
Research from the CyberPeace Institute found that 70% of NGOs are not confident they could recover from a disruptive cyberattack. Staying safe depends less on the size of a security budget than on a handful of specific habits built into how a team works. This guide covers eight of them, drawn from a working session with Nord Security inside the Tech To The Rescue Cybersecurity Hub.
Cybercriminals increasingly target nonprofit organizations. Research from the CyberPeace Institute, now Protect.ngo, found that 70% of non-governmental organizations (NGOs) are not confident they could recover from a disruptive cyberattack. In the same research, 33% of NGOs reported having no IT support or technical expertise, and 56% reported no budget allocated for cybersecurity.¹
Staying safe depends less on the size of a security budget than on a handful of specific habits built into how a team works. This guide covers eight of them that you can start applying right away.
In this article
Nonprofits hold information that makes them a high-value target, including donor records with contact and payment details, financial and banking information, staff and volunteer data, records relating to the people they serve, and confidential communication and strategic plans. Criminals reach that data without facing the defenses of a large enterprise security team.
Only 4% of NGOs have an actionable cybersecurity policy. Unlike industries designated as critical infrastructure, NGOs receive no specific protections in cyberspace. Funding is typically earmarked for project delivery, so security work rarely gets dedicated financial support. Most organizations recognize the threats they face, and recognizing a threat is not the same as being prepared for it.¹
Financially motivated criminals are not the only ones paying attention. Microsoft's 2025 Digital Defense Report identifies NGOs and think tanks as consistent targets for nation-state espionage, because many hold large amounts of personally identifiable information while operating with small IT teams and limited incident response capacity.²
Phishing and unauthorized account access are the openings that criminals and nation-state actors most often use. Closing them starts with how your team handles routine moments like a message in an inbox or a password reset.
The phishing email that teaches the most useful lesson is the one that looks completely legitimate at first glance. It has the right logo, a clean subject line, and no spelling errors. The sender domain is a lookalike rather than the real one.
Build the habit of checking who is really behind a message before you act on it:
Passwords are the cheapest security improvement available to any organization, and the most commonly skipped. A strong password has at least 12 characters, avoids personal information like names or birthdates, and is not reused across accounts.
NordPass publishes annual research on the most common passwords, and simple sequences like “123456,” “admin,” and “password” still appear near the top every year.³ Automated password-guessing software can break passwords like these in seconds. A password manager generates and stores complex credentials, so your team only needs to remember one master password.
Multi-factor authentication (MFA) is the second layer of defense, and it protects an account even after a password has leaked. Where the option exists, authenticator apps are stronger than SMS codes, because SMS codes can be intercepted while app-generated codes change every 30 seconds. Enable MFA on email, cloud storage, banking, and admin accounts.
Many people's first instinct after discovering ransomware on one computer is to alert IT staff, inform the board, or wait to see whether other devices are affected. The correct first action is to unplug or disconnect the affected device from the network and the internet.
Notifying IT staff and informing leadership are both necessary steps, taken in that sequence. Ransomware spreads laterally, and every minute a compromised machine stays connected is a minute it can reach shared drives and other endpoints.
Once you have disconnected the device, assess the scope of the attack. Contact your IT support or a cybersecurity expert. Then record the details, including the time, what was affected, and the exact wording of the ransom note.
Never pay the ransom. Payment does not guarantee the return of your data, and it signals to other attackers that your organization is willing to pay. Contact law enforcement, restore your systems and files from clean backups, and inform your board, staff, volunteers, and affected stakeholders. Once systems are stable, run a post-incident review focused on what to change.
Cyber thieves infiltrated the email server of Philabundance, a hunger relief nonprofit in Philadelphia, through a phishing scam in spring 2020. In July that year they sent a fake invoice mimicking a construction company that had done work for the organization, and the finance office wired close to $923,000 to an account the thieves controlled.⁴
The attack succeeded because every element was individually plausible. The vendor was real, the invoice looked legitimate, and the request arrived through a channel the finance team already trusted. The email had no spelling errors, no mismatched sender address, and no unusual formatting. The usual warning signs were absent, which is what makes this type of fraud difficult to catch in the moment.
Any change to bank details on an invoice should trigger a phone call to a number you already hold on file. Never use a number supplied in the email requesting the change. As a second safeguard, require two people to approve any payment above a threshold your organization sets. Attackers benefit most when your team moves fast on a payment decision.
