Blog / The data you hold
The data you hold
The Donor File Is Your Most Sensitive Record, and It Is Wide Open Until Thursday
Nonprofit donor data security before the year-end appeal: what sits in the CRM, who can reach it, and the six checks a Washington DC nonprofit makes first.
Two weeks before the year-end appeal
The development director of a 22-person advocacy organization two blocks off Dupont Circle is building the year-end appeal file on a Thursday afternoon. Eleven thousand donors, sorted by giving history, with a separate segment for the 140 people who might give five figures if the executive director calls them personally.
She exports it to a spreadsheet, because the mail house wants a spreadsheet, and drops it in a shared drive folder that a consultant set up during the spring campaign. The folder is set to anyone with the link. It has been that way since April.
The file has columns nobody thinks about until they are read aloud. Home addresses. Employer. Spouse. Bank routing details for the 600 monthly sustainers. And the notes field, where a program officer wrote, in the candid shorthand development teams use, that a donor's giving dropped after a divorce and that another is expected to fund a program in memory of her late husband.
The consultant's own email account was compromised in October. Nobody at the nonprofit knew: her engagement ended in June and her access never did.
The appeal goes out on the first Tuesday of December. Three weeks later a donor calls to ask why she got an email, from an address one letter off the executive director's, referencing the gift she made in memory of her husband, and asking her to wire it to a new account this time.
What the heck does this mean
Donor data is a category of its own. It behaves like customer data, employee data and health data at the same time, which is why the standard advice for a small business does not fully cover it.
Constituent relationship management system, the CRM: the database that holds every donor, gift, pledge and interaction. It is the single most valuable asset most nonprofits own, and it is rarely treated that way.
Anyone with the link: a sharing setting that turns a file into a public web page for anybody who ever receives, forwards or finds that address. Search engines and browser extensions find them.
Vendor access: the consultants, mail houses, agencies and volunteer database managers who need a login for a season and keep it for years. In your CRM they are usually indistinguishable from staff.
Impersonation of the executive director: an attacker with a copy of your donor file knows names, giving amounts and the story behind the gift. That is enough to write an email your donor believes, and to ask for money in the same voice you use.
The reason this stings for a nonprofit is not the cost of the incident. It is that trust is the product. A donor who learns their circumstances were in a spreadsheet on the open internet does not send a complaint. They stop giving, and they tell two people.
The numbers that matter
Third parties were involved in 48% of breaches in the Verizon 2026 Data Breach Investigations Report, an increase of 60% over the prior year. For an organization that runs its appeal through consultants and a mail house, that is the most relevant statistic in the report.
Business email compromise accounted for USD 3.05 billion in reported losses across 24,768 complaints in the FBI IC3 2025 Internet Crime Report, with 86% of the funds moved by wire or ACH. A redirected major gift arrives inside that number, and so does a redirected grant payment.
Ransomware featured in 88% of breaches at small and medium organizations in the Verizon 2026 DBIR. A nonprofit with an encrypted CRM in the second week of December has lost the appeal, not just the week.
What to do this week
- Open your shared drive and filter for files shared with anyone with the link. Every export, every mail merge, every board packet. Turn the setting off, then set exports to expire so it does not rebuild by April. (CIS 3 Data Protection)
- Pull the user list from your CRM and read it out loud with the executive director. Former staff, the spring consultant, the volunteer who built the reports in 2023, the intern. Remove everyone who does not have a reason today, and give the ones who remain their own named account. (CIS 6 Access Control Management)
- Turn on multi-factor authentication for the CRM, email, the payment processor and the online giving page, starting with the four people who can export the full donor list. Those four accounts are the appeal. (CIS 6 Access Control Management)
- Write the gift verification rule and tell your major donors about it in the appeal letter: this organization will never change its bank details by email, and any request to do so should be confirmed by calling the office number on the website. A rule your donors know about protects them from an email you never sent. (CIS 3 Data Protection)
- Put two clauses in the mail house and consultant agreements before the appeal drops: named individual accounts with an end date, and written notice to you within 72 hours of any incident that touches your data. (CIS 15 Service Provider Management)
- Test a restore of the CRM from a backup that is not connected to your network, note how long it took, and put that note in the board file. December is the wrong month to discover the answer. (CIS 11 Data Recovery)
Where AccuSights fits
Small teams with big files are our normal work. Our assessment shows where donor records actually live, which is usually four places nobody listed, who can reach them, and which vendor holds a copy. You get a ranked plan sized for a staff of 22, not a 90-page report. Our team implements the controls at a reasonable rate, from data loss prevention to scanning to protection of the systems that run the appeal, and we work with nonprofits across the District, Maryland and Northern Virginia. The Cyber Hygiene Test takes three minutes; a call with an engineer takes fifteen.
Questions people ask
What donor information is actually sensitive? More than the mailing address. A donor record usually carries giving history, employer, household relationships, bank details for recurring gifts and the notes your team writes after a meeting, including capacity ratings and personal circumstances. The notes are the part that ends careers and relationships, because they were written for internal use in a candid tone and read like an insult on a screenshot. Treat the notes field with the same care as the ACH details.
Do consultants and agencies need their own logins to our CRM? Yes, their own named logins, with the access their role requires and an end date on the engagement. Shared accounts and passed-around passwords make it impossible to answer the only question that matters after an incident, which is who exported what and when. Put the named-account requirement and a breach notification clause in the contract before the appeal season starts, and switch the accounts off the week the engagement ends.
Does a nonprofit have to notify donors after a breach? In practice, usually yes. Every US state has a breach notification law and they apply to nonprofits, with the trigger set by the residency of the affected people rather than by where your office is, so a national donor list means multiple state rules at once. Twenty US state privacy laws are also in force in 2026 with their own obligations. Ask counsel early, and make sure someone can produce the exact list of records touched, because the size of the notice depends on that list.
You ask people to trust you with their money and their reasons. The file where you keep both deserves better than a link that has been open since April.
Controls this post maps to
CIS Controls v8.1. These are the same controls our assessment scores and the console watches.
Sam Khan, Founder and CEO. CISA and CRISC. More than two decades in financial services security and risk, from the Federal Reserve System to Guggenheim. Reads the week in threats so an owner does not have to. About the team →
Keep reading
Three more from the same shelf.
Private Schools, Tutoring Centers and the Shared Link: Student Data When IT Is One Person Who Also Teaches Robotics
Private school student data and FERPA: what schools hold, which rules apply when you take no federal funds, and the 56 safeguards one IT person can run.
The data you holdClient Financial Data: What a Law Firm, CPA or Wealth Advisor Is Really Holding
Client financial data security for law firms, CPAs and advisors: what you are holding, the 30-day breach clocks that now apply, and the folder to lock first.
The data you holdCUI for the Shop Floor: What It Is, Where It Hides, and Why 'We Only Make Brackets' Is Not a Defense
What is controlled unclassified information, why a machine shop's drawings count, where CUI hides in email and Dropbox, and why 'we only make brackets' fails.
