Nonprofit Cybersecurity Governance Is Now a Board Issue, Not an IT Issue

Illustration showing AI-assisted grant writing for nonprofits
TL;DR: Scottship Solutions helps nonprofit boards and executive directors treat nonprofit cybersecurity governance as a leadership responsibility, not an IT chore. We provide fractional IT and cyber-oversight leadership for mission-driven organizations that cannot afford a full-time CISO, translating cyber risk into the questions, budgets, and accountability a board actually owns. This post is for board members, executive directors, and chief operating officers who know cybersecurity matters but do not know what the board is supposed to own versus what IT handles.

What You’ll Learn

  1. Is cybersecurity a governance issue or an IT issue for nonprofits?
  2. What is the board’s role in nonprofit cybersecurity?
  3. Who is legally responsible if a nonprofit has a data breach?
  4. How often should a nonprofit board review cybersecurity risk?
  5. Do we need a CISO, or a fractional CISO, for a nonprofit?
  6. How much does board-level cyber oversight cost a nonprofit?
  7. Frequently Asked Questions
  8. Your Next Steps
  9. Sources

Is cybersecurity a governance issue or an IT issue for nonprofits?

Scottship Solutions treats nonprofit cybersecurity governance as a board responsibility, not an IT task, helping nonprofit boards and executive directors own cyber-risk oversight through fractional IT and virtual CISO (vCISO)-style leadership built for organizations that cannot afford a full-time chief information security officer (CISO). With the NYU Cybersecurity Clinic now teaching under-resourced nonprofits board-level governance protocols, cyber risk has moved from the server room to the boardroom, and most nonprofit boards do not yet know where to start.

So which is it, a governance issue or an IT issue? It is both. Implementation belongs to IT, the managed services provider, or a fractional security lead. Oversight belongs to the board.

Those are two different jobs, and confusing them is how nonprofits end up with firewalls but no accountability.

Scottship’s cybersecurity work is led by Josh Bass, a CompTIA Security+ certified cybersecurity consultant who focuses on security assessments and compliance for mission-driven organizations. The governance frame he works from is simple. A board does not need to configure a firewall any more than it needs to reconcile the general ledger itself. It needs to know the risk is being managed, who is accountable, and what happens if something breaks.

Treat cyber as enterprise risk, not a helpdesk ticket. A breach threatens donor trust, mission continuity, and regulatory standing all at once. Nonprofits are the second most targeted sector for cyberattacks, behind only energy, according to NonProfit PRO. When the exposure is that high, oversight cannot live three levels below the board.

The news hook makes the point better than any argument. The NYU Cybersecurity Clinic, a collaboration between NYU School of Law and NYU Tandon School of Engineering funded by Craig Newmark Philanthropies, launched in summer 2026 to teach under-resourced nonprofits governance protocols and board-level resilience. When a law-and-engineering clinic backed by the founder of craigslist is set up to teach nonprofits governance, the sector has already reframed cyber as a leadership problem.

What is the board’s role in nonprofit cybersecurity?

The board’s role is oversight, not operation. The board approves the budget, accepts or rejects residual risk, sets policy expectations, and holds someone accountable for results. IT, an outsourced provider, or a fractional CISO owns the hands-on work: firewalls, patching, monitoring, and incident response. That division of labor is the single clearest thing a board can get right this year.

None of the top-ranking nonprofit governance articles actually draw that line. They assert that cyber is a board issue, then stop. The table below is the division of labor described plainly, so a board and its IT partner can each see their column and stop assuming the other has it covered.

The board owns (oversight) IT, the MSP, or a fractional CISO owns (implementation)
Approving the cybersecurity budget Firewalls, endpoint protection, and network configuration
Accepting or rejecting residual risk on behalf of the organization Patching, updates, and vulnerability remediation
Setting policy expectations and reviewing them annually Monitoring, alerting, and day-to-day threat detection
Holding a named person accountable for cyber outcomes Incident response execution and system recovery
Overseeing donor-data protection, HIPAA compliance, and vendor risk Staff security training delivery and access controls

Notice that several oversight items in the left column are functions the board governs but does not perform. Cybersecurity audits, donor-data protection, HIPAA (Health Insurance Portability and Accountability Act) compliance for health-adjacent nonprofits, staff security training, and vendor oversight are all governance responsibilities. The board makes sure they happen and reviews the results. Scottship provides the implementation side of each through cybersecurity for nonprofits and broader managed IT services for nonprofits, so a board with no internal IT still has a defensible answer when a funder or auditor asks who owns security.

This is a governance model, described plainly, not a branded product. There is no proprietary framework to buy here. The value is in the clarity, and any nonprofit board can adopt the split tomorrow.

