Why Providence Non-Profits Get Targeted, and the Cheap Fixes That Help Most

Non-profits get compromised more often than for-profit businesses of the same size and roughly the same budget. The usual explanation is money: non-profits spend less on IT, so they are less protected. That is part of it, but it is not the main thing. The main thing is that a non-profit's operating model makes consistent security harder than a twenty-person company's does.

It is the operating model, not the budget

Look at how a typical Providence non-profit is staffed. High turnover. Volunteers who come in for a project and leave. Board members with email addresses and file access. Part-time staff sharing responsibilities that shift every year. Grant-funded positions that exist for eighteen months and then do not. Nobody internal owns IT; it is the operations director's fourth priority, or the executive director's ninth.

None of that means the organization does not care about security. It means the number of people with access changes constantly and there is no one whose job is to keep up with it. A twenty-person for-profit on the same budget usually has the same twenty people it had last year. That stability is a security control, and non-profits do not get it for free.

“We don't have anything hackers would want” is the wrong test

This is the most common thing I hear from directors, and it is the wrong way to think about it. You may not have valuable intellectual property. You do have employee records, donor records, banking access, and email.

The email account is often the asset. Not the messages in it, the identity. An attacker inside your development director's mailbox does not need to steal anything. They need to send. A payment-instruction change to a grantor, a wire request to your bookkeeper, an urgent ask to a major donor, all sent from a real address, in a real thread, with real history behind it. Attackers are not valuing your data. They are valuing your relationships.

Rhode Island's non-profit world is small, and that cuts both ways

This is where geography actually changes the answer, and not decoratively.

Rhode Island's non-profit sector is dense and interconnected in a way a comparable sector in a larger state is not. Board members serve on two and three boards. Executive directors know each other. Organizations share funders, share vendors, share consultants, and collaborate on programs. That is a real operational strength here. It is how small organizations in this state get things done.

It is also why a compromised mailbox at one Providence non-profit is unusually useful for attacking the next one. The relationships in that mailbox are real and locally recognizable. A message from a familiar director at a familiar organization, about a funder you both work with, does not read as a phishing email. It reads as Tuesday. In a bigger market, a stolen mailbox mostly gets an attacker the people inside it. Here it gets them a network.

The same density means a board member's compromised credentials are not one organization's problem. If that person reuses a password across three boards, it is three organizations' problem.

Offboarding matters more than onboarding

Most organizations handle onboarding reasonably well, because someone is waiting to start work and complains if their account is not ready. Nobody complains about offboarding. There is no one on the other end of it.

The result is account sprawl, and honestly I worry more about the account nobody remembers than the employee sitting at their desk today. If a volunteer finished a project two years ago, there is no reason their Microsoft 365 account, shared-folder access, or remote access should still work. Nobody is watching that account. Nobody would notice a sign-in from somewhere odd. There is no unexpected prompt for anyone to question, because nobody expects a prompt at all.

Every account still standing is a door. Non-profits accumulate doors faster than most businesses, because people cycle through faster.

What $2,000 should buy, in order

If a Providence non-profit handed me $2,000 and said make us safer, this is the order:

  • Identity first. Multi-factor authentication on every account with no exceptions, a full account audit with the dead ones removed, unnecessary admin rights stripped, and Microsoft 365 configured properly rather than left at defaults.
  • Endpoints. Real endpoint protection, and just as important, every computer actually managed and patched. Not “we have antivirus.” Managed.
  • Verify the backups. Not that a job runs. That somebody has restored from it.
  • Whatever is left goes to security-awareness training, because the mailbox attacks described above are the ones that actually happen.

What I would not do is spend that $2,000 on an interesting security product while three former employees still have working accounts. The order matters more than the total. Most of what is on that list is configuration and discipline, which is why the budget explanation is incomplete. The highest-value fixes here are cheap.

The Microsoft discount is a license, not a security team

Non-profit technology programs, Microsoft's and TechSoup's among them, are worth using. Eligible organizations get access to software and cloud services at prices they could not otherwise justify, and the security tooling included in those licenses is genuinely good.

The false confidence comes from what people assume the license covers. Getting Microsoft 365 cheaply does not mean Microsoft is managing your security. The tools arrive. They do not arrive turned on, tuned, or watched. Somebody still has to enforce MFA, set conditional access, remove departed users, review admin accounts, check for mail-forwarding rules, and notice when something looks wrong. A discounted license sitting at default settings with no one minding it is not protection. It is potential.

Start with the doors that are already open

If you do one thing after reading this, pull the list of every account in your Microsoft 365 tenant and go down it name by name with someone who knows who is still involved. Most organizations find something in the first ten minutes.

That review costs nothing, and it will tell you more about your real exposure than any product will. If you want a second set of eyes on it, or you would rather hand the whole list to someone who does this all day, get in touch.