The Nonprofit's Guide to Securing Platforms You Don't Control

By Amber CraytonAmber Crayton · · Consultant updates
The Nonprofit's Guide to Securing Platforms You Don't Control

The Nonprofit's Guide to Securing Platforms You Don't Control 

When Elon Musk took over Twitter, he wanted to rename the company “X.” But someone else already had that handle and had been using it for years. This was not a problem for Elon. He owned the company, and he owned all the accounts. So he just took it. 

It's a strange, small story, but it points to something bigger: most of what we consider "ours" online, we don't actually own. We rent it. And the terms of that lease, including who gets access and how it's protected, can change without our consent. 

In the nonprofit sector, you live this reality every day, often without time to think about its implications. Your donor CRM, your email, your Facebook page, your Google Drive full of case files: almost none of it lives on infrastructure you control. That's not necessarily a problem. Free and low-cost platforms are often the only way small nonprofits can operate at all. But your security posture needs to plan for the fact that a vendor, not your organization, controls the platforms your mission depends on. 

You can't control everything, but protecting your mission starts with what you can control. Here’s how. 

Know what people use 

Ask most nonprofit leaders how many digital tools their organization uses, and you'll get a rough guess. Ask which specific platforms every staff member and volunteer actually has an account on, and the guess gets a lot rougher. That gap is a security risk in itself. 

Small nonprofits rarely have a formal IT approval process. Someone needs to share files, so they set up a personal Dropbox. Someone needs a quick way to survey volunteers, so they sign up for a free tool with their work email. None of it is malicious, and often it solves a real problem in the moment. But every one of those accounts is a place where your organization's data now lives, outside of anything you're tracking or securing. 

Start with a simple inventory: what platforms does your staff actually use to do their jobs, including the platforms nobody officially approved? A short survey or a five-minute conversation with each team member is usually enough to surface tools you didn't know existed. You're not trying to catch anyone doing something wrong; you're trying to find out where your mission's data actually lives, so you can decide what belongs there and what doesn't. 

Read the Terms of Service 

If a breach is really about unwanted access to your data, then the fine print you (or individual team members) agreed to without reading is already part of that equation. 

Every platform you use has a Terms of Service and a Privacy Policy, and buried in that fine print are the actual rules of the relationship: what the platform can do with your data, whether they can sell or share it with third parties, and what happens to your information if you stop paying or the company changes hands. For a nonprofit holding sensitive constituent data, case files, or donor information, those answers matter as much as any firewall. 

This risk goes up sharply with free tools. There's an old saying in tech: if you're not paying for the product, you are the product. Free platforms often make up the difference by monetizing user data, and "monetizing" can mean selling it, using it to train other products, or sharing it with advertisers and partners in ways you never explicitly agreed to. That doesn't mean you should stop using free tools; for many nonprofits, they're the only option. But it does mean you should know, going in, what the trade-off actually is. 

The problem, of course, is that Terms of Service documents are written to be skimmed past, not understood. They're long, dense, and full of legal language that obscures more than it reveals. This is a place where AI tools can genuinely help: you can paste a platform's Terms of Service or Privacy Policy into a tool and ask it to summarize, in plain language, what happens to your data, whether it can be sold, and what your rights are if you want it deleted. It won't replace legal advice, but it can turn an hour of dense reading into a five-minute gut check, which is often the difference between checking at all and not checking. 

Know exactly who holds the keys 

Unlike large companies with dedicated IT departments, nonprofits often rely on a revolving cast of staff, interns, and volunteers. As a result, access and login controls are spread across a number of staff members. Every person who's ever had a login to your donor database or social accounts is a potential access point. Keep a living list of who has access to what and when their access needs were last reviewed. If you can't produce that list in five minutes, that's your first project. Then, build an offboarding checklist that is utilized every time. When someone leaves, their access should leave with them. Revoke email, remove from Slack, pull CRM permissions, rotate any shared passwords they knew. This single habit closes one of the most common security gaps in small organizations. 

