Cybersecurity Guide for Nonprofits: Protect Your Data, Donors, and Mission

Cybersecurity Solutions for Small Nonprofits

TL;DR: The best cybersecurity solutions for small nonprofits are endpoint protection (Microsoft Defender for Business, ThreatDown), email security (Microsoft Defender for Office 365, Proofpoint), multi-factor authentication (Microsoft Authenticator, Duo), and staff phishing training (KnowBe4), most available free or heavily discounted to nonprofits, though note Microsoft now discounts Microsoft 365 Business Premium by 75% rather than granting it free. Scottship Solutions helps nonprofits assess their current security posture and put the right tools in place for their size and budget. Contact us to get started.

Last updated September 2026.

What You’ll Learn

  1. Why Nonprofits Are Prime Targets
  2. The 5 Biggest Cybersecurity Threats to Nonprofits
  3. Essential Protections Every Nonprofit Needs
  4. The Highest-Impact Free Cybersecurity Actions
  5. The Nonprofit Cybersecurity Checklist
  6. Building a Security-First Culture
  7. Tools and Costs
  8. Nonprofit Discount Programs
  9. What a Starter Security Stack Costs
  10. Recommended Solutions by Category
  11. Pros and Cons of Outsourcing Cybersecurity
  12. Frequently Asked Questions
  13. Your Next Steps

Why Are Nonprofits Prime Cybersecurity Targets?

A development director opens a phishing email that looks like it came from a major donor. Within 30 minutes, an attacker has access to the donor database: 15,000 names, addresses, and payment methods. The organization does not discover the breach for three weeks. By then, the damage to donor trust is irreversible.

This is not hypothetical. Nonprofits saw a 30% year-over-year increase in weekly cyberattacks in 2024, a figure from Integrity360 reported by BDO. Cloudflare’s Project Galileo, which protects at-risk civil society organizations, reported in June 2026 that the organizations it covers face vulnerability exploitation attempts at more than seven times the rate of its other customers, and that nearly 10% of all email it processed for civil society contained potential phishing material.

Why are nonprofits targeted? Attackers look for organizations that hold sensitive data but lack the resources to protect it. Nonprofits fit that profile: they store donor financial information, client case files, employee records, and grant data, often with minimal security infrastructure and no dedicated cybersecurity staff.

At Scottship Solutions, we help nonprofits close these gaps without the overhead of a full security team. Security assessments and compliance audits for mission driven organizations are led by Josh Bass, Cybersecurity Consultant at Scottship Solutions and CompTIA Security+ certified. The protections in this guide are practical, affordable, and sized for organizations that need to protect their data without diverting resources from their mission.

What Are the 5 Biggest Cybersecurity Threats to Nonprofits?

Threat How It Works Nonprofit Impact
Phishing Fake emails trick staff into clicking links or sharing credentials Present in 16% of breaches (Verizon DBIR 2026)
Ransomware Malware encrypts files and demands payment to unlock them Present in 48% of breaches; median ransom actually paid was $139,875
Credential theft Stolen or reused passwords give attackers access to systems Credential abuse was the initial access route in 13% of breaches
Business email compromise Attacker impersonates a CEO or vendor to redirect payments Roughly $123,000 per complaint (FBI IC3, 2025)
AI-powered attacks Attackers use AI to create convincing phishing and deepfakes Synthetic text in malicious email doubled over two years (Verizon DBIR 2025)

A human element was present in 62% of breaches in the 2026 Verizon Data Breach Investigations Report: someone clicking a bad link, reusing a password, or falling for a social engineering attack. Worth noting alongside it, exploitation of unpatched vulnerabilities has now overtaken credential abuse as the most common way attackers get in, at 31% of breaches. So the two highest-value investments for a small nonprofit are reducing human risk through training and keeping software patched.

What Cybersecurity Protections Does Every Nonprofit Need?

What Are the Highest-Impact Free Cybersecurity Actions?

Three actions cost nothing and take an afternoon. Do them before you price a single product.

