Nonprofits often handle sensitive donor, staff, volunteer, and program information with small teams and limited time. That does not mean security has to become a full-time project. A few repeatable steps can reduce common risks and make it easier to respond when something goes wrong. Use this checklist to review account access, software updates, backups, and daily work habits. Start with the steps you can complete this week, then assign someone to keep the routine going.
Secure accounts and access
Turn on multi-factor authentication for email, financial services, cloud storage, and other important accounts. It asks users to confirm their identity with an additional step, so a stolen password alone is less likely to open the door. Use a password manager to create and store unique passwords instead of reusing one across services. Prioritize accounts that can reset other passwords, such as your organization’s email administrator account.
Review who can access each system. Remove accounts for former employees and volunteers promptly, and limit administrator privileges to people who need them. Shared logins make it difficult to see who took an action and complicate offboarding, so give each person an individual account where possible. Keep a simple record of key systems, their owners, and the steps to regain access if an administrator is unavailable.
Keep software current
Install updates for computers, phones, browsers, apps, and network equipment. Updates often fix security weaknesses, so postponing them indefinitely can leave known gaps in place. Enable automatic updates when available, and set a recurring time to check devices that do not update on their own. Restart devices when needed to finish installing updates rather than repeatedly dismissing reminders.
Make sure every device used for nonprofit work receives updates, including staff-owned phones and laptops if they access organizational email or files. Decide who will check that routine and how people should report an update problem. If a device or application no longer receives security updates, plan to replace it or stop using it for sensitive work. Keep an inventory so unsupported tools do not quietly remain in use.
Make backups you can restore
Back up important files, including financial records, donor information, program documents, and contact lists. Use a backup method that runs on a schedule and covers the locations where your team actually stores work. A file saved only on one laptop or in one shared folder may not be recoverable after theft, damage, or a compromised account.
Protect backups from ordinary user accounts where possible, and restrict who can change or delete them. Test restoring a few files on a regular schedule; a backup is only useful if it works when needed. Write down who handles recovery and where to find instructions. Include cloud-based services in your plan, and check what recovery options your provider offers rather than assuming every deleted or changed file can be restored.
Build safer daily habits
Pause before opening unexpected links or attachments, even when a message appears to come from a familiar person. Check the sender’s full address and confirm unusual requests through a separate channel, especially requests to send money, change payment details, or share sensitive information. Report suspicious messages to a designated contact instead of forwarding them to coworkers, where they may be opened by someone else.
Use approved tools to share files, and check recipient names and permissions before sending donor or staff information. Lock screens when stepping away, use secure connections for work, and avoid handling sensitive records on public computers. Keep a short reporting plan where staff can find it: who to contact, what details to share, and what to do if an account or device may be compromised. Quick reporting gives your team more options.
Choose one person to own this checklist and review it regularly, especially when staff, volunteers, devices, or services change. Record what is complete and assign a next step for anything unfinished. Small, consistent practices can make your nonprofit more resilient without adding unnecessary complexity. Cape Fear Cyber can help your Wilmington nonprofit review its security practices and plan practical next steps.