Cybersecurity Awareness Month: Essential Practices for Protecting Donor Data
Written By: Luke Ross
October is National Cybersecurity Awareness Month, and for nonprofit organizations the timing is close to perfect. It lands just as year-end giving season begins, when donor databases see their heaviest use, when temporary volunteers arrive to help with campaigns, and when a flood of legitimate appeal emails gives fraudulent messages ideal cover. Whatever attention your organization can give to security, October is the month when it produces the most value.
Donor data deserves that attention for a reason that goes beyond compliance. A donor gives you their name, their address, their giving history, sometimes their employer and their family circumstances, and often their payment details. They do it because they trust your mission and your judgment. This article covers what donor data actually includes, the practices that protect it most effectively, how to build awareness across a team of staff and volunteers, and a simple four-week plan for using the month well.
Why October Is the Right Moment for This Work
Nonprofits rarely have a dedicated security team, so security improvements tend to happen when someone makes room for them. Cybersecurity Awareness Month supplies that room. It gives you an external reason to put an hour on the calendar, a natural framing for a board update, and a shared vocabulary that makes the conversation easier with staff who do not think of themselves as technical. The organizations that get the most from it treat October as a scheduled checkpoint rather than a campaign, an approach we explored in our look back at the lessons of a previous awareness month.
The seasonal overlap matters too. Attackers pay attention to calendars, and the weeks between late October and the end of December concentrate more nonprofit financial activity than any other stretch of the year. Getting ahead of that curve is far easier in the first week of October than in the middle of a December appeal, which is the practical case for preparing before awareness month rather than during it.
What Counts as Donor Data
Organizations often picture donor data as a single database, when in reality it is spread across many systems and formats. Naming that spread accurately is the first protective step, because you cannot secure information you have not located.
Take a few minutes with your team to identify where each of the following lives in your organization, including the copies that exist outside your main platform.
Identity and contact details, including names, home addresses, phone numbers, and personal email addresses
Giving history and pledge records, which reveal capacity and personal priorities
Payment information such as card details, bank account data for recurring gifts, and processor records
Employer, affinity, and wealth screening data used for major gift work
Notes from cultivation conversations, which frequently contain sensitive personal circumstances
Program participation records that connect a donor to services they or a family member received
Event registrations, auction bids, and volunteer forms collected outside the main database
Spreadsheets and exports on staff laptops, in email attachments, and in shared cloud folders
That final category is usually the largest surprise. Exports made for a mail house, a board report, or a reconciliation rarely get deleted, and each one is a copy of your donor file living outside your controls. Locating them is exactly the kind of groundwork that supports both endpoint security across nonprofit devices and honest answers on grant applications.
Essential Practices for Protecting Donor Data
The practices below are ordered by the protection they deliver relative to the effort they require. None of them demands a large budget, and most can be implemented by a small team with good outside support.
1. Turn On Multifactor Authentication Everywhere
Multifactor authentication is the single most effective control available to a nonprofit, because it defeats the most common attack: someone using a stolen or guessed password. Enable it on email, your donor platform, payment processors, accounting software, cloud storage, and social media accounts.
Start with the accounts that can move money or export the donor file, then extend to everyone. Expect a week of adjustment questions and plan a short walkthrough so staff are not troubleshooting alone.
2. Limit Who Can See and Export Donor Records
Most people in a nonprofit need to read a narrow slice of donor data, and very few need the ability to export the entire file. Review the permission levels in your donor platform and match them to what each role genuinely requires.
Pay particular attention to volunteers, interns, consultants, and departed staff. Seasonal helpers frequently receive full access for convenience during a campaign and keep it for years afterward.
3. Train Everyone to Recognize Fraudulent Messages
Donor data is most often lost to a convincing email rather than a technical breach. Staff should know the common patterns: an urgent request from a leader who is traveling, a supposed donor asking you to update their bank details, an invoice from a vendor whose address is slightly wrong, a login page that appears one character off.
Short, frequent, low-pressure practice works better than an annual lecture. Our guides to keeping your organization safe from phishing scams and training your team in cybersecurity awareness are both good starting material for a staff meeting.
