Tech Risk Management for Nonprofits
Executive Director Boot Camp Session :
Technology Risk Management
Summary
What: Technology Risk Management for Executive Director Boot Camp
When: Tuesday, April 28, 2026 | 3-3:45pm
Where: Chaffee County Fairgrounds - Executive Director Boot Camp Classroom
Who: Executive Director Boot Camp Track Attendees
Why: Nonprofits are fueled by trust, yet 27% of organizations worldwide fell victim to cyberattacks in 2023. While 75% of nonprofits do not actively monitor their networks, the consequences of a breach go beyond finances to include severe reputational damage. This 45-minute session moves beyond technical jargon to address the "monsters" threatening your impact—from internal occupational fraud to the emerging risks of autonomous AI agents. We will cover the "Security Fulcrum"—balancing operational ease with data protection—and provide a 3-step action plan to ensure your mission isn't derailed by preventable risks.
*** All materials on this page can be shared, downloaded, and used in any of your internal materials. **Supplemental Materials
Videos summarizing risks and strategies for nonprofits managing technology risks
Video Description: A Target on Your Mission
Is your nonprofit’s "noble mission" actually putting a bullseye on your back? In this episode, we expose why cybercriminals are ditching corporate giants to hunt in the nonprofit sector. We’re breaking down the disturbing reality of "A Target on Your Mission," exploring how hackers exploit the unique trust and limited resources of organizations dedicated to doing good.
From food banks losing millions to phishing to global humanitarian organizations having terabytes of sensitive data stolen, the threat is no longer a "what if"—it’s a "when".
What you’ll learn in this video:
The "Easy Target" Myth: Why a staggering 68% of nonprofits have confirmed at least one data breach in the last three years.
The Treasure Trove: How sensitive donor data—Social Security numbers and financial records—is harvested and sold on the dark web.
Shadow Entry Points: The danger of unvetted third-party vendors and why they represent the "weak link" in your security chain.
The Training Gap: Why 90% of nonprofits fail to provide regular cybersecurity training, leaving staff and volunteers vulnerable to sophisticated social engineering.
Ideological Warfare: Understanding "hacktivists" and state-sponsored groups who launch DDoS attacks specifically to disrupt your mission and values.
Stop being an easy target. We’ll show you how to leverage affordable tools and "Zero Trust" architecture to protect your reputation and ensure your mission continues unhindered.
Key Resources Mentioned:
Digital First Aid Kit: A free resource for diagnosing security issues in real-time.
TechSoup Security Products: Discounted software solutions for qualifying nonprofits.
CISA.gov: The official guide for critical infrastructure and cybersecurity best practices.
The Night of the Living Threat
Think your nonprofit’s mission makes you immune to hackers? Think again. Pull back the curtain on "The Night of the Living Threat," a deep dive into the 2026 post-mortem of a catastrophic infrastructure wipeout. We break down how a single AI coding agent, given unrestricted access to production systems, deleted 2.5 years of critical data in just minutes.
This isn't just a horror story for DevOps; it’s a wake-up call for the entire nonprofit sector. While organizations are busy changing the world, cybercriminals are busy exploiting their limited budgets and outdated protocols.
What you’ll learn in this video:
The $10 Mistake: How a small decision to save a few dollars on cloud costs created a "blast radius" that leveled an entire production environment.
The Rise of Wiper Attacks: Why state-directed groups are increasingly targeting US organizations with destructive malware.
Nonprofits in the Crosshairs: The sobering reality that 27% of nonprofits worldwide have already fallen victim to cyber-attacks.
The "Vibe Coding" Danger: Why autonomous AI agents lack the intuitive risk assessment of an experienced engineer.
Proactive Defense: 5 essential safeguards—from Just-In-Time (JIT) access to immutable backups—that can save your mission from vanishing overnight.
Don't let your mission become a post-mortem. Watch now to learn how to build a culture of security that protects your donors, your data, and your impact.
Key Resources Mentioned:
NTEN Tech Accelerate: Free assessment tool for nonprofit digital maturity.
NIST Cybersecurity Framework: The gold standard for identifying and recovering from threats.
AWS Business Support: Why upgrading your support tier before a crisis is a mission-critical investment.
Infographics
Download and share with your board, staff, and volunteers.
Resource Bibliography
Immediate Action
(Monday Morning Moves)
CISA - No Cost Cybersecurity Tools : The gold standard for free toolkits and incident response templates.
NIST Small Business Cybersecurity Corner: Policy templates for Acceptable Use and Data Privacy.
ACFE 2024 Report to the Nations: Benchmark data on internal fraud to share with your Board
Deep Dive
(Long-Term Strategic Planning)
NTEN Nonprofit Tech Readiness: (NTEN = Nonprofit Technology Enterprise Network) Cohorts for tech that is geared towards nonprofits.
NTEN Courses for nonprofit technology: variety of video courses
TechSoup Cybersecurity Courses: Affordable training for your staff and volunteers.
Level5 Management CSRA Grant: Information on applying for free cybersecurity risk assessments.
Access Now Digital Security Helpline: Real-time assistance if you believe you have been hacked.