8 cybersecurity habits to help protect your nonprofit’s mission

Cybercriminals increasingly target nonprofit organizations. Research from the CyberPeace Institute (now Protect.ngo) found that 70% of non-governmental organizations (NGOs) aren’t confident they could recover from a disruptive cyberattack. That lack of confidence has a cause: 33% of NGOs report having no IT support or technical expertise, and 56% report having no budget allocated for cybersecurity.¹ Yet the organizations that stay safe aren’t necessarily those with the biggest security budgets — they’re the ones whose teams have built a handful of specific habits into how they work. This guide covers eight of them that you can start applying right away.

August 14, 2026

14 min read

Cybersecurity habits checklist

Why do criminals target NGOs?

Nonprofits hold information that makes them a high-value target, including donor records with contact and payment details, financial and banking information, staff and volunteer data, records on often-vulnerable beneficiaries, and confidential communication and strategic plans. Their defenses, however, are often comparatively weak. Criminals get access to valuable, sensitive data while facing the security of a small, often under-resourced office.

Only 4% of NGOs have an actionable cybersecurity policy. Unlike industries designated as critical infrastructure, NGOs receive no specific protections in cyberspace. Funding is typically earmarked for project delivery, so NGOs can’t take measures to improve their cybersecurity because doing so doesn’t get dedicated financial support. Most organizations recognize the threats they face, but recognizing a threat doesn’t mean an organization is prepared for it.¹

Financially motivated criminals aren’t the only ones paying attention. Microsoft’s 2025 Digital Defense Report identifies NGOs and think tanks as consistent targets for nation-state espionage because many hold large amounts of personally identifiable information while operating with small IT teams and limited incident response capacity.2

Phishing and unauthorized account access are the openings that criminals and nation-state actors most often use to breach an organization’s systems. Closing them starts with how your team handles the routine moments — a message in an inbox, a login request, or a password reset.

Habit #1: Verify who’s contacting you before you respond

The phishing email that teaches the most useful lesson is the one that looks completely legitimate at first glance. It has the right logo, a clean subject line, and no spelling errors but has a sender domain that’s a lookalike rather than the real one.

Build the habit of checking who’s really behind a message before you act on it:

  • Check the sender domain character by character.
  • Treat any request for a password as illegitimate — real services don’t ask for credentials by email.
  • Ask yourself whether the request makes sense for a service you actually use.
  • Run any unfamiliar link or file through a link checker or file checker before you open it.

Also, consider dark web monitoring to catch leaked credentials tied to your domain. A tool like Dark Web Monitor™ can enable you to act as soon as you get a notification.

Habit #2: Get passwords and multi-factor authentication right

Passwords are the cheapest security improvement available to any organization. They’re also the most commonly skipped. A strong password has at least 12 characters, avoids personal information like names or birthdates, and isn’t reused across accounts.

NordPass publishes annual research on the most common passwords, and simple sequences like “123456,” “admin,” and “password” still appear near the top every year.³ Automated password-guessing software can break passwords like these in seconds. A password manager fixes weak, reused passwords by generating and storing complex credentials, so your team only needs to remember one master password.

Multi-factor authentication (MFA) is the second layer of defense. It protects an account even after a password has already leaked. Where the option exists, authenticator apps are stronger than SMS codes. SMS codes can be intercepted, but app-generated codes change every 30 seconds. Enable MFA on email, cloud storage, banking, and admin accounts.

PRO TIP

Watch our cybersecurity video course for nonprofit organizations to help reinforce these habits in your team’s everyday routine.

Habit #3: When ransomware hits, contain first — then call

Many people’s first instinct after discovering ransomware on one computer is to alert IT staff, inform the board, or wait to see whether other devices are affected. But the correct first action is to unplug or disconnect the affected device from the network and the internet.

Notifying IT staff and informing leadership are both necessary steps that should be taken in proper sequence. Ransomware spreads laterally, and every minute a compromised machine stays connected is a minute it can reach shared drives and other endpoints.

