaos. For a fuller walkthrough, our team put together a guide on getting nonprofit cybersecurity in place before a breach hits.

What This Costs and Where to Start

Cybersecurity for nonprofits does not start with a purchase, it starts with a week of free changes. Turn on multi-factor authentication, give everyone their own login, and write the one-page response plan. Those three moves are free and block most of the damage we see. Next, inventory your donor data and test one backup restore. Only after that should you consider paid tools, and even then many vendors offer donated licensing to registered nonprofits. If money is the blocker, our guide on building a security budget for a small organization shows how to stage spending against the highest risks first. One of our clients went through this same sequence and turned a fragile setup into a stable one without a large check, a story we shared in this cloud and cybersecurity case study.

Frequently Asked Questions

Why are nonprofits targeted by cyberattacks?

Nonprofits are targeted because they hold valuable donor, payment, and beneficiary data while running on small budgets with thin defenses. Automated attacks scan for that mix of high-value records and weak protection, and the size of the mission does not make an organization less appealing to an attacker.

How much does cybersecurity for nonprofits cost?

The first and most effective steps cost nothing, since multi-factor authentication, individual logins, data cleanup, and a written response plan use tools you already have. Paid protection can come later, and many security vendors and cloud providers offer discounted or donated licensing to registered nonprofits, so budget is rarely the true blocker.

What is the single most important security step for a small nonprofit?

Turn on multi-factor authentication for every email and administrator account, because stolen passwords are the most common way nonprofits get breached. It is free on Microsoft 365 and Google Workspace, and it blocks the majority of account takeovers that lead to wire fraud and data theft.

How do we secure volunteer devices without buying new equipment?

Set three rules instead of buying hardware: keep data inside cloud tools rather than downloaded to personal machines, require a screen lock and current updates, and remove access the day a volunteer leaves. These rules protect your systems at no cost and survive the high turnover that comes with volunteer teams.

What should a nonprofit do first if it suspects a breach?

Call your designated internal lead and outside security contact, then disable the affected accounts to stop the spread. Work from a one-page plan that lists who to notify, including your board, bank, affected donors, and any regulator, so the first hour follows a checklist instead of panic.

Protect Your Mission, Not Just Your Network

Cybersecurity for nonprofits comes down to protecting the people who trust you with their data, and the six gaps above are where that trust usually breaks. You can close most of them this month with free settings, individual accounts, a data inventory, a tested backup, and a plan on the wall. The organizations that get breached are rarely the ones that spent the most. They are the ones that never turned on the second lock or wrote down who to call. Start with the free moves, stage the paid ones against your real risks, and treat each fix as protection for the families, donors, and communities you serve. If you want a second set of eyes, our team offers a free strategy call to walk through your setup and point you to the changes that matter most, through our managed cybersecurity services.

Related Posts

Matt Rosenthal