3 Improvements Your Nonprofit Can Make to its Data Protection and Cybersecurity Practices
Investing in cybersecurity and data protection practices can seem like a big challenge for a lot of community groups – maybe because of time and maybe because of knowledge. But nonprofits keep a lot of very sensitive data, often about people who are also vulnerable in other ways. In this blog post, we are going to share three key ways you can improve your data protection practices.
Table of Contents
Passwords
You have certainly heard this before, but you really need a better password! Password attacks are one of the most common threats on the internet, and passwords are the cornerstone of improving security practices for your organization. Many of us might imagine an attacker sitting down to guess the name of a beloved childhood pet and then manually entering their guesses into a login page. But the reality of password attacks looks pretty different. Password attacks are:
- Automated: In most attacks, computers are doing the guessing.
- Often offline: Attackers are often trying to resolve a scrambled (hashed) password they have retrieved from a dataleak or otherwise captured. This means that they’re not interacting with the login page directly and are not limited by lockouts from too many bad guesses.
- Very fast: Automated tools can make millions of guesses a second.
- Use lists of common words and passwords: Attackers will increase their chances of guessing the right password, by using lists of common words and passwords compiled from historical leaks.
- Easiest when people reuse passwords for multiple accounts: attackers will test a password from one compromised account against any other associated accounts they can find.
Password Strength
This is why it is extremely important to use strong passwords for your accounts. A strong password is:
- Unique
- Randomly generated
- At least 16 characters long
So a bad password could look like: Ilovedogs!
And a good password could look like: =skQ*BkfO6G_q2ml
Password Management
If all of your passwords are 16 characters or longer and randomly generated, it will become very hard to remember them. That is why we recommend using a password manager to keep track of your passwords!
With a password manager, you can:
- Easily generate secure passwords
- Track and organize unique password for every account
- Save passwords securely
There are also password management solutions for organizations (such as Proton Pass, 1Password and Bitwarden, among others), which allow you to create groups of passwords that you can share with several users at once. This is useful for organizations that have a lot of shared accounts, as it will allow you to:
- Share password securely between team members
- Control which team members can access which passwords
- Ensure that authorized team members have up-to-date passwords whenever shared passwords are changed
Even if all your passwords are stored in a password manager and you don’t need to remember them, you will still need to remember the password to your password manager. For that, we recommend using a human memorable strong password (also sometimes called a passphrase), which is a collection of random words that are easier for humans to remember than a collection of random characters while still being hard for computers to guess.
An example of this is: Stargazer-Spearfish-Flashing-System-Directory
Limit Shared Accounts
If your organization is using an online service (such as Canva, Eventbrite, Zeffy, etc.), you might have a single organizational account and multiple people using the same login credentials to use the service. Obviously, a shared password like this is a risk. When you are using an account that is shared in this way:
- Limit the number of people who use this account. The fewer people share the same account the better.
- Shared accounts should be created using an organizational email address (for ex: info@ or communications@ rather than jane@). This way if Jane leaves the organization and you deactivate her email address, the account will remain accessible.
- Some services (like Canva and Zeffy) allow for federated organizational accounts, where each person using the service has their own account and there is an admin who manages their access to the organizational account. Create a federated account wherever this is possible! Every user will be responsible for their own credentials and since you won’t need to share passwords this will reduce the risk of password leaks.
- Ensure that passwords for shared accounts are shared securely – don’t just email them to each other!
Software Updates
All software has vulnerabilities, and when a vulnerability is discovered the managers of the software will roll out updates to fix these vulnerabilities. That is why it is extremely important to keep both your computer’s operating system and any applications or programs that you use on it (such as the Zoom desktop application, Office, or your browsers) up to date. A lot of us postpone those until the last minute, and that really weakens your organizations’ cybersecurity.
Updates should be:
- Regular
- Automated wherever possible
If a software that you use no longer receives updates, it is important to replace it with another solution. We also recommend that you think about creating a clear procedure for your organization that details who is responsible for updating computers and how often these updates need to be done.
Data Backup and Recovery
Backups are an important part of your defense against cyberattacks and other incidents. If you have reliable backups it will be much easier to recover from any cyber incidents that come your way, whether that’s malware or simply a coffee-damaged laptop. We recommend that you:
- Backup important data on a regular schedule, especially if they are not stored on a cloud service.
- Where possible, try to automate backups.
- Ensure backups are stored securely (encrypted).
- Avoid “single points of failure”. This means that any services that you manage have more than one administrator account and that you have a backup plan in case an essential service that you use becomes unavailable.
If you are using a cloud service, such as Google Workspace or Sharepoint, the service provider will have backup measures in place to ensure the safety of your data. In these cases doing your own backups are less critical. However if you have the time and capacity to backup all or part of your data (maybe the most critical information) we recommend that you consider doing this, as no service can 100% guarantee the safety of your data. This could look like periodically downloading certain documents and storing them in an encrypted hard drive or a different cloud service.
Other Tech Resources for Community Groups
We initially shared this information as part of an Ateliers/C called “Reflections on cybersecurity issues in your organization”, and we may offer more workshops there about technology for nonprofits!
You can always reach out to us using our intake form to learn more about the support we offer to organizations with their information technology needs.










