Skip to content

Nonprofits, foundations, and associations

Cybersecurity for Nonprofits and Foundations

Cybersecurity for nonprofits means protecting donor records, online giving, and client data with a small IT budget and a changing cast of staff, volunteers, and board members. Invadel tests the systems that hold them at a fixed price, with a free retest and reports written for funders, boards, and insurers.

Senior certified testers, manual-first185+ years combined experienceOnboarding within 24 hoursFree retest includedOur methodology
LatentPerygeeCity National BankAubaDesteiaDTCC

The stakes

Why nonprofits get tested differently

Attackers go after nonprofits for the same things they take from any business, plus some specific to the sector. Donor records hold names, addresses, giving history, and sometimes bank details. Finance staff release grant payments and vendor invoices on instructions that arrive by email. Advocacy, cultural, and faith-based groups can also draw state-sponsored attackers: in May 2024, CISA, the FBI, and partner agencies published joint guidance for civil society organizations facing exactly that.

Funders and partners ask as well. Recipients of federal awards, including subrecipients that receive federal money through a state or city agency, must take reasonable cybersecurity measures to safeguard information, including personally identifiable information, under 2 CFR 200.303(e). Card donations bring PCI DSS obligations, even when a payment provider hosts the form. New York’s SHIELD Act requires reasonable safeguards from any organization that owns or licenses residents’ private information in electronic form, and insurers ask about MFA and testing at renewal.

Vendor risk is real too. According to the SEC, the 2020 ransomware attack on Blackbaud, which sells donor data software to nonprofits, affected more than 13,000 customers, and the attacker took donor bank account information and Social Security numbers. Generic small business testing rarely covers the donor CRM, the donation form, or the volunteer and board accounts nobody offboards. A nonprofit test has to start where donor data and money actually move.

What we test

The systems attackers go after first

01

Donor CRM and fundraising data

Salesforce and other donor databases, tested for staff and volunteer roles with more access than they need, bulk exports anyone can run, and integrations that sync donors to email and payment tools.

02

Online giving and event pages

Donation forms, peer-to-peer fundraising pages, membership sales, and event ticketing on the website, tested for script injection on payment pages, outdated plugins, and donor account takeover.

03

Microsoft 365 or Google Workspace

The tenant most nonprofits run on, often licensed through a nonprofit program, tested for MFA coverage, shared mailboxes, forwarding rules, and external sharing of board and donor files.

04

Volunteer, board, and shared accounts

Logins handed to volunteers, interns, and board members, reviewed for shared passwords, accounts that outlive the role, and personal email addresses with access to sensitive folders.

05

Client and program systems

Case management and intake systems holding records for health, housing, education, and legal programs, tested for access between programs and exposure through reports and exports.

06

Finance staff and executives

Phishing, voice, and text campaigns built around real nonprofit workflows: a grant disbursement, a gala vendor invoice, or an urgent request that appears to come from the executive director.

Compliance

The frameworks that usually apply

  • Federal awards (2 CFR 200)

    Section 200.303(e) of the Uniform Guidance requires recipients and subrecipients of federal awards to take reasonable cybersecurity and other measures to safeguard information, including protected personally identifiable information.

  • PCI DSS

    Card donations make you a merchant, with validation requirements that depend on transaction volume. Testing covers the donation pages and any system that touches card data.

  • HIPAA

    Security Rule evidence for nonprofit clinics, behavioral health programs, and human services agencies that are covered entities or business associates.

  • NY SHIELD Act

    Reasonable administrative, technical, and physical safeguards for any person or business that owns or licenses computerized data including New York residents’ private information.

Services

What nonprofits usually buy

Funders and partners

Cybersecurity for nonprofits: who asks for evidence

Few nonprofits are required by a regulator to run a penetration test. The requests come from funders, payment providers, insurers, and partners, and each wants something slightly different.

Federal agencies and pass-through funders

What they want to see
Reasonable cybersecurity measures to safeguard information, including personally identifiable information, under 2 CFR 200.303(e)
What an engagement provides
An independent test of the systems holding program and client data, with findings ranked by severity and fixes retested

Card brands and payment providers

What they want to see
PCI DSS compliance for card donations, validated at a level set by transaction volume
What an engagement provides
Testing of donation pages and anything that touches card data. Our guide to PCI compliance levels explains which level applies.

