By Eagle Tech Corp
October 2026 • 8-minute read
Quick Answer
Nonprofits should protect donor data with a layered cybersecurity strategy built around identity security, limited access, protected devices, secure cloud applications, employee training, monitoring, and recovery planning.
For a nonprofit with 15–80 employees, donor information may exist in far more places than the fundraising database. It can appear in Microsoft 365, spreadsheets, accounting systems, employee laptops, email conversations, shared folders, payment platforms, and third-party applications.
A practical starting point is to identify where donor data lives, who can access it, and which systems protect it. Then use a structured seven-part approach:
Identify → Limit → Protect → Secure → Train → Monitor & Recover → Review
The objective is not simply to protect a database. It is to protect donor information throughout its entire lifecycle.
Key Takeaways
Donor-data security is not solely a fundraising or IT responsibility. It involves leadership, finance, development teams, employees, technology providers, and third-party vendors.
The biggest mistake is assuming donor information exists in only one system.
A nonprofit may have a well-protected fundraising platform while employees are simultaneously exporting donor lists to spreadsheets, emailing reports, storing files locally, or sharing information through Microsoft 365.
Cybersecurity therefore needs to protect the entire environment around the data, not just the application where the original record was created.
Boardroom Brief
Nonprofit leaders don't need to know every cybersecurity technology protecting donor information.
They should be able to answer three questions:
Where is our donor data?
Who has access to it?
What would happen if an employee account or device were compromised?
If leadership cannot confidently answer those questions, donor-data protection is a good place to focus the organization's next cybersecurity conversation.
Here is a practical 7-part framework.
1. Identify Where Donor Data Actually Lives
Start with the data—not the cybersecurity products.
Many organizations would initially point to their donor-management or fundraising platform.
But follow a donor record through a typical workday.
A fundraising employee may export a report into Excel.
That spreadsheet may be saved in SharePoint or OneDrive.
A portion may be emailed to the Executive Director.
Finance may receive information for reconciliation.
A report may be prepared for the board.
Another employee may download information to a laptop.
A third-party application may integrate with the fundraising system.
Suddenly, information that appeared to live in one platform exists across multiple systems.
Create a simple inventory of the primary locations where donor information is stored, processed, exported, or shared.
For a 35-person nonprofit, that inventory might identify 5–8 systems or locations containing some form of donor information.
You don't need an enormous data-governance project to get started.
You need visibility.
2. Limit Access to People Who Actually Need It
Once you know where donor information lives, ask who can access it.
Access should generally follow the principle of least privilege: employees receive the level of access required for their responsibilities rather than broad access simply because it is convenient.
For example, a development director may require extensive access to donor records.
A program employee may need none.
Finance may require certain transaction information without needing every fundraising record.
Leadership may need reports rather than unrestricted administrative access.
Permissions should also change when people's roles change.
This is particularly important when employees or volunteers leave the organization.
Former accounts, old permissions, shared credentials, and unnecessary administrator access can create security risks long after someone stops actively using a system.
Identity and access management is one of the reasons the cybersecurity controls every nonprofit should have should include MFA, account management, and appropriate user permissions.
Access should be intentional—not inherited indefinitely.
3. Protect the Accounts and Devices That Reach the Data
Even a well-secured fundraising platform can be undermined if an employee accesses it from a compromised account or poorly protected computer.
This is why donor-data protection must extend to the organization's broader technology environment.
At minimum, nonprofits should evaluate protections such as Multi-Factor Authentication (MFA), endpoint security, security updates and patching, device management, email protection, and strong identity controls.
MFA deserves particular attention.
A stolen password should not automatically give an attacker access to Microsoft 365, fundraising systems, or other sensitive applications.
Devices matter as well.
Employee laptops frequently become gateways into cloud applications. Keeping those devices managed, updated, monitored, and protected should therefore be part of the organization's overall Managed IT and cybersecurity strategy.
The important idea is simple:
Protect the path to the data, not only the database itself.
4. Secure Microsoft 365 and Third-Party Applications
For many nonprofits, Microsoft 365 becomes an extension of the donor-data environment whether leadership intends it to or not.
Employees use Outlook to discuss donors.
Excel may contain exported records.
