Guided worksheet

Prepare funder security answers without security jargon.

Answer plain-language prompts, see examples as you go, review your notes, and download a filled PDF to share with your team or bring to Secure Origin.

Start guided worksheet Get help building evidence
Guided worksheet

Answer funder security questions one step at a time.

You do not need perfect security language. The goal is to write a plain-English answer, name the evidence you already have, and identify what still needs work.

Sensitive data

Start by naming where important data lives. Funders usually want to know whether your team can identify systems, vendors, owners, and data locations.

Where is sensitive data stored?

Think about donor records, beneficiary or client data, staff files, legal records, program data, research notes, and operational documents. Name the main systems first; you can refine the answer later.

Example: Donor records are in our CRM, staff files are in Google Drive, program documents are in shared folders, and payroll is handled by an outside provider.

What evidence do you already have for that answer?

Evidence can be simple: an inventory, screenshots, admin lists, vendor contracts, policies, or notes from a recent review.

Example: We have a list of core systems, CRM admin screenshots, and a vendor agreement for payroll. We do not yet have a full data map.

What is missing or uncertain?

Write down anything you would not feel comfortable explaining to a funder yet.

Example: We need to confirm who can access old shared folders and whether beneficiary data is stored in staff inboxes.

Access control

This section helps you explain who can access sensitive systems and how accounts are protected.

How is access controlled?

Explain whether accounts use MFA, who has admin access, how staff are added or removed, and whether access is reviewed.

Example: Staff use individual accounts with MFA for email and files. Admin access is limited to the operations director and IT provider. Access is removed during offboarding.

What evidence supports your access answer?

Look for MFA settings, access review exports, admin lists, offboarding checklists, or screenshots.

Example: We have MFA screenshots for email and a spreadsheet showing current admin users. We do not have a formal quarterly review record.

Who owns the next access-control follow-up?

Pick a person or role, not just a team. This makes the worksheet useful after the conversation.

Example: Operations director by August 15.

Incident readiness

Funders may ask what you would do if an account, device, or data store were compromised.

What would you do during a breach or serious security concern?

Name who responds first, who can make decisions, when outside help is called, and how communications are handled.

Example: The operations director contacts our IT provider, disables affected accounts, preserves screenshots/logs, and escalates to the executive director for notification decisions.

What evidence shows you are ready?

Evidence might include an incident response plan, call list, tabletop notes, insurance contacts, or communication templates.

Example: We have a short response plan and IT contact list. We have not tested the plan yet.

What response-readiness gap should be fixed first?

Choose the gap that would slow you down most in the first hour of an incident.

Example: We need an after-hours contact path and a simple incident log template.

Recovery and next actions

Close with practical next steps so the worksheet becomes a work plan, not just a set of answers.

How do you recover critical data?

Explain what is backed up, who can restore it, how long recovery might take, and whether you have tested a restore.

Example: Files are backed up by our cloud provider. The IT provider can restore deleted files. We have not documented a recent restore test.

What are the top three fixes or follow-ups?

Use this as your short action list for your team or for a Secure Origin conversation.

Example: 1. Complete access review. 2. Document backup restore test. 3. Run a 30-minute incident tabletop.

Which evidence should you gather before finalizing answers?

List the documents, screenshots, exports, and notes that would make your answers easier to defend.

Example: System inventory, admin user list, MFA screenshots, backup settings, response plan, and remediation tracker.

More resources

Keep going with related resources.

Get help with the worksheet

Need evidence your team can stand behind?

Send a short note if you want help turning funder questions into a practical evidence plan, Protect The Organization program buildout, validation project, or remediation roadmap.

PGP for sensitive email
hello@secureorigin.io fingerprint:
0BA7 6A2D 2761 340E 394F 7F13 129B A65D 2CA7 34C5
Request review Book call