Nonprofits, foundations, and associations
Cybersecurity for Nonprofits and Foundations
Cybersecurity for nonprofits means protecting donor records, online giving, and client data with a small IT budget and a changing cast of staff, volunteers, and board members. Invadel tests the systems that hold them at a fixed price, with a free retest and reports written for funders, boards, and insurers.






The stakes
Why nonprofits get tested differently
Attackers go after nonprofits for the same things they take from any business, plus some specific to the sector. Donor records hold names, addresses, giving history, and sometimes bank details. Finance staff release grant payments and vendor invoices on instructions that arrive by email. Advocacy, cultural, and faith-based groups can also draw state-sponsored attackers: in May 2024, CISA, the FBI, and partner agencies published joint guidance for civil society organizations facing exactly that.
Funders and partners ask as well. Recipients of federal awards, including subrecipients that receive federal money through a state or city agency, must take reasonable cybersecurity measures to safeguard information, including personally identifiable information, under 2 CFR 200.303(e). Card donations bring PCI DSS obligations, even when a payment provider hosts the form. New York’s SHIELD Act requires reasonable safeguards from any organization that owns or licenses residents’ private information in electronic form, and insurers ask about MFA and testing at renewal.
Vendor risk is real too. According to the SEC, the 2020 ransomware attack on Blackbaud, which sells donor data software to nonprofits, affected more than 13,000 customers, and the attacker took donor bank account information and Social Security numbers. Generic small business testing rarely covers the donor CRM, the donation form, or the volunteer and board accounts nobody offboards. A nonprofit test has to start where donor data and money actually move.
What we test
The systems attackers go after first
Donor CRM and fundraising data
Salesforce and other donor databases, tested for staff and volunteer roles with more access than they need, bulk exports anyone can run, and integrations that sync donors to email and payment tools.
Online giving and event pages
Donation forms, peer-to-peer fundraising pages, membership sales, and event ticketing on the website, tested for script injection on payment pages, outdated plugins, and donor account takeover.
Microsoft 365 or Google Workspace
The tenant most nonprofits run on, often licensed through a nonprofit program, tested for MFA coverage, shared mailboxes, forwarding rules, and external sharing of board and donor files.
Volunteer, board, and shared accounts
Logins handed to volunteers, interns, and board members, reviewed for shared passwords, accounts that outlive the role, and personal email addresses with access to sensitive folders.
Client and program systems
Case management and intake systems holding records for health, housing, education, and legal programs, tested for access between programs and exposure through reports and exports.
Finance staff and executives
Phishing, voice, and text campaigns built around real nonprofit workflows: a grant disbursement, a gala vendor invoice, or an urgent request that appears to come from the executive director.
Compliance
The frameworks that usually apply
Federal awards (2 CFR 200)
Section 200.303(e) of the Uniform Guidance requires recipients and subrecipients of federal awards to take reasonable cybersecurity and other measures to safeguard information, including protected personally identifiable information.
- PCI DSS
Card donations make you a merchant, with validation requirements that depend on transaction volume. Testing covers the donation pages and any system that touches card data.
- HIPAA
Security Rule evidence for nonprofit clinics, behavioral health programs, and human services agencies that are covered entities or business associates.
NY SHIELD Act
Reasonable administrative, technical, and physical safeguards for any person or business that owns or licenses computerized data including New York residents’ private information.
Services
What nonprofits usually buy
- From $3,600
Phishing Simulation & Social Engineering Testing
Phishing and social engineering campaigns that measure real-world human risk, with click and credential metrics by department, from $3,600.
- From $4,200
Microsoft 365 Security Assessment
A manual review of your Microsoft 365 or Google Workspace tenant: identity and MFA, mail security, sharing, and OAuth apps, plus an optional attack simulation. From $4,200.
- From $4,200
External Network Penetration Testing
Testing of your internet-facing perimeter, from exposed services and VPN gateways to mail and cloud edges, with a free retest, from $4,200.
- From $5,200
Web Application Penetration Testing
Manual testing of your web application across the OWASP Top 10, business logic, and all user roles, with a free retest included, from $5,200.
- From $1,500
Vulnerability Scanning Services
Managed scanning validated by an analyst, which cuts false positives down to real, ranked risk you can act on at once. From $1,500 per scan.
Funders and partners
Cybersecurity for nonprofits: who asks for evidence
Few nonprofits are required by a regulator to run a penetration test. The requests come from funders, payment providers, insurers, and partners, and each wants something slightly different.
Federal agencies and pass-through funders
- What they want to see
- Reasonable cybersecurity measures to safeguard information, including personally identifiable information, under 2 CFR 200.303(e)
- What an engagement provides
- An independent test of the systems holding program and client data, with findings ranked by severity and fixes retested
Card brands and payment providers
- What they want to see
- PCI DSS compliance for card donations, validated at a level set by transaction volume
- What an engagement provides
- Testing of donation pages and anything that touches card data. Our guide to PCI compliance levels explains which level applies.
