There is a story that keeps most small businesses and nonprofits vulnerable, and it goes something like this: "We are too small to be a target. The hackers are after the big banks and the Fortune 500. We don't have anything worth stealing."
That story is wrong, and it is costing organizations like yours real money and real trust.
Cybersecurity is not a technology problem reserved for organizations with IT departments and six-figure security budgets. It is a business risk problem. And small businesses and nonprofits face that risk every day, often with no one in the building who is paid to think about it.
Why "We're Too Small" Is the Most Dangerous Thing You Can Say
Attackers do not browse LinkedIn to find well-known companies before they launch a phishing email. Most attacks are automated. A malicious actor runs a script that probes thousands of organizations at once looking for an unlocked door: a password reused from a leaked database, an unpatched piece of software, or a staff member who clicked a link that looked like it came from their bank.
Your size is not a shield. In some ways it is the opposite. Large enterprises invest heavily in security tooling and trained staff specifically because they know they are targets. Your organization may have spent nothing, and that gap is exactly what automated attacks are designed to find.
These numbers are not meant to frighten you into buying something. They are meant to frame the actual business risk, because that is the only honest starting point.
What Nonprofits in Particular Need to Understand
If you run or work at a nonprofit, you may have an additional reason to believe you are not a target: the assumption that what you do is inherently good, and surely no one would want to interfere with that work.
That assumption is also wrong, for a different reason. Nonprofits hold some of the most sensitive data that exists: donor financial information, client intake records, healthcare data at human services organizations, immigration case files, and protected personal information of vulnerable populations. That data has real value to attackers and real consequences for the people you serve if it is exposed.
Beyond the data risk, nonprofits are increasingly targeted with business email compromise: an attacker impersonates a staff member or board officer via email and requests a wire transfer or gift card purchase. These attacks succeed constantly, and they succeed because there was no process to verify the request before acting on it.
What "Practical Security" Actually Looks Like
The goal is not to build an enterprise security program with a team of analysts and a seven-figure software budget. The goal is to make your risk defensible: to understand what matters most to your organization, protect those things proportionally, and be able to show that you made thoughtful decisions.
For most small organizations, that starts with five areas:
1. Identity and access
Who has access to what, and does that still make sense? Former employees, old vendor accounts, and shared passwords are among the most common attack entry points. This is almost always the highest-priority starting place.
2. Email security basics
Multi-factor authentication on email accounts is one of the most impactful single steps any organization can take. It will not stop everything, but it dramatically raises the cost for an attacker to gain entry through your staff's credentials.
3. Backups that actually work
Ransomware attacks encrypt your data and demand payment for the key. Organizations that have current, tested backups stored somewhere the attacker cannot reach have real options. Organizations without those backups often pay because they have no other choice.
4. A response plan before you need one
When something goes wrong, the worst time to figure out what to do is in the middle of an incident. Even a simple, one-page plan that identifies who makes decisions, who to call, and what to communicate to clients or donors is meaningfully better than nothing.
5. Clarity about what you are protecting
Not everything you hold is equally sensitive or equally critical. Knowing the difference allows you to focus limited resources where they matter most, rather than trying to protect everything with equal effort and succeeding at nothing.
The Question Is Not Whether You Need Security
The honest conversation is about how much security you need, what form it should take, and how to make decisions about it that hold up over time. Every organization operates under constraints. Budget is finite. Staff attention is finite. The right security program is one that fits your real situation and protects what actually matters.
That is what defensible means in practice. Not perfect. Not enterprise-grade. Defensible: you understood your risk, you made considered choices, and if something went wrong you can explain what you had in place and why.
Over the coming weeks, this blog will walk through the specific areas where small businesses and nonprofits are most exposed, what practical steps look like for organizations without dedicated security staff, and how to have clearer conversations with your leadership and board about risk. No jargon. No vendor recommendations. Just practical guidance grounded in real business risk.
Ready to understand your actual risk?
A 30-day Security Business Review gives you a clear picture of your most critical gaps and a prioritized roadmap you can act on without enterprise complexity.
Start a Conversation