  • Turn on MFA everywhere. Microsoft Authenticator and Google Authenticator are free, and MFA is built into Google Workspace and Microsoft 365 at no extra charge.
  • Claim your nonprofit program. As of 2026, Microsoft grants up to 300 free Microsoft 365 Business Basic licenses and Google Workspace for Nonprofits is $0 per user per month. Business Basic does not include Defender; Defender for Business comes with Business Premium at the 75% nonprofit discount.
  • Turn on what you already pay for. Admin alerts, conditional access, data loss prevention, and advanced phishing protection in Gmail ship inside plans most nonprofits already hold.

1. Multi-Factor Authentication (MFA)

MFA requires a second form of verification, like a code from your phone, in addition to your password. Microsoft published in 2019 that MFA blocks over 99.9% of automated account compromise attacks, and that remains the single highest-value control most nonprofits can turn on. One update since then matters: attackers now routinely defeat SMS and push-approval MFA through adversary-in-the-middle phishing and push fatigue, so CISA recommends phishing-resistant methods where you can use them.

  • Enable MFA on every account that supports it: email, CRM, financial systems, cloud storage, social media
  • Use authenticator apps (Microsoft Authenticator, Google Authenticator) rather than SMS codes, and passkeys or hardware security keys for finance and administrator accounts
  • Require MFA for all staff, board members, and volunteers with system access
  • Cost: Free, built into Google Workspace, Microsoft 365, and most cloud platforms
  • Verify your nonprofit eligibility through Goodstack, which now handles validation for both Google for Nonprofits and Microsoft’s nonprofit program

2. Password Management

Deploy a password manager across your entire organization. This eliminates password reuse and makes strong, unique passwords the default.

  • 1Password offers nonprofit discounts on request. Bitwarden’s free organization covers two users; past that, Bitwarden Teams is $4 per user per month billed annually as of 2026. We do not recommend LastPass: its 2022 breach exposed customer vault backups, and TRM Labs later tied more than $35 million in cryptocurrency theft to credentials stored in those vaults
  • Require passwords of 14+ characters (length matters more than complexity)
  • Ban password sharing via email, chat apps, or sticky notes

3. Security Awareness Training

Your staff is your first line of defense, and your biggest vulnerability. Regular training measurably reduces the rate at which staff click malicious links, and it is the lowest-cost control on this list.

  • Run phishing simulations quarterly using tools like KnowBe4 (nonprofit pricing available)
  • Train all new staff during onboarding
  • Keep sessions short: 15 to 20 minutes, focused on real examples
  • Celebrate staff who report suspicious emails, and build a culture where reporting is rewarded

4. Endpoint Protection

Every device that connects to your systems needs protection. Use a centrally managed antivirus and anti-malware solution.

  • Microsoft Defender for Business is included with Microsoft 365 Business Premium, which nonprofits buy at a 75% discount, $5.50 per user per month paid yearly as of 2026. Microsoft retired the free Business Premium grant on July 1, 2025, and its free replacement, Business Basic, has no Defender, so budget for the discounted license
  • Ensure all devices receive automatic security updates
  • Maintain an inventory of every device accessing organizational data

5. Data Backup and Recovery

If ransomware hits, your backup is your lifeline. Follow the 3-2-1 rule: three copies of your data, on two different media types, with one copy off-site.

  • Automate daily backups of all critical data
  • Test restores monthly: a backup you have never tested is not a backup
  • Keep backup credentials separate from your main network so ransomware cannot encrypt your backups too
  • See our backup and disaster recovery resources for a complete guide

6. Incident Response Plan

Most small nonprofits have no documented plan for responding to a cyberattack. When an incident occurs, you do not have time to figure out who to call.

  • Document: who to notify, in what order, through what channel
  • Include legal counsel, insurance provider, IT partner, and communications lead
  • Define when and how to notify affected donors or clients
  • Run a tabletop exercise annually: walk through a scenario as a team

The Nonprofit Cybersecurity Checklist

Priority Action Cost Timeline
Critical Enable MFA on all accounts Free This week
Critical Deploy password manager to all staff Free for 2 users, then about $4 per user per month This week
Critical Verify backups are running and test a restore $0 to $50 This week
High Install endpoint protection on all devices Included with M365 Business Premium This month
High Run first security awareness training Free to $500 This month
High Create offboarding checklist for departing staff Free This month
Medium Write an incident response plan Free This quarter
Medium Conduct a security risk assessment Quote-based This quarter
Medium Set up quarterly phishing simulations Nonprofit rates on request This quarter
Ongoing Review access permissions quarterly Free Every 90 days

How Do You Build a Security-First Culture?