Cyber insurers
- What they want to see
- MFA on email and remote access, backups, and security awareness training for staff and volunteers
- What an engagement provides
- A review of the email tenant and a phishing baseline across staff, with an attestation letter for the renewal
Health and government partners
- What they want to see
- HIPAA safeguards or contract security terms for the client data you hold
- What an engagement provides
- Testing of the case management system and the network behind it, with findings mapped to the HIPAA technical safeguards where they apply
Your board
- What they want to see
- A clear answer on whether donor and client data is protected
- What an engagement provides
- An executive summary written for the board and a technical report for your IT provider
Want a framework to organize the work? Implementation Group 1 of the CIS Controls is what CIS calls essential cyber hygiene, written for organizations with limited IT and security expertise.
How it runs
Typical engagements
Illustrative scopes for this industry, written to show what a test covers and what you walk away with.
They are not client stories; our anonymized engagements are on the case studies page.
Typical engagement
Human services agency renewing its cyber insurance
A human services nonprofit with a dozen program sites receives a renewal application asking about MFA, backups, and whether the network was tested in the last year. We review the Microsoft 365 tenant, run an external test of the remote access gateway, and send a phishing baseline to staff and program managers. Two volunteer accounts with access to client folders are found and closed. The executive director files the attestation letter with the broker, and the retest confirms the fixes.
Typical engagement
Museum relaunching online giving and membership
A museum moving membership sales and donations to a new website wants the pages tested before its year-end campaign. We test the donation and membership flows, the member account portal, and the integration that writes gifts into the donor CRM. A plugin that allows script injection on the checkout page is removed, and a staff role that can export the full donor file is narrowed. The development director launches the campaign with the retest on file.
Typical engagement
Foundation paying grants on email instructions
A private foundation whose staff wire grant payments on email instructions wants to know whether its approvals would survive a targeted attack. We run a phishing and voice campaign against finance staff, review the Microsoft 365 tenant for forwarding rules and MFA gaps, and test the grants portal where applicants upload budgets and bank details. The board receives a plain-language summary, and finance adopts a callback rule for every payment change.
FAQ
What nonprofit leaders ask
01Do nonprofits need penetration testing?
Few are required to by law, but many are asked: by insurers at renewal, by payment providers, by health and government partners, and by funders who expect reasonable safeguards for the data their grants pay to collect. A test is also the fastest way to find the exposed login or the forgotten volunteer account before an attacker does. If you have never tested anything, a validated vulnerability scan from $1,500 is a low-cost first look.
02How is nonprofit cybersecurity testing different from small business testing?
The techniques are the same, and so are the prices. The priorities differ. Nonprofits hold donor records and giving pages, program data collected for funders, and accounts shared with volunteers and board members, and the report usually has to satisfy a board and a funder rather than a customer. Our small business penetration testing page covers the general approach for small teams.
03Can grant funding pay for security testing?
Sometimes, but confirm before you budget on it. FEMA’s Nonprofit Security Grant Program, for nonprofits at high risk of terrorist or other extremist attack, listed cybersecurity measures alongside security planning and training among allowable costs in fiscal year 2025. Whether a penetration test qualifies depends on the current notice of funding opportunity and your state administering agency. For program and operating grants, ask your program officer whether security testing can be charged to the award.
04What should a nonprofit with a small budget test first?
Email, because it carries payment instructions and donor files, and it is the first thing an attacker phishes. A phishing campaign from $3,600 and a Microsoft 365 or Google Workspace security assessment from $4,200 cover the most common losses. Add an external test from $4,200 if staff connect remotely, and a web application test from $5,200 if you run your own donation or member portal. Each price is fixed in writing before work starts, the penetration tests include a free retest, and every starting price is listed on our pricing page.
05Do you test donor CRMs like Salesforce?
Yes. We test the roles, sharing rules, and integrations of donor CRMs from each staff and volunteer role, and look for bulk exports and connected apps with more access than they need. Organizations running Salesforce can scope a dedicated Salesforce penetration test. We test your configuration and customizations, not the vendor’s own platform.
06Are volunteer and board accounts really a risk?
They are the finding most specific to nonprofits. Volunteers, interns, and board members often receive access for one event or one term and keep it, sometimes on a personal email address or a shared password passed from one cohort to the next. We list every account that can reach donor, client, or finance data, check which ones belong to people who have left, and test whether MFA covers them. The fix is usually a joiner and leaver checklist tied to the volunteer coordinator’s roster.
07Do you work with nonprofits outside Manhattan?
Yes, at the same fixed prices. Email, web, and external testing run remotely, and internal tests run through a small device we ship to your office. We meet organizations in person across the five boroughs and in Westchester, and work with associations and nonprofits in Washington, DC remotely, with on-site visits by arrangement.
Get a fixed price for your organization’s scope
Tell us what needs testing. You get a written fixed price within one business day, with the compliance mapping your auditors and customers expect.
Prefer the full scoping questionnaire?Get a Fixed-Scope Quote
Tell us what you need tested. We reply within one business day.
Thanks, we've received your message.
We'll be in touch shortly.