Sentry CTO

Nonprofits

Your board is asking. You need an answer you can prove.

Nonprofits are targeted more than their leaders expect, and for a reason that has nothing to do with how much money they hold. They tend to have real donor data, lean administrative staff, tight budgets, and a culture of trust, which is an excellent combination if you are trying to get in.

We work with a local nonprofit whose engagement began as ordinary IT support and became a security conversation when their board started asking questions management could not answer with evidence. We assessed them, presented the findings directly to the board, and they upgraded. They signed for three years and later renewed for five.

What makes this different

The pressures specific to nonprofits.

The board carries the responsibility

Directors have fiduciary duties, and cybersecurity has become part of that. What a board needs is not reassurance from staff. It is independent evidence they can minute and act on.

Donor data is the crown jewels

Names, addresses, giving history, sometimes payment details. A breach here does not just cost money; it damages the trust the organization runs on, and donors do not always come back.

Grant and funder requirements

Funders increasingly ask about data protection in applications and reporting. An organization that cannot answer may find itself quietly screened out of opportunities it never knew it lost.

Volunteers and turnover

People join, help for a season, and move on, often without a formal offboarding process. Accounts accumulate. We routinely find active logins for people who left years ago.

Every dollar is scrutinized

Spending on infrastructure competes directly with program spending, and that is a genuinely hard argument to make to a board. It is easier when the numbers are in front of them.

A client

A five-person chapter that took it to the board

A small team with real donor data and real obligations. We ran an assessment, presented the findings to the board of directors, and they approved the upgrade in that meeting. Initially three years, later renewed at five.

Details anonymized. Figures are real.

People on staff
5
Signed, then renewed
3 → 5 yr

Questions we get

From nonprofits, specifically.

We are five people. Do we really need this?

Some of it. Not all of it, and we will tell you which. Our smallest client is a five-person nonprofit, so the answer is clearly not "small organizations should do nothing", but it is also not the same package a thirty-person firm needs. The assessment exists precisely so the answer is specific to you rather than generic.

Will you present to our board?

Yes, and we would encourage it. Nonprofit decisions get made by a group, and the assessment briefing works considerably better when the people who vote are in the room hearing it first-hand rather than receiving a summary. We have done this and it is often the moment the conversation changes.

Do you offer nonprofit pricing?

There is nonprofit pricing available on several of the underlying products, and we pass that through rather than keeping it. We are not able to discount our own labor much, but the savings on licensing are real and we will show you exactly where they apply.

How do we justify this to our board against program spending?

By making it concrete. Not "cybersecurity is important," but what a two-week outage would cost in staff time and disrupted programs, what a donor data breach would cost in notification and lost giving, and what your insurance would and would not cover. Boards respond to that arithmetic far better than to threat statistics.

The next step

Find out where your nonprofit actually stands.

Three minutes, nine areas, no email address. Or book fifteen minutes and we will tell you honestly whether an assessment makes sense for an organization your size.

No pitch on the first call. If we are not a fit, we will say so and point you somewhere better.