The constraint is real and it shapes everything
Not-for-profits are not businesses with tighter budgets. The money is someone else’s, allocated for a purpose, and every dollar spent on systems is a dollar visibly not spent on the mission. Boards ask about it and they are right to.
That means best-practice recommendations delivered without regard to cost are not useful advice here. What is useful is knowing which controls are free, which are cheap, and which can wait.
Start with what costs nothing
For a small charity, the highest-return security work is almost entirely configuration rather than purchase.
Multi-factor authentication costs nothing beyond setup and blocks the large majority of the attacks that actually reach organisations your size. Disabling legacy authentication is free. Removing unnecessary administrator rights is free. Setting up sensible retention is free.
After that, tested backups and patching discipline. Those five things put a small organisation ahead of a great many businesses several times its size.
If a provider’s first recommendation to a charity is a paid security product rather than turning on MFA, that ordering is worth questioning.
Check your licensing entitlement
Microsoft operates substantial nonprofit pricing and donated licence programmes for eligible registered charities, and similar arrangements exist across many vendors.
We regularly find not-for-profits paying commercial rates for software they could be receiving at nonprofit pricing or at no cost. Eligibility generally rests on ACNC registration and the nature of the work, and programme terms change often enough that it is worth verifying current conditions rather than relying on what someone was told three years ago.
A licensing review is usually the single fastest way to free up budget.
Volunteers, and the offboarding problem
Volunteer turnover is a structural feature rather than a problem to solve, and it puts real pressure on access management.
Two things go wrong. A shared volunteer login, which removes any record of who accessed what — a serious matter for an organisation holding information about vulnerable people. And accounts that remain active long after the volunteer stopped attending.
The practical fix is setting an expiry at the point of creation, so access lapses by default unless someone actively renews it. That inverts the failure mode: instead of access persisting unless someone remembers to remove it, it ends unless someone remembers to extend it.
The data you hold may be more sensitive than a business’s
Donor records contain financial details. In community services, client records frequently contain information about vulnerable individuals — circumstances, health, family situations, contact with services.
That is more sensitive than what most commercial businesses of comparable size hold, and it makes the consequences of a breach different in kind rather than just in scale. It is worth being clear-eyed about that when weighing what to spend, because the framing is not “what would this cost us” but “what would this cost the people we exist to help”.