Risk in Plain Language
Myths & MistakesPart 4 of 5

Five Myths That Keep Nonprofits Exposed

Widely held beliefs about cybersecurity that are actively working against you, and what the evidence actually says about each one.

7 min read

Most cybersecurity failures do not start with a sophisticated attack. They start with a belief.

An organization believes it is too small to be worth targeting. It believes its insurance will cover whatever happens. It believes that because nothing has gone wrong yet, nothing will. And because those beliefs feel reasonable, no one questions them, and the open doors stay open.

This post is for nonprofit leaders, board members, and small business owners who want to stress-test what they think they know. These five myths are among the most widely held in the sector. Each one is verifiably wrong, and each one has contributed directly to real losses at real organizations.

1
Myth
"We're too small and obscure to be a target. Hackers go after the big organizations."
Reality Small organizations are targeted because they are small, not despite it. Size is an advantage for attackers, not a shield for you.

Nonprofits experienced a 30% year-over-year increase in weekly cyberattacks in 2024. Okta's research named nonprofits the second most targeted sector overall that year. Microsoft's Digital Defense Report listed them fourth among sectors targeted by nation-state actors.

The reason is straightforward. Automated attack tools do not distinguish by name recognition or revenue. They scan for accessible systems and exploitable credentials. An organization that has never invested in security controls is not invisible to attackers — it is, from the attacker's perspective, the easiest available target. The absence of defenses is the draw.

Nonprofits also hold data that is genuinely valuable: donor financial information, client records, immigration case files, healthcare data, and the banking relationships that receive grant disbursements. Form 990 filings are public record, which means an attacker can identify your assets, your major funders, and your leadership structure without doing any technical work at all.

The "too small to target" belief is not just wrong. It produces exactly the conditions attackers are looking for.

Consider The relevant question is not "are we a target?" Every organization with data and banking relationships is a target. The relevant question is "are we an easy one?"
2
Myth
"Our cyber insurance will cover us if something happens."
Reality Cyber insurance may not cover what you think it covers. Nearly one in four claims filed in 2024 was rejected for failing to meet coverage requirements.

Cyber insurance has become a standard recommendation, and for good reason — it can be a meaningful financial backstop. But it is not a substitute for security controls, and the gap between what organizations assume their policy covers and what it actually covers is where losses happen.

Business email compromise — the wire fraud and invoice redirection attack that drove $2.77 billion in US losses in 2024 — is the most common claim driver, accounting for roughly 60% of all cyber insurance claims. But many standard policies either exclude social engineering fraud entirely or apply a sublimit that is far lower than the headline coverage amount. A policy with a $1 million limit may cap social engineering losses at $250,000. If your actual loss is $400,000, you absorb $150,000 out of pocket.

Coverage can also be denied when the insurer determines you did not maintain the security controls you attested to at enrollment. If you said you had MFA enabled and you did not, or if your backups were not being tested as documented, the claim can be rejected. According to Fitch Ratings data, nearly one in four cyber claims in 2024 was denied, most often because coverage and implemented controls did not actually align.

Insurance is a financial backstop for residual risk. It is not a substitute for the controls that reduce the likelihood of a claim in the first place, and it cannot protect your reputation or the trust of the people you serve.

Consider Read your policy before you need it. Specifically: does it cover social engineering and business email compromise? What are the sublimits? What security controls did you attest to at enrollment, and are they actually in place?
3
Myth
"Cybersecurity is an IT issue. The board doesn't need to be involved."
Reality Nonprofit board members have a fiduciary duty that explicitly encompasses cybersecurity oversight. "We didn't know" is not a defense when the data of clients, donors, and staff is exposed.

The three core fiduciary duties of a nonprofit board — care, loyalty, and obedience — all have cybersecurity implications. The duty of care requires that board members make informed decisions. The duty of loyalty requires decisions that serve the organization's best interest, including the interests of the people whose data you hold. The duty of obedience requires compliance with applicable law, including breach notification requirements that vary by state and sector.

Governance experts and legal commentators increasingly identify cybersecurity oversight as a direct board responsibility. Failing to safeguard data and digital assets is now specifically listed among the ways board members breach their fiduciary responsibilities. For organizations that handle personal health information, immigration records, or financial data, the legal exposure is more acute.

This does not mean every board member needs to understand firewall configurations. It means the board should be asking the executive director or relevant staff: Do we have a security policy? When was it last reviewed? Have we had an assessment? Do we have an incident response plan? Those are governance questions, not technical ones, and they sit squarely within board responsibilities.

