Checklist

Nonprofit cybersecurity readiness checklist.

Use this checklist to identify the security evidence, controls, and practical fixes your organization should have before a funder, board, insurer, or partner asks.

Review the checklist Get nonprofit security help
Checklist

Use this to find the next practical security fixes.

Mark each item as done, not sure, or needs work. For funders, boards, insurers, and partners, the most useful answer is usually evidence that the control exists or a clear plan to fix the gap.

Identity and access

Data, backups, and recovery

Incident readiness

Remediation worksheet

Gap Risk if ignored Fix Owner Evidence when complete
Example: no access review...Former staff retain access...Review and remove stale accounts...Name...Access review record...
Gap...Risk...Fix...Owner...Evidence...
Gap...Risk...Fix...Owner...Evidence...
Readiness support

Need a second set of eyes?

Secure Origin helps nonprofits and NGOs turn this checklist into an assessment, remediation plan, and funder-ready evidence package.

PGP for sensitive email
hello@secureorigin.io fingerprint:
0BA7 6A2D 2761 340E 394F 7F13 129B A65D 2CA7 34C5