Cybersecurity Guide for Nonprofits: Protect Your Data, Donors, and Mission

Cybersecurity Solutions for Small Nonprofits

TL;DR: The best cybersecurity solutions for small nonprofits are endpoint protection (Microsoft Defender for Business, ThreatDown), email security (Microsoft Defender for Office 365, Proofpoint), multi-factor authentication (Microsoft Authenticator, Duo), and staff phishing training (KnowBe4), most available free or heavily discounted to nonprofits, though note Microsoft now discounts Microsoft 365 Business Premium by 75% rather than granting it free. Scottship Solutions helps nonprofits assess their current security posture and put the right tools in place for their size and budget. Contact us to get started.

What You’ll Learn

  1. Why Nonprofits Are Prime Targets
  2. The 5 Biggest Cybersecurity Threats to Nonprofits
  3. Essential Protections Every Nonprofit Needs
  4. The Nonprofit Cybersecurity Checklist
  5. Building a Security-First Culture
  6. Tools and Costs
  7. Recommended Solutions by Category
  8. Pros and Cons of Outsourcing Cybersecurity
  9. Frequently Asked Questions
  10. Your Next Steps

Why Are Nonprofits Prime Cybersecurity Targets?

A development director opens a phishing email that looks like it came from a major donor. Within 30 minutes, an attacker has access to the donor database: 15,000 names, addresses, and payment methods. The organization does not discover the breach for three weeks. By then, the damage to donor trust is irreversible.

This is not hypothetical. BDO reports that nonprofits saw a 30% year-over-year increase in weekly cyberattacks in 2024. Cloudflare’s Project Galileo, which protects at-risk civil society organizations, reported in June 2026 that the organizations it covers face vulnerability exploitation attempts at more than seven times the rate of its other customers, and that nearly 10% of all email it processed for civil society contained potential phishing material.

Why are nonprofits targeted? Attackers look for organizations that hold sensitive data but lack the resources to protect it. Nonprofits fit that profile: they store donor financial information, client case files, employee records, and grant data, often with minimal security infrastructure and no dedicated cybersecurity staff.

At Scottship Solutions, we help nonprofits close these gaps without the overhead of a full security team. The protections in this guide are practical, affordable, and sized for organizations that need to protect their data without diverting resources from their mission.

What Are the 5 Biggest Cybersecurity Threats to Nonprofits?

Threat How It Works Nonprofit Impact
Phishing Fake emails trick staff into clicking links or sharing credentials Present in 16% of breaches (Verizon DBIR 2026)
Ransomware Malware encrypts files and demands payment to unlock them Present in 48% of breaches; median ransom actually paid was $139,875
Credential theft Stolen or reused passwords give attackers access to systems Credential abuse was the initial access route in 13% of breaches
Business email compromise Attacker impersonates a CEO or vendor to redirect payments Roughly $123,000 per complaint (FBI IC3, 2025)
AI-powered attacks Attackers use AI to create convincing phishing and deepfakes Synthetic text in malicious email doubled over two years

A human element was present in 62% of breaches in the 2026 Verizon Data Breach Investigations Report: someone clicking a bad link, reusing a password, or falling for a social engineering attack. Worth noting alongside it, exploitation of unpatched vulnerabilities has now overtaken credential abuse as the most common way attackers get in, at 31% of breaches. So the two highest-value investments for a small nonprofit are reducing human risk through training and keeping software patched.

What Cybersecurity Protections Does Every Nonprofit Need?

1. Multi-Factor Authentication (MFA)

MFA requires a second form of verification, like a code from your phone, in addition to your password. Microsoft published in 2019 that MFA blocks over 99.9% of automated account compromise attacks, and that remains the single highest-value control most nonprofits can turn on. One update since then matters: attackers now routinely defeat SMS and push-approval MFA through adversary-in-the-middle phishing and push fatigue, so CISA recommends phishing-resistant methods where you can use them.

  • Enable MFA on every account that supports it: email, CRM, financial systems, cloud storage, social media
  • Use authenticator apps (Microsoft Authenticator, Google Authenticator) rather than SMS codes, and passkeys or hardware security keys for finance and administrator accounts
  • Require MFA for all staff, board members, and volunteers with system access
  • Cost: Free, built into Google Workspace, Microsoft 365, and most cloud platforms
  • Verify your nonprofit eligibility through Goodstack, which now handles validation for both Google for Nonprofits and Microsoft’s nonprofit program

2. Password Management

Deploy a password manager across your entire organization. This eliminates password reuse and makes strong, unique passwords the default.

  • 1Password offers nonprofit discounts and Bitwarden has a free tier that covers most small teams. We do not recommend LastPass: its 2022 breach exposed customer vault backups, and researchers later tied more than $35 million in cryptocurrency theft to credentials stored in those vaults
  • Require passwords of 14+ characters (length matters more than complexity)
  • Ban password sharing via email, Slack, or sticky notes

3. Security Awareness Training

Your staff is your first line of defense, and your biggest vulnerability. Regular training measurably reduces the rate at which staff click malicious links, and it is the lowest-cost control on this list.