Funders are beginning to agree. Grant applications and funder due diligence processes are increasingly including questions about security posture. A breach that exposes donor data or client records does not just create legal exposure — it creates the kind of trust damage that undermines fundraising for years.

Consider When did the board last receive a security update from leadership? If the answer is "never" or "I'm not sure," that is a governance gap worth addressing at the next meeting.
4
Myth
"Our staff would never fall for a phishing email. They know better."
Reality 68% of all breaches in 2024 involved a human element — phishing, credential theft, or human error. The attacks have changed significantly. Confidence that your team would recognize one is not the same as testing whether they actually do.

The phishing email your staff learned to spot in 2019 is not the phishing email being sent today. Modern business email compromise attacks are crafted using AI that can replicate the writing style, terminology, and cadence of real people your staff actually know. They reference real projects, real vendor names, and real invoice amounts. They do not contain the typos, awkward phrasing, or suspicious links that older awareness training taught people to look for.

One in three BEC attack emails that reach an inbox results in a reply. That is not a failure of individual intelligence — that is the design working as intended. These attacks are engineered specifically to feel routine.

Volunteers and part-time staff create additional exposure that many nonprofits have not fully considered. Volunteers rotate frequently, receive minimal or no security orientation, and often have access to systems with sensitive data because limiting that access would slow down the work. Each person with access to your email system, your CRM, or your donor database is a potential entry point.

The standard for "our staff knows better" is not awareness — it is tested behavior. Organizations that run periodic phishing simulations consistently find that a meaningful percentage of staff click on test emails, even after training. That is not a condemnation of those staff members. It is an accurate measurement of realistic risk.

Consider When did your organization last conduct a phishing simulation? If the answer is never, or if your last security training was more than a year ago, your confidence about staff awareness is untested.
5
Myth
"We can't afford to do anything about security. It's not in the budget."
Reality The most impactful first steps in security cost nothing. The belief that meaningful security requires significant spending is itself a risk, because it produces inaction.

Multi-factor authentication on email and critical systems is free on Microsoft 365 and Google Workspace. An access review — identifying and removing accounts that should not still have access — costs nothing but time. A one-page incident response plan costs one hour. These three actions, covered in last week's post in more detail, close the gaps that account for the majority of successful attacks against organizations like yours.

The cost comparison that matters is not "security spending vs. zero." It is "security spending vs. incident cost." The average cost of a data breach for a small organization now exceeds $250,000 when direct losses, recovery, notification, and reputational impact are included. For a nonprofit operating on a $1.5 million annual budget, that is not a recoverable number. The Blue Hills Civic Association in Boston lost $300,000 in grant funding in 2023 after a cybertheft — and had to lay off staff as a direct result.

The budget constraint is real and should be respected. But it does not justify inaction on the steps that cost nothing. And for the steps that do have a cost, the framing should be explicit: what is the organization's actual financial exposure if an incident occurs, and how does that compare to the cost of the control that would prevent it?

Funders are also beginning to factor security into their decisions. An organization that can demonstrate a thoughtful, documented security posture — even a modest one — is in a meaningfully stronger position than one that cannot.

Consider Before security spending is rejected because it is "not in the budget," ask what it would cost the organization if a breach occurred. That comparison belongs in the same conversation.

What these myths have in common

Each of these beliefs has a surface logic that makes it feel reasonable. Organizations are small. Insurance exists. Staff are smart. Budgets are tight. None of those facts is wrong. What is wrong is the conclusion drawn from each of them — that security is therefore someone else's problem, or a future problem, or a problem that does not actually apply here.

The organizations that suffer significant breaches are rarely the ones that made a considered decision to accept a known risk. They are most often the ones that never stopped to ask the question.

The honest ask: Which of these myths is currently operating in your organization? Naming it is the first step toward addressing it. You do not have to fix everything at once. You have to stop letting a false belief prevent you from fixing anything at all.

A note for board members specifically

If you serve on the board of a nonprofit, the content of this post is part of your governance responsibility, not just your personal interest. The questions at the end of each myth section are reasonable items to raise at a board or committee meeting. You do not need to be a security expert to ask them. You need to be a fiduciary who takes oversight seriously.

The ask is not to add a new committee or hire a new staff member. The ask is to make sure someone in leadership is thinking about these questions, that the answers are documented somewhere, and that the board receives periodic updates on where the organization stands. That is governance. That is what a board is for.

Not sure which myths are operating in your organization?

A structured assessment separates assumption from evidence. A 30-day Security Business Review tells you exactly where you stand and what decisions are worth making. No vendor pitches. No enterprise complexity.

Start a Conversation
Myths and Mistakes Nonprofit Security Board Governance Cyber Insurance Phishing Awareness Fiduciary Duty