A practical guide for Executive Directors of social service and health & human service nonprofits.
Most compliance problems don't begin with a cybersecurity breach.
They begin with assumptions.
"We already have cybersecurity."
"Our IT company handles that."
"We'll pull the documentation together if an auditor asks."
Unfortunately, grant funders, cyber insurance providers, and regulatory agencies expect more than good intentions.
They expect evidence.
For growing nonprofits, especially those providing social, health, or human services, a mid-year technology review is one of the best ways to identify hidden compliance gaps before they become expensive problems.
Here are four areas every nonprofit leader should review.
- Are Your Security Tools Being Actively Managed?
Many nonprofits already invest in:
- Microsoft Defender
- Multifactor authentication (MFA)
- Email security
- Endpoint protection
- Firewalls
- Backup solutions
Owning security software doesn't automatically make your organization secure.
Ask your IT partner:
- Are these tools fully configured?
- Are alerts monitored every day?
- Are failed updates investigated?
- Is someone documenting security activity for audits and cyber insurance?
Technology only protects your organization when it's actively managed.
- Has Staff Training Kept Up With New Risks?
People remain the most common target of cyberattacks.
Today's threats include:
- AI-generated phishing emails
- Business email compromise
- Fake Microsoft login pages
- Text message scams
- Credential theft
At the same time, many nonprofits are beginning to use AI tools without clear guidance.
Ask yourself:
- Have employees received cybersecurity awareness training this year?
- Do we have an acceptable use policy for AI?
- Does staff understand what client information should never be entered into AI tools?
Clear policies protect both your organization and the people you serve.
- Could You Produce Documentation Tomorrow?
If a grantor, auditor, or cyber insurance carrier requested documentation today, could you provide it quickly?
You should be able to demonstrate:
- Security policies
- Password standards
- User access reviews
- Vendor management
- Incident response plans
- Backup testing
- Employee training records
Strong documentation builds confidence with boards, funders, and insurance providers.
- Has Your Technology Changed Faster Than Your Policies?
Many nonprofits have experienced significant growth over the past few years.
New staff.
Remote work.
Additional locations.
Cloud applications.
AI tools.
New grant-funded programs.
Yet policies often remain unchanged.
Technology governance should evolve alongside your organization.
Conduct a mid-year review to confirm:
- User permissions remain appropriate.
- Vendors still require access.
- Microsoft 365 security settings reflect current best practices.
- AI tools are being used responsibly.
- Cybersecurity controls still meet grant and insurance requirements.
Growing organizations require growing governance.
Compliance Supports Your Mission
Compliance isn't about checking boxes.
It's about protecting the trust your clients, donors, board members, and funding partners place in your organization.
Strong technology governance helps nonprofits:
- Protect confidential client information.
- Maintain grant eligibility.
- Strengthen cyber insurance readiness.
- Reduce operational risk.
- Build confidence with donors and board members.
Most importantly, it allows your staff to stay focused on delivering services—not responding to preventable technology issues.
Technology That Supports Growth, Not Just Compliance
At I-M Technology, our Tech4NonProfits program helps social service and health & human service organizations throughout Southern New England build secure, compliant technology environments that support long-term growth.
We combine:
- Predictable managed IT services
- Cybersecurity monitoring
- Microsoft Nonprofit and Azure grant administration
- TechSoup support
- Password and device management
- AI implementation guidance
- Staff technology and cybersecurity training
Our goal is to help nonprofit leaders spend less time worrying about technology—and more time advancing their mission.
Schedule Your Complimentary Nonprofit IT Optimization Plan
If you're unsure whether your technology environment would stand up to a grant review, cybersecurity assessment, or insurance audit, now is the perfect time to find out.
During your complimentary 30-Minute Nonprofit IT Optimization Plan, we'll identify compliance gaps, review your cybersecurity posture, evaluate Microsoft 365 and AI governance, and recommend practical improvements that help your organization stay secure, compliant, and prepared for future growth.


