Nonprofit Data Security

Nonprofit data security, run by CISSP and CISA certified engineers.

ETTE protects donor, client, grant, and financial data for nonprofits in Washington, DC and nationwide. Senior engineers holding CISSP and CISA certifications design the controls, our help desk runs them every day, and your board gets a plain-language security report each quarter. Support is bilingual in English and Spanish.

What Is at Risk

The data a nonprofit holds, and who wants it.

A nonprofit with 30 staff typically holds donor payment records, client case files, grant reports, payroll, and board minutes spread across Microsoft 365 or Google Workspace, a CRM, and an accounting system. Attackers target that mix because it is valuable and lightly defended. Business email compromise aimed at finance staff, ransomware on shared files, and account takeover through a reused password are the three incidents we are called into most often.

Funders, insurers, and state regulators now ask how that data is protected before they renew. The controls below are the ones their questionnaires ask about, and they are included in every ETTE managed plan rather than sold as a separate security program.

Controls ETTE Manages

Eight controls, named and owned.

Multi-factor authentication and conditional accessMFA on every account, with Microsoft Entra ID conditional access rules that block legacy sign-ins and require a compliant device for finance and admin roles.
Microsoft Defender for Business on every deviceEndpoint detection and response on every laptop and desktop, watched around the clock by managed detection, so a 2 a.m. alert is contained rather than discovered on Monday.
Email protection with Defender for Office 365Filtering for phishing, impersonation, and malicious attachments, plus SPF, DKIM, and DMARC on your domain so nobody else can send as your executive director.
Device management with IntuneDisk encryption, patching, screen lock, and remote wipe enforced on staff and volunteer devices, including Macs and personal phones that hold work email.
Backup and recovery, testedIndependent backup of Microsoft 365 or Google Workspace, file servers, and key program systems, with documented restore tests and recovery objectives your board has seen.
Incident response you can callA written incident response plan with named roles, and an engineer on the line within our 20-minute urgent response objective when something happens.
Security awareness trainingShort monthly training and simulated phishing for staff, fellows, and volunteers, with completion reports ready for your insurer.
Access reviews and offboardingQuarterly review of who can reach donor, client, and financial systems, and same-day account shutoff when staff or volunteers leave.

Where your organization runs Microsoft 365 Business Premium, Defender for Business, Defender for Office 365 Plan 1, Intune Plan 1, and Entra ID P1 are already in the license at the $5.50 per user nonprofit price. ETTE configures and runs them; you do not buy a second security stack. Licensing options are compared in the nonprofit IT discounts guide.

Who Does the Work

Certified engineers, not a rotating call center.

ETTE's senior engineers hold CISSP (Certified Information Systems Security Professional) and CISA (Certified Information Systems Auditor) certifications. That matters in two places: designing controls that hold when an attacker is creative, and answering an auditor or insurer in their own vocabulary.

Support is bilingual in English and Spanish, delivered by an Americas-based team that documents every environment it manages. The engineer who takes your call has already read the record of your last one. The help desk is staffed Monday through Friday, 7 AM to 7 PM ET, with managed threat detection running 24/7, and we work to a 20-minute response objective on urgent tickets.

Evidence

Reports your board, funder, and insurer can read.

Every managed plan includes ETTE GuardRail, a quarterly security posture score with the evidence behind each control: MFA coverage, device compliance, backup test results, training completion, and open risks with owners. When a cyber insurance application or a grant questionnaire arrives, the answers are already written.

For organizations that need someone to own security governance, a Virtual CISO adds a risk register, policy ownership, and audit coordination on top of these controls.

Common Questions

Nonprofit data security FAQs.

Let's Talk

Find out where your data stands today.

Start with the free Email Security Scorecard or Cyber Insurance Readiness Check, then talk with an advisor about closing the gaps.