Nonprofits handle some of the most sensitive data around (donor financial information, client records, sometimes health details) often with a fraction of the security budget and staffing that a similarly sized business would have. That combination makes Minnesota nonprofits an attractive target, not a low-risk one. At CSI Tech Corp, we’ve partnered with nonprofits and community organizations throughout Minneapolis, St. Paul, and the Twin Cities since 2004. And we have prepared this checklist that covers the threats nonprofits actually face and the practical steps to close the gaps, without requiring an enterprise security budget. 

There are 10 Most Common IT Threats Facing Nonprofits:

  1. Phishing emails impersonating vendors, donors, or leadership 
  2. Business email compromise and donation-redirect fraud
  3. Ransomware targeting client and donor databases 
  4. Weak or reused passwords across shared accounts 
  5. Unpatched software and operating systems 
  6. Poorly secured donor and CRM databases 
  7. Social engineering aimed at volunteers unfamiliar with security protocols 
  8. Data exposure from lost or stolen devices 
  9. Third-party vendor and platform risk (payment processors, event platforms) 
  10. Insufficient or untested data backups 
  1. Multi-factor authentication enabled on every account, especially email and financial systems 
  2. Strong, unique password policy enforced org-wide 
  3. Regular review of admin-level account access 

 

Multi-Factor Authentication (MFA) adds an extra layer of security, making it significantly harder for attackers to gain access, even if passwords are compromised. 

Every nonprofit should enable MFA for: 

  • Microsoft 365 
  • Email 
  • Financial systems 
  • Cloud applications 
  • Remote access 
  • Administrative accounts 

It’s one of the simplest improvements an organization can make to strengthen cybersecurity. 

CSI Tech Corp helps nonprofit organizations deploy MFA across their entire environment, making implementation straightforward for employees while improving protection for critical systems.

  1. Endpoint protection installed on every device, including personal devices used for work 
  2. Full-disk encryption enabled on laptops 
  3. Consistent patch management schedule 
  4. E-Recycle retiring equipment 

Software updates aren’t just about new features; they often contain critical security patches that protect your organization from known vulnerabilities. Every nonprofit should have a process for updating:

  • Windows computers 
  • Macs 
  • Mobile devices 
  • Microsoft 365 applications 
  • Antivirus software 
  • Network equipment 

Managing updates across multiple devices can quickly become time-consuming, especially for organizations without dedicated IT staff. 

CSI Tech Corp provides proactive device management, patch management, endpoint monitoring, and ongoing maintenance through our Managed IT Services, helping nonprofits stay secure without disrupting daily operations. 

Request E-Recycling – CSI Tech Corp offers secure Electronic Recycling services, helping Minnesota organizations safely retire outdated technology through certified data destruction and environmentally responsible recycling practices. Before retiring equipment, it’s important to ensure data is securely removed and devices are disposed of responsibly. 

  1. Backups run automatically and are monitored for successful completion. 
  2. A written data retention and deletion policy 

Having backups is only half the equation. The real question is whether your organization can successfully recover its data when something goes wrong. 

Ask yourself: 

  • Are backups running automatically? 
  • Are copies stored securely off-site or in the cloud?
  • Have you tested restoring files recently? 
  • Are your Microsoft 365 emails and documents included? 

Many nonprofits assume cloud applications automatically protect everything. Unfortunately, that’s not always the case. A reliable backup strategy helps your organization recover from ransomware, accidental deletions, hardware failures, and other unexpected events. 

 

At CSI Tech Corp, we help nonprofits implement automated Backup & Disaster Recovery solutions that protect Microsoft 365, cloud data, and on-premises systems while regularly testing recovery to ensure everything works when it’s needed most.

  1. Annual (at minimum) phishing simulation for staff and key volunteers 
  2. Security basics included in new staff and volunteer onboarding 

Invest in your people with security awareness training. Employees and volunteers are often the first line of defense, which makes ongoing cybersecurity education essential. Regular training helps staff recognize: 

  • Phishing emails 
  • Fake login pages 
  • Business email scams 
  • Password best practices 
  • Safe file sharing

Short, practical training sessions throughout the year are often much more effective than a single annual presentation. 

CSI Tech Corp provides cybersecurity awareness training designed specifically for small businesses and nonprofits, helping organizations reduce risk through practical, easy-to-understand education.

  1. A simple, written incident response plan — who to call, in what order 
  2. Annual review of vendor and platform security practices 
  3. Cyber liability insurance in place and understood 

Review Your Cyber Insurance Requirements. Cyber insurance has become increasingly important for nonprofit organizations, but insurance providers are also raising their cybersecurity expectations. 

Many policies now require organizations to demonstrate security controls such as:

  • Multi-Factor Authentication 
  • Secure backups 
  • Endpoint protection 
  • Employee cybersecurity training 
  • Access controls 
  • Incident response planning 

Reviewing these requirements before your renewal can help avoid surprises and identify areas that may need improvement. 

CSI Tech Corp works with nonprofit organizations to evaluate their current IT environment, identify security gaps, and prepare for cyber insurance renewals through practical technology planning and IT consulting. 

 

How to Build a Security Culture on a Tight Budget 

  • Put security training on the calendar as a recurring event. 
  • Name an internal “security champion” — one person for reporting suspicious activity. 
  • Use free phishing-simulation tools to build muscle memory without a big spend. 
  • Write down your incident response plan in one page — who to call first (including your IT provider’s number); it matters more during an actual incident than a long formal policy. 
  • Get buy-in from your executive director and board — security culture starts at the top, even at a small nonprofit. 

Explore Free and Discounted Security Tools for Nonprofits

Nonprofit Page

Your Questions, Answered

Phishing, business email compromise (including donation-redirect fraud), and ransomware targeting donor or client databases are consistently the most common and most damaging threats nonprofits face. 

Some tools are free — password managers, CISA guidance, and Microsoft 365 Business Basic’s baseline protections — while more advanced tools like Defender for Business come through steep nonprofit discounts rather than being free outright. 

Keep it short and recurring: a brief phishing-awareness session during onboarding, plus an annual refresher and simulated phishing test, is enough to build habits without requiring a big-time commitment from volunteers. 

Minnesota law requires notifying affected individuals if certain personal information is exposed, and depending on the type of data involved, you may also need to notify funders, regulators, or your cyber insurance provider. Having an incident response plan in place before a breach happens makes this process far less chaotic. 

CSI Tech Corp has supported Minnesota nonprofits with security, compliance, and grant-funded technology since 2004, including free research into grants that can offset your security spending. Call (952) 928-1788 to talk about your organization’s specific risks.