IT and Cybersecurity Checklist for Nonprofits and Charities

A nonprofit or charity needs IT that protects donor trust and keeps a small team working: an inventory of every system and who controls it, individual accounts with multi-factor authentication for staff, volunteers and board members who touch donor data, a same-day offboarding process for people who leave, a call-back rule for any payment or banking change, SPF, DKIM and DMARC on your email domain, tested backups of the donor database and finance files, and written evidence of all of this for your board and your insurer. The difference from a typical business is the people. Charities rely on volunteers, part-time staff and board members who come and go, often on personal devices and shared logins, and that turnover is where most problems start.
This checklist is for executive directors, operations and finance managers, and the staff member or volunteer who ends up looking after technology at charities, nonprofits, foundations and community organizations in Ontario. It is written by IT Rapid Support, a managed IT and cybersecurity provider at 7810 Keele St in Vaughan, so read it with that in mind; the checklist applies whoever runs your IT.
Start With a Systems Inventory
You cannot protect what nobody has written down. List every system you rely on to raise money, run programs and pay people:
- Email, calendars and files, usually Microsoft 365 or Google Workspace.
- The donor or member CRM and any fundraising, event or peer-to-peer platform.
- The online donation page and payment processor, plus any tap or card terminals used at events.
- Accounting, payroll, banking portals and the system used to issue tax receipts.
- Program or client case management systems, which may hold sensitive information about the people you serve.
- The website and domain registrar, social media accounts and email marketing tools.
- Laptops, phones, printers, the internet connection, Wi-Fi and any office or program-site equipment.
For each one, record who supplies it, who the administrators are, where the admin login is kept, and when the subscription renews.
Donor Data and CRM Access
- Give access by role. Most volunteers and many staff need to see contact details or event lists, not giving history, bank details or notes about major donors.
- Stop exporting the full donor list to spreadsheets on personal laptops or USB keys. If an export is needed for a mailing, delete it when the job is done.
- Keep sharing settings in OneDrive, SharePoint or Google Drive restricted to your organization by default, and check for old links shared with "anyone".
- Never store full card numbers. Let the payment processor handle card data so it never sits in your CRM, email or spreadsheets.
MFA, Shared Accounts and Volunteers
- Turn on multi-factor authentication for every staff account, every administrator and anyone with access to donor data, finance or banking. Our multi-factor authentication guide explains which methods to choose.
- Replace shared logins such as a single "info@" or "volunteer@" account that several people sign into. Use shared mailboxes or group access attached to individual accounts so you can see who did what and remove one person without changing everyone's password.
- Where a shared credential cannot be avoided, keep it in a password manager, not a sticky note or a group chat, and change it when anyone with access leaves.
- Volunteers who handle donor or client information get their own accounts with the least access their role needs, and a short orientation on phishing and privacy.
Offboarding Staff, Volunteers and Board Members
- Keep a written offboarding checklist and run it on the person's last day: disable the account, remove CRM and finance access, revoke shared drive and social media access, and change any shared passwords they knew.
- Collect organization-owned laptops and phones, or wipe organization data from personal devices if they were enrolled in device management.
- Review volunteer access at the end of each campaign, event or season. Volunteer accounts are the ones most often left open for months.
Microsoft 365 and Google Nonprofit Programs
Both Microsoft and Google run programs for eligible registered charities and nonprofits that include donated or discounted versions of their productivity and security tools, and other software and cloud vendors offer similar programs. Eligibility rules and what is included change from time to time, so check the current terms directly with each vendor. Licences only help once they are configured: MFA, mailbox auditing, sharing restrictions and device policies mostly need to be switched on.
Donation, Payment and Impersonation Fraud
Charities are attractive targets for email fraud because they publish their leadership, their board and their events, and because staff want to be helpful. The common patterns are a message that appears to come from the executive director asking for gift cards or an urgent wire, a vendor or grant recipient "updating" their banking details, and fake donation pages or refund requests after a large gift.
- Any request to change vendor, payroll, grant recipient or refund banking details is confirmed by phone using a number you already have, never the one in the email.
- Requests from the executive director or board chair for gift cards or urgent transfers are treated as fraud until confirmed in person or by a known phone number. Tell staff and volunteers that leadership will never ask for this by email or text.
- Payments above a set threshold need two people to approve them.
- Run short, regular phishing awareness sessions for staff and active volunteers. Our guide to stopping phishing attacks covers what to teach.
Email Authentication: SPF, DKIM and DMARC
Your domain should publish SPF, DKIM and DMARC records so that criminals cannot easily send email that appears to come from your organization to donors, funders or your own staff. SPF lists the services allowed to send as your domain, DKIM signs your outgoing mail, and DMARC tells receiving mail servers what to do with messages that fail those checks. Include every service that sends on your behalf, such as your email marketing platform, CRM and donation receipts, then move DMARC toward enforcement once legitimate mail passes. Our SPF, DKIM and DMARC explainer walks through the records, and the free email spoofing check shows where your domain stands today.
Backups and Recovery
- Back up the donor database, finance and payroll data, shared files and mailboxes. Cloud platforms keep your services running, but deleted or encrypted data may not be recoverable without a separate backup.
- Keep at least one copy that ransomware on your network cannot reach, and test a restore at least twice a year.
- Know how you would issue tax receipts, pay staff and reach donors if your main system were unavailable during a year-end campaign.
- Write down who decides and who to call if an account is compromised or data is exposed. Our IT emergency checklist covers the first hour.
Board Reporting and Cyber Insurance Readiness
Boards are increasingly expected to oversee cyber risk, and insurers ask detailed questions before they renew a policy. A one-page report each quarter is usually enough: MFA coverage, number of accounts with admin rights, accounts removed for departed staff and volunteers, backup and restore test results, phishing training completed, and any incidents. The same evidence answers most insurance questionnaires; our cyber insurance readiness checklist lists the controls insurers ask about and the records to keep on file.
Privacy Obligations
Charities hold sensitive information about donors, members, clients and volunteers. Which privacy law applies depends on the organization and the activity. PIPEDA may apply to some commercial activities of charities and nonprofits, such as selling donor lists or certain fundraising and retail operations, while health information or work funded under government agreements can bring in other rules. Confirm with your counsel which obligations apply to you. The technical safeguards in this checklist, access control, MFA, encryption and tested backups, are expected either way, and our PIPEDA compliance IT checklist explains the breach record-keeping side.
What to Ask an IT Provider
- Have they managed Microsoft 365 or Google Workspace for charities, including nonprofit licensing and the security settings that come with it?
- How do they handle joiners, leavers and volunteer accounts, and is the process documented?
- Is their helpdesk available 24/7, and how fast does a person answer when a staff member is locked out the night before a gala or a year-end campaign?
- How do they protect and back up the donor database, and how often do they test a restore?
- Is the agreement clear about what is included, and is project work scoped and quoted in writing before it starts? Our guide on what a managed IT contract should include lists the clauses to check.
How IT Rapid Support Works With Nonprofits
IT Rapid Support provides managed IT, Microsoft 365 administration and cybersecurity for charities, nonprofits and community organizations across the Greater Toronto Area from our office at 7810 Keele St in Vaughan. Our helpdesk is available 24/7, we work alongside your staff, volunteers and existing software vendors, and on-site work is dispatched across the GTA. Support is scoped to your users, devices and data, and projects are scoped and quoted in writing. The service details are on our page for managed IT services for nonprofits and charities. To review your organization against this checklist, call (289) 582-9930 or contact us.
Frequently Asked Questions
What IT security does a small charity need?
At minimum: an inventory of your systems and their admin logins, individual accounts with multi-factor authentication for everyone who touches donor, finance or client data, same-day offboarding for staff and volunteers, a call-back rule for any banking change, SPF, DKIM and DMARC on your email domain, and tested backups of the donor database and finance files.
How should a nonprofit manage volunteer accounts?
Give each volunteer who needs system access their own account with only the access their role requires, rather than a shared login. Review volunteer access at the end of each campaign or season, and disable accounts the day someone stops volunteering.
Can charities get Microsoft 365 or Google Workspace through a nonprofit program?
Yes. Microsoft and Google both run programs for eligible registered charities and nonprofits that include donated or discounted editions of their tools. Eligibility and what is included change, so check the current terms with each vendor, and make sure the security features are actually configured once you have the licences.
How do we stop gift card and wire fraud that impersonates our executive director?
Tell staff and volunteers in writing that leadership will never ask for gift cards or urgent transfers by email or text, confirm any such request in person or by a known phone number, require two approvers for payments over a set amount, and publish DMARC on your domain so your executive director's address is harder to spoof.
Does PIPEDA apply to charities and nonprofits?
It can. PIPEDA may apply to some commercial activities of charities and nonprofits, such as selling or renting donor lists, while other activities and other types of information may fall under different laws. Confirm with your counsel which obligations apply to your organization; the technical safeguards in this checklist are expected either way.
What should a nonprofit report to its board about cybersecurity?
A short quarterly report covering MFA coverage, the number of admin accounts, accounts removed for departed staff and volunteers, backup and restore test results, phishing training completed, and any incidents and how they were handled. The same evidence supports your cyber insurance renewal.
Share this resource

