Skip to main content
Cybersecurity Basics for Small Nonprofit Organizations
Running Your Community

Cybersecurity Basics for Small Nonprofit Organizations

By Somiti Team

Somewhere right now, a volunteer club treasurer is logging into the organization’s bank account using a password written on a Post-it note stuck to a shared laptop. That password is “ClubName2023!” and it hasn’t been changed since the last treasurer left. The old treasurer still knows it. So does the former secretary. And probably the secretary’s teenager, who needed “quick access” during last year’s fundraiser.

Nobody thinks twice about it. The club has 80 members and $12,000 in a checking account. Who would bother targeting them?

More people than you’d think.

The Threats That Actually Hit Small Organizations

When most people hear “cybersecurity,” they picture hooded figures typing green code into dark terminals. Hollywood stuff. The reality for a small community organization is far more mundane, and far more common.

The real risks look like this:

A phishing email hits the president’s inbox. It looks like it came from Google, says “Your account has been compromised,” and includes a link to “verify your identity.” The president clicks, enters their Gmail password, and now someone else has access to every Google Doc, every spreadsheet, every contact list the organization uses.

An ex-board member still has access to everything. The previous treasurer stepped down eight months ago but still has the login for the bank account, the email list tool, and the shared Dropbox. Nobody revoked anything because nobody thought to. Most of the time this is fine. Sometimes it’s not.

Someone reuses the same password everywhere. The club’s Facebook page uses the same password as the club’s email account, which uses the same password the vice president uses for their personal Netflix account. When any one of those services gets breached, every account sharing that password is exposed.

A board member’s personal laptop gets compromised. They had club financial records in their Downloads folder. Now whoever infected the machine has them too.

None of these scenarios involve sophisticated hacking. They’re all human mistakes. And they happen constantly to organizations of every size.

Password Hygiene: The Single Biggest Win

If your club does exactly one thing after reading this post, it should be fixing your passwords. Not because passwords are glamorous. Because weak passwords are the entry point for the overwhelming majority of account compromises.

The rules are simple:

Every account gets a unique password. Not “ClubName2023” for the bank and “ClubName2024” for the email. Every single account gets a completely different password that looks nothing like the others.

Passwords should be long and random. “Tr0ub4dor&3” is a bad password. “correct-horse-battery-staple” (a passphrase of random words) is better. A 20-character string of random letters, numbers, and symbols generated by a password manager is best. You don’t need to memorize it. That’s what the password manager is for.

No sticky notes. No shared text documents. No email threads with passwords in them. All of these are ways passwords leak. The whole point of a password is that only authorized people know it, and writing it on a note stuck to a monitor defeats the entire purpose.

Use a password manager. A password manager stores all your passwords in an encrypted vault protected by one strong master password. You remember one password. The manager handles the rest. For small nonprofits, Bitwarden is free and works on every device. It has an “Organizations” feature that lets you share specific passwords with board members without revealing the actual password text.

How does your club currently store its shared passwords? If the answer involves a Google Doc titled “Club Logins” or a group text, you’ve got a problem worth fixing this week.

Setting Up Bitwarden for Your Organization

  1. Go to bitwarden.com and create a free account
  2. Create a “Free Organization” (supports two users, or upgrade to Teams for more)
  3. Add your board members by email invitation
  4. Create shared collections like “Banking,” “Social Media,” “Email Tools”
  5. Add each login to the right collection
  6. Remove the sticky notes and delete the shared Google Doc

The whole process takes about an hour. The next time a board member rotates off, you remove their access in Bitwarden and every shared password stays secure.

Two-Factor Authentication: Your Second Lock

Even with a perfect password, accounts can still get compromised. Maybe someone looks over your shoulder while you type. Maybe a service you use gets breached and your password leaks. Two-factor authentication (2FA) adds a second layer so that knowing the password alone isn’t enough.

With 2FA turned on, logging in requires two things: your password (something you know) and a code from your phone (something you have). Even if someone steals your password, they can’t get in without your phone.

