Cybersecurity guidance built for nonprofit realities
Nonprofits manage sensitive employee, donor, member, participant, and financial information while often relying on lean internal teams and multiple outside providers. A practical assessment should account for those operating realities rather than apply an enterprise checklist without context.
Areas the assessment can review
Governance and ownership
Decision rights, policies, leadership reporting, risk acceptance, and accountability.
Identity and access
Multifactor authentication, privileged access, onboarding, offboarding, and account reviews.
Microsoft 365 and core systems
Security settings, email protection, device controls, data handling, and administrative practices.
Vendors and IT providers
Responsibilities, contract expectations, access, evidence, and third-party risk oversight.
Resilience and response
Backups, recovery, incident response, communications, and decision-making during disruption.
Insurance and external requirements
Cyber insurance applications, grant expectations, contracts, and customer questionnaires.
What leadership receives
- A plain-English summary of material risks
- A prioritized improvement roadmap
- Clear separation of urgent, near-term, and longer-term work
- Identification of owners and outside-provider dependencies
- Practical recommendations that consider cost and organizational capacity
Not another shelf report
The assessment is designed to support decisions. Findings should help leadership determine what to fix, what to verify, what to document, and what risk may need to be accepted or transferred.