4. Keep Payment Data Out of Your Own Systems
Wherever possible, let a reputable payment processor hold card and bank details so your organization never stores them. Handle phone gifts by entering the payment directly into the processor rather than writing numbers on a form, and shred any paper that captured them.
Also make sure nobody accepts payment details by email or text, and give staff a scripted, gracious alternative to offer donors who try. Reducing what you hold reduces what you can lose.
5. Update Software and Devices on a Schedule
Attackers rely heavily on known flaws in software that has not been patched. Enable automatic updates on laptops, phones, browsers, and network equipment, and put a monthly reminder on someone's calendar to confirm they actually applied.
This unglamorous habit closes more openings than any product purchase, as we discuss in our overview of how regular software updates affect cybersecurity.
6. Back Up the Donor Database and Test the Restore
Keep an independent backup of your donor records, held separately from the live system, and confirm at least twice a year that you can actually restore from it. A backup you have never tested is an assumption rather than a safeguard.
Reliable backups are also your strongest position against ransomware, which is why they feature so prominently in guidance on preventing ransomware attacks.
7. Write Down What Happens If Something Goes Wrong
Decide in advance who gets called, who speaks to donors, who contacts your processor and insurer, and how you will document the timeline. Keep it to a page and keep a printed copy, since the plan may be needed when systems are unavailable.
A short written plan turns a frightening event into a sequence of tasks. Our guide to donor data incident response plans walks through what to include.
Working through these seven practices in order gives a small organization meaningful protection within a single month, and each one makes the next one easier to sustain.
Building Awareness Beyond the IT Team
Nonprofits run on the goodwill of many hands, which is a strength operationally and a complication for security. Awareness has to reach beyond whoever manages technology to everyone who touches donor information.
The three groups below tend to be overlooked, and each needs a slightly different conversation.
Board Members and Senior Leadership
Board members receive donor lists, financial reports, and campaign updates, usually on personal devices and personal email accounts. Give them a brief annual orientation on handling those materials, and be explicit that leadership impersonation is a favorite tactic of fraudsters.
Leadership attention also determines whether security stays funded, which is part of why a genuine security culture has to start at the top rather than in the server closet.
Volunteers and Seasonal Staff
Volunteers deserve clear, friendly instruction rather than a policy document: what they may access, what they must not copy, who to ask, and how to report something odd without fear of blame. Set access to expire at the end of the engagement by default.
Program Staff Who Serve Clients
In many organizations, the same person may see both program records and donor records, and the ethical stakes of mixing them are high. Make the boundary explicit, and make sure the reporting path for a suspected problem is short and safe to use.
A Four-Week Plan for October
If you want one concrete way to use the month, spread the work across four short sessions instead of one long project.
Week one: locate your donor data using the list above and note every copy outside the main platform.
Week two: enable multifactor authentication on financial and donor systems and review who holds export rights.
Week three: hold a thirty-minute staff and volunteer conversation about fraudulent messages, using real examples your organization has received.
Week four: verify a backup restore and draft or refresh your one-page incident plan, then send a brief summary to your board.
Four sessions, roughly four hours, and your organization ends October materially safer than it began.
Protecting Data, Protecting Trust
Donor data protection is ultimately relationship protection. People give because they believe your organization is careful, competent, and worthy of the information they hand over, and that belief is difficult to rebuild once shaken. The good news is that the practices that matter most are neither expensive nor exotic: strong logins, tight access, informed people, minimal stored payment data, current software, tested backups, and a plan on paper.
Use this October to move a few of them from intention to reality, then put the next checkpoint on the calendar so the progress holds. Kotman Technology helps nonprofit organizations protect donor information without diverting resources from the mission, and the same discipline strengthens your position when pursuing grants that ask how you safeguard data. Reach out to talk through your current setup, or learn more about IT support designed for nonprofit organizations.
Kotman Technology has been delivering comprehensive technology solutions to clients in California and Michigan for nearly two decades. We pride ourselves on being the last technology partner you'll ever need. Contact us today to experience the Kotman Difference.