  • Run phishing simulations quarterly using tools like KnowBe4 (nonprofit pricing available)
  • Train all new staff during onboarding
  • Keep sessions short: 15-20 minutes, focused on real examples
  • Celebrate staff who report suspicious emails, and build a culture where reporting is rewarded

4. Endpoint Protection

Every device that connects to your systems needs protection. Use a centrally managed antivirus and anti-malware solution.

  • Microsoft Defender for Business is included with Microsoft 365 Business Premium, which nonprofits can buy at a 75% discount. Microsoft retired the free Business Premium grant, so budget for the discounted license rather than assuming it is free
  • Ensure all devices receive automatic security updates
  • Maintain an inventory of every device accessing organizational data

5. Data Backup and Recovery

If ransomware hits, your backup is your lifeline. Follow the 3-2-1 rule: three copies of your data, on two different media types, with one copy off-site.

  • Automate daily backups of all critical data
  • Test restores monthly: a backup you have never tested is not a backup
  • Keep backup credentials separate from your main network so ransomware cannot encrypt your backups too
  • See our backup and disaster recovery resources for a complete guide

6. Incident Response Plan

Most small nonprofits have no documented plan for responding to a cyberattack. When an incident occurs, you do not have time to figure out who to call.

  • Document: who to notify, in what order, through what channel
  • Include legal counsel, insurance provider, IT partner, and communications lead
  • Define when and how to notify affected donors or clients
  • Run a tabletop exercise annually: walk through a scenario as a team

The Nonprofit Cybersecurity Checklist

Priority Action Cost Timeline
Critical Enable MFA on all accounts Free This week
Critical Deploy password manager to all staff Free tier available This week
Critical Verify backups are running and test a restore $0-$50 This week
High Install endpoint protection on all devices Included with M365 Business Premium This month
High Run first security awareness training Free-$500 This month
High Create offboarding checklist for departing staff Free This month
Medium Write an incident response plan Free This quarter
Medium Conduct a security risk assessment Quote-based This quarter
Medium Set up quarterly phishing simulations Nonprofit rates on request This quarter
Ongoing Review access permissions quarterly Free Every 90 days

How Do You Build a Security-First Culture?

Technology alone cannot protect your nonprofit. The strongest firewall in the world does nothing if a staff member shares their password with a vendor over email. Security is a culture issue, not just a technology issue.

What Security Culture Looks Like

  • Staff report suspicious emails without fear. Create a simple “report phishing” button in your email client and thank people who use it.
  • Leadership models good behavior. If the executive director skips MFA, staff will too. Security starts at the top.
  • Training is ongoing, not annual. A single yearly training session has minimal impact. Short, quarterly touchpoints keep security top of mind.
  • Policies exist and are enforced. Written policies on acceptable use, password management, and data handling set clear expectations.

“Nonprofits must educate staff, volunteers, and board members on recognizing threats and maintaining security hygiene. Cybersecurity is not just an IT responsibility, it is an organizational responsibility.”

KahnLitwin, What Nonprofit Board Members Need to Know About Cybersecurity (2025)

How Much Does Nonprofit Cybersecurity Cost?

Tool Purpose Nonprofit Cost
Microsoft Defender for Business Endpoint protection (antivirus, anti-malware) Included in M365 Business Premium, 75% nonprofit discount
1Password / Bitwarden Password management Bitwarden free tier; 1Password nonprofit discount
KnowBe4 Security awareness training + phishing simulation Nonprofit pricing available
Google Workspace / Microsoft 365 Built-in MFA, email filtering, admin controls Google Workspace free for nonprofits (verified via Goodstack); M365 discounted
Backblaze / Carbonite Cloud backup From about $6/month for single devices; business plans around $24/month cover up to 25 machines
Cisco Umbrella / DNSFilter Web filtering and DNS security DNSFilter publishes $1.00 to $2.50 per license; Cisco Umbrella is quote-based

A 25-person nonprofit can implement the critical and high-priority items on the checklist above for under $2,000 per year. The cost of not doing it is orders of magnitude higher. BDO puts the average cost of a data breach at up to $2 million.

Category Recommended Tool Nonprofit Discount Available
Endpoint protection Microsoft Defender for Business, ThreatDown (formerly Malwarebytes business) Yes, 75% nonprofit discount on M365 Business Premium
Email security Microsoft Defender for Office 365, Proofpoint 365 Total Protection Yes, included in discounted M365 Business Premium
Multi-factor authentication Microsoft Authenticator, Duo Security Free (Microsoft and Google Authenticator); check Duo terms directly
Staff phishing training KnowBe4, Proofpoint Security Awareness KnowBe4 offers nonprofit discounts on request; check Proofpoint directly
Backup & recovery Veeam, Acronis Cyber Protect Cloud Check current TechSoup catalog; terms change
Password management Bitwarden (free tier), 1Password Teams Free tier available; nonprofit pricing (1Password)

Should Your Nonprofit Outsource Cybersecurity?

