Nonprofits are built on trust. Donors trust you with their payment details, clients trust you with personal information, and funders trust you to spend their money well. A single phishing email or ransomware attack can put all three at risk. The good news is that the controls that stop most attacks are not expensive. They just have to be in place, configured correctly and watched.
This guide covers the security basics every nonprofit should have, the threats that target nonprofits most often, and how to protect donor and client data without a large IT budget.
Why attackers target nonprofits
Attackers look for organizations with valuable data and limited defenses. Many nonprofits fit that description. You may hold donor records, payment card data, bank details for grants and payroll, and sensitive information about the people you serve. At the same time, staff are often stretched thin, volunteers come and go, and security tends to fall behind program work.
The most common attacks against nonprofits are not sophisticated. They are phishing emails that steal passwords, fake invoices and payment change requests aimed at finance staff, and ransomware that locks files until a payment is made.
The security basics every nonprofit needs
These controls stop the majority of the attacks nonprofits face:
- Multifactor authentication on every account. A stolen password is useless without the second factor. Turn it on for email, your donor database, banking and any cloud system that holds sensitive data.
- Email filtering and phishing protection. Most attacks start in the inbox. Good filtering catches malicious links and attachments before staff ever see them.
- Endpoint protection with monitoring. Modern antivirus is not enough on its own. Someone should be watching alerts and able to isolate a compromised laptop quickly.
- Regular patching. Keep operating systems, browsers and applications updated automatically, including on laptops that rarely come into the office.
- Tested backups. Back up email, files and key systems, keep a copy that ransomware cannot reach, and test restores on a schedule.
- Access that follows people. When staff or volunteers leave, their access should end the same day. Shared passwords should be replaced with individual accounts and a password manager.
Protecting donor and client data
Start by knowing where sensitive data lives. For most nonprofits that means a donor management system, a finance system, email and shared files. For each one, confirm who has access, whether multifactor authentication is on and whether the data is backed up.
Limit access to what each role needs. A volunteer coordinator does not need access to payroll, and a program assistant does not need to export the full donor list. Encrypt laptops so a lost or stolen device does not become a data breach. If you accept donations online, rely on your payment processor to handle card data rather than storing it yourself.
Training staff and volunteers
Technology stops most threats, but people stop the rest. Short, regular security awareness training helps staff recognize phishing, verify payment requests by phone before sending money and report anything suspicious right away. Make reporting easy and never punish someone for asking. The fastest way to contain an attack is a staff member who speaks up early.
Answering funders, insurers and auditors
More funders and cyber insurers now ask nonprofits to describe their security controls, often through a questionnaire. Insurers frequently expect multifactor authentication, endpoint protection and tested backups before they will write or renew a policy. Having these controls in place, and documented, makes those conversations simple instead of stressful.
A practical starting point
If you are not sure where your organization stands, start with an assessment. A good review checks your accounts, devices, email, backups and access, then ranks what to fix by risk and cost so you can tackle the most important items first.
E-Valve Technologies helps nonprofits across New York, New Jersey and Connecticut put these protections in place as part of one all inclusive managed IT service. Book a free technology assessment and a senior engineer will review your security and give you a clear, prioritized plan. You can also read more about our managed security services and IT for nonprofits.


