Every October, Cybersecurity Awareness Month gives us a reason to pause and ask a question that's easy to put off: if something went wrong tomorrow, would we be ready?
For many nonprofits, the honest answer is "not quite." Most organizations hold sensitive information about donors, clients, volunteers, and staff, and their missions depend on the trust of the people they serve. Yet limited budgets, small (or nonexistent) IT teams, and competing priorities leave a gap between the protection they need and the protection they have. We call it the digital safety gap, and closing it is one of the most important tech trends for nonprofits heading into the final quarter of 2026.
Here's where to focus.
Generative AI has made phishing emails more convincing, more personalized, and much harder to spot. The old advice to look for typos and awkward phrasing doesn't hold up when a scammer can generate flawless, on-brand messages in seconds. Voice cloning and deepfake video add another layer, such as a "call" from your executive director asking finance to rush a payment.
What to do: Build verification habits that don't depend on spotting a bad email. Require a second channel, like a quick call to a known number, for any request involving money, credentials, or sensitive data. Make it normal, not awkward, for staff to double-check.
Staff is already using AI tools to draft grant proposals, summarize meeting notes, and analyze spreadsheets. That's often a great use of limited time, but pasting donor records or client case details into a public AI tool can create real privacy and compliance exposure.
What to do: Don't simply ban AI (regulating is incredibly more effective). Write a simple, plain-language AI acceptable use policy. Spell out which tools are approved, what data should never be entered, and whom to ask when someone isn't sure. A one-page policy that people actually read beats a ten-page one that no one does.
Stolen credentials remain one of the most common ways attackers get in. Multi-factor authentication (MFA) blocks the vast majority of those attempts, and newer options like passkeys make strong security easier on users, not harder.
What to do: Turn on MFA for email, file storage, your CRM, and financial systems first. Adopt a password manager across the organization. Where your platforms support passkeys, start piloting them.
Nonprofits rely on a growing web of cloud platforms: donor databases, payment processors, email tools, volunteer portals. A breach at one of your vendors can become your problem, and your donors will hold you accountable.
What to do: Take inventory of the tools that touch sensitive data. Ask vendors about their security practices, including encryption, MFA, and breach notification. Remove accounts and integrations you no longer use.
What to do: Write down a one-page "who does what" plan for a security incident. Confirm that backups are stored separately and actually restore. Run a short tabletop exercise with leadership. Even 30 minutes of "what would we do if..." reveals gaps.
Technology only goes so far. Staff and volunteers who understand the risks and who feel safe reporting mistakes are your best early warning system. The goal of training isn't to catch people out; it's to build confidence and shared responsibility.
What to do: Keep training short, regular, and relevant to real nonprofit scenarios. Celebrate people who report suspicious messages, even when it turns out to be a false alarm.
If this list feels overwhelming, start small. This week, you can:
Closing the digital safety gap doesn't happen all at once, but each step protects the people and the mission you work so hard for.
Not sure where your organization stands?
Our team at Roundtable helps nonprofits assess their security posture and build practical, right-sized protection. Reach out for a conversation about your digital safety strategy heading into 2027!
Want free resources?
Check out our free webinars for cyber-safe training fit for your whole team!