Nonprofit Cybersecurity Risk Assessment Explained for 2026

A nonprofit cybersecurity risk assessment is a structured process that identifies, evaluates, and prioritizes cybersecurity threats to protect donor data and organizational operations. The industry standard term for this process is a cybersecurity risk assessment, and it follows the same core methodology used by commercial organizations. What makes it distinct for nonprofits is the combination of limited IT staff, high-value donor data, and a public trust obligation that commercial businesses rarely face. Frameworks like the NIST Cybersecurity Framework (NIST CSF) and CIS Controls give nonprofits a proven structure to work from, even with constrained budgets. Getting this process right is not optional. Nonprofits face an average of 19 cyber incidents per year, matching the threat volume faced by commercial organizations.

What are the key steps in a nonprofit cybersecurity risk assessment?
A nonprofit security evaluation follows five core steps: asset inventory, threat identification, vulnerability analysis, risk evaluation, and mitigation planning. Each step builds on the last, and skipping one creates blind spots that attackers exploit.
1. Asset inventory. List every system that stores or processes sensitive data. This includes donor databases, email platforms, cloud storage, and any third-party software your organization uses for fundraising or case management.

2. Threat identification. Map the realistic threats to each asset. For nonprofits, the most common threats are phishing emails targeting staff, ransomware, and donor impersonation scams that exploit your public-facing domain.
3. Vulnerability analysis. Identify weaknesses in each asset. Common findings include unpatched software, shared passwords, and missing multi-factor authentication (MFA) on email and financial accounts.
4. Risk evaluation. Score each vulnerability by likelihood and impact. A donor database with no MFA and an unpatched operating system scores high on both dimensions. That combination moves it to the top of your remediation list.
5. Mitigation planning. Assign owners, set deadlines, and define measurable targets. Key Risk Indicator thresholds recommend 100% MFA coverage on critical systems and patching of known exploited vulnerabilities within 14 days.
Pro Tip: Before running any technical scans, complete a gap assessment against NIST CSF or CIS Controls. This maps your existing protections to a recognized framework and tells you exactly where to focus your limited resources.
Third-party vendors deserve a dedicated review. Many nonprofits grant payment processors, grant management platforms, and volunteer coordination tools access to sensitive data without reviewing those vendors' security practices. Include vendor access in your asset inventory from day one.
How does the 2026 nonprofit cybersecurity landscape shape assessment priorities?
The data on nonprofit cybersecurity is direct and concerning. 46.4% of nonprofit domains lack DMARC records, leaving them open to domain spoofing and phishing attacks. That means nearly half of all nonprofits have no technical control preventing attackers from sending emails that appear to come from their official domain.
The enforcement gap is even sharper. Only 11.6% of nonprofits enforce a strict DMARC policy (p=reject), which is the only setting that actually blocks spoofed emails. The remaining organizations either have no policy or use weaker settings that monitor without blocking. This is a direct risk to donor trust, because impersonation scams using your domain can drain donor funds before anyone notices.
Key focus areas for your 2026 nonprofit security evaluation include:
- Email authentication. Deploy DMARC, DKIM, and SPF records on every domain your organization uses, including subdomains used for fundraising campaigns.
- MFA enforcement. Apply MFA to email, financial platforms, and any system with donor data. The 100% coverage target is the verified standard.
- Patch management. Track known exploited vulnerabilities from the CISA Known Exploited Vulnerabilities (KEV) catalog and patch within 14 days.
- Staff phishing training. Regular simulated phishing tests reduce click rates measurably. Nonprofits that lack formal training face median ransomware demands of $115,000.
- Incident response planning. Document who does what when a breach occurs. Without a tested plan, response time extends and damage multiplies.
The ransomware figure deserves attention. A $115,000 median demand would shut down most small nonprofits permanently. The assessment process exists precisely to prevent that outcome by identifying and closing the gaps attackers use to deploy ransomware in the first place.
| Risk area | Current nonprofit gap | Target standard |
|---|---|---|
| DMARC enforcement | 11.6% at p=reject | 100% enforcement |
| MFA on critical systems | Inconsistent adoption | 100% coverage |
| Patch cycle for known exploits | Often 30+ days | Under 14 days |
| Formal cybersecurity policy | 70% lack one | Documented and reviewed annually |
| Incident response plan | Rarely tested | Tested at least once per year |
What frameworks and tools can nonprofits use for risk assessments?
The NIST Cybersecurity Framework and CIS Controls are the two most widely used frameworks for nonprofit risk assessments. Both are free to access and designed to scale with organizational size.
NIST CSF organizes security into five functions: Identify, Protect, Detect, Respond, and Recover. This structure maps directly to the five-step assessment process described above. CIS Controls offers a prioritized list of 18 control categories, with the first six covering the highest-impact protections for organizations with limited staff. For most nonprofits, starting with CIS Controls 1 through 6 delivers the greatest risk reduction per hour invested.
The choice between a gap assessment, a vulnerability scan, and a penetration test depends on your current maturity level:
- Gap assessment. Compares your existing controls to a framework. No technical tools required. Best starting point for organizations with no prior assessment.
- Vulnerability scan. Automated tool that checks systems for known weaknesses. Tools like Microsoft Defender for Business include basic scanning at low cost.
- Penetration test. A security professional actively attempts to breach your systems. Appropriate after gap and vulnerability work is complete. Higher cost, higher specificity.
Effective risk assessments map technical controls to organizational risk frameworks to communicate findings to leadership and prioritize based on mission impact. That translation matters. Board members do not respond to CVE scores. They respond to statements like, "A gap in our email security could allow attackers to impersonate our organization and redirect donor payments."
Managed service providers (MSPs) can conduct assessments and implement controls on your behalf. Working with an MSP does not eliminate your organization's accountability. Nonprofit leadership retains legal responsibility for cybersecurity risk management regardless of who handles the technical work. Your board must review and approve security policies, even when an MSP writes them. For nonprofits looking at low-cost cybersecurity options, pairing free frameworks with an MSP for implementation is a practical and cost-effective approach.
How can nonprofits maintain cybersecurity risk management with limited resources?
Sustainability is the hardest part of nonprofit data protection. A one-time assessment produces a report. Ongoing risk management produces actual security. The difference is whether your organization builds habits around the findings.
The most secure system is the one your current team can manage reliably, not the most feature-rich option available. This is the principle that should guide every tool and control decision your nonprofit makes. A complex endpoint detection platform that no one monitors provides less protection than a simpler tool that staff actually use and understand.
Practical steps for ongoing risk management include:
- Set measurable Key Risk Indicators with defined thresholds. Track MFA coverage percentage, days-to-patch for critical vulnerabilities, and phishing simulation click rates quarterly.
- Assign a named owner for each control area. Ownership without a name attached is ownership that belongs to no one.
- Schedule an annual reassessment. Threats evolve, staff turns over, and new tools get added. Your risk profile changes every year.
- Involve leadership in the process. Nonprofit boards that lack cybersecurity awareness consistently underfund security until a major incident forces the conversation.
- Build a basic incident response plan. Document the first five actions your team takes when a breach is detected. Practice it once per year.
UC Berkeley researchers identified a structural barrier in nonprofit resilience: organizations often lack the internal expertise to act promptly after a breach, delaying improvements until a major incident forces change. The assessment process breaks that cycle by creating a documented baseline before an incident occurs.
Pro Tip: Phishing simulation tools like KnowBe4 or Proofpoint Security Awareness Training let you test staff without waiting for a real attack. Run a simulated campaign before your annual assessment to get current click-rate data that feeds directly into your risk scoring.
Why I think most nonprofits are assessing risk in the wrong order
Most nonprofit cybersecurity conversations start with tools. Which antivirus? Which firewall? That is the wrong starting point. The assessment comes first, and the tools follow from what the assessment reveals.
I have seen organizations spend money on endpoint protection while their email domain had no DMARC record. Attackers do not need to breach your endpoint if they can impersonate your domain and redirect donor payments directly. The gap assessment would have caught that in an afternoon.
The other pattern I see consistently is treating the assessment as a compliance exercise rather than a planning tool. A report filed in a drawer does not protect anyone. The value is in the prioritized action list that comes out of it, and in getting leadership to commit to a remediation timeline with real deadlines.
Nonprofits also underestimate how much cybersecurity training changes the risk profile. Technical controls matter, but a staff member who recognizes a phishing email is a control that costs almost nothing to maintain. The assessment should always include a human risk component, not just a technical one.
Start the assessment now, even if your resources are limited. A gap assessment against CIS Controls costs nothing but time and gives you a defensible baseline. That baseline is what separates an organization that responds to incidents with a plan from one that responds with panic.
— Nicholas
How Greatplainsnetworking helps nonprofits assess and manage cybersecurity risk
Nonprofits in Norman, Moore, and Oklahoma City have a local partner for this work. Greatplainsnetworking provides managed IT support that includes cybersecurity risk assessments, 24/7 monitoring, and ongoing management tailored to organizations with limited IT staff.

