The attack that takes your money arrives as an invoice.
Security marketing aimed at nonprofits leads with ransomware because it makes a better headline. The risk that actually lands is a fraudulent payment instruction reaching a finance team of one, and it arrives with no malware for anything to detect.
Nonprofit cybersecurity has the same requirements as any other organization and two conditions that change the priorities.
The first is that the highest-impact risk is usually business email compromise rather than ransomware. A fraudulent payment instruction is disproportionately effective against a small finance function without a second approver, and it involves no malware, so the defense is identity monitoring and procedure rather than a better endpoint product.
The second is that there is no security team, and there is not going to be one. A staffed 24/7 rotation is several full-time salaries. That is why this arrives as a managed service or not at all.
Federal grant funding exists: FEMA's Nonprofit Security Grant Program made $300 million available in fiscal year 2026 and explicitly covers cybersecurity alongside physical security.
Four risks, in the order they bite.
Business email compromise, first
The highest-impact risk for most nonprofits is not ransomware. It is a fraudulent payment instruction that looks like it came from the executive director, landing on a finance function of one or two people with no second approver. The control that stops it is procedural as much as technical, and the detection that catches it is identity monitoring rather than endpoint.
Donor and beneficiary data
Payment details, giving history, and in many organizations case records about vulnerable people. The reputational cost of losing the second category is not measured in dollars, and it is the thing a board will ask about first.
Volunteers and turnover
Accounts created for people who are not employees, often in a hurry, frequently not removed when they stop volunteering. Every dormant account is a credential that still works and that nobody is watching.
Grant and contract obligations
Funders increasingly ask what security controls you operate, and government contracts can carry explicit requirements. The question usually arrives during a renewal, when there is no time to build an answer.
There is federal money, and it covers cybersecurity.
FEMA’s Nonprofit Security Grant Program made $300 million available in fiscal year 2026, split evenly between a designated urban-area stream and a state-administered stream. Each site can request up to $200,000, and an organization can apply for up to three sites per stream, to a maximum of $600,000 per state or territory.
It is commonly assumed to be physical security only. The fiscal year 2026 notice explicitly supports measures that strengthen cybersecurity alongside physical security, which makes it one of the few routes through which a nonprofit can fund monitoring rather than only doors and cameras.
Application windows open and close annually and are administered through your State Administrative Agency, which frequently sets an earlier internal deadline than the federal one. We have deliberately not printed a date here, because a funding page showing a window that has already closed is worse than one showing none. Ask us, or ask your state agency, what is genuinely open.
Built for an organization with no security engineer.
Identity and email are where the monitoring starts, because that is where the loss happens. Sign-in anomalies, mailbox rule changes, OAuth grants and account takeover patterns across Microsoft 365 or Google Workspace, in the same investigation queue as everything else.
Endpoints are covered too, over whatever you already run rather than requiring a replacement. From the Advanced tier the SOC acts under a runbook you approve in advance, which for an organization with no out-of-hours staff is the difference between the service working and the service notifying.
Onboarding assumes you do not have a security engineer, because you do not.
Including the one about price.
What is the biggest cybersecurity risk for a nonprofit?
For most, business email compromise rather than ransomware. A fraudulent payment instruction is disproportionately effective against a small finance team without a second approver, and it does not require any malware. That is worth knowing because it changes what to buy: the defense is identity monitoring and a payment verification procedure, not a better antivirus.
Is there grant funding for nonprofit cybersecurity?
Yes, and the principal federal one is FEMA’s Nonprofit Security Grant Program. For fiscal year 2026 it made $300 million available, split evenly between a designated urban-area stream and a state-administered stream, with each site able to request up to $200,000 and an organization able to apply for up to three sites per stream, to a maximum of $600,000 per state or territory. The FY2026 notice explicitly covers cybersecurity alongside physical security. Windows open and close annually, so ask your state administering agency what is currently open rather than working from a date you read somewhere.
Do you offer nonprofit pricing?
Ask us. We are not going to publish a discount percentage we would then have to qualify, and any provider who quotes you a nonprofit rate before understanding your environment is quoting a number rather than a service. What we can say is that the cost driver is endpoints, log volume, retention and how much response mandate you want, and that a small organization is genuinely a smaller number.
We have almost no IT staff. Is this realistic for us?
It is more realistic than the alternative, which is asking the person who also manages the database and the website to be the security team at 2am. The service exists precisely because a staffed rotation is several full-time salaries and almost nobody outside a large enterprise can justify that. Onboarding assumes you do not have a security engineer.
What do we tell our board?
That the organization has continuous monitoring with a named provider, a defined response mandate, and an incident timeline it can produce if asked. Those three things are what a board and a funder actually want to hear, and they are the things a tool purchase alone does not deliver.
Can our existing IT provider deliver this?
Often, yes, and that is frequently the better arrangement. Many nonprofits are served by an MSP that can run our SOC white-label behind them, so you keep the relationship you already have. We never compete with our partners for their clients.
Start with the free check
that takes ten seconds.
Your email trust posture, SPF, DMARC and DKIM, is the single control that most affects whether a fraudulent invoice reaches your finance team. Check it before you buy anything.