You Don’t Need a Large IT Department to Reduce Your Risk
Cybersecurity can sound like an issue for banks, hospitals, governments, and large corporations.
But small nonprofits have something cybercriminals value too: information.
Organizations may maintain donor records, employee information, financial accounts, email systems, program records, and—in organizations serving people with disabilities—potentially sensitive information about the people and families they serve.
The good news is that improving cybersecurity doesn’t necessarily require a huge technology budget. Some of the most important protections are relatively straightforward.
Here are five places to start.
1. Turn On Multi-Factor Authentication
If your organization makes only one cybersecurity improvement this month, make it multi-factor authentication, commonly called MFA.
MFA requires an additional form of verification beyond a password when someone signs into an account.
Prioritize MFA for:
- Banking and financial systems
- Payroll
- Cloud storage
- Donor databases
- Social media
- Website administration
- Any system containing sensitive information
A stolen password is much less useful to a criminal when another form of authentication is required.
2. Take Passwords Seriously
Using the same password across multiple systems creates unnecessary risk. If one account is compromised, criminals may try those same credentials elsewhere.
Encourage employees to use unique, strong passwords and consider an organizational password manager rather than storing passwords in spreadsheets, documents, notebooks, or email.
Shared accounts should also be minimized. Whenever practical, employees should have individual accounts so access can be controlled and removed when necessary.
3. Train Everyone to Recognize Phishing
Cybersecurity isn’t only an IT responsibility.
An employee receiving a convincing email that appears to come from an executive director, board member, vendor, or colleague may be the doorway into your organization.
Build a simple habit:
Stop. Look. Verify.
Before clicking an unexpected link, opening an attachment, changing payment instructions, buying gift cards, or sending sensitive information, verify unusual requests through another communication method.
Creating a culture where employees feel comfortable questioning a suspicious message is one of the simplest defenses an organization can build.
4. Back Up What You Can’t Afford to Lose
Ask a simple question:
If our systems became unavailable tomorrow, what information would we need to continue operating?
Identify those files and systems and make sure they are backed up.
But don’t stop there. A backup only helps if it can actually be restored.
Periodically test your backups and consider maintaining a copy that is separate from your primary network or systems. That can be particularly important if ransomware or another attack affects your primary files.
5. Have an “Employee Leaves Tomorrow” Checklist
Access management is easy to overlook in small organizations, especially when employees wear many hats.
When someone leaves, your organization should know how to quickly remove access to:
- Shared drives
- Financial systems
- Donor or client databases
- Social media accounts
- Website administration
- Cloud applications
- Building or remote-access systems
The same principle applies to vendors and contractors. People should have access only to the systems they need—and only for as long as they need them.
One More Step: Know Who You Would Call
Don’t wait for a cybersecurity incident to decide what to do.
Create a simple one-page response sheet identifying:
- Your IT provider or technology contact
- Insurance contact
- Bank contact
- Key organizational decision-makers
- Systems containing critical information
- Where backups are located
- Who has authority to shut down or secure compromised accounts
Keep a copy somewhere accessible even if your normal computer systems are unavailable.
Start Small. Start Now.
Cybersecurity doesn’t have to begin with an expensive technology project.
Turn on MFA. Improve passwords. Teach employees to recognize suspicious messages. Verify your backups. Review who has access to your systems.
Five relatively simple actions can make your nonprofit a much harder target—and help protect the information, resources, and trust that allow you to carry out your mission.