This is another reason to have a complete list of the software team members use. If someone is storing work files under an account they set up, then you can lose access to it when they leave. 

Don’t trust default settings 

The free and discounted tools nonprofits rely on often have weaker default security and slower support than their enterprise versions. That's often a necessary trade-off for being able to do your work, but it means basic protections, like MFA, access review, and login alerts, are your responsibility, not the platform's. Check what security features your tools offer and whether they're actually turned on. Defaults are rarely the safest setting. Where applicable, consider upgrading your more sensitive systems to a paid plan if it gives you a higher level of security. 

Take ownership back with backups 

You can't own the platform, but you can own a copy of what's on it. Regular, tested backups of donor records, financials, and program data mean that if you get locked out of a platform, or even if it simply goes down, your mission's history doesn't go down with it. This is also an essential protection from ransomware attacks and malicious deletions from hacked accounts. 

Be sure to test your backups on a regular schedule. 

“ A backup never tested is a hope, not a plan. "

Ensure that any manual procedures are being followed and that any automated systems are not experiencing sync errors. You don’t want to find out after a ransomware attack that the backups you thought you had do not actually exist. 

Have a response plan 

Backup procedures, offboarding checklists, and regular settings reviews illustrate how digital security is as much about policies as it is about technology. You need to act as if eventually something will go sideways: a hacked account, a platform error, or a departed staffer who was the only one with the password. An incident response plan can help keep you accountable to take proactive steps to prevent a security issue and take quick and decisive action if something does happen. Decide now, not during the emergency, who has authority to work with the platform's support team, where your backup contact information lives, and how you'll communicate with your community if a channel goes dark temporarily. 

If you don’t have an incident response plan, our team can help you develop one. 

None of this means you should stop using cloud technologies and go back to paper forms and filing cabinets. Apart from the fact that that’s practically impossible today, these tools do help you work better. They help keep you connected with your team and your constituents. They improve service delivery, increase fundraising, and add efficiencies that save you money. But building on rented land comes with risks you need to consider. It means knowing what you can’t control, controlling what you can, and taking proactive steps to ensure your mission's memory doesn't live in only one place. 

Sources 

● IBM, Cost of a Data Breach Report 2025 

● FBI Internet Crime Complaint Center (IC3), 2025 Internet Crime Report ● RipRap Security, Nonprofit Data Breaches & Their Impact 

● VikingCloud, Cybersecurity Statistics 2026 

● Cal Nonprofits Insurance Services, Cyber Liability Risks Every Nonprofit Faces in 2026 Nten Cybersecurity for Nonprofit guide 

Amber Crayton
Associate Cybersecurity Consultant

Undaunted Consulting
she/her

Amber is a self-motivated and detail-oriented cybersecurity professional bringing over four years of hands-on experience in cybersecurity and over seven years in customer service. With strong problem-solving skills, she focuses on troubleshooting technical and security issues. She has a strong foundation in risk assessment, digital privacy, and network security. With a background in both public and private sectors, Amber has worked across diverse IT environments performing system audits, evaluating security protocols, and supporting data protection initiatives.

Her expertise includes conducting vulnerability assessments to identify and mitigate risks, supporting secure system configurations, and managing sensitive information through strong compliance practices. Amber is also skilled in implementing secure file handling protocols, auditing embedded systems, and assisting with phishing simulations and user awareness training to improve organizational resilience. She is passionate about translating technical concepts for non-technical stakeholders, improving end-user security behaviors, and enhancing privacy in AI-integrated environments.

With a Bachelor’s Degree in Applied Technology: Cybersecurity, Amber holds the CompTIA Security+ (SY0-701) certification and a level one CISSP certificate, as well as a Cybersecurity Infrastructure Technician certificate. Her proactive mindset, attention to detail, and ability to foster collaboration make her an asset to the Undaunted team and its clients.

Amber is committed to continuous learning and brings ethical judgment, strategic thinking, and a detail-oriented mindset to every engagement. To learn more about Amber and Undaunted Consulting, reach out to
hello@undaunted.llc or visit www.undaunted.llc