Non-profits are frequently treated as small businesses with tighter budgets. The budget part is true and it is the least interesting difference. The structural differences — how funding works, who touches systems, and what data is held — change the shape of the problem.
Licensing is genuinely cheaper, if you claim it
The most immediate practical difference. Eligible non-profits can access substantially discounted or donated software:
- Microsoft offers grants of Microsoft 365 Business Premium seats to eligible organisations, plus heavy discounts beyond the granted allocation. Business Premium is significant because it includes the device management and security tooling that would otherwise be a separate purchase.
- Google Workspace is available free to eligible non-profits.
- Many security, backup and productivity vendors run non-profit pricing, often at 50 per cent or better.
- TechSoup aggregates donated and discounted offerings across a wide range of vendors and is the usual starting point.
The gap worth naming: many organisations qualify and never claim, or claim once and never revisit as programmes change. It is worth an annual review, and it is a reasonable thing to expect an IT provider to raise.
One caution — the security tooling included in donated Microsoft licensing is frequently never configured. Holding the licence and using it are different things, and the unconfigured case is common.
Volunteer and turnover realities
Non-profits often have a mix of paid staff, part-time workers, volunteers, board members and seasonal helpers — with far higher turnover than a comparable business and much less formal onboarding.
This makes access management the central discipline:
- Role-based access rather than per-person decisions, so a new volunteer gets a defined, limited set automatically
- Time-limited accounts for seasonal or project roles, expiring by default rather than requiring someone to remember
- A genuine offboarding process, which is where non-profits most commonly have gaps — volunteers frequently stop attending rather than formally leaving
- Board member access, which is a recurring blind spot. Board members often have access to sensitive material, use personal devices, and turn over on a fixed cycle
- Quarterly access reviews, which matter more here than almost anywhere else
Donor data carries real obligations
Donor records are among the more sensitive datasets a small organisation holds: names, addresses, giving history, sometimes payment details, and occasionally information about circumstances.
The obligations depend on what you hold:
- Taking card payments brings you within PCI-DSS. Using a hosted payment provider dramatically reduces scope and is almost always the right choice for a small organisation.
- New York's SHIELD Act imposes data security requirements on any business holding private information about New York residents, and non-profits are not exempt.
- Health-related services can bring HIPAA obligations, which surprises organisations that do not consider themselves healthcare providers.
- Serving minors brings additional considerations around consent and record handling.
The reputational dimension is also disproportionate. A non-profit that loses donor data faces a trust problem that directly affects future giving, and trust is closer to the core of the operating model than it is for most businesses.
Grant funding shapes what you can buy
The structural budget problem is not the size of the budget. It is that grant funding is frequently restricted to programme delivery and cannot be spent on infrastructure, and that it arrives as one-off amounts rather than recurring.
This produces a specific pattern: capital purchases are fundable, ongoing subscriptions are not. Which is precisely backwards from how modern IT is priced.
Practical responses:
- Include IT costs in programme budgets where the technology genuinely supports programme delivery, rather than treating all of it as overhead
- Look for capacity-building grants specifically, which some funders offer for infrastructure
- Use one-off funding for the items that are genuinely one-off — hardware, migration projects, security assessments — and fund recurring costs from unrestricted income
- Take advantage of annual billing discounts where cash flow allows, which often align better with grant cycles
Where non-profits are most exposed
Attackers do not treat non-profits as low-value targets. Payment fraud in particular is a recurring problem, and the operating pattern makes it easier:
- Business email compromise targeting finance staff, often impersonating an executive director. Small finance teams with informal approval processes are the ideal target.
- Fraudulent invoices, which succeed more often where multiple programmes and vendors make an unfamiliar invoice unremarkable.
- Donation page compromise, redirecting funds or harvesting card details.
- Grant application phishing, targeting the people whose job is to open documents from organisations they do not know.
The most effective control against most of this is not technical. It is a payment verification procedure — any change to payment details verified by phone to a known number, and any transfer above a threshold requiring two people. That costs nothing and prevents the most expensive failure mode.
A sensible baseline
- Claim your licensing entitlements and configure the security features they include
- MFA on everything, with no exceptions for board members or long-serving volunteers
- Role-based access with time-limited accounts for temporary roles
- Quarterly access reviews against a current people list
- A written payment verification procedure
- Backups that are tested, covering your donor database specifically
- Security awareness training, extended to volunteers and board members rather than staff only
Most of this is process rather than purchase, which suits an organisation with more constraint on money than on discipline.