In 2022, the International Committee of the Red Cross (ICRC) disclosed a data breach that affected the personal data of more than 515,000 people worldwide. The compromised system supported Restoring Family Links, the program that reconnects families separated by conflict, migration, and disaster. The breach occurred on November 9, 2021, and went undetected until January 18, 2022. The entry point was an unpatched critical vulnerability in an authentication module for which a fix already existed.⁵
Reduce the risk of an unpatched vulnerability being your entry point with a few consistent practices:
Social impact organizations often run on volunteers, fellows, contractors, and seasonal staff, which means people join and leave far more often than in a comparably sized company. Every departing individual who leaves an active account behind provides an open door for bad actors.
A tracking spreadsheet listing which tools each person can access, maintained from the day they join, is an important record-keeping step. When someone leaves:
Use the same discipline when you onboard. New hires are 44% more likely to fall for phishing and social engineering attacks than tenured employees during their first 90 days, and their average phishing susceptibility during onboarding runs as high as 71%.⁶
When someone joins:
The highest-leverage decision in nonprofit security is naming one person to own incident response, even if the role takes only a few hours a week. Without a named owner, an incident produces a room full of people who each assume someone else knows the plan.
The plan itself is straightforward:
For organizations without an internal IT team or a security contractor, the Access Now Digital Security Helpline provides free technical assistance to civil society organizations, including in the middle of an active incident.
Most of an organization's standard protections do not reach the field or the home office. Public networks in airports, hotels, and cafes usually lack authentication and device isolation, so an attacker on the same network can intercept traffic from other users. Fake hotspots are straightforward to set up. The real network might be called “Airport Wi-Fi” while the attacker uses a more tempting name like “Free Airport Wi-Fi” to lure people in.
To protect your connection wherever you are working from:
Most staff members of social impact organizations use their own personal devices, because purchasing hardware for every volunteer is rarely realistic. Keep software updated, install apps only from trusted sources, separate work and personal files where you can, and report a lost or stolen device to your team immediately. A missing phone or computer puts the organization's data at risk, not only the device owner's.
This guide draws on a working session with Jurgita Kačkytė, nonprofit partnerships manager at Nord Security, held as part of the Tech To The Rescue Cybersecurity Hub within the AI Impact Scaling Program.
Organizations that join the hub work through these procedures directly rather than reading about them. If your organization has a proven intervention ready to scale with AI, application details and eligibility criteria are on the AI Impact Scaling Program page.
Nord Security's nonprofit team can be reached at nonprofit@nordvpn.com. NordVPN offers free or discounted VPN subscriptions to eligible nonprofits through its dedicated program at nordvpn.org.
After discovering a ransomware attack, disconnect the affected device from the network and the internet immediately. Containment stops the ransomware from spreading to shared drives and other machines while the response is organized.
After containing it, contact your IT support or a cybersecurity expert. Record the details of the attack, including the time and the exact wording of the ransom note. Notify law enforcement and restore your systems and files from clean backups. Never pay the ransom.
Nonprofits hold donor payment details, financial records, staff and volunteer data, and information about the people they serve, who may already be at risk. That combination makes them valuable targets. Most also operate without a dedicated IT team or a budget line for digital defenses, which makes them easier to breach once targeted.
A small nonprofit can improve its cybersecurity without a budget by focusing on measures that cost little and have a high impact:
You can spot a phishing email by checking a few specific signs before you act on it:
Even security-focused organizations see employees click on simulated phishing emails during internal testing, which is why building a habit of checking works better than trusting a message on sight.
A nonprofit's offboarding checklist should include the following steps:
Maintain a spreadsheet listing which tools each person can access, updated from the day they join.
Public Wi-Fi is not safe by default. Networks in airports, hotels, and cafes generally lack authentication and device isolation, so cybercriminals can intercept your traffic. Staff working remotely can reduce that risk with a few precautions:
A nonprofit's incident response plan should cover seven steps:
Name one person to own this plan before an incident happens.
Tech To The Rescue supports cybersecurity for social impact organizations through its AI Impact Scaling Program, which includes a dedicated Cybersecurity Hub delivered with partners including Nord Security. Organizations in the program work through practical sessions and toolkits, and get pro bono matching with technology partners from the Tech To The Rescue global ecosystem.
1. CyberPeace Institute. (2023). Analytical Report: NGOs serving Humanity at risk: Cyber Threats affecting “International Geneva.” Protect.ngo. Read the report
2. Microsoft. (2025, October). Microsoft Digital Defense Report 2025. Read the report
3. NordPass. (2025). Top 200 Most Common Passwords. See the list
4. Brandt, J. (2020, December 1). Philabundance says cyber thieves took nearly $1M in a scam this year. WHYY. Read the article
5. International Committee of the Red Cross. (2022, February 16). Cyber attack on ICRC: What we know. Read the statement
6. Keepnet Labs. (2025, June 23). 2025 New Hires Phishing Susceptibility Report. Read the report