NONPROFIT CYBER GOVERNANCE
Nonprofit Board Cybersecurity: Questions Directors Should Ask
A nonprofit board does not need to configure security tools. It does need enough visibility to understand material cyber risk, confirm that someone owns it, and ensure the organization can protect its mission, people, funds, and sensitive information.
Cybersecurity is mission oversight
A cyber incident can interrupt programs, redirect donations, expose beneficiary or employee information, damage relationships, and consume funds meant for the mission. This makes cybersecurity more than an IT issue. It is connected to continuity, financial stewardship, privacy, reputation, and organizational resilience.
Board oversight should be risk-based and proportionate. The goal is not to eliminate every possible threat. It is to understand the most consequential scenarios, ensure reasonable safeguards exist, and make deliberate decisions about residual risk.
Who owns cyber risk?
The board should know which executive is accountable for cybersecurity and how technology providers, staff, and outside specialists support that person. Outsourced IT can operate systems, but leadership still owns business decisions about access, data, recovery priorities, vendors, and incident response.
Ask how often cyber risk reaches leadership, what information is reported, and who has authority during an incident. If responsibility is spread across several vendors with no internal owner, that is itself a governance gap.
What information and services matter most?
Request a plain-language inventory of the organization’s most important data, accounts, systems, and services. This may include donor records, beneficiary information, employee data, grants, payment platforms, email, file storage, fundraising systems, and program-delivery tools. The board should understand which operations cannot be unavailable and for how long.
Also ask what information the organization collects but no longer needs. Reducing unnecessary data can lower exposure and simplify response obligations.
Are identity and money protected?
Confirm that multifactor authentication protects email, financial systems, cloud administration, remote access, and other critical services. Ask whether privileged access is limited, former-worker access is removed quickly, and account recovery belongs to the organization rather than one employee or vendor.
Financial procedures should independently verify new payees, bank-detail changes, payroll changes, and unusual transfers. A strong technology control cannot compensate for a process that allows one convincing email to move funds.
Can the organization recover?
The board should ask when backups were last restored successfully, how critical services would operate during an outage, and who would make time-sensitive decisions. A written incident plan should include current contacts for leadership, IT, legal counsel, cyber insurance, banks, communications, and relevant authorities.
At least annually, leadership and the board should walk through a realistic scenario such as ransomware, payment fraud, a lost device, or donor-data exposure. A short tabletop often reveals unclear authority and missing contact information more effectively than a lengthy policy review.
How should vendors be governed?
Nonprofits often depend on managed IT, cloud applications, payment processors, fundraising tools, and consultants. Ask which vendors can access sensitive information or critical systems, what security expectations appear in contracts, how incidents must be reported, and how access and data are removed when the relationship ends.
Vendor branding is not evidence of correct configuration. Leadership should know which party is responsible for multifactor authentication, backups, logging, retention, incident notification, and recovery.
What should a useful board report contain?
Keep reporting short and decision-oriented. Useful measures include critical accounts protected by multifactor authentication, overdue high-priority updates, backup restoration results, completion of access reviews, time to remove former-worker access, significant vendor risks, incident trends, and progress against an approved improvement plan.
A dashboard should explain changes, obstacles, and decisions—not create the appearance of certainty with a single score. The board should be told when a major safeguard is missing, an accepted risk has changed, or budget and staffing prevent an important improvement.
Budget according to mission impact
Ask management to connect proposed spending to specific business risks and outcomes. Priority commonly belongs to protected identity, reliable devices, tested recovery, safe payment processes, prompt offboarding, employee reporting, vendor visibility, and incident readiness. Buying more tools is not automatically the same as reducing risk.
Document and revisit decisions
Record significant cyber-risk discussions, assigned actions, accepted risks, and follow-up dates in an appropriate governance record. Revisit the program after material technology changes, new services, major vendors, incidents, or changes in legal and insurance requirements.
This article provides general educational information, not legal advice. Duties differ by organization and jurisdiction; boards should seek qualified legal, insurance, privacy, and technical guidance for their circumstances.
Authoritative resources
The National Council of Nonprofits recommends a risk-based approach and points nonprofits to the NIST Cybersecurity Framework. CISA’s Cyber Essentials offers a leadership-oriented starting point.
GOVERNANCE WITHOUT THE TECHNICAL FOG
Give the board a clear view of cyber risk and priorities.
Cyber Valet provides nationwide remote assessments and practical guidance designed for nonprofits with real missions, limited time, and complex responsibilities.