Pros of Outsourcing Cons of Outsourcing
Access to specialized security expertise Ongoing monthly cost
24/7 monitoring without hiring shifts Less direct control over security decisions
Stay current on evolving threats Requires trust in an external partner
Faster incident response Quality varies by provider
Compliance expertise built in Staff still need training regardless

For most nonprofits, outsourcing cybersecurity to a trusted IT support partner is the practical choice. Few organizations can justify a dedicated security hire, but every organization needs security expertise.

Frequently Asked Questions

What are the best cybersecurity solutions for small nonprofits?

The most effective cybersecurity stack for a small nonprofit includes endpoint protection (Microsoft Defender for Business or ThreatDown), email security with phishing filtering (Microsoft Defender for Office 365 or Proofpoint 365 Total Protection), multi-factor authentication on all accounts, and regular staff phishing awareness training. Most are free or heavily discounted through nonprofit programs, though note that Microsoft now discounts Microsoft 365 Business Premium by 75% rather than granting it free. Scottship Solutions can help you assess which tools are missing from your current setup.

How much does cybersecurity cost for a nonprofit?

Basic cybersecurity tools (endpoint protection, MFA, and email filtering) can cost as little as $0 to $10 per user per month using nonprofit discounts from Microsoft, Google, and TechSoup, as of 2026. A managed cybersecurity layer (monitoring, incident response, vulnerability scanning) is priced per user per month by most providers, but few publish rates, so get quotes rather than budgeting from a figure you found online. The foundational tooling above is the part you can price today; the managed layer on top is the part that varies most by scope.

What cybersecurity threats do nonprofits face most often?

Nonprofits are most frequently targeted through phishing emails (attempting to steal credentials or deploy ransomware), business email compromise (BEC) attacks targeting finance staff, and ransomware. A 2023 report from Proofpoint found that nonprofits are 2x more likely to be targeted by phishing than average organizations, largely because of their public donor lists and often under-resourced IT environments. Staff training is consistently the highest-ROI cybersecurity investment for small nonprofits.

Does my nonprofit need cyber liability insurance?

Yes, and many funders and board members now require it. Cyber liability insurance covers breach notification costs, legal fees, and remediation expenses if donor or staff data is compromised. Premiums vary widely by coverage limits, revenue, and the data you hold, so get quotes rather than budgeting from a published range. Insurers increasingly require documented security practices (MFA enabled, endpoint protection active, staff training completed) before issuing coverage, making basic cybersecurity hygiene both a security and insurance requirement.

Is Microsoft Defender enough for nonprofit cybersecurity?

Microsoft Defender (included with Microsoft 365 Business Premium) provides strong baseline protection: endpoint detection, email filtering, and identity protection. For most nonprofits under 50 staff using Microsoft 365, it covers the majority of attack vectors when properly configured. What Defender alone does not provide: security monitoring, incident response, vulnerability scanning, or staff training. A managed security layer from a provider like Scottship Solutions fills those gaps.

What is the first cybersecurity step a small nonprofit should take?

Enable multi-factor authentication (MFA) on all staff accounts: email, cloud storage, and any donor management or finance tools. Microsoft has published that MFA blocks over 99.9% of automated account compromise attacks, and it costs nothing on most platforms. Use passkeys or hardware keys for finance and administrator accounts.

After MFA, the highest-impact next steps are deploying endpoint protection on all devices and completing a phishing simulation to assess staff awareness. Scottship Solutions offers a free cybersecurity assessment to help nonprofits identify their most urgent gaps.

Your Next Steps

  1. Enable MFA today. Start with email (Google Workspace or Microsoft 365 both support it at no cost) and your CRM. This is the single highest-impact action you can take.
  2. Deploy a password manager this week. Request 1Password’s nonprofit discount directly, or set up Bitwarden’s free tier for your team.
  3. Verify your backups. Check that your critical data is being backed up daily. Test a restore right now to confirm it works.
  4. Schedule security training. Run a 20-minute all-staff session covering phishing awareness. Use real phishing examples from your own inbox.
  5. Write a basic incident response plan. Even a 2-page document is better than nothing. Define who to call and in what order.
  6. Get a security assessment: Contact us with Scottship Solutions. We will assess your current security posture and build a prioritized improvement plan sized for your budget.

Sources

Work With Scottship

At Scottship Solutions, we help nonprofits protect their data, their donors, and their mission. From managed IT support with built-in security monitoring to fractional CIO services that include cybersecurity oversight, we build practical security programs that fit nonprofit budgets. Start with a tech stack audit to identify your gaps, then explore our IT services for ongoing protection. Request a consultation today to find out where your organization stands.

Looking for more? Explore our managed IT services for nonprofits hub for guides, case studies, and service details.

Josh Bass

Written by

Josh Bass

Cybersecurity Consultant at Scottship Solutions

Josh leads security assessments and compliance audits for mission-driven organizations. He helps nonprofits build defensible security postures, meet HIPAA and state privacy requirements, and respond to threats before they become incidents.

Certifications

CompTIA Security+ Certified

Industries Served

Healthcare & Community Health (HIPAA), Human Services, Child Advocacy, Foundations & Grantmakers

Archives