Cyber insurers

What they want to see
MFA on email and remote access, backups, and security awareness training for staff and volunteers
What an engagement provides
A review of the email tenant and a phishing baseline across staff, with an attestation letter for the renewal

Health and government partners

What they want to see
HIPAA safeguards or contract security terms for the client data you hold
What an engagement provides
Testing of the case management system and the network behind it, with findings mapped to the HIPAA technical safeguards where they apply

Your board

What they want to see
A clear answer on whether donor and client data is protected
What an engagement provides
An executive summary written for the board and a technical report for your IT provider

Want a framework to organize the work? Implementation Group 1 of the CIS Controls is what CIS calls essential cyber hygiene, written for organizations with limited IT and security expertise.

How it runs

Typical engagements

Illustrative scopes for this industry, written to show what a test covers and what you walk away with. They are not client stories; our anonymized engagements are on the case studies page.

Typical engagement

Human services agency renewing its cyber insurance

A human services nonprofit with a dozen program sites receives a renewal application asking about MFA, backups, and whether the network was tested in the last year. We review the Microsoft 365 tenant, run an external test of the remote access gateway, and send a phishing baseline to staff and program managers. Two volunteer accounts with access to client folders are found and closed. The executive director files the attestation letter with the broker, and the retest confirms the fixes.

Typical engagement

Museum relaunching online giving and membership

A museum moving membership sales and donations to a new website wants the pages tested before its year-end campaign. We test the donation and membership flows, the member account portal, and the integration that writes gifts into the donor CRM. A plugin that allows script injection on the checkout page is removed, and a staff role that can export the full donor file is narrowed. The development director launches the campaign with the retest on file.

Typical engagement

Foundation paying grants on email instructions

A private foundation whose staff wire grant payments on email instructions wants to know whether its approvals would survive a targeted attack. We run a phishing and voice campaign against finance staff, review the Microsoft 365 tenant for forwarding rules and MFA gaps, and test the grants portal where applicants upload budgets and bank details. The board receives a plain-language summary, and finance adopts a callback rule for every payment change.

FAQ

What nonprofit leaders ask

01Do nonprofits need penetration testing?

Few are required to by law, but many are asked: by insurers at renewal, by payment providers, by health and government partners, and by funders who expect reasonable safeguards for the data their grants pay to collect. A test is also the fastest way to find the exposed login or the forgotten volunteer account before an attacker does. If you have never tested anything, a validated vulnerability scan from $1,500 is a low-cost first look.

02How is nonprofit cybersecurity testing different from small business testing?

The techniques are the same, and so are the prices. The priorities differ. Nonprofits hold donor records and giving pages, program data collected for funders, and accounts shared with volunteers and board members, and the report usually has to satisfy a board and a funder rather than a customer. Our small business penetration testing page covers the general approach for small teams.

03Can grant funding pay for security testing?

Sometimes, but confirm before you budget on it. FEMA’s Nonprofit Security Grant Program, for nonprofits at high risk of terrorist or other extremist attack, listed cybersecurity measures alongside security planning and training among allowable costs in fiscal year 2025. Whether a penetration test qualifies depends on the current notice of funding opportunity and your state administering agency. For program and operating grants, ask your program officer whether security testing can be charged to the award.

04What should a nonprofit with a small budget test first?

Email, because it carries payment instructions and donor files, and it is the first thing an attacker phishes. A phishing campaign from $3,600 and a Microsoft 365 or Google Workspace security assessment from $4,200 cover the most common losses. Add an external test from $4,200 if staff connect remotely, and a web application test from $5,200 if you run your own donation or member portal. Each price is fixed in writing before work starts, the penetration tests include a free retest, and every starting price is listed on our pricing page.

05Do you test donor CRMs like Salesforce?

Yes. We test the roles, sharing rules, and integrations of donor CRMs from each staff and volunteer role, and look for bulk exports and connected apps with more access than they need. Organizations running Salesforce can scope a dedicated Salesforce penetration test. We test your configuration and customizations, not the vendor’s own platform.

06Are volunteer and board accounts really a risk?

They are the finding most specific to nonprofits. Volunteers, interns, and board members often receive access for one event or one term and keep it, sometimes on a personal email address or a shared password passed from one cohort to the next. We list every account that can reach donor, client, or finance data, check which ones belong to people who have left, and test whether MFA covers them. The fix is usually a joiner and leaver checklist tied to the volunteer coordinator’s roster.

07Do you work with nonprofits outside Manhattan?

Yes, at the same fixed prices. Email, web, and external testing run remotely, and internal tests run through a small device we ship to your office. We meet organizations in person across the five boroughs and in Westchester, and work with associations and nonprofits in Washington, DC remotely, with on-site visits by arrangement.

Get a fixed price for your organization’s scope

Tell us what needs testing. You get a written fixed price within one business day, with the compliance mapping your auditors and customers expect.

Prefer the full scoping questionnaire? 

Get a Fixed-Scope Quote

Tell us what you need tested. We reply within one business day.