Great Plains NetworkingGreat Plains NetworkingGet Support

Nonprofit Cybersecurity Checklist 2026: 15 Controls That Matter

Discover the nonprofit cybersecurity checklist 2026. Protect donor data and meet regulatory requirements with 15 essential controls for your organization.

11 min readBy Great Plains Networking
Nonprofit Cybersecurity Checklist 2026: 15 Controls That Matter — Great Plains Networking
nonprofit cybersecurity checklist 2026

Nonprofit Cybersecurity Checklist 2026: 15 Controls That Matter

Woman reviewing nonprofit cybersecurity checklist at table
Woman reviewing nonprofit cybersecurity checklist at table

A nonprofit cybersecurity checklist is a set of verifiable security controls that protect donor data, meet regulatory requirements, and keep your organization operational after an attack. The 15 foundational controls recommended by security experts cover everything from multi-factor authentication (MFA) to incident response planning. Regulatory frameworks including HIPAA, PCI DSS, and state breach notification laws now apply directly to most nonprofits. Donor trust is your most valuable asset, and a documented, tested security program is the clearest way to protect it. This nonprofit cybersecurity checklist 2026 gives you a prioritized, plain-language path to get there.

1. What does a nonprofit cybersecurity checklist 2026 cover?

The checklist covers three categories: technical controls, access management, and organizational policy. Technical controls stop attacks at the system level. Access management limits who can reach sensitive data. Policy and compliance work keeps your program legally sound and audit-ready. Together, these three layers address the full range of cyber risks for charities that security teams document year after year.

Two professionals reviewing cybersecurity controls chart
Two professionals reviewing cybersecurity controls chart

2. Enable MFA on every privileged and email account

MFA is the single highest-impact control a nonprofit can implement. It blocks the vast majority of credential-based attacks, which remain the leading entry point for ransomware. Every email account, admin login, and cloud platform must require MFA. No exceptions for executives or board members.

Pro Tip: Use an authenticator app like Microsoft Authenticator or Google Authenticator rather than SMS codes. SMS-based MFA is vulnerable to SIM-swapping attacks.

3. Apply software patches within 30 days

Patch management within 30 days is the standard cadence security experts recommend for nonprofits. Unpatched software is the second most common attack vector after stolen credentials. This applies to operating systems, browsers, plugins, and any software that touches donor or financial data. Automate updates wherever possible and document exceptions.

Platforms like Microsoft 365 include built-in update management tools. Use them. If your team runs a mix of Windows and Mac devices, a managed IT provider can enforce patch compliance across all endpoints from a single console.

4. Deploy endpoint protection on all devices

Every device that accesses organizational data needs endpoint protection software installed and actively monitored. This includes staff laptops, volunteer devices used for organizational work, and any mobile phones with access to email or donor records. Endpoint protection catches malware that gets past email filters.

The standard for 2026 is endpoint detection and response (EDR), not legacy antivirus. EDR tools monitor behavior in real time and can isolate a compromised device before an attacker moves laterally through your network.

5. Run encrypted, daily off-site backups and test them quarterly

Daily encrypted backups stored off-site are non-negotiable for nonprofit data protection. A backup that has never been tested is a hypothesis, not a recovery plan. Quarterly restoration tests verify that your data is actually recoverable and that your recovery time objective (RTO) is realistic. Store at least one backup copy in a location physically separate from your primary systems.

Pro Tip: Follow the 3-2-1 rule: three copies of data, on two different media types, with one stored off-site. Cloud backup counts as off-site only if it is a separate account from your primary cloud environment.

6. Authenticate your email with DMARC, DKIM, and SPF

Email authentication records, specifically DMARC, DKIM, and SPF, prevent attackers from spoofing your domain to send phishing emails that appear to come from your organization. Without these records, a scammer can impersonate your executive director and request a wire transfer from your finance team. Setting up all three records takes less than an hour with DNS access and costs nothing.

A DMARC policy set to "reject" gives you the strongest protection. Start with "none" to monitor traffic, then move to "quarantine" and finally "reject" over 60–90 days as you verify legitimate senders.

7. Limit admin access to two named individuals

Administrative access to your systems, cloud platforms, and donor database should belong to no more than two named individuals at any time. This limits the blast radius of a compromised account and makes access reviews manageable. Leadership transitions are the highest-risk moments for administrative access oversights. Document who holds admin rights and review that list every quarter.

8. Conduct quarterly access reviews

Quarterly access reviews verify that every user account still needs the permissions it has. Staff roles change, volunteers cycle in and out, and software subscriptions accumulate over time. An access review catches accounts that should have been deactivated months ago. Build a simple spreadsheet that lists every user, their role, and their access level, then review it with your IT lead each quarter.

9. Revoke all access within 24 hours of departure

Offboarding gaps are one of the most common and most preventable security failures in nonprofits. When a staff member or volunteer leaves, every account must be disabled within 24 hours. This includes primary email, shared folders, cloud storage, donor management platforms, and any secondary accounts they created on behalf of the organization. A written offboarding checklist prevents items from being missed under time pressure.

10. Train staff and volunteers on phishing annually

Annual phishing awareness training is a baseline requirement, not a nice-to-have. Volunteers and part-time staff are often the weakest link because they receive less organizational context than full-time employees. Simulated phishing exercises, where you send a fake phishing email and track who clicks, are the most effective training format. Staff who click on simulated phishing should receive immediate, non-punitive coaching.

Read more about why training matters for nonprofit teams specifically, including how to structure it for mixed volunteer and staff groups.

Pro Tip: Update your passphrase policy to align with NIST SP 800-63B. Passphrases of four or more random words are more secure and easier for staff to remember than complex strings of characters.

