Cybersecurity, Cyber Insurance and Business Survivability for Nonprofits

For most nonprofits, cybersecurity can feel like a problem meant for larger organizations. The headlines usually focus on ransomware attacks against hospitals, major corporate data breaches or sophisticated attacks against government agencies. That can create the impression that a smaller nonprofit with a limited technology budget simply isn’t an interesting target. Attackers don’t necessarily make that distinction. They look for opportunity, and nonprofits often have more worth protecting than they realize.

Donor information, employee records, payment data, financial accounts, grant information, volunteer records and sometimes sensitive information about the people an organization serves all live somewhere inside the nonprofit. Even a relatively small organization now depends heavily on technology and information to operate. That means cybersecurity is no longer just something the IT provider handles. It has become part of whether the organization can continue fulfilling its mission when something goes wrong.

That is the idea behind a presentation I recently developed called The Mission Must Survive. It also connects directly to something I have been writing and speaking about more broadly: Business Survivability. The basic idea is that organizations rarely fail because one bad thing happens. They get into trouble when a disruption exposes dependencies and weaknesses that were already there, and the organization cannot adapt quickly enough to keep operating.

For nonprofits, I think that is a much more useful way to think about cybersecurity.

Start With the Mission

One of the biggest mistakes organizations make with cybersecurity is starting with technology. They begin with firewalls, endpoint products, identity tools and security platforms before asking what the organization actually needs to keep operating.

For a nonprofit, that could mean email, payroll, donor systems, banking access, case management, grant information or another application supporting day-to-day operations. The answer will be different for every organization, but identifying those dependencies changes the cybersecurity conversation considerably. Instead of trying to protect everything equally, leadership can focus its attention and limited resources on the systems and information that matter most to the mission.

This is where cybersecurity becomes a survivability issue. The important question isn’t simply whether a particular system is secure. Leadership needs to understand what happens to the organization if that system becomes unavailable and how long the organization can realistically function without it.

That matters because nonprofits rarely have unlimited security budgets or large internal technology teams. Many depend on outsourced IT providers, small staffs and people already wearing several different hats. Trying to replicate the cybersecurity program of a large corporation doesn’t make much sense. Understanding where disruption would cause the greatest damage does.

Prevention Is Important, but It Isn’t Enough

Basic security practices still matter a great deal. Multi-factor authentication (MFA) should be enabled wherever possible, important data should be backed up, former employees and volunteers should lose access quickly, financial processes should have sensible controls and employees should receive enough security awareness training to recognize common threats. These aren’t particularly complicated ideas, but they can prevent a surprising number of incidents.

The mistake is assuming those controls eliminate the possibility of an attack. They don’t. A vendor can be compromised, a password can be stolen, someone can respond to a convincing phishing message or an attacker can exploit a vulnerability before the organization knows it exists. AI is making some attacks easier to create and more convincing, but it hasn’t changed the basic reality that preventative controls eventually fail.

Business Survivability starts with accepting that reality rather than designing the organization around the assumption that nothing bad will happen. Once you assume that something eventually gets through, the conversation changes. You start thinking much more seriously about whether the organization will recognize the problem quickly enough to limit the damage.

For smaller nonprofits, that can be difficult because someone actually has to be watching. An IT provider keeping systems running is not necessarily the same thing as having someone continuously looking for signs of an attack. Understanding who is responsible for detection, and what happens when suspicious activity is identified, is much more important than simply knowing which security products have been purchased.

Someone Still Has to Make the Decision

Technology can identify a problem, but it cannot run the organization during a crisis. Once an incident happens, someone still has to decide what happens next. Leadership needs to know who has the authority to shut systems down, contact the insurance carrier, communicate with employees, involve legal counsel and keep the board informed. Those decisions become much harder if nobody has discussed them before an incident occurs.

This is where cybersecurity stops being purely an IT issue and becomes an operating issue. Technical teams can investigate an attack and contain systems, but leadership still has to decide what matters most to the organization. If several systems are unavailable and everything cannot be restored immediately, somebody needs to understand which capabilities are most important to the mission.

