8 cybersecurity habits to help protect your nonprofit's mission

August 13, 2026
Tech To The Rescue
5min read

Research from the CyberPeace Institute found that 70% of NGOs are not confident they could recover from a disruptive cyberattack. Staying safe depends less on the size of a security budget than on a handful of specific habits built into how a team works. This guide covers eight of them, drawn from a working session with Nord Security inside the Tech To The Rescue Cybersecurity Hub.

Cybercriminals increasingly target nonprofit organizations. Research from the CyberPeace Institute, now Protect.ngo, found that 70% of non-governmental organizations (NGOs) are not confident they could recover from a disruptive cyberattack. In the same research, 33% of NGOs reported having no IT support or technical expertise, and 56% reported no budget allocated for cybersecurity.¹

Staying safe depends less on the size of a security budget than on a handful of specific habits built into how a team works. This guide covers eight of them that you can start applying right away.

In this article

Why criminals target NGOs

Nonprofits hold information that makes them a high-value target, including donor records with contact and payment details, financial and banking information, staff and volunteer data, records relating to the people they serve, and confidential communication and strategic plans. Criminals reach that data without facing the defenses of a large enterprise security team.

Only 4% of NGOs have an actionable cybersecurity policy. Unlike industries designated as critical infrastructure, NGOs receive no specific protections in cyberspace. Funding is typically earmarked for project delivery, so security work rarely gets dedicated financial support. Most organizations recognize the threats they face, and recognizing a threat is not the same as being prepared for it.¹

Financially motivated criminals are not the only ones paying attention. Microsoft's 2025 Digital Defense Report identifies NGOs and think tanks as consistent targets for nation-state espionage, because many hold large amounts of personally identifiable information while operating with small IT teams and limited incident response capacity.²

Phishing and unauthorized account access are the openings that criminals and nation-state actors most often use. Closing them starts with how your team handles routine moments like a message in an inbox or a password reset.

Habit 1: verify who is contacting you before you respond

The phishing email that teaches the most useful lesson is the one that looks completely legitimate at first glance. It has the right logo, a clean subject line, and no spelling errors. The sender domain is a lookalike rather than the real one.

Build the habit of checking who is really behind a message before you act on it:

  • Check the sender domain character by character.
  • Treat any request for a password as illegitimate, because real services do not ask for credentials by email.
  • Ask yourself whether the request makes sense for a service you actually use.
  • Run any unfamiliar link or file through a link checker or file checker before you open it.

Habit 2: get passwords and multi-factor authentication right

Passwords are the cheapest security improvement available to any organization, and the most commonly skipped. A strong password has at least 12 characters, avoids personal information like names or birthdates, and is not reused across accounts.

NordPass publishes annual research on the most common passwords, and simple sequences like “123456,” “admin,” and “password” still appear near the top every year.³ Automated password-guessing software can break passwords like these in seconds. A password manager generates and stores complex credentials, so your team only needs to remember one master password.

Multi-factor authentication (MFA) is the second layer of defense, and it protects an account even after a password has leaked. Where the option exists, authenticator apps are stronger than SMS codes, because SMS codes can be intercepted while app-generated codes change every 30 seconds. Enable MFA on email, cloud storage, banking, and admin accounts.

Habit 3: contain ransomware before you call anyone

Many people's first instinct after discovering ransomware on one computer is to alert IT staff, inform the board, or wait to see whether other devices are affected. The correct first action is to unplug or disconnect the affected device from the network and the internet.

Notifying IT staff and informing leadership are both necessary steps, taken in that sequence. Ransomware spreads laterally, and every minute a compromised machine stays connected is a minute it can reach shared drives and other endpoints.

Once you have disconnected the device, assess the scope of the attack. Contact your IT support or a cybersecurity expert. Then record the details, including the time, what was affected, and the exact wording of the ransom note.

Never pay the ransom. Payment does not guarantee the return of your data, and it signals to other attackers that your organization is willing to pay. Contact law enforcement, restore your systems and files from clean backups, and inform your board, staff, volunteers, and affected stakeholders. Once systems are stable, run a post-incident review focused on what to change.

Habit 4: verify payment changes with a call

Cyber thieves infiltrated the email server of Philabundance, a hunger relief nonprofit in Philadelphia, through a phishing scam in spring 2020. In July that year they sent a fake invoice mimicking a construction company that had done work for the organization, and the finance office wired close to $923,000 to an account the thieves controlled.⁴

The attack succeeded because every element was individually plausible. The vendor was real, the invoice looked legitimate, and the request arrived through a channel the finance team already trusted. The email had no spelling errors, no mismatched sender address, and no unusual formatting. The usual warning signs were absent, which is what makes this type of fraud difficult to catch in the moment.

Any change to bank details on an invoice should trigger a phone call to a number you already hold on file. Never use a number supplied in the email requesting the change. As a second safeguard, require two people to approve any payment above a threshold your organization sets. Attackers benefit most when your team moves fast on a payment decision.