Once you’ve disconnected the device, assess the scope of the attack. Contact your IT support or a cybersecurity expert. Then record the details, including the time, what was affected, and the exact wording of the ransom note.

Never pay the ransom. Payment doesn’t guarantee the return of your data, and it signals to other attackers that your organization is willing to pay. Instead, contact law enforcement, restore your systems and files from clean backups, and inform your board, staff, volunteers, and affected stakeholders. Once systems are stable, run a post-incident review focused on what to change.

Habit #4: Verify payment changes with a call, not through email

In July 2020, Philabundance — a hunger relief nonprofit in Philadelphia — had its email server infiltrated by cyber thieves. The attackers mimicked a construction company that had done work for the organization, sent a fake invoice, and walked away with close to $923,000.4

The attack succeeded because every element was individually plausible. The vendor was real, the invoice looked legitimate, and the request arrived through a channel the finance team already trusted. The email itself had no spelling errors, no mismatched sender address, and no unusual formatting — the usual warning signs simply weren’t there, which is what makes this type of fraud difficult to catch in the moment.

Any change to bank details on an invoice should trigger a phone call to a number you already hold on file — never a number supplied in the email requesting the change. As a second safeguard, require two people to approve any payment above a threshold your organization sets. Attackers benefit most when your team moves fast on a payment decision.

Habit #5: Apply updates the day they are released

In 2022, the International Committee of the Red Cross (ICRC) disclosed a data breach that affected the personal data of more than 515,000 people worldwide. The compromised system supported Restoring Family Links, the program that reconnects families separated by conflict, migration, and disaster. The breach occurred on November 9, 2021, and went undetected until January 18, 2022. The entry point was an unpatched critical vulnerability in an authentication module — one for which a fix already existed.5

Reduce the risk of an unpatched vulnerability being your entry point with a few consistent practices:

  • Update operating systems and software as updates arrive, not when convenient.
  • Retire software that no longer receives security support.
  • Run an antivirus, use a firewall, and implement endpoint protection.
  • Segment your network so a compromise in one system stays contained to that system — the same principle the ICRC credited for keeping its breach limited to one set of servers.
  • Back up frequently, store at least one backup offline or in a secured cloud environment, and run a test to ensure you can restore so you know it works before you need it.

Habit #6: The day someone leaves, remove their access

Social impact organizations often run on volunteers, fellows, contractors, and seasonal staff, which means people join and leave far more often than in a comparably sized company. Every departing individual who leaves an active account behind provides an open door for bad actors.

A tracking spreadsheet listing which tools each person can access, maintained from the day they join, is an important record-keeping step. When someone leaves:

  • Revoke their access to email, file storage, donor databases, social media accounts, collaboration tools, and MFA apps.
  • Retrieve and wipe any organization-owned devices.
  • Change shared credentials.
  • Transfer ownership of files, folders, calendars, and email to someone still on the team.

Use the same strategy when you onboard personnel. New hires are 44% more likely to fall for phishing and social engineering attacks than tenured employees during their first 90 days, and their average phishing susceptibility during onboarding is as high as 71%.

When someone joins:

  • Define their access by role rather than granting broad permissions by default.
  • Set up accounts with strong passwords and MFA from day one.
  • Start security training in the first week and follow up with short reminders — new hires are unlikely to retain everything covered in that first, information-heavy week.

PRO TIP

For more details on building an offboarding checklist and setting up secure onboarding, see our guide to secure onboarding and offboarding for nonprofits.

Habit #7: Name an incident-response owner from day one

The highest-leverage decision in nonprofit security is naming one person to own incident response — even if it’s just a few hours a week. Without a named owner, an incident produces a room full of people who each assume someone else knows the plan.

The plan itself is straightforward:

  1. 1.Contain the problem by disconnecting affected devices and locking compromised accounts.
  2. 2.Figure out what happened, including the attack type, what was reached, and what the logs show.
  3. 3.Notify the right people. You might need to alert IT support, leadership, affected individuals, and any regulator you report to under the GDPR or similar frameworks.
  4. 4.Secure systems by patching vulnerabilities and requiring password changes with MFA enabled.
  5. 5.Recover by restoring from clean, verified backups.
  6. 6.Learn from what happened by identifying the weak point and sharing it with your team.
  7. 7.Strengthen defenses through ongoing training, monitoring, access controls, and scheduled reviews.