A useful exercise for any nonprofit is to think through what the next seven days would look like after a serious cyber incident. Consider which parts of the organization would stop functioning, how services would continue and what technology would have to be restored first. The exercise usually exposes dependencies that are easy to overlook when everything is working normally.

I refer to these kinds of dependencies as hidden fragility. They exist in almost every organization. A particular employee may be the only person who knows how something works. One vendor may support a critical process. A single cloud application may contain information that nobody can easily access elsewhere. None of those situations necessarily looks like a cybersecurity problem until a cyber incident makes that dependency unavailable.

That is why survivability is broader than security. The objective is not simply getting the attacker out. The organization still has to function afterward.

Cyber Insurance Is the Financial Side of Recovery

Cyber insurance is an important part of this conversation, but it is often misunderstood. Having a policy does not mean every consequence of a cyberattack will automatically be covered, and it certainly does not mean the organization will automatically recover.

A cyber insurance policy may provide access to incident response specialists, legal support and other resources that can become extremely valuable when something happens. It may also provide financial protection for certain covered losses. At the same time, every policy has conditions, limits, exclusions and requirements that the organization needs to understand before a claim occurs.

Nonprofit leaders should know whether the organization has cyber insurance, where the policy is located, who is responsible for contacting the carrier and what the organization represented about its security practices during the application process. Those are relatively simple questions, but discovering the answers during an active incident adds unnecessary confusion at exactly the wrong time.

There is another part of the insurance conversation that I think deserves more attention. The amount of insurance an organization carries should have some relationship to what a serious cyber event could actually cost. That becomes difficult to determine if nobody has considered how long critical systems could be unavailable or what it would take to keep the organization operating during recovery.

This is where I see an important distinction between being insured and being survivable. Insurance can absorb some of the financial consequences of an incident. Survivability is the organization's ability to continue functioning through it. A nonprofit can have a good cyber insurance policy and still discover that it was operationally unprepared for the event that created the claim.

Cybersecurity Should Match the Organization

One of the reasons cybersecurity becomes unnecessarily complicated is that organizations are often told what they should buy before anyone understands what they actually need. A nonprofit with twenty employees does not need the same security program as a multinational corporation, but that does not mean it needs no security program at all.

The right approach should reflect the organization itself. Leadership needs enough understanding of its environment to know where meaningful risk exists and whether the organization has the ability to recognize and respond to an incident. Recovery needs to reflect the systems the mission actually depends upon, and insurance needs to make sense in the context of the financial impact the organization could realistically face.

For many nonprofits, some of those capabilities will come from outside providers because building everything internally simply doesn't make financial sense. That is perfectly reasonable, but outsourcing a function does not remove the organization's dependency on it. Leadership still needs to understand what the provider is responsible for and what remains the responsibility of the nonprofit.

This is another place where hidden fragility can develop. An organization may have an IT provider, security products, cloud services, backups and cyber insurance and reasonably assume that somebody has the entire problem covered. In reality, each provider may be responsible for only one piece of the problem. The gaps between those responsibilities often remain invisible until something goes wrong.

Business Survivability is largely about finding those gaps while you still have time to do something about them.

The Mission Is the Point

Nonprofits do not exist to practice cybersecurity. They exist to serve communities, support people, advance causes and fulfill missions that matter to the people who depend on them. Security should support that purpose rather than becoming another complicated technology initiative competing for attention and funding.

This is why I think the survivability conversation works particularly well for nonprofit leaders and boards. They do not need to become cybersecurity experts. They need enough understanding of the organization to know what the mission depends upon and whether the organization could continue operating if one of those dependencies suddenly disappeared.

That requires looking beyond security controls and considering how the organization actually operates. Technology matters, but so do people, vendors, finances, insurance and the decisions leadership will have to make during a disruption. Cybersecurity becomes much easier to understand when it is viewed as part of that larger operating picture.

A cyber incident does not have to destroy every system or steal every piece of information to threaten a nonprofit. It only has to interrupt something the mission depends on badly enough, or long enough, that the organization can no longer do what it exists to do.

That is ultimately what Business Survivability is about. For a nonprofit, there may be no simpler way to say it. The mission must survive.