Skip to main content

Live panel · Oct 8Who's Accountable at Machine Speed? Free, with the recording either way.

Save my seat
Nonprofit organizations

The attack that takes your money arrives as an invoice.

Security marketing aimed at nonprofits leads with ransomware because it makes a better headline. The risk that actually lands is a fraudulent payment instruction reaching a finance team of one, and it arrives with no malware for anything to detect.

The short version

Nonprofit cybersecurity has the same requirements as any other organization and two conditions that change the priorities.

The first is that the highest-impact risk is usually business email compromise rather than ransomware. A fraudulent payment instruction is disproportionately effective against a small finance function without a second approver, and it involves no malware, so the defense is identity monitoring and procedure rather than a better endpoint product.

The second is that there is no security team, and there is not going to be one. A staffed 24/7 rotation is several full-time salaries. That is why this arrives as a managed service or not at all.

Federal grant funding exists: FEMA's Nonprofit Security Grant Program made $300 million available in fiscal year 2026 and explicitly covers cybersecurity alongside physical security.

What actually happens

Four risks, in the order they bite.

Business email compromise, first

The highest-impact risk for most nonprofits is not ransomware. It is a fraudulent payment instruction that looks like it came from the executive director, landing on a finance function of one or two people with no second approver. The control that stops it is procedural as much as technical, and the detection that catches it is identity monitoring rather than endpoint.

Donor and beneficiary data

Payment details, giving history, and in many organizations case records about vulnerable people. The reputational cost of losing the second category is not measured in dollars, and it is the thing a board will ask about first.

Volunteers and turnover

Accounts created for people who are not employees, often in a hurry, frequently not removed when they stop volunteering. Every dormant account is a credential that still works and that nobody is watching.

Grant and contract obligations

Funders increasingly ask what security controls you operate, and government contracts can carry explicit requirements. The question usually arrives during a renewal, when there is no time to build an answer.

There is federal money, and it covers cybersecurity.

FEMA’s Nonprofit Security Grant Program made $300 million available in fiscal year 2026, split evenly between a designated urban-area stream and a state-administered stream. Each site can request up to $200,000, and an organization can apply for up to three sites per stream, to a maximum of $600,000 per state or territory.

It is commonly assumed to be physical security only. The fiscal year 2026 notice explicitly supports measures that strengthen cybersecurity alongside physical security, which makes it one of the few routes through which a nonprofit can fund monitoring rather than only doors and cameras.

Application windows open and close annually and are administered through your State Administrative Agency, which frequently sets an earlier internal deadline than the federal one. We have deliberately not printed a date here, because a funding page showing a window that has already closed is worse than one showing none. Ask us, or ask your state agency, what is genuinely open.

What it looks like

Built for an organization with no security engineer.

Identity and email are where the monitoring starts, because that is where the loss happens. Sign-in anomalies, mailbox rule changes, OAuth grants and account takeover patterns across Microsoft 365 or Google Workspace, in the same investigation queue as everything else.

Endpoints are covered too, over whatever you already run rather than requiring a replacement. From the Advanced tier the SOC acts under a runbook you approve in advance, which for an organization with no out-of-hours staff is the difference between the service working and the service notifying.

Onboarding assumes you do not have a security engineer, because you do not.

How we work with you

What the sector actually needs is not a discount.

Through your IT provider, or direct. Most nonprofits are already served by someone who knows their systems and their people. Our SOC runs white-label behind that provider so nothing about the relationship changes. Where an organization would rather hold the contract itself, it can. We never compete with our partners for their clients.

Onboarding written for no security engineer. The assumption is not that someone on staff will configure a connector over a weekend. It is that nobody can, because the person who would is also running the donor database and the website.

Evidence a board and a funder will accept. Continuous monitoring by a named provider, a written response mandate, and incident timelines that can be produced on request. Those three sentences are what a due-diligence questionnaire is really asking for, and a tool purchase on its own does not produce any of them.

Help scoping the technical half of a grant. The hardest part of a security line in a funding application is describing it precisely enough to be approved. We will write that scope with you whether or not the application names us.

Questions

Including the one about price.

What is the biggest cybersecurity risk for a nonprofit?

For most, business email compromise rather than ransomware. A fraudulent payment instruction is disproportionately effective against a small finance team without a second approver, and it does not require any malware. That is worth knowing because it changes what to buy: the defense is identity monitoring and a payment verification procedure, not a better antivirus.

Is there grant funding for nonprofit cybersecurity?

Yes, and the principal federal one is FEMA’s Nonprofit Security Grant Program. For fiscal year 2026 it made $300 million available, split evenly between a designated urban-area stream and a state-administered stream, with each site able to request up to $200,000 and an organization able to apply for up to three sites per stream, to a maximum of $600,000 per state or territory. The FY2026 notice explicitly covers cybersecurity alongside physical security. Windows open and close annually, so ask your state administering agency what is currently open rather than working from a date you read somewhere.

Do you offer nonprofit pricing?

Ask us. We are not going to publish a discount percentage we would then have to qualify, and any provider who quotes you a nonprofit rate before understanding your environment is quoting a number rather than a service. What we can say is that the cost driver is endpoints, log volume, retention and how much response mandate you want, and that a small organization is genuinely a smaller number.

We have almost no IT staff. Is this realistic for us?

It is more realistic than the alternative, which is asking the person who also manages the database and the website to be the security team at 2am. The service exists precisely because a staffed rotation is several full-time salaries and almost nobody outside a large enterprise can justify that. Onboarding assumes you do not have a security engineer.

What do we tell our board?

That the organization has continuous monitoring with a named provider, a defined response mandate, and an incident timeline it can produce if asked. Those three things are what a board and a funder actually want to hear, and they are the things a tool purchase alone does not deliver.

Can our existing IT provider deliver this?

Often, yes, and that is frequently the better arrangement. Many nonprofits are served by an MSP that can run our SOC white-label behind them, so you keep the relationship you already have. We never compete with our partners for their clients.

We're online · book a SOC walkthrough today

Start with the free check
that takes ten seconds.

Your email trust posture, SPF, DMARC and DKIM, is the single control that most affects whether a fraudulent invoice reaches your finance team. Check it before you buy anything.