Managed Compliance & Cybersecurity for Nonprofits
Protect donor, employee, volunteer and beneficiary information without building an expensive internal cybersecurity or compliance team.
TEKYHOST helps Canadian nonprofits and charities assess cyber risk, strengthen security controls, organize policies and compliance evidence, and continuously monitor their security posture.
Privacy and regulatory requirements vary based on an organization's activities, location and the information it handles. TEKYHOST provides cybersecurity and compliance-readiness services and does not provide legal advice.
Cybersecurity and Compliance Shouldn't Take Resources Away From Your Mission
Nonprofits are responsible for large amounts of sensitive information but often operate with smaller IT teams and tighter budgets than commercial organizations.
Donor records, financial information, employee data, volunteer information, beneficiary records and Microsoft 365 accounts can all become targets for cybercriminals.
TEKYHOST provides a managed approach that combines compliance management with practical cybersecurity so your organization can strengthen protection without creating another full-time internal role.
Nonprofits Hold More Sensitive Information Than Many Realize
Donor Information
Names, contact information, donation history and financial records may all require appropriate protection.
Employee & Volunteer Data
HR files, payroll information, identity documents and confidential internal records can be highly sensitive.
Beneficiary Information
Organizations delivering community, social or humanitarian services may hold particularly sensitive personal information.
Financial Systems
Online donations, banking information and payment systems create additional cybersecurity and fraud risks.
Give Your Board, Funders and Partners Confidence in Your Security Program
Cybersecurity is increasingly a governance issue rather than simply an IT issue.
Boards, funding organizations, insurers, business partners and stakeholders may want evidence that your nonprofit has appropriate security controls and a process for managing risk.
TEKYHOST helps turn technical security information into organized risks, controls, evidence and actionable reporting that leadership can understand.
We can help organizations maintain:
- Cybersecurity risk register
- Security policies and procedures
- Compliance evidence
- Remediation plans
- Incident response documentation
- Business continuity planning
- Vendor risk information
- Executive and board-level security reporting
Compliance Backed by Real Cybersecurity Controls
TEKYHOST evaluates and helps manage the technical controls that protect your organization's users, systems and information.
Identity & Access
- Multi-factor authentication
- Administrative accounts
- Conditional Access
- User access reviews
- Account provisioning
- Employee and volunteer offboarding
Microsoft 365 Security
- Microsoft Entra ID
- Exchange Online security
- SharePoint and OneDrive
- External sharing
- Guest access
- Security configuration review
Endpoint Protection
- Endpoint detection and response
- Patch management
- Disk encryption
- Device security posture
- Local administrator controls
- Threat monitoring
Email & Phishing Protection
- Advanced email protection
- Phishing protection
- DMARC, DKIM and SPF
- Account compromise detection
- Security awareness training
- Phishing simulations
Cloud & Infrastructure
- AWS and Azure security
- Firewall controls
- Secure remote access
- Zero Trust controls
- Cloud configuration review
- Logging and monitoring
Backup & Recovery
- Microsoft 365 backup
- Cloud and server backup
- Recovery testing
- Ransomware resilience
- Retention controls
- Business continuity readiness
Know What Information You Have — and Protect It Appropriately
Privacy requirements can differ based on your organization's activities and jurisdiction, but every nonprofit benefits from knowing what personal information it holds, who can access it, where it is stored and how long it should be retained.
TEKYHOST helps organizations assess the cybersecurity controls supporting their privacy management practices.
- Personal information inventory
- Access-control review
- Data retention considerations
- Secure sharing controls
- Third-party access
- Employee and volunteer access
- Security safeguards
- Incident and breach readiness
Not every Canadian nonprofit is automatically subject to PIPEDA.
Applicable privacy requirements depend on factors including commercial activities, jurisdiction and the type of information being handled. Regardless of legal applicability, recognized privacy and security practices can help nonprofits reduce risk and demonstrate responsible stewardship of personal information.
Turn Security Practices Into a Documented Program
Good cybersecurity requires both technology and repeatable organizational processes.
Security Governance
- Information security policies
- Acceptable use policies
- Access-control procedures
- Security responsibilities
Incident Preparedness
- Incident response plan
- Breach response procedures
- Emergency communications plan
- Cybersecurity escalation procedures
Risk Management
- Risk register
- Vendor risk tracking
- Remediation tracking
- Business continuity planning
Build Your Program Around Recognized Security Standards
TEKYHOST can help organize your nonprofit's cybersecurity controls, risks and evidence around established security frameworks and applicable requirements.
Applicable privacy laws and compliance obligations depend on the organization, jurisdiction and activities involved. TEKYHOST provides cybersecurity and compliance-readiness services and does not provide legal advice.
Manage the Growing Risk of Shadow AI
Staff and volunteers may already be using ChatGPT, Microsoft Copilot and other generative AI applications with organizational information.
TEKYHOST helps nonprofits adopt AI securely by identifying unauthorized AI usage, improving data controls and establishing practical AI governance policies.
- Shadow AI visibility
- Approved AI application policies
- Microsoft Copilot security readiness
- Sensitive information protection
- Data access reviews
- AI usage policies
- User awareness and training
- Multi-factor authentication verification
- Endpoint protection review
- Email security controls
- Backup and recovery controls
- Privileged access controls
- Security awareness training
- Incident response readiness
Be Better Prepared for Cyber Insurance Reviews
Cyber insurance applications increasingly ask detailed questions about cybersecurity safeguards.
TEKYHOST can help verify the technical controls behind your organization's answers and identify gaps that should be addressed before renewal.
Don't Let Compliance Become an Annual Spreadsheet Exercise
Employees leave. Volunteers change. New applications are added. Microsoft 365 settings change. Cybersecurity requirements evolve.
TEKYHOST helps continuously track security controls, compliance evidence, risks and outstanding remediation work.
Automated Evidence Collection
Where supported, collect technical security evidence directly from Microsoft 365 and cloud platforms.
Continuous Security Monitoring
Monitor users, identities, endpoints, email and cloud systems for security weaknesses and changes.
Risk & Remediation Tracking
Keep identified gaps visible, prioritized and tracked until they are addressed.
A Practical Managed Compliance Process
Assess
Understand your environment, risks, information and compliance objectives.
Identify Gaps
Identify missing technical, policy and operational controls.
Prioritize
Build a realistic roadmap based on risk, budget and organizational priorities.
Remediate
TEKYHOST helps implement and improve the underlying cybersecurity controls.
Document
Organize policies, evidence, risks and remediation activities.
Monitor
Continue reviewing changes and security posture throughout the year.
One Partner for IT, Cybersecurity and Compliance
A compliance assessment is much more useful when the same organization can help resolve the technical issues it identifies.
TEKYHOST combines managed IT, Microsoft 365, cloud, cybersecurity and compliance management so nonprofits can reduce vendor complexity and work with a single technology partner.
- 30+ years of IT and security experience
- Canadian managed IT and cybersecurity team
- Experience supporting nonprofit organizations
- Microsoft 365 and Entra expertise
- AWS and cloud security expertise
- Managed endpoint and email security
- Zero Trust and secure remote access
- AI security and Shadow AI governance
- Compliance assessment and monitoring
- Hands-on technical remediation
Do You Know Where Your Organization's Biggest Cybersecurity Risks Are?
TEKYHOST can review your Microsoft 365 environment, cybersecurity controls, policies and compliance objectives and help build a practical roadmap that fits your nonprofit's resources and priorities.