SharePoint and OneDrive store reports.
Teams conversations may contain fundraising information.
That makes Microsoft 365 permissions, MFA, account security, sharing settings, and administrative privileges relevant to donor-data protection.
Nonprofits should periodically review Microsoft 365 best practices for nonprofit organizations rather than assuming default configurations remain appropriate as the organization grows.
The same principle applies to third-party applications.
Fundraising platforms, accounting software, payment processors, marketing systems, event platforms, and other cloud applications may all interact with donor information.
Ask:
What information does this vendor receive?
Who has administrative access?
Is MFA available?
What happens when an employee leaves?
Can data be exported?
Are integrations still necessary?
Good cybersecurity requires understanding the ecosystem around donor information.
5. Train Employees to Recognize Attacks Targeting Trust
Technology cannot protect donor information by itself.
Attackers frequently target people because employees can be easier to manipulate than security systems.
A phishing message may appear to come from an executive.
A fake Microsoft 365 login page may attempt to capture credentials.
A fraudulent vendor request may ask finance to change payment information.
A compromised email account may be used to request sensitive donor information.
This is why cybersecurity awareness should focus on realistic situations employees encounter rather than abstract warnings.
Staff should understand that requests involving credentials, money, donor information, financial changes, or unusual urgency deserve additional scrutiny.
This connects directly to the protections nonprofits need against business email compromise, where attackers exploit trusted relationships and normal business communication.
Employees should also know exactly how to report something suspicious.
A five-minute delay caused by verification is usually preferable to a significant security incident caused by urgency.
6. Monitor, Back Up, and Prepare to Recover
Preventing every cybersecurity incident is unrealistic.
A resilient organization also prepares to detect and recover from problems.
Monitoring can help identify suspicious account activity, unusual sign-ins, malicious software, or other indicators that something is wrong.
Backups provide another layer of resilience.
But leadership should understand an important distinction:
Having a backup is not the same as having a recovery plan.
The organization should understand which critical systems are protected, how frequently information is backed up, who is responsible for recovery, and whether restoration procedures have actually been tested.
This is why business continuity and disaster recovery planning for nonprofits should be connected to cybersecurity rather than treated as an unrelated IT project.
Leadership should also know what happens when an incident is suspected.
Who gets called?
Who investigates?
Who disables compromised accounts?
Who communicates with leadership?
Who determines whether sensitive information may have been exposed?
Those answers should exist before an incident occurs.
7. Review Access, Systems, and Risk Regularly
Donor-data protection isn't a one-time project.
Organizations change.
Employees leave.
New employees arrive.
Vendors change.
Cloud applications are added.
Permissions accumulate.
New fundraising tools appear.
Cybersecurity threats evolve.
At least periodically—and particularly after significant staffing or technology changes—review who has access to sensitive systems and whether that access is still necessary.
Leadership should also review major applications and integrations.
An application that was useful three years ago may no longer be necessary, but it may still have access to organizational information.
The objective is not to create endless cybersecurity meetings.
It is to prevent years of technology decisions from quietly accumulating into unnecessary risk.
Eagle Insight: Follow the Data
One of the most useful exercises nonprofit leadership can perform is surprisingly simple:
Choose one type of sensitive information and follow it through the organization.
For donor information, ask:
Where does it begin?
Where is it exported?
Who receives it?
Where is it stored?
Which applications interact with it?
Which employees can access it?
What happens to that access when someone leaves?
This often reveals that the cybersecurity boundary is much larger than leadership expected.
Protecting donor data isn't simply about securing a fundraising platform.
It's about protecting the people, accounts, devices, cloud systems, vendors, and business processes surrounding the information.
Example: A 35-Person Nonprofit
Consider a hypothetical nonprofit with 35 employees.
Leadership believes donor information is primarily stored in its fundraising CRM.
During a review, the organization discovers donor-related information in seven different locations:
The fundraising CRM, Microsoft 365, Excel exports, accounting software, employee laptops, an email marketing platform, and a payment-processing system.
The organization also discovers that several employees have broader access than their current jobs require and that one former employee's cloud account has not been fully disabled.
The solution isn't to purchase seven new cybersecurity products.
