Skip to content
Not-for-profit · Australia

Donor trust is the asset you cannot replace.

Rich donor data and the assumption of weaker defences make not-for-profits an easy, high-reward target. We protect donor and beneficiary information with the same calm rigour we bring to any regulated business, because the people behind that data deserve it.

Dossier 07 / 10

Not-for-Profit

Lean budgets and rich donor data make not-for-profits an easy, high-reward target.

  • Privacy Act 1988 / APPs
  • Donor & beneficiary data protection
  • Grant & funder security conditions
Named obligations

What the obligation actually requires of you.

  1. 01

    Privacy Act 1988 / APPs

    Where the Privacy Act applies, donor and beneficiary information requires reasonable protection; coverage depends on the organisation and its activities.

  2. 02

    Donor & beneficiary data protection

    Beneficiaries are often vulnerable people; a breach of their data is a duty-of-care failure as much as a security one.

  3. 03

    Grant & funder security conditions

    Government and philanthropic funders increasingly write security requirements into grant agreements — requirements worth meeting before they're tested.

7

controls to review

Use this sector-specific set of practical prompts to identify owners, evidence and the next control to verify.

Illustrative scenario · Community services charity, NSW

A volunteer laptop targeting a donor database.

Illustrative scenario — In this example, A volunteer's personal laptop, used to access the organisation's donor and case-management platform, was compromised through a phishing link opened outside work hours. The attacker attempted to log in to the donor CRM using cached credentials.

Example response — A suitable response is to isolate the volunteer device, revoke its access, reset affected credentials and review donor-system logs before restoring least-privilege access.

What to verify — Confirm the relevant control is configured, tested and evidenced for this scenario; record the owner, review date and any exception before treating the risk as addressed.

Control evidence to collect

Configuration, test evidence, an accountable owner and a review date for the controls described in this scenario.

Illustrative scenario only. It is not a client case study, endorsement, zero-loss claim or proof of a security outcome.

The compliance checklist

Run it yourself, then see the priorities.

Review each practical control, assign an owner, and get an educational action list before you request a prepared follow-up.

These are practical control prompts, not a legal compliance determination. Exact obligations vary by entity, asset, contract and jurisdiction.

Not-for-profit Cybersecurity Checklist

0 / 7 reviewed0%

MFA enforced on the donor database and fundraising or CRM platforms

Verify the setting or process in your environment, record its accountable owner, and retain current evidence for review: MFA enforced on the donor database and fundraising or CRM platforms.

Volunteer and casual-staff access reviewed and revoked promptly when roles end

Verify the setting or process in your environment, record its accountable owner, and retain current evidence for review: Volunteer and casual-staff access reviewed and revoked promptly when roles end.

Donor and beneficiary data encrypted at rest and access-logged

Verify the setting or process in your environment, record its accountable owner, and retain current evidence for review: Donor and beneficiary data encrypted at rest and access-logged.

Grant and funder security conditions mapped against your actual controls

Verify the setting or process in your environment, record its accountable owner, and retain current evidence for review: Grant and funder security conditions mapped against your actual controls.

Backup and recovery tested for the donor and case-management database

Verify the setting or process in your environment, record its accountable owner, and retain current evidence for review: Backup and recovery tested for the donor and case-management database.

Staff and volunteers trained to spot phishing targeting donation processing

Verify the setting or process in your environment, record its accountable owner, and retain current evidence for review: Staff and volunteers trained to spot phishing targeting donation processing.

An incident response plan naming a board member and a communications lead

Verify the setting or process in your environment, record its accountable owner, and retain current evidence for review: An incident response plan naming a board member and a communications lead.

Complete each control to see your prioritised plan before submitting.

Request a prepared action plan

Share business details so GMAN IT can prepare a useful follow-up by email and with the team.

Optional business context

Your submitted details and checklist answers are shared with GMAN IT to prepare the plan and follow up. Read our Privacy Policy. If a delivery link is generated, it expires after 7 days.

Before you call us

The questions this vertical always asks.

Find out exactly where your donor data is exposed.

The Cyber Readiness Assessment is the forensic starting point, backed by a 100% refund guarantee. Enquire for scope and terms.

Melbourne VIC · Australia · gmanit.com.au