Nonprofit team in a cybersecurity planning meeting

By Eagle Tech Corp

September 2026 • 7-minute read

Quick Answer: Every nonprofit leadership team should hold a short, recurring readiness meeting that answers five questions: which systems to restore first, who makes decisions during an incident, how the team will communicate if normal tools fail, where donor and client data actually lives, and whether the organization could prove to a funder or auditor that it is protected. For nonprofits in Northern Virginia, Maryland, and Washington, DC that often run lean, with sensitive donor data and no dedicated IT security, this 15-minute conversation surfaces the gaps that a ransomware attack or phishing email would otherwise expose at the worst possible moment.

Key Takeaways

  • Nonprofits are targeted because they hold valuable donor data with small teams and limited security, not despite it.
  • Most attacks begin with a single phishing email, often disguised as a grant notification or a message from leadership.
  • Your donor data lives across multiple systems and outside vendors, and a breach at any one of them can expose it.
  • Funders, insurers, and boards increasingly require documented proof of cybersecurity. "We think we're fine" no longer qualifies.
  • Preparedness is a leadership decision, not a technical one. Fifteen minutes and five questions is enough to start.

In the summer of 2024, OneBlood, a nonprofit that supplies blood to more than 250 hospitals, was hit by ransomware. Its systems were encrypted overnight. Staff were forced back to pen and paper. Blood collection, testing, and distribution slowed to the point that hospitals had to activate critical-shortage protocols. Months later, the organization sent letters to donors admitting that their names and Social Security numbers had been copied off the network. A mission built on saving lives spent that fall managing an identity-theft crisis instead.

If your first thought is "that's a big organization, that won't happen to us," that's exactly the assumption attackers count on. Nonprofits are targeted precisely because they hold valuable donor data with small teams, tight budgets, and often no dedicated IT security. In 2024 alone, more than 30% of charities reported a cyberattack or breach, and the vast majority of phishing attempts went straight after donor and financial information.

You don't have to be the next headline, but avoiding it takes more than hope. It takes 15 minutes, the right people at the table, and five direct questions. September is National Preparedness Month, so there's no better time to ask them.

1. If we lost access to our systems tomorrow, what would we protect first?

This is the OneBlood question. When their systems locked, the staff didn't have hours to debate priorities. They had patients waiting. For your organization, the honest answer usually starts with the same things: your donor database, your financial and payroll systems, and the records that protect the people you serve.

If everything went dark tomorrow, your team should already know which systems come back first and why. Name those priorities now, while it's calm, because the middle of an attack is the worst possible time to figure it out. The reputation you're protecting took years to build and can be lost in a weekend.

2. Who makes the call when something goes wrong?

Here's how these attacks often start: not with a dramatic break-in, but with a single email. In one documented case, a nonprofit received a message spoofed to look like a grant notification from a funder they already knew. A staff member clicked. The attackers sat quietly inside the network for days before locking everything and demanding tens of thousands of dollars within 72 hours.

When that email lands, who decides what happens next? Your team should know who leads the response, who updates staff and volunteers, who talks to the community you serve, and who handles funders and vendors. Settle it before a well-meaning employee wires money to a fake board member because no one told them to stop and verify.

3. How would we communicate if our normal tools weren't available?

Email is both the target and the casualty. It's the number-one way attackers get in, and it's often the first thing you lose when they do. If your team suddenly couldn't trust or reach their inbox, would they know where to turn?

If staff couldn't access email, would they know where to look for direction? If your phone system failed, how would the families, clients, or partners who count on you get through? A backup communication plan doesn't need to be elaborate. It just needs to exist before the day you need it.

4. Where does our donor and client data actually live, and who can reach it?

In 2026, a single CRM provider used by roughly 1,500 charities was breached. Those organizations did nothing wrong themselves, yet their supporters' names, contact details, and donation histories were exposed through a vendor they trusted. That's the uncomfortable truth: your data rarely sits in one place you control. It's spread across a donor CRM, accounting software, email tools, cloud storage, and outside vendors, each one a potential doorway.