The team at Greatplainsnetworking translates technical findings into plain language your board and leadership can act on. Services include cybersecurity assessment and monitoring, MFA deployment, patch management, and incident response planning. There are no long-term contracts, and response times are same-day. If your nonprofit has not completed a formal risk assessment, or if your last one is more than a year old, contact Greatplainsnetworking to schedule a consultation and build a realistic security roadmap.
Key Takeaways
A nonprofit cybersecurity risk assessment is the foundation of every effective data protection strategy, and the five-step process from asset inventory to mitigation planning gives any organization a clear path forward regardless of budget.
| Point | Details |
|---|---|
| Start with a gap assessment | Map existing controls to NIST CSF or CIS Controls before running any technical scans. |
| Email security is the top gap | Only 11.6% of nonprofits enforce DMARC p=reject, leaving most open to domain spoofing. |
| MFA and patching are non-negotiable | Aim for 100% MFA coverage and patch known exploits within 14 days. |
| Leadership retains accountability | Outsourcing to an MSP does not transfer legal responsibility for cybersecurity risk. |
| Assessments must be repeated annually | Threats, staff, and systems change every year, so your risk profile does too. |
FAQ
What is a nonprofit cybersecurity risk assessment?
A nonprofit cybersecurity risk assessment is a structured process that identifies, evaluates, and prioritizes cybersecurity threats to an organization's data and operations. It follows frameworks like NIST CSF or CIS Controls and produces a prioritized list of controls to implement.
How often should nonprofits conduct a cybersecurity risk assessment?
Nonprofits should conduct a full risk assessment at least once per year. Any significant change to systems, staff, or vendors warrants an interim review.
What is the biggest cybersecurity risk for nonprofits right now?
Email security is the most widespread gap. Nearly half of nonprofit domains lack DMARC records, making them vulnerable to phishing and donor impersonation scams that can redirect charitable funds.
Does hiring an MSP remove our cybersecurity responsibility?
No. Nonprofit leadership retains legal accountability for cybersecurity risk management even when an MSP handles technical execution. Boards must review and approve security policies directly.
What framework should a small nonprofit use to start its risk assessment?
CIS Controls is the best starting point for small nonprofits. The first six controls cover the highest-impact protections and require no specialized tools to assess against.
Recommended
Want help putting this into practice?
We'll audit your security, speed, and hardware in under an hour — no commitment, no sales pitch. Just a clear roadmap of what to fix and why.