Skip to main content
Industry · Not-for-Profit

IT support for Brisbane not-for-profits — grant-funded budgets, real obligations

Managed IT for charities and community organisations. Nonprofit licensing you are entitled to, volunteer turnover handled properly, and donor data protected on a budget that has to be justified to a board.

16+ years

Brisbane-based since 2010

1,500+

Employees supported across SEQ

Named engineers

The same team every time

Essential Eight aligned

Microsoft Partner

What we hear from not-for-profit

The IT problems specific to your sector

Budgets that must be defended

Every dollar spent on administration is a dollar not spent on the mission, and boards scrutinise it accordingly. IT has to be justified in those terms rather than on best practice.

Volunteer turnover at scale

Volunteers come and go constantly, often with access to systems holding personal information about vulnerable people. Offboarding rarely keeps pace.

Donor and client data sensitivity

Donor records include financial details. Client records in community services frequently include information about vulnerable individuals, which raises the stakes considerably.

Grant funding that will not fund infrastructure

Programme grants cover programme delivery. The systems underneath are frequently unfunded, which is why so many NFPs run on ageing equipment.

Nonprofit licensing left on the table

Substantial Microsoft and other vendor discounts and grants exist for eligible organisations, and a surprising number of NFPs are paying commercial rates.

Reporting obligations to funders

Funders and the ACNC require reporting, and the data behind it is often spread across spreadsheets nobody can reconcile.

The constraint is real and it shapes everything

Not-for-profits are not businesses with tighter budgets. The money is someone else’s, allocated for a purpose, and every dollar spent on systems is a dollar visibly not spent on the mission. Boards ask about it and they are right to.

That means best-practice recommendations delivered without regard to cost are not useful advice here. What is useful is knowing which controls are free, which are cheap, and which can wait.

Start with what costs nothing

For a small charity, the highest-return security work is almost entirely configuration rather than purchase.

Multi-factor authentication costs nothing beyond setup and blocks the large majority of the attacks that actually reach organisations your size. Disabling legacy authentication is free. Removing unnecessary administrator rights is free. Setting up sensible retention is free.

After that, tested backups and patching discipline. Those five things put a small organisation ahead of a great many businesses several times its size.

If a provider’s first recommendation to a charity is a paid security product rather than turning on MFA, that ordering is worth questioning.

Check your licensing entitlement

Microsoft operates substantial nonprofit pricing and donated licence programmes for eligible registered charities, and similar arrangements exist across many vendors.

We regularly find not-for-profits paying commercial rates for software they could be receiving at nonprofit pricing or at no cost. Eligibility generally rests on ACNC registration and the nature of the work, and programme terms change often enough that it is worth verifying current conditions rather than relying on what someone was told three years ago.

A licensing review is usually the single fastest way to free up budget.

Volunteers, and the offboarding problem

Volunteer turnover is a structural feature rather than a problem to solve, and it puts real pressure on access management.

Two things go wrong. A shared volunteer login, which removes any record of who accessed what — a serious matter for an organisation holding information about vulnerable people. And accounts that remain active long after the volunteer stopped attending.

The practical fix is setting an expiry at the point of creation, so access lapses by default unless someone actively renews it. That inverts the failure mode: instead of access persisting unless someone remembers to remove it, it ends unless someone remembers to extend it.

The data you hold may be more sensitive than a business’s

Donor records contain financial details. In community services, client records frequently contain information about vulnerable individuals — circumstances, health, family situations, contact with services.

That is more sensitive than what most commercial businesses of comparable size hold, and it makes the consequences of a breach different in kind rather than just in scale. It is worth being clear-eyed about that when weighing what to spend, because the framing is not “what would this cost us” but “what would this cost the people we exist to help”.

Not-for-Profit IT support FAQs

What nonprofit IT discounts are we entitled to?

Microsoft offers substantial nonprofit pricing and a number of donated licences for eligible registered charities, and similar programmes exist across many vendors. Eligibility generally depends on ACNC registration and the nature of your work. It is worth checking properly, because we regularly find organisations paying commercial rates for products they could obtain at nonprofit pricing or free. Programme terms change, so verify current eligibility rather than relying on what was true a few years ago.

How do we manage volunteer access safely?

With accounts that are individual, time-limited and revoked automatically where possible. The two failure modes are a shared volunteer login, which removes any audit trail of who accessed what, and accounts that outlive the volunteer by months. For organisations working with vulnerable people, both are serious rather than administrative problems. Setting an expiry date at creation, so access lapses unless renewed, solves most of it without relying on anyone remembering.

We cannot afford enterprise security. What should we prioritise?

MFA first, and it costs nothing but configuration time. Then tested backups. Then patching discipline. Those three deliver the large majority of practical risk reduction and are achievable on any budget. Not-for-profits are frequently sold security products they do not need while missing controls that are free. If a provider's first recommendation to a small charity is a paid product rather than turning on MFA, that is worth noticing.

Our equipment is old and grants will not fund replacement. What are the options?

A few things genuinely help. Nonprofit hardware programmes and refurbishment schemes exist and are worth investigating. Some funders will fund infrastructure if it is written into the programme budget as a delivery requirement rather than presented as overhead, which is a framing question worth testing. And extending the useful life of existing hardware through a lightweight, well-managed configuration is legitimate — an older machine that is patched, encrypted and running current software is far better than an unmanaged new one.

Do the Privacy Act obligations apply to us?

It depends on turnover and activity, and the small business exemption is narrower than many organisations assume — it does not apply where you provide a health service, and there are other exclusions. Many not-for-profits are covered. More practically, funding agreements frequently impose data handling obligations regardless of statutory position, and organisations working with vulnerable people have obligations that go well beyond privacy law. It is worth establishing your actual position rather than assuming exemption.

Ready to talk?

A 30-minute consultation with an engineer, not a salesperson. You'll get an honest read on whether we're a fit.

Call Get a quote