Sunday morning, the sound board volunteer is out sick and nobody else knows the login. The check-in laptop is a donated machine from a member’s old office, it takes four minutes to wake up, and the person who set it up moved away years ago. The giving platform works, thankfully, because that one you cannot afford to have break. Somewhere there is a spreadsheet with every donor’s name, address, and giving history, and it has been emailed around more times than anyone wants to count.
None of that means anyone did anything wrong. It means the organization grew the way nonprofits and churches actually grow: on the goodwill of people who volunteered a Saturday, on hardware somebody handed over, and on a budget where every dollar spent on technology is a dollar not spent on the mission. Here is how to tighten things up without a big check. One note first: this is general information, not legal or compliance advice. If your organization handles donor data, processes card gifts, or works with children, a qualified advisor or attorney needs to confirm what applies to you.
The Volunteer Account Nobody Ever Closed
This is the most common gap we find, and it is not unique to faith based groups. People join, get an email address and access to a shared drive, serve faithfully for two years, then step back. Nobody removes the account, because removing accounts is nobody’s job. Five years on, an organization with twelve active people has forty live logins. The risk is not that a former volunteer turns malicious. It is that an old, unwatched account is exactly what someone else takes over, and nobody notices because nobody was watching.
- Make one list. Every login you own, who holds it, when it was last used. A spreadsheet is fine.
- Attach it to the exit conversation. Closing the account goes on the same checklist as returning the key. Review the whole list twice a year.
- Give access by role, not by person. “Whoever runs children’s check-in” is a role. Build access around that and handoffs stop being a crisis.
The Shared Login Problem
Nearly every small organization has one: a password everyone on the team knows, written somewhere in the office, unchanged since a board member set it up. It is understandable. Individual accounts felt like overhead. But shared logins have a specific failure mode. When leadership rotates, and it always does, nobody can say who has the password anymore, so nobody changes it, because changing it would break something for someone unknown.
- Individual accounts wherever the software allows it. Then a departure means removing one person, not resetting the world.
- Use a password manager for the rest. Some systems genuinely have one login. A shared vault lets you rotate it centrally instead of texting it around.
- Turn on multi-factor authentication. This is the highest value free thing most organizations can do. If you want the plain English comparison, we wrote one on YubiKey versus passkeys versus standard MFA.
- Two people, never one. At least two trusted people should be able to get into anything critical. One is a single point of failure.
Donor Data Deserves the Same Care as Customer Data
People give you their name, address, phone number, email, giving history, and sometimes a note about why they gave. In a congregation, records may touch families, children, and pastoral care. That information is at least as sensitive as anything a business holds about a customer, and donors would be surprised how casually it often gets handled.
The Federal Trade Commission’s business guidance “Start with Security,” published in August 2023, opens with a principle that translates perfectly here: “No one can steal what you don’t have.” The FTC also advises holding information “only as long as you have a legitimate business need,” limiting access on a need to know basis, and requiring complex and unique passwords. That is a strong starting checklist for a nonprofit board.
- Stop emailing the donor spreadsheet. Every copy in an inbox is another place it can leak. Share a permissioned link instead.
- Not everyone needs the giving records. Plenty of volunteers need contact information. Very few need to see amounts.
- Keep it in one system. Scattered copies on personal laptops cannot be protected.
- Ask vendors what they do with it. The FTC advises putting security expectations in writing with service providers, then verifying rather than assuming.
Donated Hardware of Every Vintage
Donated equipment is a real gift and we would never tell you to turn it down flatly. But a computer too old to receive security updates is not free. It is a liability handed over with a bow on it, and it usually lands on the volunteer least equipped to deal with it.
- Ask one question first: can it still get updates? If the manufacturer no longer supports it, thank the donor and decline gracefully.
- Wipe and rebuild every donated machine. You do not know what was on it, and the donor’s old files are now your problem.
- Keep old equipment off the main network. If a device must stay for one job, isolate it and keep it away from donor records.
- Ask donors for money instead. Three hundred dollars toward a supported machine beats a free one that fails in eight months.
Free and Discounted Software You May Qualify For
Budget is genuinely tight, so this part matters. Major technology vendors run nonprofit programs, and many organizations qualify without realizing it. Microsoft, for example, publishes nonprofit offers that include free access to a business productivity plan for a capped number of users, annual cloud service credits, and discounted security add-ons, with organizations asked to register and confirm eligibility. Offers and eligibility rules change over time, so confirm current terms with the vendor rather than relying on any article, including this one.
Ask every vendor you already pay whether they have a nonprofit rate. Many do and never advertise it. The savings often fund the security work you have been postponing.
Protecting Online Giving
Online and mobile giving is now how a lot of support arrives. Two things matter most. First, use a reputable giving provider that handles card data on their systems, so card numbers never sit on your laptops or in your files. Second, protect the accounts that control the money. The realistic attack is not someone breaking your giving page. It is someone getting into a staff email account and quietly redirecting where funds land.
The related risk is the impersonation email. A message that looks like it came from your pastor or director, urgently asking a bookkeeper to move money or buy gift cards, has separated a lot of good organizations from real money. The defense is a rule everyone knows: any payment change or unusual request gets verified by phone, on a number you already had. More on why these are so hard to block in our piece on the surge in phishing attacks.
The Bottom Line
CISA and partner agencies including the FBI published guidance titled “Mitigating Cyber Threats with Limited Resources: Guidance for Civil Society,” aimed at nonprofits, faith based organizations, and similar groups, on the premise that they are meaningfully targeted and rarely have a budget to match. The good news is that the highest value steps cost almost nothing: close old accounts, stop sharing logins, turn on multi-factor authentication, keep donor data in one controlled place, and verify money requests by phone. To repeat what we said at the top, this is general information rather than legal or compliance advice, so have a qualified advisor confirm what applies to your organization.
We work with churches and nonprofits around Denton County, and we know the budget conversation is real. If you want an honest look at where you stand and a short list of what matters first, we are glad to help. Contact us today.
Sources:
Comments are closed