The cybersecurity industry often makes protection sound expensive and complex. For most small nonprofits, the highest-impact steps cost nothing. Here are five of them.
1. Turn On Multi-Factor Authentication Everywhere
Multi-factor authentication, or MFA, requires a second form of verification when someone logs in. Even if an attacker has your password, they cannot get in without the second factor.
Enable MFA on email, donor databases, financial accounts, and any cloud platform your organization uses. Google, Microsoft, and most major platforms offer MFA at no cost. This one step blocks the majority of account takeover attacks targeting nonprofits in 2026.
2. Set a Password Policy and Enforce It
Stop allowing shared passwords. Every staff member and volunteer gets their own account with a unique password. Require passwords of at least 16 characters. Free password managers like Bitwarden make this easy to enforce without requiring anyone to memorize complex strings.
The goal is simple: when someone leaves your organization, you remove their account. You do not change a shared password and hope everyone updates it.
3. Run a Free Phishing Simulation
Most breaches start with a phishing email. Your team needs to recognize them. Google’s Phishing Quiz and several free tools let you test your staff and volunteers without spending anything.
Run a simulation, review the results, and spend 30 minutes walking your team through what to look for. This costs nothing and reduces your most common attack vector significantly.
4. Remove Old User Accounts
Pull a list of every active account across every platform your organization uses. Email, donor software, accounting tools, social media, cloud storage. Remove every account belonging to someone who no longer works or volunteers with you.
Old, inactive accounts are open doors. Attackers find them, use credential stuffing to get in, and operate inside your systems without anyone noticing. Removing them costs nothing and closes a significant exposure.
5. Review Who Has Admin Access
Admin accounts have elevated privileges. If one gets compromised, an attacker has broad access to your systems. Most organizations have more admin accounts than they need.
Review every admin account on every platform. Remove admin access from anyone who does not strictly need it. Standard user access is enough for most staff and all volunteers.
Where to Go From Here
These five steps address the most common attack entry points for nonprofits. They cost nothing to implement. Do them this week.
For a practical way to continue, use my free Nonprofit Cybersecurity Starter Kit. It turns these first actions into a broader, manageable security baseline.
Once they are in place, the next step is a full security assessment to find what else needs attention. A fractional cybersecurity consultant does this work at a cost most nonprofits absorb without a line item budget change.

Leave a Reply