Most services your club probably uses already support 2FA:

  • Gmail/Google Workspace - Settings > Security > 2-Step Verification
  • Facebook - Settings & Privacy > Password and Security > Two-Factor Authentication
  • Bank accounts - Check your bank’s security settings (most banks now require it)
  • Stripe, PayPal, Venmo - All support 2FA in their security settings
  • Mailchimp, Constant Contact - Account settings > Security

Turn it on for every account that matters. Start with the bank account and email, because those two are the keys to everything else. If someone gets into your email, they can reset passwords for every other service. If they get into the bank account, the consequences are obvious.

The most common 2FA method is a text message code. It’s better than nothing. But authenticator apps (Google Authenticator, Microsoft Authenticator, or the built-in option in Bitwarden) are more secure because text messages can be intercepted. If your board members will actually use text message codes but won’t install an authenticator app, go with text message codes. A security measure people actually use beats a perfect one they ignore.

Access Management: Who Has the Keys?

Most volunteer organizations fail badly at this, and not because of carelessness. It’s because volunteer leadership changes constantly.

Think about it. Your average community organization might turn over a third of its board every year. The outgoing treasurer hands off a binder of documents and maybe walks through the major accounts during a coffee meeting. But does anyone systematically revoke the old treasurer’s access to the bank portal, the email list, the payment processor, the social media accounts?

Almost never.

The fix is a simple document. Call it your Access Register. A spreadsheet works fine. It lists:

Account URL Who Has Access Admin? Last Password Change
Bank of America Business Checking bankofamerica.com President, Treasurer Treasurer Jan 2026
Gmail ([email protected]) gmail.com President, Secretary President Mar 2026
Facebook Page facebook.com President, Social Media Chair President Never
Mailchimp mailchimp.com Secretary Secretary Sep 2025

Update it whenever someone joins or leaves the board. When a board member’s term ends, go down the list and remove their access from every account. Change shared passwords they knew. This takes 30 minutes once a year and prevents months of worry about whether someone who’s no longer involved can still access your stuff.

If your organization uses membership software with role-based permissions, this gets easier. You can assign people specific roles (admin, editor, viewer) and revoke them with a few clicks instead of changing shared passwords across a dozen services.

The Offboarding Checklist

When a board member steps down:

  1. Remove them from the password manager organization
  2. Change any shared passwords they had direct access to
  3. Remove their admin access from social media accounts
  4. Remove them from the bank account’s authorized users
  5. Transfer ownership of any Google Docs or Drives to a current board member
  6. Remove them from the email sending tool
  7. Thank them for their service (seriously, they volunteered)

Print this list. Stick it in your board transition binder. Use it every time.

Phishing: The Email That Looks Right But Isn’t

Phishing is the most common way small organizations get compromised, and it works because the emails look legitimate. They mimic Google, Microsoft, your bank, PayPal, or even other members of your organization.

A typical phishing email might say:

“Your Google account has unusual activity. Click here to verify your identity within 24 hours or your account will be suspended.”

The urgency is the giveaway. Legitimate services rarely threaten to shut you down in 24 hours. But when you’re a busy volunteer checking email between meetings, that pressure works.

Train your board to spot the signs:

Check the sender’s actual email address. Hover over the “From” name. “Google Security” might actually be sent from “[email protected].” The display name lies. The email address usually doesn’t.

Don’t click links in urgent emails. If Google says your account has a problem, open a new browser tab and go to google.com directly. Log in there. If there’s actually a problem, you’ll see it. If there isn’t, you just avoided a trap.

Watch for bad grammar and generic greetings. “Dear User” or “Dear Account Holder” from a service that knows your name is suspicious. Awkward phrasing and spelling mistakes are common in phishing, though AI is making phishing emails more polished.

When in doubt, ask someone. Forward the suspicious email to another board member before clicking anything. Two sets of eyes catch what one might miss.