The board carries the duty of care, and that duty extends to cyber risk. A director’s fiduciary duty of care means acting with the diligence a reasonably prudent person would use in similar circumstances, which includes overseeing foreseeable risks to the organization. The National Council of Nonprofits describes duty of care as the obligation to pay attention to the organization’s activities and oversight, and cybersecurity now sits squarely inside that obligation.

This is not legal advice, and it is not a prediction that individual directors will be sued after every incident. It is a governance reality. When a board fails to oversee a known, foreseeable risk, that failure can create personal exposure for directors, which is why oversight cannot be waved off as “the IT person’s problem.”

OneDigital, one of the few nonprofit governance publishers to address this directly, connects board cyber oversight to directors and officers liability insurance and cyber-liability coverage. Those policies are a board-level lever, not an IT purchase. Confirming that your organization carries appropriate D&O and cyber-liability insurance, and that the coverage actually reflects your data risk, is an oversight decision the board should make with eyes open.

The practical takeaway is that liability follows attention. Boards that document their oversight, ask for reporting, and fund reasonable protection are demonstrating the diligence their duty of care requires. Boards that never put cyber on the agenda are not.

How often should a nonprofit board review cybersecurity risk?

At least once a year, as a floor. The governance consensus reflected across nonprofit-board advisory sources is that a board should review cyber risk at least annually, with a standing agenda item so it does not get dropped. Higher-risk organizations, such as those handling health data or large donor databases, should move to quarterly risk reporting.

Annual is the minimum, not the goal. A board that only touches cybersecurity once a year is reacting; a board that receives a short quarterly summary is governing. The right cadence depends on how much sensitive data the organization holds and how exposed its mission makes it.

Cadence only matters if the board asks to see the right artifacts. Before you can oversee cyber risk, you have to know what to request from IT or your provider. A board should expect to see these four things on a regular basis:

  • A risk register: the top cyber risks, ranked, with an owner and a status for each
  • Incident-response status: whether a plan exists, when it was last tested, and any incidents since the last meeting
  • Audit and assessment findings: results from the most recent cybersecurity audit, and progress closing gaps
  • Vendor and third-party risk: which outside vendors touch sensitive data and how they are vetted

If those artifacts do not exist yet, that absence is itself the first finding. Standing up basic policy documentation is often the fastest governance win, and our nonprofit IT policy guide walks through the specific policies a board should expect to be in place. For a deeper grounding in the controls behind these questions, our nonprofit cybersecurity guide covers the implementation layer this post deliberately leaves to IT.

Questions your board should be asking

Boards do not need to become security experts. They need to ask better questions. These are nonprofit-native versions of the questions corporate boards already ask their management teams:

  • Who is the single person accountable for our cybersecurity, and do they have the authority and budget to act?
  • What are our top three cyber risks right now, and what are we doing about each?
  • When did we last test our incident-response plan, and what did we learn?
  • What sensitive data do we hold, and which outside vendors can access it?
  • Do we carry D&O and cyber-liability insurance that matches our actual risk?
  • If we were breached tomorrow, who gets called, and in what order?

Do we need a CISO, or a fractional CISO, for a nonprofit?

Most nonprofits do not need, and cannot afford, a full-time chief information security officer. What they need is the oversight a CISO would provide, delivered at a scale that fits a nonprofit budget. For an organization with no internal IT at all, a fractional or virtual CISO is the bridge that gives the board real oversight without hiring a security team.

This is the exact blind spot in most governance advice. Article after article assumes an IT function already exists for the board to oversee. Many nonprofits have no such function.

They have an office manager who resets passwords and a board that hopes for the best. A fractional model puts an accountable, credentialed leader between that board and its risk.

The talent math reinforces the point. Roughly two-thirds of organizations report a cybersecurity talent shortage, according to a 2024 ISC2 study cited by NonProfit PRO. A nonprofit competing for a full-time security hire against banks and hospitals will lose more often than not, and will overpay if it wins. Fractional leadership sidesteps that competition entirely.

Scottship positions its fractional-leadership model as that governance bridge. The same leadership that oversees security can steer broader technology decisions, which is why board-level cyber oversight often sits alongside our fractional CIO for nonprofits service. The board gets a named, accountable point of contact. The organization gets oversight and implementation that actually connect.

How much does board-level cyber oversight cost a nonprofit?

Board-level cyber oversight should cost a nonprofit far less than a full virtual CISO engagement, because the goal is governance and accountability, not a full security operations center. To set expectations, the table below shows external market benchmarks for the common options, as of 2026. Data tables like this are worth reading closely, because the range between options is wide.