For organizations without an internal IT team or a security contractor, the Access Now Digital Security Helpline opens in a new tab provides free technical assistance to civil society organizations — even in the middle of an active incident.

Habit #8: Stay secure while traveling or working remotely

Most of an organization’s standard protections don’t work out in the field or for remote workers. Public networks in airports, hotels, and cafes usually lack authentication and device isolation — an attacker on the same network can intercept traffic from other users. Fake hotspots are straightforward to set up — the real network might be called “Airport Wi-Fi,” while the attacker uses a more tempting name like “Free Airport Wi-Fi” to lure people in.

To protect your connection wherever you’re working from:

  • Use a VPN to encrypt traffic on any network you don’t control.
  • Confirm the sites you visit are using HTTPS.
  • Avoid banking and other activities that involve sensitive information on public networks.
  • Disable file sharing and turn off Wi-Fi auto-connect.
  • Where possible, use your own mobile data.
  • Avoid public USB charging stations, which can be used to move malware onto a device or pull data from it — carry your own power bank instead.

Most staff members of social impact organizations use their own personal devices because purchasing hardware for every volunteer isn’t realistic. Keep software updated, install apps only from trusted sources, separate work and personal files where you can, and report a lost or stolen device to your team immediately. A missing phone or computer puts the organization’s data at risk, not just the device owner’s personal data.

NORDVPN’S INITIATIVE

Through the NordVPN Nonprofits program, we offer eligible organizations free or discounted VPN subscriptions. Nonprofits, journalists, human rights advocates, and educators can apply to join the program to securely access information, protect communication, and work without fear of surveillance.


Strengthen your online security so you can focus on what truly matters.

This guide draws on a working session with Jurgita Kačkytė opens in a new tab, nonprofit partnerships manager at Nord Security, NordVPN’s parent company, held as part of the Cybersecurity Hub within Tech To The Rescue’s AI Impact Scaling Program opens in a new tab. Nord Security is one of the program’s delivery partners. If your organization has a proven intervention ready to scale with AI, you can find application details and eligibility criteria for the program on the Tech To The Rescue website.

FAQ

References

1 CyberPeace Institute. (2023). Analytical Report: NGOs serving Humanity at risk: Cyber Threats affecting “International Geneva.” Protect.ngo. https://protect.ngo/resources/cyberpeace-analytical-reportngos-serving-humanity-at-risk-cyber-threats-affecting-international-geneva opens in a new tab 

2 Microsoft. (2025, October). Microsoft Digital Defense Report 2025. Microsoft. https://www.microsoft.com/en-us/corporate-responsibility/topics/cybersecurity/reports/microsoft-digital-defense-report-2025/ opens in a new tab 

3 NordPass. (2025). Top 200 Most Common Passwords: Generations change, password habits remain. NordPass. https://nordpass.com/most-common-passwords-list/ opens in a new tab 

4 Brandt, J. (2020, December 1). Philabundance says cyber thieves took nearly $1M in a scam this year. WHYY. https://whyy.org/articles/philabundance-says-cyber-thieves-took-nearly-1m-in-a-scam-this-year/ opens in a new tab 

5 International Committee of the Red Cross. (2022, February 16). Cyber attack on ICRC: What we know. https://www.icrc.org/en/document/cyber-attack-icrc-what-we-know opens in a new tab 

6 Keepnet Labs. (2025, June 23). 2025 New Hires Phishing Susceptibility Report. https://keepnetlabs.com/reports/new-hires-phishing-susceptibility-report opens in a new tab

Violeta Lyskoit | NordVPN

Violeta Lyskoit

Violeta is a copywriter who is keen on showing readers how to navigate the web safely, making sure their digital footprint stays private.