Security
Cover the basics before buying new tools.
Most small organizations reduce a lot of risk by using password managers, multi-factor authentication, software updates, secure backups, and basic phishing awareness. Start with the accounts and files that would hurt most if lost.
- Turn on multi-factor authentication for email, finance, donor, and admin accounts.
- Use a password manager so staff are not reusing passwords.
- Keep at least one backup separate from day-to-day devices.
CISA Secure Our World
Security
Write down who can access what.
Nonprofits often inherit accounts from former staff, board members, or volunteers. Keep an owner list for critical systems, remove access when roles change, and make account recovery part of onboarding and offboarding.
- Review admin users quarterly.
- Separate shared public inboxes from personal staff accounts.
- Know where domain, website, email, and donation credentials live.
FTC cybersecurity guidance
Websites
Make essential information easy to find.
A useful nonprofit website does not need to be complicated. Prioritize current program information, eligibility, location, hours, contact methods, donation paths, and the few pages staff can realistically maintain.
- Put services, hours, and contact details near the top.
- Use plain page titles and short paragraphs.
- Remove stale news, broken links, and PDF-only content when possible.
W3C accessibility introduction
Accessibility
Accessibility is part of serving the public.
Accessible content helps people using screen readers, keyboards, captions, small screens, low bandwidth, translated pages, or older devices. It also tends to make sites clearer for everyone.
- Use real headings in order.
- Write meaningful link text.
- Check color contrast and keyboard navigation.
Learn accessibility basics
Data
Clean data beats clever dashboards.
Before building reports, make sure the source data is understandable. Define columns, pick consistent values, remove duplicate records, and decide which information is sensitive enough to limit or delete.
- Create a short data dictionary for important spreadsheets.
- Use consistent names for programs, locations, and statuses.
- Keep personally sensitive information only when it has a clear purpose.
TechSoup digital assessment resources
Planning
Assess the organization, not just the tool.
Technology projects work better when teams understand their current capacity: staff time, budget, skills, policies, data, security, and maintenance. A lightweight assessment can reveal what to fix first.
- List your core systems and who owns each one.
- Identify the process that wastes the most staff time.
- Choose one improvement that can be completed in weeks, not years.
TechSoup assessment resources
Tools
Check nonprofit discounts before paying retail.
Many nonprofits, libraries, and foundations can access donated or discounted software and services. Check eligibility before committing to long subscriptions, especially for productivity, design, security, and infrastructure tools.
- Confirm eligibility and administrative fees.
- Buy only what staff can actually adopt.
- Plan ownership before setting up new accounts.
TechSoup technology access
Community
Learn from nonprofit technology peers.
Good technology decisions are not only technical. Nonprofit peers can help with governance, equity, staffing, accessibility, vendor choices, and realistic adoption plans.
- Ask what similar organizations already use.
- Look for practices that fit your team size.
- Include the people affected by the system before choosing it.
Explore NTEN