Cyber-oversight option Typical market range (as of 2026) Source
One-time cyber risk assessment $5,000 to $50,000 (up to $150,000 for complex orgs) Cynomi, PurpleSec, Asher Security pricing guides
Full vCISO retainer $2,600 to $11,600 per month Vendor pricing guides
Full vCISO annual engagement $28,800 to $350,000 per year Vendor pricing guides
Grant-funded nonprofit risk assessment Free (grant-eligible orgs) Level5 Management
Scottship fractional board cyber-oversight Contact for a nonprofit-specific quote Scottship Solutions

Two honest notes on that table. First, free options exist. Level5 Management offers a grant-funded risk assessment at no cost to eligible nonprofits, and if you qualify, that is a legitimate place to start before you spend anything.

Second, we do not publish a fixed price for board cyber-oversight, because the right scope depends on your data, your compliance obligations, and whether you already have any IT support. A nonprofit-specific quote is more useful to your board than a headline number that assumes a size you are not.

The value story is straightforward. A board can get real, accountable oversight for meaningfully less than a full vCISO retainer, because it is buying governance and a named point of accountability rather than a full-time security operation. That is the fusion the market has been missing: nonprofit-specialized, board-governance framing, priced honestly.

Frequently Asked Questions

Is cybersecurity a board responsibility for nonprofits?

Yes. Cybersecurity oversight is a board responsibility, even though the hands-on implementation belongs to IT or a security provider. The board owns budget approval, risk acceptance, policy expectations, and accountability. Directors carry a fiduciary duty of care that now includes overseeing foreseeable cyber risk, so a board that never puts cybersecurity on its agenda is not meeting that duty.

How often should a nonprofit board review cybersecurity risk?

At least once a year, as a floor, with a standing agenda item so it does not get skipped. Organizations that hold health data, large donor databases, or other sensitive information should move to quarterly risk reporting. Each review should include a risk register, incident-response status, recent audit findings, and vendor risk, so the board is governing rather than reacting.

Who is legally responsible if a nonprofit has a data breach?

The board carries the duty of care for overseeing cyber risk, and failing to oversee a known, foreseeable risk can create personal exposure for directors. This is not legal advice, but it is why cybersecurity cannot be delegated away as purely an IT problem. Documenting oversight, requesting regular reporting, and confirming D&O and cyber-liability insurance are the practical ways a board demonstrates the diligence its duty requires.

Do we need a CISO or a fractional / virtual CISO for our nonprofit?

Most nonprofits do not need a full-time CISO, and most cannot afford one. What they need is the oversight a CISO provides, which a fractional or virtual CISO can deliver at nonprofit scale. For an organization with no internal IT, a fractional security lead is the bridge that gives the board genuine oversight without building a security team, and at Scottship this often sits alongside our fractional CIO leadership.

How much does nonprofit cyber-risk oversight (vCISO) cost?

As of 2026, external benchmarks put a one-time cyber risk assessment at $5,000 to $50,000, a full vCISO retainer at $2,600 to $11,600 per month, and a full annual vCISO engagement at $28,800 to $350,000. Grant-eligible nonprofits can access a free risk assessment through programs like Level5 Management. Board-level oversight is designed to cost well below a full vCISO retainer, and Scottship provides a nonprofit-specific quote rather than a fixed published price because scope varies by organization.

Your Next Steps

  1. Put cyber on the agenda: Add a standing cybersecurity item to your board or committee meetings so oversight has a home.
  2. Adopt the division of labor: Use the board-owns-oversight versus IT-owns-implementation split above so everyone knows their column.
  3. Name an accountable owner: Identify the single person responsible for cyber outcomes, and confirm they have budget and authority.
  4. Ask for the four artifacts: Request a risk register, incident-response status, audit findings, and vendor risk at your next meeting.
  5. Check your coverage: Confirm your organization carries D&O and cyber-liability insurance that matches your real data risk.
  6. Consider a fractional bridge: If you have no internal IT, talk to Scottship about a fractional model that gives your board oversight without a full-time hire.

Sources

Give Your Board Real Cyber Oversight With Scottship

At Scottship Solutions, we help nonprofit boards and executive directors own cyber-risk oversight without hiring a full-time security team. From cybersecurity to fractional technology leadership, our team translates cyber risk into the questions, budgets, and accountability a board can actually govern. We have helped mission-driven organizations stand up staff security training and stronger email defenses, an approach documented in our email security for nonprofits case study.

If your board is not sure what it owns versus what IT owns, that division of labor is worth twenty minutes at your next meeting. Schedule a consultation today and we will tell you honestly what board-level oversight should look like for an organization your size.

Josh Bass

Written by

Josh Bass

Cybersecurity Consultant at Scottship Solutions

Josh leads security assessments and compliance audits for mission-driven organizations. He helps nonprofits build defensible security postures, meet HIPAA and state privacy requirements, and respond to threats before they become incidents.

Certifications

CompTIA Security+ Certified

Industries Served

Healthcare & Community Health (HIPAA), Human Services, Child Advocacy, Foundations & Grantmakers

Archives