A Cybersecurity Checklist for Nonprofits

Group of women engaged in a collaborative meeting at an office table with laptops.

Nonprofits often manage donor records, payment details, staff information, and community services with limited time and technology support. That makes simple, consistent safeguards especially important. You do not need a large IT department to reduce common risks. Start with this checklist: strengthen account access, secure devices, handle data carefully, and help staff recognize suspicious messages. Assign an owner to each task, record what you have completed, and revisit the checklist when your systems or team change.

Protect accounts and access

Turn on multifactor authentication for email, cloud storage, banking, donation platforms, and social media. It adds a second verification step if someone obtains a password. Begin with administrator and financial accounts, then extend it to all staff accounts. Use an authenticator app or security key where available, and store backup codes in a secure place that authorized staff can reach.

Use a password manager to create and store unique passwords. Give each person an individual account instead of sharing logins, and limit access to what each role requires. Remove access promptly when someone leaves or changes roles. Review administrator accounts regularly, and keep a current list of who can reset passwords or manage critical services.

Secure computers and phones

Enable automatic updates for operating systems, browsers, and common applications. Updates often address security weaknesses, so avoid postponing them indefinitely. Turn on device encryption, screen locks, and automatic locking after a short period of inactivity. Require a passcode or biometric unlock on organization-owned phones and tablets, especially those used to check email or access donor systems.

Keep antivirus or built-in security protection active, and remove software your organization no longer uses. Set up a way to locate and remotely erase organization devices if they are lost, when the device and service support it. For shared computers, use separate accounts and sign out of sensitive services after each session. Keep a simple inventory of devices, assigned users, and operating system versions.

Handle data with care

Decide what information you truly need to collect and how long you need to keep it. Limit access to donor, client, employee, and payment information to people with a clear work need. Avoid storing sensitive records in personal email accounts or unapproved file-sharing services. When a service provider stores information for you, review its access settings and security options before uploading records.

Back up important files and systems on a regular schedule, and make sure at least one backup cannot be changed or deleted through the everyday user account. Test restoring a file so you know the backup works. Write down who to contact if an account is compromised, a device goes missing, or information is sent to the wrong person. Include steps for preserving relevant records and notifying appropriate leaders.

Help staff spot risks

Teach staff and volunteers to pause before opening unexpected attachments, following urgent payment requests, or sharing login codes. Check the sender address and confirm unusual requests through a known phone number or another trusted channel. Attackers may imitate a familiar person or organization, so a convincing name alone does not prove a message is genuine.

Make reporting easy and blame-free. Tell everyone whom to contact when a message seems suspicious or they may have clicked a harmful link. Practice a short scenario, such as a fake password-reset message, and review what staff should do next. Keep instructions accessible, including for temporary staff and volunteers, and refresh them when your tools or procedures change.

Choose a few checklist items to complete first, then assign owners and set a date to review progress. A shared document can track account access, device updates, backups, and staff guidance without adding complex processes. Buffalo Cyber Commons can help your nonprofit assess priorities and build practical safeguards; contact the team to discuss your needs.