Habit 5: apply updates the day they are released

In 2022, the International Committee of the Red Cross (ICRC) disclosed a data breach that affected the personal data of more than 515,000 people worldwide. The compromised system supported Restoring Family Links, the program that reconnects families separated by conflict, migration, and disaster. The breach occurred on November 9, 2021, and went undetected until January 18, 2022. The entry point was an unpatched critical vulnerability in an authentication module for which a fix already existed.⁵

Reduce the risk of an unpatched vulnerability being your entry point with a few consistent practices:

  • Update operating systems and software as updates arrive, not when convenient.
  • Retire software that no longer receives security support.
  • Run an antivirus, use a firewall, and implement endpoint protection.
  • Segment your network so a compromise in one system stays contained to that system.
  • Back up frequently, store at least one backup offline or in a secured cloud environment, and test the restore so you know it works before you need it.

Habit 6: remove access the day someone leaves

Social impact organizations often run on volunteers, fellows, contractors, and seasonal staff, which means people join and leave far more often than in a comparably sized company. Every departing individual who leaves an active account behind provides an open door for bad actors.

A tracking spreadsheet listing which tools each person can access, maintained from the day they join, is an important record-keeping step. When someone leaves:

  • Revoke their access to email, file storage, donor databases, social media accounts, collaboration tools, and MFA apps.
  • Retrieve and wipe any organization-owned devices.
  • Change shared credentials.
  • Transfer ownership of files, folders, calendars, and email to someone still on the team.

Use the same discipline when you onboard. New hires are 44% more likely to fall for phishing and social engineering attacks than tenured employees during their first 90 days, and their average phishing susceptibility during onboarding runs as high as 71%.⁶

When someone joins:

  • Define their access by role rather than granting broad permissions by default.
  • Set up accounts with strong passwords and MFA from day one.
  • Start security training in the first week and follow up with short reminders, because new hires are unlikely to retain everything covered in an information-heavy first week.

Habit 7: name an incident response owner from day one

The highest-leverage decision in nonprofit security is naming one person to own incident response, even if the role takes only a few hours a week. Without a named owner, an incident produces a room full of people who each assume someone else knows the plan.

The plan itself is straightforward:

  • Contain the problem by disconnecting affected devices and locking compromised accounts.
  • Figure out what happened, including the attack type, what was reached, and what the logs show.
  • Notify the right people. You might need to alert IT support, leadership, affected individuals, and any regulator you report to under the GDPR or similar frameworks.
  • Secure systems by patching vulnerabilities and requiring password changes with MFA enabled.
  • Recover by restoring from clean, verified backups.
  • Learn from what happened by identifying the weak point and sharing it with your team.
  • Strengthen defenses through ongoing training, monitoring, access controls, and scheduled reviews.

For organizations without an internal IT team or a security contractor, the Access Now Digital Security Helpline provides free technical assistance to civil society organizations, including in the middle of an active incident.

Habit 8: stay secure while traveling or working remotely

Most of an organization's standard protections do not reach the field or the home office. Public networks in airports, hotels, and cafes usually lack authentication and device isolation, so an attacker on the same network can intercept traffic from other users. Fake hotspots are straightforward to set up. The real network might be called “Airport Wi-Fi” while the attacker uses a more tempting name like “Free Airport Wi-Fi” to lure people in.

To protect your connection wherever you are working from:

  • Use a VPN to encrypt traffic on any network you do not control.
  • Confirm the sites you visit are using HTTPS.
  • Avoid banking and other activities that involve sensitive information on public networks.
  • Disable file sharing and turn off Wi-Fi auto-connect.
  • Where possible, use your own mobile data.
  • Avoid public USB charging stations, which can be used to move malware onto a device or pull data from it. Carry your own power bank instead.

Most staff members of social impact organizations use their own personal devices, because purchasing hardware for every volunteer is rarely realistic. Keep software updated, install apps only from trusted sources, separate work and personal files where you can, and report a lost or stolen device to your team immediately. A missing phone or computer puts the organization's data at risk, not only the device owner's.

Key takeaways

  • Use a password manager to create strong, unique passwords, and enable MFA on email, cloud storage, banking, and admin accounts, preferably with an authenticator app rather than SMS.
  • Check sender domains character by character and treat emailed password requests as illegitimate. Confirm any change to bank details by phone using a number you have already verified. Philabundance lost close to $923,000 in 2020 after attackers impersonated a construction company it had worked with.
  • If your organization gets hit by ransomware, disconnect the affected device before alerting IT staff or leadership, and never pay, because payment does not guarantee that you will get your data back.
  • Patch software as soon as updates are released, and back up data regularly, testing your restore process so it works when you need it. The ICRC breach disclosed in 2022, which exposed data belonging to more than 515,000 people, started with an unpatched vulnerability for which a fix already existed.
  • The day someone leaves, revoke their access. Start security training for a new hire in the first week, when they are most likely to fall for phishing.
  • Name one person to be responsible for cybersecurity and write a one-page incident response plan.
  • When working remotely or traveling, use a VPN and avoid sensitive transactions on public Wi-Fi.

