Skip to content

Strengthening Cybersecurity for Nonprofits

Posted by Bo Garner and Antonina McAvoy in Cybersecurity, Not-for-Profit, Consulting.

Key topics covered in this article:

    • Nonprofits face a growing range of cyber risks, including phishing, business email compromise, ransomware, third-party vendor exposure, and the emerging risks tied to public AI tool usage. Because these threats can disrupt operations and damage trust, cybersecurity has become an important part of protecting mission delivery, donor relationships, and sensitive organizational data.
    • Strengthening cybersecurity starts with understanding where critical data lives, who can access it, and what would happen if systems were compromised. Core safeguards such as risk assessments, multifactor authentication, staff training, vendor oversight, and incident response planning help nonprofits reduce risk and improve resilience.
    • Outside cybersecurity support can help nonprofits close security gaps without building a full internal security function. Specialized guidance on assessments, controls, training, vendor reviews, and response planning can make cybersecurity more manageable and more effective over time.

 

Nonprofit organizations depend on technology to manage donor information, financial activity, employee and volunteer data, and the services they provide to their communities. A cyber incident can interrupt those operations, expose sensitive information, and damage trust with donors, grant makers, and the people an organization serves. For nonprofit leaders, the challenge is not only understanding the risks. It is also figuring out how to strengthen cybersecurity in a way that fits the organization.  

That is one reason many nonprofits bring in outside cybersecurity support. Some do not have enough internal capacity. Others have IT staff but still rely on specialists for work such as risk assessments and incident response planning. The goal is to close security gaps, strengthen internal controls, and keep the organization focused on its mission. 

Current Cyber Risks for Nonprofits

What are the current risks? Nonprofits are dealing with several at once. One of the most common starting points is phishing and other forms of social engineering. This often involves getting someone to click a link that looks legitimate, enter login information into a fake prompt, or respond to a request that seems to have come from a trusted source. These attacks may also lead to business email compromise, where an attacker impersonates an executive, employee, vendor, or other trusted party to request a payment, change banking information, or obtain sensitive information. 

Third-party risk is also becoming more important to watch. Many nonprofits rely on payroll vendors, fundraising platforms, cloud software providers, and other third parties that may store, process, transmit, or have access to organizational data.  If one of those providers experiences a security incident, the nonprofit may also be at risk. That means vendor relationships need to be a regular part of the organization’s security review. 

If attackers gain access to a nonprofit’s environment, they may deploy ransomware. Ransomware was present in 44% of breaches in 2025; that’s up from the year before. For nonprofits, it can be especially disruptive because it may lock staff out of files, accounting systems, donor records, and other tools the organization needs to operate. Attackers may then demand payment to restore access, leaving staff to manage delays, service interruptions, and other challenges. 

AI is making these threats harder to detect. It can help attackers create more convincing phishing messages, impersonation attempts, and urgent requests. For nonprofit leaders, that means suspicious messages may look more polished and more credible than they did in the past. 

AI can also introduce risk from inside the organization. Employees and volunteers may use publicly available AI tools to summarize documents, draft communications, or analyze information without realizing that sensitive donor, employee, beneficiary, financial, or other organizational data is being shared with a third party. Nonprofits should establish clear expectations around approved AI tools, acceptable use, and what information should not be entered into public AI Platforms. 

How Nonprofits Can Strengthen Cybersecurity

With so much at stake, nonprofit leaders often ask where to start. The NIST Cybersecurity Framework provides useful structure for organizations to govern and understand cybersecurity risk, protect important systems and data, detect potential incidents, and prepare to respond and recover when an incident occurs. For many nonprofits, that starts with a few core components. 

Risk Assessment — Before investing in tools or training, the organization needs a clear picture of what data it collects, where that data is stored, who can access it, and what would happen if it were exposed or unavailable. This helps leaders focus on the areas that would create the most disruption. 