11. Document and practice your incident response plan

An incident response plan that lives in a shared drive and has never been rehearsed will fail when you need it most. At least two trained staff members must be able to execute the plan without looking up instructions. The plan should define who declares an incident, who contacts law enforcement or legal counsel, and who notifies affected donors. Test it with a tabletop exercise at least once per year.

12. Review vendor security before granting data access

Every vendor with access to your donor data, payment systems, or internal network is a potential attack vector. Require vendors to complete a security questionnaire before onboarding and review their answers annually. Ask specifically about their data encryption practices, breach notification timelines, and subcontractor relationships. A vendor breach can trigger your own notification obligations even if your systems were never directly compromised.

13. Align your audit program with NIST CSF or CIS Controls

NIST CSF 2.0 added a governance function in its latest update, making it more relevant for nonprofits with board-level security accountability. CIS Controls v8 offers an implementation group structure that maps well to small organizations with limited IT staff. Pick one framework and use it consistently. Annual self-assessments against your chosen framework give you a documented baseline and show auditors that your program is structured and intentional.

Avoid compliance drift, the common pattern where policies are written once and never updated. Schedule a policy review every 12 months and assign a named owner to each document.

14. Understand your regulatory obligations: HIPAA, PCI DSS, and state laws

Nonprofits that handle health data, such as those running clinics or wellness programs, fall under HIPAA and must implement a full security rule compliance program. Nonprofits that accept card donations must meet PCI DSS requirements. Fully hosted payment pages reduce your PCI scope to the simplest self-assessment questionnaire, SAQ A, which is the most practical option for most nonprofits.

State breach notification laws apply based on where your donors live, not where your organization is incorporated. If you collect data from residents of California, Colorado, or Virginia, their state privacy laws apply to you. Oklahoma nonprofits should review the state breach notification requirements that took effect for organizations of all sizes.

15. Review cyber liability insurance every 24 months

Cyber liability insurance must be reviewed every 24 months to keep pace with evolving threats and coverage gaps. Ransomware and social engineering attacks are now standard policy exclusions unless specifically included. Confirm that your policy covers business interruption, data recovery costs, and regulatory fines. Bring your IT provider into the review process so your documented controls match what your insurer expects.


Key Takeaways

A nonprofit cybersecurity program built on verified technical controls, disciplined access management, and documented policy is the most reliable defense against data loss and donor trust damage in 2026.

PointDetails
MFA is the top priorityEnable MFA on all email and admin accounts before addressing any other control.
Offboarding is a critical gapRevoke all access within 24 hours of departure, including secondary accounts and shared folders.
Compliance drift undermines programsAssign named policy owners and schedule annual reviews to keep documentation current.
Regulatory scope follows donor geographyState privacy laws apply based on where donors live, not where your nonprofit is based.
Insurance must match your riskReview cyber liability coverage every 24 months and confirm ransomware and social engineering are included.

What I've learned working with nonprofits on cybersecurity

The most common failure I see is not a technical one. It is the assumption that cybersecurity is an IT problem rather than a leadership problem. Boards approve budgets and set organizational priorities. When leadership does not treat security as a standing agenda item, policies go unreviewed, training gets skipped, and offboarding checklists get ignored under the pressure of a busy transition.

The second pattern is compliance drift. A nonprofit will do excellent work building a security program, document everything carefully, and then let those documents sit untouched for three years. The threat environment changes. Staff turns over. New platforms get adopted. The documented policies no longer reflect reality, and the organization fails its next audit not because it lacks controls but because it lacks discipline.

Donor trust is the real motivator here. Regulatory compliance sets a floor, not a ceiling. The nonprofits that handle security well treat it as a stewardship obligation to the people who fund their mission. That framing changes how leadership engages with it. For practical guidance on where to start, the nonprofit IT support best practices resource covers the leadership accountability piece in detail.

— Nicholas


How Greatplainsnetworking helps nonprofits stay secure

Greatplainsnetworking provides managed IT support tailored for nonprofits and small organizations in Norman, Moore, and Oklahoma City. The team handles patch management, endpoint protection, encrypted backups, and 24/7 monitoring so your staff can focus on your mission rather than your firewall.

https://greatplainsnetworking.com
https://greatplainsnetworking.com

If your organization is working through this checklist and needs a professional assessment, Greatplainsnetworking offers a customized nonprofit cybersecurity review with no long-term contract required. The cybersecurity services include incident response planning, access reviews, and compliance mapping for HIPAA and PCI DSS. Same-day response and plain-language reporting are standard. Schedule a consultation to find out exactly where your program stands.


FAQ

What is a nonprofit cybersecurity checklist?

A nonprofit cybersecurity checklist is a structured list of verifiable security controls covering technical safeguards, access management, and organizational policy. Experts recommend at least 15 foundational controls as a baseline for 2026.

Does HIPAA apply to nonprofits?

HIPAA applies to any organization that handles protected health information, including nonprofits running health programs, clinics, or employee wellness initiatives. Covered nonprofits must implement the full HIPAA Security Rule.

How often should nonprofits review their cybersecurity policies?

Security policies should be reviewed at least annually, with cyber liability insurance reviewed every 24 months. Quarterly access reviews and patch compliance checks are separate, ongoing requirements.

What is compliance drift and why does it matter?

Compliance drift occurs when documented security policies are not updated or made accessible to staff, reducing their effectiveness during audits and incidents. It is one of the most common reasons nonprofits fail security assessments despite having written policies.

Do state data breach laws apply to nonprofits?

State breach notification laws apply to nonprofits that collect personal information from residents of those states, regardless of where the nonprofit is incorporated. Notification timelines and requirements vary by state.

Recommended

Free Network Assessment

Want help putting this into practice?

We'll audit your security, speed, and hardware in under an hour — no commitment, no sales pitch. Just a clear roadmap of what to fix and why.