Security

IT security for nonprofits: protecting your donors' and members' data

2 min read Guillaume Duveau

Donor and member data held by nonprofits is a genuine target for cyber attackers; protecting it takes concrete measures, not just good intentions.

A treasurer at a humanitarian nonprofit receives an email that appears to come from a government agency, asking him to send a file with donor bank details. The logo looks right, the tone is official. He complies. Three days later, fraudulent transactions start appearing. It was a targeted phishing attack, and it worked because nobody was prepared.

This kind of incident happens regularly in the nonprofit sector. Nonprofits are not random targets: they hold sensitive data and often lack the protections that businesses have put in place.

Why nonprofits are targets

Cyber criminals do not choose their victims by size or budget. They look for the easiest route to exploitable data. A nonprofit with 500 members, their contact and banking details, and no multi-factor authentication or tested backups is an easier target than a well-protected SME.

The data nonprofits hold is genuinely valuable: full contact records, bank details for recurring donations, sometimes medical or social data for frontline organisations. A breach directly exposes your donors and can trigger a regulatory investigation.

The most common attacks

Phishing is still the most frequent threat. Messages are increasingly convincing, sometimes personalised using details from your public communications. Treasurers and directors are particularly targeted, because they have access to bank accounts.

Ransomware encrypts all your data and demands payment to restore it. For a nonprofit without tested backups, this can mean losing years of records.

Both attacks exploit human and organisational weaknesses as much as technical ones.

Practical measures to put in place

Multi-factor authentication on every account: email, collaboration tools, banking access. This single measure gives the best protection-to-effort ratio available. A stolen password is no longer enough to take control of an account.

Regular, tested backups. An untested backup is not a backup. At minimum, keep a copy offsite and verify regularly that restoration actually works.

Access controls. Each volunteer or staff member should only be able to access the data they need for their role. A communications volunteer does not need to see the full donor list with amounts.

Staff training. One hour of awareness training per year significantly reduces phishing risk. Teach your team to check sender addresses carefully, to never transmit sensitive data by email without a phone confirmation, and to report suspicious messages.

What the law requires

You are responsible for the data you collect. In the event of a breach, you must notify the relevant authority within 72 hours and inform the individuals affected. In the most serious cases, penalties can reach 4% of annual turnover. This isn’t meant to frighten you; it is simply the legal reality you are responsible for. Beyond the legal risk, a donor data breach destroys trust that took years to build.

To find out how InfraPro supports nonprofits with IT security, visit /en/nonprofits/.

Frequently asked

Why are nonprofits targeted by cyberattacks?
Because they hold sensitive data, such as donor bank details and member records, and often have fewer protections in place than businesses. Attackers look for the easiest path, not the most profitable target.
What is a phishing attack and how can nonprofits defend against it?
A fraudulent email that impersonates a trusted partner or authority to extract information or trigger a payment. Protection comes from staff training, double-checking sensitive requests by phone, and multi-factor authentication on all accounts.
Are nonprofits subject to data protection law?
Yes, in full. Any organisation that processes personal data, whether members, donors or beneficiaries, is bound by the same obligations, financial penalties included. What matters most, though, is protecting information people have entrusted to you, and the trust that comes with it.
What are the minimum security measures a nonprofit should have?
Multi-factor authentication on all accounts, regular tested backups, staff training on phishing recognition, and access controls so each person only sees the data they genuinely need.
What should a nonprofit do after a security incident?
Isolate the affected systems, contact your IT provider immediately, notify the relevant data protection authority within 72 hours if personal data is involved, and inform the people whose data was compromised.

In their words

Since InfraPro started managing our IT, we've reached a new stage in our growth.
Claudia Giampietri — Director, HFHPNon-profit

Let's talk.

Book a call