Cybersecurity Best Practices for Your Nonprofit

According to a 2023 cybersecurity report, nonprofit organizations have experienced rising cybersecurity risks, yet many operate without cyber insurance due to limited resources and board support. Okta highlighted the increasing challenges of cyberattacks for nonprofits, with potential consequences for both organizations and their beneficiaries.
Does Your Nonprofit Need Cybersecurity Protection Layers?
Nonprofits hold sensitive data including employment information, donor details, and grant funding sources—making them attractive targets. Hackers target nonprofits because most lack funding and expertise in incident response and threat modeling. Email phishing scams, including impersonation of grant writers and government employees, are widespread.
Nonprofits must prioritize protecting their revenue information sources: donation newsletters, e-commerce sites, and grant management platforms.
How Should Nonprofits Protect Their E-Commerce Site?
Hosting providers like GoDaddy assist nonprofits with domain setup, e-commerce presence, PCI-DSS-compliant infrastructure, encryption services, and integrated security against denial-of-service attacks. GlobalGiving offers tools, resources, and security for global donation collection.
Recommended security practices include:
- Enable multi-factor authentication (MFA) to protect against stolen credentials
- Restrict e-commerce administration access to authorized personnel
- Back up collected data in separate cloud repositories
- Enable advanced AI email security solutions
Note: Organizations are 100% responsible for protecting their data.
What Are Some Best Practices Regarding Protecting Data Transmitted to the Cloud?
- Inventory and classify all data sources
- Document data locations across donor systems, e-commerce, email lists, and newsletters
- Ensure unauthorized applications cannot access donor collection systems
- Document and store backups in cloud depositories with restricted access
- Enable encryption for data-at-rest and data-in-transit
How Should NonProfits Protect Their Grant Management System?
Grant management software like Boomerang stores critical information: grant funding sources, administrator contacts, donation amounts, and renewal dates. This valuable data is vulnerable to cyberattacks through email phishing and social engineering.
Nonprofits should enable MFA, restrict SaaS application access, and ensure secure cloud backup storage.
How Should Organizations Securely Merge Their Data Sources?
Nonprofits typically manage data across multiple platforms: e-commerce sites, grant management systems, newsletter programs, and event spreadsheets. Best practices include:
- Utilize comprehensive features within grant management system subscriptions
- Phase out standalone donor collection systems
- Encrypt all data sources
- Only merge data using proven, secure APIs between platforms
GlobalGiving offers an API to integrate donation information securely.
What Areas Where Nonprofits Are Most Susceptible to Cyberattacks?
Common threats include:
- Business email compromise (BEC) attacks: Hackers impersonate donors or CEOs requesting banking information
- Ransomware attacks: Malware-laden emails encrypt files and demand payment
- Social engineering attacks: Hackers exploit LinkedIn profiles to gain access to donor or grant systems
- Fraudulent donation requests: Attackers create lookalike domains resembling legitimate nonprofits with fake donation forms
What Does an MSSP/MSP Play in Supporting Nonprofits' Cybersecurity Strategy?
Managed Security Service Providers (MSSPs) like Hypershift offer cost-effective services including:
- 24x7x365 incident response, threat modeling, and remediation
- MFA, data encryption, and secure backup implementation
- Security awareness training for employees
- Advanced email security with encryption, anti-phishing, anti-malware, and data loss prevention
Despite budget constraints, nonprofits need multiple protective layers against threat actors targeting sensitive donor information.