Technology alone cannot protect your nonprofit. The strongest firewall in the world does nothing if a staff member shares their password with a vendor over email. Security is a culture issue, not just a technology issue.

What Security Culture Looks Like

  • Staff report suspicious emails without fear. Create a simple “report phishing” button in your email client and thank people who use it.
  • Leadership models good behavior. If the executive director skips MFA, staff will too. Security starts at the top.
  • Training is ongoing, not annual. A single yearly training session has minimal impact. Short, quarterly touchpoints keep security top of mind.
  • Policies exist and are enforced. Written policies on acceptable use, password management, and data handling set clear expectations.

“Educate staff, volunteers, and board members on recognizing threats and maintaining security hygiene.”

KahnLitwin, What Nonprofit Board Members Need to Know About Cybersecurity (2025)

How Much Does Nonprofit Cybersecurity Cost?

Published nonprofit rates as of 2026:

Tool Purpose Nonprofit Cost
Microsoft Defender for Business Endpoint protection (antivirus, anti-malware) Included in M365 Business Premium, 75% nonprofit discount, $5.50 per user per month
1Password / Bitwarden Password management Bitwarden free for 2 users, then $4 per user per month; 1Password nonprofit discount, rate not published
KnowBe4 Security awareness training + phishing simulation Nonprofit pricing available
Google Workspace / Microsoft 365 Built-in MFA, email filtering, admin controls Google Workspace free for nonprofits (verified via Goodstack); M365 discounted
Backblaze / Carbonite Cloud backup Backblaze is $99 per computer per year, about $8.25 per computer per month, for Personal and Business Backup
Cisco Umbrella / DNSFilter Web filtering and DNS security DNSFilter publishes $1.00 to $2.50 per license; Cisco Umbrella is quote-based

A 25-person nonprofit can implement the critical and high-priority items on the checklist above for roughly $3,000 per year, with Business Premium at $1,650 and Bitwarden Teams at $1,200 making up most of it. Scope the same stack to the free Business Basic grant plus free tools and it lands far lower, at the cost of Defender coverage. The cost of not doing it is orders of magnitude higher: BDO cites an average data breach cost of up to $2 million.

Which Nonprofit Discount Programs Should You Know About?

Four programs carry most of the savings. All require 501(c)(3) status and a validation step, and every term below is current as of 2026.

Microsoft for Nonprofits. Up to 300 free Business Basic licenses, and Business Premium discounted 75% to $5.50 per user per month paid yearly. The free Business Premium grant was retired on July 1, 2025, and only Business Premium carries Defender for Business and Defender for Office 365.

TechSoup. Discounted and donated software from hundreds of technology companies. The current security catalogue includes Okta, Bitdefender, Norton, Avast CloudCare, ThreatDown, Dashlane, Box, Dropbox, and KnowBe4.

Google for Nonprofits. Google Workspace for Nonprofits is $0 per user per month and includes 2-step verification, an admin security dashboard, data loss prevention, and advanced phishing protection in Gmail.

Cloudflare Project Galileo. Business-plan protection at no cost, including unmetered DDoS mitigation, WAF, DNS, and SSL. A donation page alone does not qualify you: eligibility is scoped to at-risk public interest work in human rights, civil society, journalism, and democracy.

What Does a Starter Security Stack Cost a 25 Person Nonprofit?

Here is the same tooling as one worked example, priced at nonprofit rates as of 2026 for a 25-person nonprofit that qualifies for Microsoft’s program and pays yearly.

Tool What It Covers Annual Cost (25 staff)
Microsoft 365 Business Premium (75% discount) Endpoint, email, MFA, identity protection $1,650 ($5.50 per user per month, paid yearly)
Bitwarden Teams Password management for all staff $1,200 ($4 per user per month billed annually)
KnowBe4 Phishing simulations and awareness training Quote based, nonprofit discount on request
Cloudflare Project Galileo Website DDoS and web-layer protection, at-risk organizations only $0
Total, Business Premium plus Bitwarden Teams About $2,850 per year, before training and backup

Swap Business Premium for the free Business Basic grant and the licensing line drops to $0, but Defender for Business and Defender for Office 365 go with it. Price it both ways before committing.

