The email looked like it came from the executive director. It asked the bookkeeper to change the bank details for a vendor payment. It was polite, urgent, and fake — and versions of it land in nonprofit inboxes every single day. Small organizations get hit not because attackers care who they are, but because automated attacks hit everyone, and small nonprofits are the least defended targets holding donor payment data.

The good news: you are five moves away from being a hard target, and four of them are free.

1. Turn On MFA Everywhere (Free, One Afternoon)

Multi-factor authentication — the code on your phone — defeats the attack responsible for most breaches: a stolen or reused password. Enable it on email first, then your donation platform, bank, and donor database. If you do exactly one thing from this article, it's this.

2. Get a Password Manager (A Few Dollars, One Week)

The alternative is what small organizations actually do: one shared password in a spreadsheet named “Logins,” reused across ten services. A team password manager (Bitwarden and 1Password both offer nonprofit-friendly pricing) makes unique passwords automatic and — critically — makes offboarding possible: one click removes a departed volunteer's access to everything.

3. Put Accounts in the Organization's Name (Free)

Security isn't just intruders — it's continuity. The donation platform registered to a former treasurer's personal Gmail is a breach waiting for a bad breakup. Organization-owned accounts on organization-owned email, with at least two admins on everything critical, is the unglamorous foundation the rest sits on.

4. Make Backups Someone's Job (Mostly Free)

Google Workspace and Microsoft 365 protect files in their world; your donor database, website, and accounting system each need their own export schedule. The test isn't “do we have backups” — it's “when did someone last download one and open it.” Quarterly, on a named person's calendar.

5. Train the Inbox Reflex (Free, One Hour a Year)

Every scenario in this article starts with an email. One hour a year with staff and key volunteers covering the big three — urgent payment changes, gift-card requests, login links — plus one standing rule: any money or credential request gets verified by a second channel. A text to the real ED defeats the fake one every time.

What You Can Skip (For Now)

Enterprise endpoint suites, SOC monitoring, penetration tests — at ten staff, that spend protects you less than the five habits above executed well. Where security does intersect with bigger decisions is infrastructure: aging servers, unpatched plugins on a neglected website, and legacy systems nobody dares touch — those are technology-strategy problems wearing a security costume, and they're worth a real assessment.

Frequently Asked Questions

Why would hackers target a small nonprofit?

They mostly don't target you — they target everyone, automatically. Phishing and credential-stuffing attacks are sprayed at millions of inboxes, and small nonprofits get hit because they hold donor financial data and have the least protection. You don't need to outrun the bear; you need to not be the easiest organization on the block.

What is the single most important security step for a nonprofit?

Multi-factor authentication (MFA) on every account that offers it, starting with email and your donation platform. It's free, takes an afternoon to roll out, and neutralizes the most common attack — a stolen or reused password — almost entirely.

How much should a small nonprofit spend on cybersecurity?

For most small organizations: close to nothing in dollars. MFA is free, password managers cost a few dollars per user monthly (with nonprofit discounts), and backups are included in Google Workspace and Microsoft 365 nonprofit plans. The real spend is a few hours of setup and an annual hour of staff training.

Do nonprofits need cyber insurance?

Increasingly, funders and boards ask for it. Worth knowing: insurers now require the basics — MFA, backups, and documented practices — before they'll write a policy at a reasonable premium. Doing the five things in this article is effectively the application prep.

What should we do if we think we've been phished?

Change the affected password immediately, revoke active sessions from the account's security page, enable MFA if it wasn't on, and check mail forwarding rules (attackers add silent forwards). Then tell your team without blame — the organizations that get hurt worst are the ones where nobody admits the click for a week.

Want a Security Once-Over?

Our Technology Assessment includes the security basics — who owns what, what's exposed, what to fix first — in plain language your board can act on.

Book a Free Discovery Call