AccuSights
PartnersBlogAbout
Book my 30-minute demo

Nonprofits & Associations · Cybersecurity, compliance and GRC, in plain English

The mission is yours. The donor list should stay that way.

A donor database going back to 1994, a volunteer login still active from the spring gala and a Giving Tuesday campaign that is a third of the year. Attackers do not check your tax status. We close the shared logins, back up the database where ransomware cannot reach it, protect the finance inbox from the fake grant request and watch it all, at a price sized for a nonprofit.

Nonprofit pricingFunder-ready policy setSee your score immediately

The test is scored against CIS Controls v8.1 IG1 and the CIS Community Defense Model. You see your score immediately, then we talk if you want to.

A story we hear too often

The Giving Tuesday the donor database asked for a ransom

the executive director of a 25-person food bank

Grace runs a food bank on the West Side with 25 staff, four hundred volunteers and a donor database that goes back to 1994. Giving Tuesday is a third of the year’s individual gifts, and the email goes out at 6 a.m.

At 6:40 the development director cannot open the donor system. The screen says the files are encrypted and lists the names of three major donors as proof. Somewhere in the last week, a volunteer’s shared login, still active from the spring gala, was used to install something on the fundraising PC.

The version that goes badly: the gifts that day land on a page that no longer works, the donor list is posted online with giving histories, the board learns from a reporter, and a foundation pauses a grant pending a security review nobody can pass.

In Grace’s version, the protection agent quarantined the fundraising PC at 2:12 a.m. and the engineer on watch restored the donor database from the offline copy before staff arrived. The 6 a.m. email goes out at 6. The only thing Grace changes that day is the volunteer account policy, and she changes it by nine.

The screen says the files are encrypted and lists the names of three major donors as proof.

What changes the ending

  1. No shared or volunteer logins that outlive the event, and MFA on every account (CIS Control 5, Account Management)
  2. Offline, tested backups of the donor database and the finance system (CIS Control 11, Data Recovery)
  3. Endpoint protection on the fundraising and finance PCs, with someone watching overnight (CIS Controls 10 and 13)
Show me this running for my business

The questions owners are afraid to ask

Ask them anyway. Here are the answers.

We are a nonprofit. Why would anyone bother attacking us?

Because the donor database holds names, addresses, giving capacity and sometimes card details, and because nonprofits pay when a Giving Tuesday campaign is on the line. In the latest DBIR, 96% of ransomware victims where size was known were small and mid-size organizations, and attackers do not check your tax status.

What if the finance manager wires a grant payment to a fraudster’s account?

That is business email compromise, and it hits nonprofits through fake vendor invoices, fake executive-director requests and diverted payroll. MFA on every mailbox, a two-person rule for any payment or bank change and inbox monitoring stop it; the assessment tests whether those rules exist in practice.

A funder is asking for our cybersecurity policy before renewing. What do we send?

Funders increasingly ask for a written policy, evidence of MFA and backups, and an incident plan. The assessment produces the policy set and the evidence, and Protect keeps it true so next year’s renewal is a formality.

What you hold, and why someone wants it

Your data protection needs, by the data.

The donor database

Names, addresses, giving history and capacity ratings: a targeting list for fraud against your most generous supporters. Access limits, MFA and offline backups protect it.

Program participant records

Clients of a food bank, a shelter or a clinic whose information can put them in danger. Encryption, minimal collection and access reviews protect them.

Online donations and card data

Donation pages and event checkouts carry cards under PCI DSS. Hardened platforms and vendor review protect them.

Grant, finance and payroll files

Bank details, budgets and the payroll file that business email compromise targets. Two-person approval and mailbox security protect them.

Volunteer and staff accounts

Dozens of logins that outlive the event or the person. Account lifecycle rules and quarterly reviews protect them.

96%
of ransomware victims where size was known were small and mid-size organizations; attackers do not check your tax status
Source: Verizon 2026 Data Breach Investigations Report
$3.05B
lost to business email compromise in 2025; fake vendor invoices and diverted grant payments are the nonprofit variant
Source: FBI IC3 2025 Internet Crime Report
$6.75M
paid by a nonprofit fundraising-software vendor to California in June 2024 over a breach of donor data, on top of settlements with 49 other states and the FTC
Source: California Attorney General, June 13, 2024

No regulator at the door, still rules that apply

What you are still on the hook for, in one page.

State charitable solicitation and breach notification laws
State attorneys general
Donor and participant data stolen in a breach triggers notification in all 50 states; several states add security duties for charities that solicit online.
PCI DSS v4.0.1
PCI Security Standards Council
Donation pages, event checkouts and any card taken at the desk fall under the standard.
HIPAA, if you provide health services
HHS Office for Civil Rights
Clinics, counseling and community health programs are covered entities regardless of nonprofit status.

Verified September 2026 from the regulators' own publications. We map all of it to one control set so evidence is produced once.

A note on authority: the regulator, auditor or certifying body has the final say on whether you comply. We help interpret the requirements, scope what applies, gap-assess against what is published today, and keep you compliance-ready and secure as the guidance evolves. We hold no regulatory authority and do not certify.

