What Nonprofits and Small Businesses Should Do Right Now

Reading about data breaches is useful. Acting on that information is what actually reduces risk.

These are not long-term projects or enterprise recommendations. These are specific steps that any nonprofit or small business can take, most within days and many for free or close to it.

Start Here: Multi-Factor Authentication

If your organization uses Microsoft 365 or Google Workspace, multi-factor authentication is already available. For many nonprofit plans, it is included at no extra cost.

Enabling it means that even if an attacker steals a staff member’s password, they cannot log in without a second factor tied to a device that person controls.

According to Microsoft, MFA blocks more than 99 percent of automated account compromise attempts.

Turn it on for every account. Start with finance, HR, and anyone with access to donor data or administrative systems. Extend it to all staff as quickly as you can manage the rollout.

Use an authenticator app, not SMS text messages. SMS codes are vulnerable to SIM swapping. Apps like Microsoft Authenticator or Google Authenticator generate codes on the device itself.

Get Your Email Under Control

Most nonprofit breaches start with email. That makes email the first place to harden.

Review who has administrative access to your email platform. Remove access for anyone who no longer needs it, including former staff and volunteers.

Enable email filtering that flags messages sent from outside your organization. Microsoft 365 and Google Workspace both support this. A simple banner that says “This email was sent from outside the organization” stops a significant number of impersonation attempts because staff know to look twice.

Turn off email forwarding rules unless there is a specific business reason. Attackers frequently set up auto-forwarding rules on compromised accounts to receive copies of all incoming mail without triggering an active login.

Back Up Your Data

Ransomware works because organizations depend on data they cannot restore without paying.

A backup that lives on the same network as your primary systems is not a backup. Ransomware encrypts everything on the network it can reach.

Your backups need to be stored somewhere separate. A cloud backup service, an external drive kept offsite, or a backup system that is not connected to your main network.

Test your backups. Run a test restore every few months. The worst time to discover a backup does not work is when you need it.

Train Your Staff Once a Quarter

You do not need an all-day security training or an expensive vendor platform.

Once a quarter, spend fifteen minutes with your team walking through what a phishing email looks like, how to verify an unexpected request before acting on it, and what to do when something feels off. The answer is always to pick up the phone and call the sender using a number you already have, not the one in the email.

Cover vendor impersonation specifically. Most business email compromise attacks work by pretending to be a vendor, a board member, or a grant funder. Staff who know this pattern are far harder to deceive.

Document that training happened. If you ever face a regulatory inquiry or an insurance claim, records of training help.

Write a One-Page Incident Response Plan

When something goes wrong, you do not want to be figuring out who to call while you are also trying to contain the problem.

A one-page document that answers four questions is enough to start:

Who do we call first if we suspect a breach? Who has authority to make decisions during an incident? What systems do we shut down and in what order? Who do we notify, and when?

Add your insurance carrier’s breach response line, your IT contact, and your legal contact. Print it and put it somewhere accessible.

Take Advantage of What Is Free

TechSoup provides discounted or donated software to nonprofits, including Microsoft 365 Business Premium, which includes advanced security tools like Defender for Office 365.

The Global Cyber Alliance offers a free cybersecurity toolkit built for mission-based organizations. It covers the most common attack vectors and walks through implementation without requiring technical expertise.

CISA, the federal cybersecurity agency, provides free vulnerability assessments for organizations of any size. No budget required and no special eligibility.

Cyber insurance is increasingly accessible for small organizations. Many policies now cost less than $1,500 per year and cover breach notification costs, legal fees, and ransomware response. The application process also forces a useful conversation about what controls you have in place.

The Bottom Line

No organization is perfectly secure. The goal is not perfection. The goal is to make your organization harder to attack than the next one, and to have a plan for when something does happen.

The steps above do not require a security team. They require time, consistency, and a decision from leadership that this is worth doing.

The organizations that get hit and recover are the ones that had backups, had a plan, and had staff who knew what to do. The organizations that get hit and struggle are the ones that assumed it would not happen to them.

You have enough information now to make a different choice.


NexSecure Solutions helps nonprofits and small businesses build practical security programs that match their actual capacity. To talk through where your organization stands, schedule a free discovery and needs assessment.

Schedule a free discovery and needs assessment.

Categories: