When a for-profit company gets hit with ransomware, they call their IT team. If the situation is serious, they call an incident response firm. Legal gets involved. Communications gets involved.
Most nonprofits have none of that. They have a part-time IT volunteer, a director who is already stretched, and a board that will hear about the breach two weeks after it happened.
That gap is not a critique. It is a structural reality, and it is one of the main reasons nonprofits stay in attackers’ sights.
The Resource Problem Is Real
Seventy percent of nonprofits have no formal cybersecurity policies. Most have no dedicated security staff. A third of organizations across all sectors report they cannot adequately staff their security function, even when they have a budget for it. For nonprofits, the problem is more acute.
Competing priorities are part of it. A nonprofit focused on housing stability, food access, or community health is not going to shift budget toward cybersecurity until something forces the conversation. Security spending feels abstract. The work the organization does feels immediate.
Staffing is another layer. The global cybersecurity workforce shortage exceeds four million open positions. Experienced professionals have options. They take jobs at companies that pay market rate. Nonprofits, even ones that want to invest in security, struggle to compete.
So what fills the gap? Usually nothing.
What “No Support” Looks Like Day to Day
It looks like one person managing the email platform, the donor database, and the website alongside their actual job.
It looks like passwords shared over Slack because there is no password manager and no policy against it.
It looks like software that has not been updated in eight months because no one has time to test updates and push them.
It looks like new staff getting access to every system because no one has built a process for limiting access to what each role needs.
None of these are failures of effort. They are failures of infrastructure. The organization was never resourced to do it differently.
Why Attackers Know This
Attackers scan for exposed systems. They look for outdated software, unprotected login pages, and email accounts without multi-factor authentication. Those findings are not random, they cluster in organizations that have limited IT resources.
Nonprofits appear in those scans at a higher rate than organizations with dedicated security teams. When an attacker finds an unprotected Microsoft 365 tenant or a donor portal running software from three years ago, they do not need to know anything about the organization. The vulnerability tells them what they need to know.
What Can Change Without a Big Budget
The most effective security controls for under-resourced nonprofits are not expensive. They are structural.
Multi-factor authentication on email is free with Microsoft 365 and Google Workspace. Turning it on takes less than a day of work. It stops the majority of credential-based attacks.
A password manager costs a few dollars per user per month. It eliminates shared passwords and reduces the risk that one breach on an external site compromises internal accounts.
Access control, deciding who gets access to which systems based on their role, does not require software. It requires a policy and someone willing to enforce it during onboarding and offboarding.
A written incident response plan, even a one-page document that says who to call and in what order when something goes wrong, is more valuable than most organizations realize. The middle of an incident is not the time to figure out who owns the decision to notify donors.
Free and Discounted Resources for Nonprofits
Several organizations offer free or discounted security tools specifically for nonprofits.
TechSoup provides discounted or donated software from Microsoft, Google, and dozens of other vendors. Many nonprofits can get Microsoft 365 Business Premium, which includes advanced security features, at a steep discount.
The Global Cyber Alliance offers a free cybersecurity toolkit built specifically for mission-based organizations. It covers the basics without requiring technical expertise to implement.
CISA, the federal cybersecurity agency, provides free assessments and resources for organizations of all sizes. Their services are available at no cost and require no special eligibility.
The barrier is rarely money. It is awareness of what is available and someone willing to spend the time to implement it.
The nonprofit sector does extraordinary work with limited resources. But operating without basic security infrastructure is not a resource decision. It is a risk decision. And right now, most organizations are absorbing that risk without fully understanding what it looks like when things go wrong.
That is worth changing.
Nigel Roberts, CISSP, is the founder of NexSecure Solutions LLC. He works with nonprofits and small businesses to build security programs that fit their actual capacity. Schedule a free discovery call at nexsecuresolutions.com.