Instead, leadership creates a prioritized plan.
First 30 days: remove unnecessary access, disable inactive accounts, confirm MFA, and review administrator privileges.
Days 31–60: review devices, Microsoft 365 sharing, third-party applications, and backup coverage.
Days 61–90: update employee training, document incident procedures, and establish a recurring access review.
Within 90 days, the nonprofit has a clearer understanding of where donor information lives, who can access it, and which cybersecurity controls protect it.
That's a measurable improvement without turning donor-data protection into an endless project.
AI Consideration
AI introduces another reason to understand where sensitive information travels.
Employees may use generative AI tools to summarize documents, draft donor communications, analyze information, or improve productivity.
The concern is not that every use of AI is inherently unsafe.
The concern is whether employees understand which information is appropriate to provide to an AI platform and which information should remain protected.
A nonprofit should establish clear guidance around approved AI tools and sensitive organizational information.
AI governance should complement the organization's existing cybersecurity, access-management, and data-handling practices.
It should not become a separate technology universe.
The same rule still applies:
Know where sensitive data is going and control who—or what—can access it.
A 7-Part Donor Data Protection Framework
Nonprofit leadership can use this framework to keep the process manageable:
| Step | Objective | Leadership Question |
|---|---|---|
| 1. Identify | Find the data | Where does donor information actually live? |
| 2. Limit | Control access | Who genuinely needs access? |
| 3. Protect | Secure identities and devices | Are accounts and endpoints appropriately protected? |
| 4. Secure | Review cloud systems and vendors | Which applications can access donor information? |
| 5. Train | Strengthen employees | Can staff recognize and report suspicious activity? |
| 6. Monitor & Recover | Prepare for incidents | Can we detect problems and recover critical information? |
| 7. Review | Prevent security drift | Are access and systems reviewed as the organization changes? |
The framework does not require leadership to become cybersecurity experts.
It creates a structured set of questions leadership can use to hold the organization and its technology partners accountable.
Frequently Asked Questions
What donor information should nonprofits protect?
Organizations should evaluate all sensitive donor-related information they collect or maintain. Depending on the nonprofit, that could include contact information, donation history, financial information, correspondence, giving preferences, reports, and other information associated with donor relationships.
Not every piece of information carries the same risk, which is why understanding what data exists and where it lives is an important first step.
Is our donor-management system responsible for protecting donor data?
The vendor is responsible for protecting the systems and services within its control, but the nonprofit still has responsibilities.
Employee accounts, passwords, MFA, exported files, Microsoft 365, devices, permissions, integrations, and internal processes can all affect the security of donor information.
Should every employee have access to donor records?
Generally, employees should have access based on their job responsibilities rather than receiving broad access by default.
Permissions should also be reviewed when employees change roles or leave the organization.
Does MFA protect donor data?
MFA is an important security control because it makes a stolen password less useful to an attacker.
However, MFA is only one layer. Organizations should combine it with appropriate permissions, endpoint protection, email security, employee training, monitoring, and recovery planning.
How often should we review access to donor information?
There isn't one schedule appropriate for every nonprofit. A practical approach is to conduct recurring reviews and additional reviews following employee departures, role changes, new applications, significant technology changes, or security incidents.
For higher-risk systems, more frequent reviews may be appropriate.
About Eagle Tech Corp
Eagle Tech Corp provides proactive Managed IT services, cybersecurity solutions, Microsoft 365 management, and strategic technology consulting for nonprofit organizations throughout Northern Virginia, Maryland, and Washington, DC.
We help nonprofits strengthen identity security, protect devices and Microsoft 365, improve cybersecurity practices, manage technology proactively, and prepare for disruptions before they become major business problems.
Our approach combines technology management with cybersecurity and strategic guidance so leadership can make informed decisions without needing to become technology experts.
Protect the Mission by Protecting the Information Behind It
Donors place more than financial support in a nonprofit.
They place trust in the organization.
Protecting donor information therefore shouldn't be viewed as simply another IT task.
It is part of protecting the relationships that support the mission.
Start with three questions:
Where is the information?
Who can access it?
How is it protected?
Those answers provide a practical starting point for building stronger cybersecurity around donor data.