The threat picture

What actually goes wrong, and what we do about it.

  • Ransomware on the fundraising PC the week of the year-end appeal, with donor names posted as proof.
  • A fake vendor invoice or executive-director request that diverts a grant payment.
  • Shared and volunteer logins that outlive the gala and open the donor database to whoever kept the password.

It happened to businesses like yours

The BianLian ransomware group claimed in September 2023 to have taken about 7 TB of data from Save the Children International, including financial, health and medical files; the charity confirmed an IT incident.

September 2023 · The Register

A RansomHub ransomware attack on Planned Parenthood of Montana in August 2024 took systems offline; the affiliate later notified patients that medical and insurance information had been taken.

August 2024 · HIPAA Journal

Public incidents, listed to show the pattern, never to shame a victim.

Protect, for a nonprofit business

We protect your people, every device, the servers and the website. Day and night.

  • We protect your staff’s inboxes, where the fake grant request and the fake vendor invoice arrive.
  • Every laptop and workstation, including the shared fundraising and finance PCs.
  • The server and the file share holding participant records and finance files.
  • The website and the donation pages, including the forms your donors trust.
  • The cloud apps: the donor CRM, accounting, email, payroll and volunteer scheduling.
  • Day and night, with an AI agent that contains a threat in seconds and a named human engineer watching.

Think of it as a per-employee service, like payroll. Except that this is the one corner that, if you cut it, can empty the account and take the business with it. We have your back.

How Protect works →

Where we start

Cybersecurity and Data Protection Assessment for Nonprofits

Built on the CIS Controls v8.1 IG1 and scoped from what a nonprofit stands to lose: the donor database, the grant payment and the trust of the people it serves. Priced for a nonprofit budget, and it produces the policy set your funders are starting to ask for.

  • Inventory of every device, shared PC and cloud app, including the donor CRM and the volunteer tools (CIS Controls 1 and 2)
  • Account audit: volunteer and board logins, ex-staff access, MFA everywhere (CIS Controls 5 and 6)
  • Backup and restore test for the donor database, finance and participant records (CIS Control 11)
  • Payment and bank-change controls for grants, vendors and payroll, with a rehearsed response plan (CIS Control 17)
  • Donation page and card-flow review against PCI DSS v4.0.1, plus vendor review of the CRM and payment processor (CIS Control 15)
  • A funder-ready cybersecurity policy set and a ranked remediation plan sized to a nonprofit budget
Start with the 3-minute test

Packages

Built for nonprofit businesses, with the price on the page.

Cyber and Data Protection Assessment

A complete read on your exposure: every endpoint, server, cloud account and identity inventoried, controls tested against CIS and NIST CSF 2.0, threats mapped to your industry, and a plan ranked by what would actually hurt.

Fixed feescoped in 30 minutes
1 to 3 weeks
Details →

Governance, Risk and Compliance (GRC), simplified

The discipline the largest institutions run, sized for a business that cannot hire a department for it.

Governance, Risk and Compliance is how a bank or a hospital system decides what to protect, proves it is protected, and shows a regulator the evidence. We ran it for those institutions. We now run it for the 30-person supplier, the medical practice and the defense subcontractor, because that is where the supply chain is thinnest and where a breach does the most damage, sometimes to more than one company.

Governance

Who owns security, which policies are real, and what the owner signs. One page, not a binder.

Risk

What could stop the business, ranked by likelihood and cost, refreshed as the threats change, not once a year.

Compliance

The evidence a regulator, a prime contractor or a customer asks for, produced once and kept current every day.

A defense contractor with 40 people is a link in a national supply chain. A breach there is not a small-business story; it is a national-security one. The same is true, at a smaller scale, for the accounting firm that holds 900 client returns and the clinic that holds 12,000 patient records.

Questions owners ask

Straight answers.

How do nonprofits protect donor data?
Start with who can log in: remove shared and volunteer accounts, add MFA, and limit exports. Then back up the database offline and test the restore. Then protect the finance and development inboxes, because the fake invoice arrives there. The 3-minute test tells you which of those steps is missing.
Is our donor CRM vendor responsible for security?
For their platform, yes; for your accounts, your staff’s devices and your copy of the data, no. The 2020 breach at a major nonprofit software vendor ended with settlements in all 50 states, and the nonprofits still had to notify their own donors.
How much should a small nonprofit spend on cybersecurity?
Less than you fear. The assessment is a fixed fee scoped in a 30-minute call, Protect is priced per user, and both are set for nonprofit budgets. Several funders now reimburse security spending as a capacity-building cost, and we help you write it into the grant.

People also search: cybersecurity for nonprofits near me · nonprofit IT security in Chicago · for a 25-person food bank · for a community health nonprofit · donor data protection for small charities · cybersecurity for faith-based organizations · for a nonprofit with 400 volunteers · grant-ready cybersecurity policy for nonprofits

Never too big or too small

Let's talk about your cyber anxieties. Thirty minutes with an engineer.

3-min test