By Amanda Lovell
Digital Marketing Manager
Big Buzz Idea Group
Do you know the potential costs and impacts that a cyberattack could have on your organization? Are you prepared?
In today’s digital age, nonprofits are increasingly becoming targets for cyberattacks, data breaches and ransomware. Your organization’s cybersecurity efforts are crucial, not only to protect sensitive information from theft and damage, but also to maintain the trust and confidence of your stakeholders and your members.
Here are some key stats that every nonprofit needs to know:
- 50% of NGOS reported being targeted by a cyberattack in 2021.
- 500K confidential records of personal data were compromised during an attack on the servers of the Internal Committee of the Red Cross in September 2022.
- 35M of private data was breached—including social security numbers—at Broward Health of California, a nonprofit that manages health care in Florida in January 2022.
Nonprofits are unprepared, and here’s why:
- $30B of funds are raised by NGOs and nonprofits each year, but they don’t always have the necessary security measures in place to protect themselves from hackers.
- 9 out of 10 organizations do not regularly train staff on cybersecurity.
- 75% of organizations do not monitor their networks
- 80% of organizations do not have any type of cybersecurity plan in place.
- 22 days is the average length of interruption time after a ransomware attack.
So, what are some essential steps your nonprofit can take to enhance its cybersecurity and safeguard itself against common threats?
- Educate Your Staff
One of the most effective ways to protect your organization is by educating your staff. Conduct regular training sessions on cybersecurity best practices, including recognizing phishing attempts and other common scams. See a questionable email or link? Don’t click! An informed team is your first line of defense against cyber threats.
- Use Strong Passwords
Implement a policy that requires the use of strong, complex passwords. Encourage staff to use a combination of upper- and lower-case letters, numbers and special characters. Additionally, passwords should be changed regularly to minimize the risk of unauthorized access. A good password manager (such as 1Password) can be used to keep all passwords organized and secure.
- Enable Two-Factor or Multi-Factor Authentication
2FA requires you to use one authentication method in addition to your username and password, whereas MFA requires one or more additional authentication methods to your username and password. Adding these extra layers of security can significantly reduce the risk of account breaches. Ensure that all accounts, especially those with access to sensitive information, have these security methods enabled.
- Keep Software and Security Tools Updated
Regularly update all software, including operating systems, applications, antivirus programs and firewalls. Updates often contain patches for security vulnerabilities, so keeping everything current helps protect against known threats.
- Backup and Encrypt Your Data
Regularly back up all critical data and store these backups securely off-site. Additionally, encrypt sensitive data both in transit and at rest to ensure that even if it is intercepted, it remains unreadable.
- Restrict Access and Secure Physical Locations
Limit access to sensitive information to only those who need it. Additionally, make sure to protect physical access to computers, servers and other critical infrastructure. Use locks, access cards and other security measures to ensure that only authorized personnel can access sensitive areas.
- Monitor Systems Continuously
Implement continuous monitoring of your networks and systems to detect suspicious activity. Promptly investigate and respond to any unusual behavior to mitigate potential threats quickly.
- Develop an Incident Response Plan
Have a comprehensive incident response plan in place and ensure it is regularly updated. This plan should outline the steps to take in the event of a cyberattack, data breach, or other security incidents to minimize damage and recover quickly.
- Conduct Regular Risk Assessments and Vendor Management
Perform regular cybersecurity risk assessments to identify vulnerabilities and areas for improvement. Ensure that third-party vendors who have access to your systems or data comply with your cybersecurity standards.
- Be Compliant with Legal Requirements
Stay informed about and comply with relevant data protection laws and regulations. Ensure your cybersecurity practices meet or exceed legal requirements to avoid potential legal and financial penalties.
By implementing these cybersecurity measures, your nonprofit can better protect itself against cyber threats, ensuring the safety of your data and maintaining the trust of your supporters. Cybersecurity is an ongoing process, and staying vigilant is key to keeping your organization secure.
Statistics Source: “Nonprofits and Cyberattacks: Key Stats That Boards Need to Know” by BoardEffect

