Cybersecurity is no longer something only large organisations need to worry about. Not for profits across Australia are now among the most targeted sectors for cybercrime.

This often comes as a surprise. Many leaders assume attackers only go after banks, large companies or government departments. In reality, not for profits are attractive targets because they manage sensitive information but typically have fewer security controls in place.

Why not for profits are targeted

Most not for profits hold a significant amount of personal information, even if they are not aware of it. This includes:

  • Donor names and contact details.
  • Client or participant data.
  • Volunteer records.
  • Financial and payment information.

At the same time, many organisations operate with limited IT budgets and small teams. Cyber criminals know this. They look for environments where entry is easy and detection is slow.

Email remains the most common entry point. One convincing phishing email can give an attacker access to shared files, systems, and internal communications.

The preparedness gap

In many not for profits, cybersecurity has grown organically rather than strategically. Systems have been added over time, policies have been copied from templates, and training has been informal.

This often results in:

  • Inconsistent use of multi factor authentication.
  • Shared or weak passwords.
  • Limited security awareness training.
  • No clear plan for responding to an incident.

These gaps are not a reflection of capability or intent. They are the result of constrained capacity and competing priorities.

What risk looks like in real life

Cyber risk does not always look dramatic at first. It often starts small:

  • A staff member clicks a fake invoice.
  • An email account is quietly compromised.
  • Files are accessed or forwarded externally.

Weeks or months later, donor details appear online or funds are diverted. By the time the breach is discovered, the damage is already done.

Why this matters for mission and trust

For not for profits, cybersecurity failures rarely stop at technology. They affect:

  • Donor confidence.
  • Client safety.
  • Funding applications.
  • Board confidence.

Trust is hard to earn and easy to lose. A single incident can impact years of relationship building.

A realistic path forward

Cybersecurity does not need to be overwhelming. The strongest improvements come from focusing on a few basics and doing them well:

  • Securing email accounts.
  • Enforcing stronger sign ins.
  • Training staff in simple awareness.
  • Knowing who to call if something goes wrong.

Security done well supports service delivery. It protects the organisation so it can keep doing its most important work.