IT Rapid Support Team
Managed IT & Cybersecurity, GTA
IT Rapid Support Team is a security expert with extensive experience in creating security guidelines.
More from this authorRelated Resources

IT and Cybersecurity Checklist for Schools: Accounts, Devices, Wi-Fi and Student Data
The IT and security controls a private or independent school needs: student and staff accounts with MFA, Chromebook and laptop fleets, separate student, staff and guest Wi-Fi, content filtering, student records privacy, tuition and vendor payment fraud, backups, the summer refresh and what to ask an IT provider.
Read more: IT and Cybersecurity Checklist for Schools: Accounts, Devices, Wi-Fi and Student Data
IT and Cybersecurity Checklist for Restaurants: Keeping the POS, Wi-Fi and Card Data Safe
The IT and security controls a restaurant needs: keeping the POS running during service, internet failover, separating guest Wi-Fi from payment systems, PCI DSS basics, staff turnover and shared logins, delivery platform and payment fraud, multiple locations and what to ask an IT provider.
Read more: IT and Cybersecurity Checklist for Restaurants: Keeping the POS, Wi-Fi and Card Data Safe
IT and Cybersecurity Checklist for Manufacturers: A Practical Guide for Ontario Plants
The IT and security controls a manufacturer needs: separating office IT from the plant floor, containing legacy machine PCs, ERP and EDI uptime, backups of machine programs, vendor remote access, payment fraud, customer security questionnaires, shift coverage and what to ask an IT provider.
Read more: IT and Cybersecurity Checklist for Manufacturers: A Practical Guide for Ontario PlantsNeed Expert Security Advice?
Our team of cybersecurity experts is ready to help you secure your organization. Schedule a free consultation today.
Get in Touch