This stack covers phishing, credential theft, endpoint malware, and email attacks. It does not cover 24/7 monitoring or incident response, which need a managed security layer on top. For a nonprofit running none of these controls today, it is still a defensible starting point.

Category Recommended Tool Nonprofit Discount Available Nonprofit Cost (2026)
Endpoint protection Microsoft Defender for Business, ThreatDown (formerly Malwarebytes business) Yes, 75% nonprofit discount on M365 Business Premium $5.50 per user per month via Business Premium; ThreatDown on request
Email security Microsoft Defender for Office 365, Proofpoint 365 Total Protection Yes, included in discounted M365 Business Premium Included in Business Premium; Proofpoint from $2.75 per user per month list, no published nonprofit rate
Multi-factor authentication Microsoft Authenticator, Duo Security Free (Microsoft and Google Authenticator); check Duo terms directly $0 for authenticator apps; Duo Free covers 10 users, then $3 per user per month list
Staff phishing training KnowBe4, Proofpoint Security Awareness KnowBe4 offers nonprofit discounts on request; check Proofpoint directly Quote based
Backup & recovery Backblaze Business Backup No published nonprofit program; buy direct from the vendor $99 per computer per year
Password management Bitwarden Teams, 1Password Teams Bitwarden free for 2 users; nonprofit pricing (1Password) Bitwarden $4 per user per month; 1Password quote based

Should Your Nonprofit Outsource Cybersecurity?

Pros of Outsourcing Cons of Outsourcing
Access to specialized security expertise Ongoing monthly cost
24/7 monitoring without hiring shifts Less direct control over security decisions
Stay current on evolving threats Requires trust in an external partner
Faster incident response Quality varies by provider
Compliance expertise built in Staff still need training regardless

For most nonprofits, outsourcing cybersecurity to a trusted IT support partner is the practical choice. Few organizations can justify a dedicated security hire, but every organization needs security expertise.

Frequently Asked Questions

What are the best cybersecurity solutions for small nonprofits?

The most effective cybersecurity stack for a small nonprofit includes endpoint protection (Microsoft Defender for Business or ThreatDown), email security with phishing filtering (Microsoft Defender for Office 365 or Proofpoint 365 Total Protection), multi-factor authentication on all accounts, and regular staff phishing awareness training. Most are free or heavily discounted through nonprofit programs, though note that Microsoft now discounts Microsoft 365 Business Premium by 75% rather than granting it free. Scottship Solutions can help you assess which tools are missing from your current setup.

How much does cybersecurity cost for a nonprofit?

Basic cybersecurity tools (endpoint protection, MFA, and email filtering) can cost as little as $0 to $10 per user per month using nonprofit discounts from Microsoft, Google, and TechSoup, as of 2026. A managed cybersecurity layer (monitoring, incident response, vulnerability scanning) is priced per user per month by most providers, but few publish rates, so get quotes rather than budgeting from a figure you found online. The foundational tooling above is the part you can price today; the managed layer on top is the part that varies most by scope.

How much should a small nonprofit budget for cybersecurity per year?

A 25-person nonprofit should budget roughly $3,000 per year for foundational security at 2026 rates: Business Premium at the 75% nonprofit discount is $1,650 and Bitwarden Teams is $1,200. KnowBe4 phishing training is quote based, with a nonprofit discount on request. Organizations that claim the free Business Basic grant instead come in far lower, though Business Basic does not include Defender. Managed monitoring on top is priced per user per month and few providers publish rates, so get a quote.

What cybersecurity threats do nonprofits face most often?

Nonprofits are most frequently targeted through phishing emails (attempting to steal credentials or deploy ransomware), business email compromise (BEC) attacks targeting finance staff, and ransomware. Cloudflare reported in June 2026 that the civil society organizations in Project Galileo faced website vulnerability exploitation attempts at more than seven times the rate of its other customers, and that nearly 10% of the email it processed for them contained potential phishing material. Staff training is consistently the highest-ROI cybersecurity investment for small nonprofits.

