Authored by RSM US LLP, March 12, 2025
Donors entrust their personal and financial information to nonprofits with the expectation that organizations will protect this data from malicious actors. But as cyberthreats grow more sophisticated, nonprofits must work harder than ever to safeguard donor information. Failure to do so erodes donor trust, undermines the nonprofit’s mission and even endangers the organization’s financial foundation.
Comprehensive security awareness training can increase the ability of employees to recognize social engineering attempts. Secondary process controls are particularly effective for financial security.
For example, a nonprofit could institute a policy that any request for a financial data change must involve a secondary verification step, like a callback to an established point of contact or a safe word, to confirm the request’s legitimacy. Additionally, nonprofits should educate donors on secure practices and provide secure portals or other authorized channels for sensitive exchanges, limiting the risks of unauthorized access or the compromise of data. Helping donors recognize red flags, such as signs of social engineering, can reduce the likelihood of a security event.
Nonprofits should also implement endpoint threat detection and response tooling across their infrastructure. Organizations should require regular vulnerability assessments and remediation to identify and address security gaps that malicious actors could exploit.
Protecting donor information isn’t just about shielding sensitive data from malicious actors. It’s also about preserving the trust that sustains nonprofits. By investing in comprehensive cybersecurity measures, nonprofits can demonstrate their commitment to safeguarding donors’ data, promoting trust and mitigating the risk of security incidents.
This article was written by Gianna Kubiak and originally appeared on 2025-03-12. Reprinted with permission from RSM US LLP.
© 2024 RSM US LLP. All rights reserved. https://rsmus.com/insights/industries/nonprofit/how-nonprofits-protect-donor-information-cyberattacks.html
RSM US LLP is a limited liability partnership and the U.S. member firm of RSM International, a global network of independent assurance, tax and consulting firms. The member firms of RSM International collaborate to provide services to global clients, but are separate and distinct legal entities that cannot obligate each other. Each member firm is responsible only for its own acts and omissions, and not those of any other party. Visit rsmus.com/about for more information regarding RSM US LLP and RSM International.




