Nonprofit Data Security
Nonprofit data security, run by CISSP and CISA certified engineers.
ETTE protects donor, client, grant, and financial data for nonprofits in Washington, DC and nationwide. Senior engineers holding CISSP and CISA certifications design the controls, our help desk runs them every day, and your board gets a plain-language security report each quarter. Support is bilingual in English and Spanish.
What Is at Risk
The data a nonprofit holds, and who wants it.
A nonprofit with 30 staff typically holds donor payment records, client case files, grant reports, payroll, and board minutes spread across Microsoft 365 or Google Workspace, a CRM, and an accounting system. Attackers target that mix because it is valuable and lightly defended. Business email compromise aimed at finance staff, ransomware on shared files, and account takeover through a reused password are the three incidents we are called into most often.
Funders, insurers, and state regulators now ask how that data is protected before they renew. The controls below are the ones their questionnaires ask about, and they are included in every ETTE managed plan rather than sold as a separate security program.
Controls ETTE Manages
Eight controls, named and owned.
Where your organization runs Microsoft 365 Business Premium, Defender for Business, Defender for Office 365 Plan 1, Intune Plan 1, and Entra ID P1 are already in the license at the $5.50 per user nonprofit price. ETTE configures and runs them; you do not buy a second security stack. Licensing options are compared in the nonprofit IT discounts guide.
Who Does the Work
Certified engineers, not a rotating call center.
ETTE's senior engineers hold CISSP (Certified Information Systems Security Professional) and CISA (Certified Information Systems Auditor) certifications. That matters in two places: designing controls that hold when an attacker is creative, and answering an auditor or insurer in their own vocabulary.
Support is bilingual in English and Spanish, delivered by an Americas-based team that documents every environment it manages. The engineer who takes your call has already read the record of your last one. The help desk is staffed Monday through Friday, 7 AM to 7 PM ET, with managed threat detection running 24/7, and we work to a 20-minute response objective on urgent tickets.
Evidence
Reports your board, funder, and insurer can read.
Every managed plan includes ETTE GuardRail, a quarterly security posture score with the evidence behind each control: MFA coverage, device compliance, backup test results, training completion, and open risks with owners. When a cyber insurance application or a grant questionnaire arrives, the answers are already written.
For organizations that need someone to own security governance, a Virtual CISO adds a risk register, policy ownership, and audit coordination on top of these controls.
Related Services
Part of one connected service.
Common Questions
Nonprofit data security FAQs.
Multi-factor authentication and conditional access, Microsoft Defender for Business on every device with around-the-clock managed detection, Defender for Office 365 email protection with SPF, DKIM, and DMARC, Intune device management, independently tested backup and recovery, a written incident response plan, monthly security awareness training, and quarterly access reviews. All of it is included in ETTE managed IT, which starts at $125 per user per month remote-only and $150 fully managed, with nonprofit pricing on both.
ETTE's senior engineers hold CISSP (Certified Information Systems Security Professional) and CISA (Certified Information Systems Auditor) certifications. They design the controls and review the evidence; our Americas-based help desk runs them daily and documents every environment. Support is bilingual in English and Spanish.
For anyone who handles donor, client, grant, or financial data, yes. Business Premium at the $5.50 per user nonprofit price carries Defender for Business, Defender for Office 365 Plan 1, Intune Plan 1, and Entra ID P1 conditional access. The free Business Basic grant has none of those, so we recommend Basic or F3 only for roles that need email and Teams alone. Google Workspace organizations get equivalent controls from Workspace security settings plus third-party endpoint protection.
No. We map the controls to familiar families such as CIS Controls and NIST-style categories so a board or funder can see what is covered, and we assemble the evidence behind each answer. ETTE does not claim certification or formal compliance with any named framework.
You call the help desk and an engineer responds within the 20-minute urgent objective. Managed detection isolates the affected device or account, we restore from tested backups where data was touched, and we work the written incident response plan with your leadership, including what to tell the board, funders, and your cyber insurer and when.
Let's Talk
Find out where your data stands today.
Start with the free Email Security Scorecard or Cyber Insurance Readiness Check, then talk with an advisor about closing the gaps.