You don't need a security budget to fix your biggest risk.


Issue #16

Hey there, fellow accidental techie ๐Ÿ‘‹

Last week an email showed up asking you to update the bank routing number for a vendor payment. It looked right. Right logo, right signature block, even the right tone. You paused for half a second, then moved on to the next fire, because four other things were due today and this looked like routine business.

That half-second pause is worth paying attention to. It's usually where these things go wrong, or where they get stopped.

You didn't sign up to be your org's cybersecurity person. You signed up to run operations, manage the database, create new systems that help your organization growth. Somewhere along the way, "figure out our security" landed on your desk anyway, with no budget line and no training to match it.

Here's the question worth asking, and it's not "how do we get enterprise-grade security." It's smaller and more useful: what's actually going to hurt us, and what can we fix without a consultant or a five-figure contract.

What's in this issue:

โœ… The actual threat, and it's not what the headlines make it look like

โœ… A real case, and what it cost one nonprofit

โœ… The access problem almost every small org has and doesn't know about

โœ… Three moves you can make this week, in order of difficulty

โœ… What I'm reading


The actual threat isn't who you think

Every cybersecurity headline features a hoodie and a dark room. Picture something duller instead: an email that looks exactly like it's supposed to, sitting in your inbox next to eleven others you haven't opened yet.

None of this is because nonprofit staff are careless. It's because the sector runs lean by design, with public donor lists, thin IT setups, and staff wearing five hats, and lean means nobody owns this full time.

Here's what one of these actually looks like. A staffer at a mid-sized nonprofit got an email that looked like it came from a partner organization's bank, saying the account was under a routine audit and payments should go to a new account until it cleared. The email chain looked legitimate. Names were right. Tone was right. The org wired more than $600,000 before anyone realized the "audit" didn't exist. Most of it was gone. The project it was funding, a shelter build, got delayed for months while everyone tried to recover what they could.

Nothing about that story required a sophisticated hack. It required patience, some research on a public website, and one moment where nobody picked up the phone to double check.

Common objection: We're too small to be a target.

Reality: Small is exactly what makes you easier. A public donor list, a thin IT setup, and staff wearing five hats is precisely the profile these emails are built for.


The access problem nobody's tracking

There's a quieter version of this risk sitting in your Google Drive right now. Someone who left the org eight months ago probably still has access to something. Maybe it's the donor database. Maybe it's just the shared drive with your board minutes in it. Almost nobody formally revokes access on someone's last day, because offboarding a person's tech footprint isn't anyone's assigned job.

This is where the Projects Bridge shows up. Nobody handed you ownership of "who has access to what." It became yours because you're the one who knows where the logins live. No training course fixes this, because the problem was never your skills. The gap is infrastructure that never got built, and it'll feel uncomfortable the first time you actually run the audit and see who's still on the list.

Join The Accidental Techie Community in Linkedin


Three moves, easiest to hardest

Turn on multi-factor authentication this week. Email, your donor database, your financial accounts, in that order. It's free on almost every platform your org already uses. It creates a little friction, someone will grumble about the extra step, and it's still the single highest-return move available to you. Success looks like: MFA active on the three systems that would hurt most if someone got into them.

Build the access list, then make it a standing process. Start with one page this week: every system, who has access, and whether they still work there. The harder part comes next. Turn that list into a real onboarding and offboarding checklist, and build it with your HR lead and hiring managers as partners, not as something you own alone. This is a Relationships Bridge move wearing a Projects Bridge hat. You can't fix access sprawl by yourself, because you're not the one who knows when someone's actually leaving.

Use October to formalize training, and start planning now. Cybersecurity Awareness Month lands every October, and it's a built-in excuse to do the training you've been meaning to schedule. Start with something free: NTEN's cybersecurity hub links directly to KnowBe4's free phishing simulation test, so you can see where your team actually stands before you spend anything. TechSoup's security marketplace (techsoup.org/security) is the place to check for discounted paid tools once you know what you need. Either way, the training matters less than what happens after it. Build a culture where someone can say "I think I clicked something" without getting reprimanded for it.

Instead of: "Who clicked on this?" Try: "Thanks for flagging it. Let's fix it together."

The org that catches a mistake in an hour because someone felt safe admitting it beats the org that doesn't find out for three weeks because someone was afraid to say anything.

Success looks like this: a one-page access list that's actually current, MFA on your highest-risk systems, and a team that would tell you if they clicked the wrong thing.

Until next time,

Hugo

P.S. NTEN's Cybersecurity Resource Hub links to Tech Accelerate, a free assessment tool that scores your org and points you to resources for each gap it finds. Worth doing before your next board meeting: nten.org/learn/resource-hubs/cybersecurityโ€‹

Need this for your whole team?

A one-time email is a start. A staff-wide digital hygiene workshop is what actually changes behavior, because this only works if it's not just the accidental techie thinking about it. I run these for nonprofits who want their whole team on the same page. Get in touch โ†’ hugo@flourishcollectivellc.comโ€‹


Join the Waitlist

A 6-week cohort program for nonprofit professionals ready to stop firefighting and start shaping technology strategy.

Join the waitlist for early access and beta pricing.

BEFORE YOU GO

None of this requires you to become a security expert. It requires you to close the gaps that don't need a budget, and to build the systems that don't depend on you remembering everything. That's the Projects Bridge in practice: not heroics, just infrastructure that holds up when you're not looking.

Next issue, we're staying in this same territory: what happens when a vendor tells you they specialize in nonprofits, and how to make sure that's actually true before you sign anything.

P.S. If someone on your team handles the passwords, the donor database, or "whatever's broken with the computers," forward this to them. They're probably doing this job without anyone calling it a job.

600 1st Ave, Ste 330 PMB 92768, Seattle, WA 98104-2246
โ€‹Unsubscribe ยท Preferencesโ€‹