Nonprofit cybersecurity guide

The Complete Cybersecurity Checklist for Canadian Nonprofits

Nonprofits depend on trust. Donors, employees, volunteers, beneficiaries and community partners expect their information to be handled responsibly. Yet many organizations must protect that information with limited budgets, small internal teams and a constantly changing mix of users and devices.

This practical checklist will help your organization identify its most important cybersecurity gaps and build a realistic improvement plan.

Published by TEKYHOST  |  Canadian Managed IT & Cybersecurity Provider  |  Updated September 2026

Short on time? Begin with five priorities: require multi-factor authentication, remove unused accounts, protect every device, maintain tested backups and create a written incident-response plan. These basic measures can substantially reduce your exposure.

Cybersecurity is not only an IT issue. A successful attack can interrupt programs, prevent staff from communicating, expose donor information, redirect payments and damage the reputation an organization spent years building. Leadership should treat cyber risk as part of operational resilience and governance.

1. Assign responsibility for cybersecurity

Every nonprofit needs someone who is accountable for cybersecurity, even when day-to-day technical work is outsourced. That person does not need to be a full-time security specialist, but leadership and the board should know who owns decisions, receives reports and coordinates the response to an incident.

  • Name an internal cybersecurity and privacy lead.
  • Document which board committee or executive receives security updates.
  • Maintain a current inventory of users, devices, applications, vendors and important data.
  • Create written policies for acceptable use, remote work, passwords, data handling and AI tools.
  • Include cybersecurity in budgeting, strategic planning and risk-register discussions.
  • Review cyber-insurance requirements before renewal, not after completing the application.

2. Protect user accounts and identities

Stolen credentials are especially dangerous because an attacker can appear to be a legitimate employee or volunteer. Access should be based on each person's role, limited to what they require and removed promptly when the relationship ends.

  • Require multi-factor authentication (MFA) for email, Microsoft 365, cloud applications, finance systems and remote access.
  • Prefer phishing-resistant authentication, such as passkeys or security keys, for administrators and other high-risk roles.
  • Give every person an individual account; never share usernames and passwords.
  • Use a business password manager for unique, long passwords.
  • Separate administrative accounts from ordinary email and web-browsing accounts.
  • Apply least privilege so users only have the access needed for their work.
  • Review privileged accounts, guest users and external sharing at least quarterly.
  • Disable accounts immediately when employees, contractors or volunteers leave.
  • Block outdated authentication methods that do not support MFA.
High priority: MFA should protect every user, but finance, fundraising, leadership and administrator accounts should be reviewed first because they are attractive targets for impersonation and payment fraud.

3. Secure email and Microsoft 365

Email remains a common entry point for phishing, malicious attachments, account takeover and fraudulent payment requests. Microsoft 365 includes useful security capabilities, but licensing alone does not guarantee that they are configured correctly.

  • Configure MFA and risk-based access policies for Microsoft 365.
  • Enable email protection against phishing, malicious links, attachments and impersonation.
  • Configure SPF, DKIM and DMARC to reduce domain spoofing.
  • Restrict automatic forwarding to external addresses.
  • Alert on suspicious sign-ins, impossible travel, unusual inbox rules and privilege changes.
  • Review SharePoint, Teams and OneDrive sharing settings.
  • Use separate accounts and stronger controls for Microsoft 365 administrators.
  • Establish a process for independently verifying banking and payment-detail changes.
  • Determine whether your nonprofit is eligible for Microsoft nonprofit grants or discounts.

Eligible organizations may receive discounted Microsoft nonprofit solutions. The correct plan and configuration should be chosen around the organization's security, device-management and compliance needs—not price alone.

4. Protect computers, servers and mobile devices

A secure Microsoft 365 environment cannot compensate for an unpatched or unmanaged device. Every laptop, workstation and server that accesses organizational information should meet a consistent security standard, including personally owned devices where they are permitted.

  • Maintain an up-to-date inventory of computers, servers, phones and tablets.
  • Deploy centrally managed endpoint detection and response protection.
  • Apply operating-system and application security updates promptly.
  • Encrypt laptops and mobile devices.
  • Require screen locks and secure device sign-in.
  • Remove local administrator rights from routine user accounts.
  • Use mobile-device or application-management controls where sensitive information is accessed.
  • Replace unsupported operating systems, applications and network equipment.
  • Secure remote access with Zero Trust principles or a properly managed VPN.
  • Create a process for reporting and remotely securing lost or stolen devices.

5. Understand and protect sensitive information

Nonprofits may collect donor records, payment details, employee information, volunteer screening records, beneficiary information and, in some cases, health or other highly sensitive data. You cannot protect information effectively if you do not know where it is stored, who can access it or how long it is retained.