Internal Controls — This is where multifactor authentication (MFA), user access reviews, password practices, software updates, and written policies come together. These internal controls help limit access to sensitive systems and information, reduce the likelihood that stolen credentials alone can be used to access an account, and support more consistent data handling across the organization. Organizations should also limit administrative privileges to individuals who need them and promptly remove or adjust access when employees or volunteers change roles or leave the organization. 

Staff and Volunteer Training — Many cyber incidents begin with a human mistake. Employees and volunteers need to understand how phishing works, what suspicious messages look like, and what to do when something feels off. Tabletop exercises and phishing simulations can also help identify gaps before a real incident occurs. 

Vendor Oversight — Many nonprofits rely on vendors and other service providers that store, process, transmit, or have access to systems and sensitive data. Those relationships should be part of the organization’s cybersecurity strategy. At a minimum, leaders should understand what systems and data a vendor can access, what security controls the vendor has in place, how the vendor would respond and notify the organization if an incident occurred, and whether those risks are periodically reassessed. 

Response and Recovery — An incident response plan should identify who gets notified, who makes decisions, and what the first steps look like. Backups should be performed on a regular basis and tested to confirm they will work when needed. Organizations should also periodically review their cyber insurance coverage and understand any notification or response requirements that may apply following an incident. The goal is to help the organization respond quickly and restore operations with less disruption. 

Cybersecurity is an ongoing process. Systems, vendors, technologies, and risks all change over time. Organizations should periodically reassess their cybersecurity program and consider additional reviews when significant changes occur, such as implementing a new system, changing key vendors, adopting new technologies such as AI, or experiencing a security incident. It’s a key part of protecting the organization, and regular reviews keep protections current and effective.  

The Role of Outside Support

Outside support can help nonprofits strengthen cybersecurity without trying to build a full internal security function. For some organizations, that support may start with a risk assessment or vendor review. For others, it may involve phishing testing/training, incident response planning, or help reviewing internal controls.  

This kind of support can also help internal teams stay focused. Instead of asking internal staff to manage every aspect of cybersecurity on their own, nonprofits can bring in advisors for specialized or risk-based work. That can help close gaps, improve consistency, and make cybersecurity easier to manage over time. 

Conclusion

Cybersecurity is part of protecting a nonprofit’s operations, information, and reputation. The most practical approach is to understand how risk starts, strengthen the controls that matter most, and prepare for disruption before it happens. Outside support can help many nonprofits do that more effectively, whether they need added capacity, specialized expertise, or both. For more information, contact PBMares Not-for-Profit Partner Bo Garner or Cybersecurity & Risk Advisory Services Partner Antonina McAvoy 


Be sure to consult with your financial or tax advisor on this topic as individual situations may vary. The information contained in this article or webinar, and any related materials, are for informational purposes only, and cannot be relied upon for legal, financial, tax, accounting, or other professional services advice. The content is provided on an “as is” basis and PBMares makes no representations or warranties about the accuracy or sustainability of any information for your purposes. For any specific questions you may have, please contact us.

This content is accurate at the time of publication. Always ensure you are reviewing the most recent information available. Contact your tax or financial advisor if you need clarification.

Contact Us

About the Authors

Antonina McAvoy
Antonina McAvoy

CISA, CISM, QSA, PCIP
Partner, Risk Advisory Services
Norfolk

Antonina McAvoy specializes in cybersecurity, data protection, and privacy. She has 14 years of experience leading and performing a wide spectrum of cybersecurity reviews.

View Bio
Bo Garner
Bo Garner

CPA, MBA
Partner, Not-for-Profit Team Leader
Newport News

Bo specializes in overseeing attest engagements with the firm’s not-for-profit, healthcare, and contractor clients, leveraging his expertise to provide clients with clear and actionable insights.

View Bio

Get News, Alerts, and Guidance

PBMares provides timely insights that help businesses build smarter, well-informed strategies. Join them.