Where this guide came from

This guide draws on a working session with Jurgita Kačkytė, nonprofit partnerships manager at Nord Security, held as part of the Tech To The Rescue Cybersecurity Hub within the AI Impact Scaling Program.

Organizations that join the hub work through these procedures directly rather than reading about them. If your organization has a proven intervention ready to scale with AI, application details and eligibility criteria are on the AI Impact Scaling Program page.

Nord Security's nonprofit team can be reached at nonprofit@nordvpn.com. NordVPN offers free or discounted VPN subscriptions to eligible nonprofits through its dedicated program at nordvpn.org.

Frequently asked questions

What should a nonprofit do first after discovering a ransomware attack?

After discovering a ransomware attack, disconnect the affected device from the network and the internet immediately. Containment stops the ransomware from spreading to shared drives and other machines while the response is organized.

After containing it, contact your IT support or a cybersecurity expert. Record the details of the attack, including the time and the exact wording of the ransom note. Notify law enforcement and restore your systems and files from clean backups. Never pay the ransom.

Why do cybercriminals target nonprofits and NGOs?

Nonprofits hold donor payment details, financial records, staff and volunteer data, and information about the people they serve, who may already be at risk. That combination makes them valuable targets. Most also operate without a dedicated IT team or a budget line for digital defenses, which makes them easier to breach once targeted.

How can a small nonprofit improve its cybersecurity without a budget?

A small nonprofit can improve its cybersecurity without a budget by focusing on measures that cost little and have a high impact:

  • Enable MFA on email, cloud storage, banking, and admin accounts.
  • Use a password manager so every account has a unique password of at least 12 characters.
  • Apply software updates as they are released.
  • Back up data regularly and keep one copy of the backup offline.
  • Name a person responsible for security, even at a few hours per week, and write a one-page incident response plan.
  • Reach out to the Access Now Digital Security Helpline, which provides free technical support to civil society organizations.

How do you recognize a phishing email?

You can spot a phishing email by checking a few specific signs before you act on it:

  • Check the sender's domain character by character. Lookalike domains are the most common giveaway in an otherwise convincing message.
  • Treat any request for a password as illegitimate, because real services do not ask for credentials by email.
  • Be skeptical of language with an urgent tone that pressures you to act without thinking.

Even security-focused organizations see employees click on simulated phishing emails during internal testing, which is why building a habit of checking works better than trusting a message on sight.

What should a nonprofit's offboarding checklist include?

A nonprofit's offboarding checklist should include the following steps:

  • Revoke access to email, file storage, donor databases, social media accounts, collaboration tools, and MFA apps.
  • Retrieve and wipe any organization-owned devices.
  • Change the shared credentials that the departing person knew.
  • Transfer ownership of files, folders, calendars, and email to a current team member.

Maintain a spreadsheet listing which tools each person can access, updated from the day they join.

Is public Wi-Fi safe for nonprofit staff working while traveling?

Public Wi-Fi is not safe by default. Networks in airports, hotels, and cafes generally lack authentication and device isolation, so cybercriminals can intercept your traffic. Staff working remotely can reduce that risk with a few precautions:

  • Use a VPN to encrypt your connection.
  • Confirm that sites use HTTPS.
  • Avoid banking and other sensitive transactions on public networks.
  • Disable file sharing and turn off Wi-Fi auto-connect so devices do not join networks automatically.
  • Use your own mobile data where possible, which is safer than any public network.
  • Avoid public USB charging stations, which can be used to install malware or extract data from a device.

What does a nonprofit incident response plan need to cover?

A nonprofit's incident response plan should cover seven steps:

  • Contain the problem by disconnecting devices and locking compromised accounts.
  • Assess what happened and what was affected.
  • Notify IT support, leadership, affected individuals, and any regulator you report to under the GDPR or similar frameworks.
  • Secure systems by patching vulnerabilities and requiring password changes.
  • Recover from verified clean backups.
  • Review what went wrong and share the findings with the team.
  • Strengthen defenses through training, monitoring, and access controls.

Name one person to own this plan before an incident happens.

How does Tech To The Rescue support cybersecurity for social impact organizations?

Tech To The Rescue supports cybersecurity for social impact organizations through its AI Impact Scaling Program, which includes a dedicated Cybersecurity Hub delivered with partners including Nord Security. Organizations in the program work through practical sessions and toolkits, and get pro bono matching with technology partners from the Tech To The Rescue global ecosystem.

References

1. CyberPeace Institute. (2023). Analytical Report: NGOs serving Humanity at risk: Cyber Threats affecting “International Geneva.” Protect.ngo. Read the report

2. Microsoft. (2025, October). Microsoft Digital Defense Report 2025. Read the report

3. NordPass. (2025). Top 200 Most Common Passwords. See the list

4. Brandt, J. (2020, December 1). Philabundance says cyber thieves took nearly $1M in a scam this year. WHYY. Read the article

5. International Committee of the Red Cross. (2022, February 16). Cyber attack on ICRC: What we know. Read the statement

6. Keepnet Labs. (2025, June 23). 2025 New Hires Phishing Susceptibility Report. Read the report

Latest News

See all news