You don’t need formal security training sessions. Just forward the next suspicious email your club receives to the board group chat and say, “This is what phishing looks like.” Real examples from your own inbox teach better than any presentation.

Backup Basics: Don’t Lose Everything

What would happen if your club’s primary computer died tomorrow? Or if someone accidentally deleted the shared Google Drive? Or if ransomware encrypted every file?

Could you recover your member list? Financial records? Event history? Bylaws?

If the answer is “I’m not sure,” you need a backup strategy. It doesn’t need to be complicated.

For Google Workspace/Drive users: Google Takeout (takeout.google.com) lets you download a complete copy of everything in your Google account. Do it quarterly. Save the download to an external hard drive or a different cloud account. Takes five minutes to start, runs in the background.

For important spreadsheets and documents: Keep copies in two places. If your primary copy is in Google Drive, download a backup to a USB drive or a second cloud service. If your primary copy is on someone’s laptop, upload it to the cloud.

For your member database: If you’re tracking members in a spreadsheet, export it monthly and store the export somewhere separate. If you use membership management software, check whether it offers automatic backups or data export. Most do.

For financial records: Your treasurer should have digital copies of bank statements, expense receipts, and financial reports stored somewhere that isn’t just their personal laptop. A shared cloud folder with restricted access works.

The rule of thumb: any file that would cause real problems if lost should exist in at least two places that aren’t the same physical device.

Free Security Tools Worth Setting Up This Week

You don’t need a budget to improve your club’s security. These tools are all free:

Bitwarden (bitwarden.com) - Password manager. Free for personal use, free organization tier for two users. The best single improvement you can make.

Google Security Checkup (myaccount.google.com/security-checkup) - If your club uses Gmail, this walks you through reviewing connected apps, recent sign-in activity, and recovery options. Takes three minutes.

Have I Been Pwned (haveibeenpwned.com) - Enter any email address and it’ll tell you if that address appeared in a known data breach. Check the email addresses your club uses. If they show up, change the passwords immediately.

Built-in 2FA - Google Authenticator, Microsoft Authenticator, or Apple’s built-in verification codes. All free. All work.

Your browser’s built-in password checker - Chrome, Firefox, and Safari all flag passwords that have appeared in known breaches. Run the check. Change the flagged passwords.

Start with Bitwarden and the Google Security Checkup. Those two cover the most ground for the least effort.

Building a Security Culture (Without Being the Paranoid Board Member)

Nobody joins a volunteer cultural association or parent booster club expecting to sit through a cybersecurity lecture. And you don’t need to deliver one. What you need is a handful of simple habits that become part of how your digitalized organization operates.

Add security to your leadership transition. When a new board takes over, include the Access Register handoff and the offboarding checklist. Make it as routine as handing over the checkbook.

Mention it once at a board meeting. Not a full presentation. Thirty seconds: “I set up Bitwarden for our shared passwords. Here’s how to access it. Please don’t share login info over text anymore.” Done.

Lead by example. When you stop emailing passwords around, other board members notice. When you forward a phishing email to the group with “heads up, this is fake,” you’re training people without calling it training.

Review access annually. Once a year, pull up the Access Register and ask: does everyone listed still need access? Are there former board members who should have been removed? Are there accounts nobody currently manages? This annual check catches the gaps that accumulate over time.

The goal isn’t to turn your volunteer club into a security fortress. It’s to close the obvious holes that cause real problems: the ex-treasurer who still has the bank login, the shared password that hasn’t changed in three years, the board member who’ll click any link that looks official.

Fix those, and you’ve eliminated the most likely ways your club gets hurt. No hoodie-wearing hackers required.


Keeping your organization’s accounts secure is easier when you’re not managing access across a dozen disconnected tools. Somiti gives you role-based access control, individual logins for every board member, and one-click permission changes when leadership rotates.

Spend your volunteer time on people, not paperwork.

Somiti handles dues, member lists, and communication for volunteer-run clubs. Free for clubs up to 50 members.