  • Identify what personal, financial, confidential and health-related information the organization holds.
  • Document where that information is stored, including cloud applications and staff devices.
  • Limit collection to information the organization genuinely needs.
  • Restrict access according to role and sensitivity.
  • Encrypt sensitive information in transit and at rest where appropriate.
  • Create retention and secure-destruction schedules.
  • Review public links, anonymous sharing and external guest access.
  • Prevent staff from entering confidential organizational information into unapproved AI services.
  • Identify the privacy laws, contracts and funding requirements that apply to your activities.
Canadian privacy note: PIPEDA applies to personal information handled during commercial activities and to certain cross-border situations. Provincial privacy laws and sector-specific rules may also apply. For example, nonprofits that provide healthcare or handle personal health information may have additional obligations. Obtain legal advice when determining your organization's exact requirements.

6. Maintain secure, tested backups

Backups help organizations recover from ransomware, accidental deletion, malicious insiders and service failures. Cloud retention and recycle bins are useful, but they are not always substitutes for an independent backup strategy.

  • Back up Microsoft 365 email, SharePoint, OneDrive and Teams data where required by your recovery needs.
  • Back up servers, databases, websites and line-of-business systems.
  • Keep at least one backup copy isolated from ordinary user and administrator accounts.
  • Protect backup administration with MFA and separate credentials.
  • Define recovery time and recovery point objectives for critical services.
  • Test restoration regularly and document the results.
  • Confirm who can initiate recovery and how the organization will operate during an outage.

A backup is only useful when it can be restored within the time your programs and operations can tolerate.

7. Train employees and volunteers

People are part of the security system. Training should be short, practical and repeated throughout the year. Volunteers, temporary workers and board members should not be excluded simply because they are not permanent employees.

  • Provide cybersecurity training during onboarding and at least annually.
  • Run ongoing phishing simulations and brief refresher exercises.
  • Teach users how to report suspicious messages without fear of blame.
  • Explain how to verify payment, banking and gift-card requests through a second channel.
  • Train users to handle donor and beneficiary information securely.
  • Provide practical rules for remote work, personal devices, file sharing and public Wi-Fi.
  • Create guidance for safe use of ChatGPT, Microsoft Copilot and other AI tools.

8. Manage technology vendors and cloud services

Your nonprofit may outsource IT, fundraising, payroll, communications, website management and payment processing, but it cannot outsource accountability for its information. Vendor access and security should be reviewed before contracts are signed and throughout the relationship.

  • Maintain a list of vendors that store, process or access organizational information.
  • Confirm what data each vendor holds and where it is stored.
  • Require MFA and individual accounts for vendor access.
  • Limit vendor permissions and remove access when work ends.
  • Review security, privacy, breach-notification, backup and data-return terms.
  • Ask critical providers about incident response, business continuity and independent assurance.
  • Avoid unsanctioned applications and free consumer tools for sensitive work.
  • Reassess important vendors at least annually.

9. Prepare an incident-response plan

During an incident, confusion costs time. A concise written plan gives leadership, staff and external partners a shared process for containing the threat, preserving evidence, communicating responsibly and restoring operations.

  • Document who must be contacted, including leadership, IT, legal counsel, insurance and communications support.
  • Define how employees and volunteers report a suspected incident.
  • Keep an offline copy of emergency contacts and response instructions.
  • Create procedures for compromised email, ransomware, lost devices and accidental disclosure.
  • Know how to disable accounts, revoke sessions and isolate affected devices quickly.
  • Preserve logs and evidence; avoid making uncoordinated changes that could destroy them.
  • Document regulatory, contractual and insurance-notification requirements.
  • Record decisions, actions and timelines throughout the incident.
  • Run a tabletop exercise with leadership at least annually.

Organizations subject to PIPEDA have breach reporting, notification and record-keeping responsibilities in specified circumstances. Your response plan should help the appropriate decision-makers assess those obligations promptly.

10. Review security throughout the year

Cybersecurity is not a one-time project. Staff change, new services are introduced, vulnerabilities are discovered and attackers adjust their methods. A manageable review schedule keeps security from becoming an emergency-only activity.

  • Review security alerts and backup results continuously.
  • Review user, guest and administrator access quarterly.
  • Review policies, vendors, insurance requirements and the incident plan annually.
  • Perform regular vulnerability scanning and remediate high-risk findings.
  • Arrange periodic independent security assessments and authorized penetration testing where appropriate.
  • Report key risks, improvements and unresolved decisions to leadership and the board.
  • Maintain a prioritized security roadmap tied to risk, budget and organizational objectives.

What should your nonprofit do first?

Do not wait until every item can be completed. Start with the controls that reduce the greatest risk: MFA, account cleanup, endpoint protection, reliable backups and incident readiness. Then work through the remaining gaps in a planned and measurable way.

The objective is not to buy every available security product. It is to establish a practical combination of people, processes and technology that protects the mission and fits the organization's resources.

Helpful Canadian resources

This article provides general cybersecurity information and is not legal, insurance or regulatory advice. Privacy and regulatory obligations depend on an organization's activities, jurisdiction, contracts and the information it handles. TEKYHOST provides cybersecurity and compliance-readiness services and does not provide legal opinions, formal certification or guaranteed regulatory compliance.

Scroll to Top