Does my nonprofit need cyber liability insurance?

Yes, and many funders and board members now require it. Cyber liability insurance covers breach notification costs, legal fees, and remediation expenses if donor or staff data is compromised. Premiums vary widely by coverage limits, revenue, and the data you hold, so get quotes rather than budgeting from a published range. Insurers increasingly require documented security practices (MFA enabled, endpoint protection active, staff training completed) before issuing coverage, making basic cybersecurity hygiene both a security and insurance requirement.

Is Microsoft Defender enough for nonprofit cybersecurity?

Microsoft Defender (included with Microsoft 365 Business Premium) provides strong baseline protection: endpoint detection, email filtering, and identity protection. For most nonprofits under 50 staff using Microsoft 365, it covers the majority of attack vectors when properly configured. What Defender alone does not provide: security monitoring, incident response, vulnerability scanning, or staff training. A managed security layer from a provider like Scottship Solutions fills those gaps.

Is free cybersecurity software safe enough for nonprofits?

Yes, with the right tools. Google Workspace for Nonprofits is $0 per user per month as of 2026, and its built-in protections (2-step verification, data loss prevention, advanced phishing filtering in Gmail) are the same features Google sells commercially. Microsoft’s free tier changed: Business Basic is granted to up to 300 users but has no Defender, so endpoint and email protection means paying $5.50 per user per month for Business Premium. The gap between free and paid security is rarely software quality; it is the monitoring, incident response, and expertise layered on top.

What is the minimum cybersecurity setup a nonprofit needs?

Start with multi-factor authentication on every staff account: email, cloud storage, and any donor management or finance tool. Microsoft published in 2019 that MFA blocks over 99.9% of automated account compromise attacks, it costs nothing on most platforms, and passkeys or hardware keys belong on finance and administrator accounts. After MFA, the minimum is endpoint protection on every device, which as of 2026 means Business Premium at $5.50 per user per month, plus a password manager for all staff, free for two users with Bitwarden and $4 per user per month beyond that. Scottship Solutions offers a free cybersecurity assessment to help nonprofits identify their most urgent gaps.

Your Next Steps

  1. Enable MFA today. Start with email (Google Workspace or Microsoft 365 both support it at no cost) and your CRM. This is the single highest-impact action you can take.
  2. Claim your nonprofit program. Validate through Goodstack, then take the free Business Basic licenses or free Google Workspace for Nonprofits, and price Business Premium at the 75% discount if you need Defender.
  3. Deploy a password manager this week. Request 1Password’s nonprofit discount directly, or start Bitwarden Teams at $4 per user per month; the free Bitwarden organization covers only two users.
  4. Verify your backups. Check that your critical data is being backed up daily. Test a restore right now to confirm it works.
  5. Schedule security training. Run a 20-minute all-staff session covering phishing awareness. Use real phishing examples from your own inbox.
  6. Write a basic incident response plan. Even a 2-page document is better than nothing. Define who to call and in what order.
  7. Get a security assessment: Contact us with Scottship Solutions. We will assess your current security posture and build a prioritized improvement plan sized for your budget.

Sources

Work With Scottship

At Scottship Solutions, we help nonprofits protect their data, their donors, and their mission. From managed IT support with built-in security monitoring to fractional CIO services that include cybersecurity oversight, we build practical security programs that fit nonprofit budgets. Start with a tech stack audit to identify your gaps, then explore our IT services for ongoing protection. Request a consultation today to find out where your organization stands.

Looking for more? Explore our managed IT services for nonprofits hub for guides, case studies, and service details.

Josh Bass

Written by

Josh Bass

Cybersecurity Consultant at Scottship Solutions

Josh leads security assessments and compliance audits for mission-driven organizations. He helps nonprofits build defensible security postures, meet HIPAA and state privacy requirements, and respond to threats before they become incidents.

Certifications

CompTIA Security+ Certified

Industries Served

Healthcare & Community Health (HIPAA), Human Services, Child Advocacy, Foundations & Grantmakers

Archives

Get Scottship’s research in your Google results