If any one of those providers is breached, or if a volunteer's account stayed active months after they left, you're exposed, whether you realized it or not. Knowing where your data lives and who can reach it is the difference between confidently answering a grant application's security questions and finding out the hard way.

5. If a funder or auditor asked today, could we prove we're protected?

More and more, someone is asking. Grantmakers, insurers, and boards increasingly want documented proof that you handle data responsibly, and "we think we're fine" is no longer an acceptable answer, or an insurable one.

Your team may wish it had documented a process, tested its backups, tightened access controls, or written down who's responsible for what, long before the question arrived. None of these tasks feel urgent during a busy grant cycle, which is exactly why they get pushed aside until the moment you can least afford it.

Where the right IT partner comes in

Every organization in these stories had one thing in common: the gaps were invisible until the day they weren't. A good partner's job is to find them while you still have a choice.

That means helping you protect donor data, verify your backups actually restore, tighten who can access what, document the systems your programs depend on, and walk into a funder conversation or audit prepared instead of panicked. You shouldn't have to become a cybersecurity expert to know your organization is safe.

Eagle Tech Corp has helped nonprofits and mission-driven organizations across Northern Virginia, Maryland, and Washington, DC since 2012, keeping technology from getting in the way of their mission, with local support in both English and Spanish. The goal was never to make preparedness feel technical. It's to keep donor-funded time and resources focused on your community, not on the fallout from a problem you could have seen coming.

A simple next step

OneBlood didn't get to choose whether to spend that fall on damage control. You still can. If a few of those five questions gave you pause, that's not a reason to panic. It's a reason to act before a funder, an auditor, or an attacker forces the issue.

If working through these questions surfaced a few uncertain answers, that's worth a conversation. Send us a note through the contact form at https://eagletechcorp.com/contact-us/ and we'll help you find the gaps and map out a practical next step, with no pressure and no need to have all the answers first. If it's helpful, we can walk through a complimentary IT & Cybersecurity Assessment together, so you leave with a clear picture of where your organization stands.

Frequently Asked Questions

Why are nonprofits targeted by cyberattacks?

Nonprofits are targeted because they hold valuable donor and client data, including names, contact details, giving histories, and sometimes Social Security numbers, while typically operating with small teams, tight budgets, and little or no dedicated IT security. Attackers see high-value data behind low-resistance defenses. In 2024, more than 30% of charities reported a cyberattack or breach.

What should a nonprofit protect first during a cyberattack?

Most nonprofits should prioritize the systems that hold or protect sensitive data and keep the mission running: the donor database, financial and payroll systems, and records that protect the people you serve. Decide the order of restoration before an incident happens.

How do most nonprofit cyberattacks start?

Most attacks start with a single phishing email, often spoofed to look like a grant notification from a known funder or a message from a board member. A staff member clicks, attackers gain access, and they may sit inside the network for days before locking systems or stealing data. Email remains the most common entry point.

Where does a nonprofit's donor data actually live?

Donor data rarely sits in one place. It is typically spread across a donor CRM, accounting software, email tools, cloud storage, and several outside vendors, each a potential point of exposure. A breach at a single shared vendor can expose supporter data for many organizations at once.

How can a nonprofit prove to a funder or auditor that it is protected?

Be ready to show tested backups, multi-factor authentication, access controls, documented critical systems, and a written incident-response plan that names who is responsible for what. "We think we're fine" is no longer an insurable or fundable answer.

Does Eagle Tech Corp provide IT and cybersecurity support for nonprofits in the DC Metro area?

Yes. Eagle Tech Corp is a managed IT and cybersecurity provider that has helped nonprofits across Northern Virginia, Maryland, and Washington, DC since 2012, helping them protect donor data, verify backups, prepare for funder and audit questions, and align technology with their mission, with local support in English and Spanish.