Cybersecurity Responsibility for Nonprofits: Who Owns What?

Cybersecurity responsibility is shared across a nonprofit, but accountability starts with leadership. The CEO or executive director does not need to become a cybersecurity expert. But leadership is responsible for making sure the organization is protecting the people, information, funding, and systems its mission depends on.

That means establishing priorities, approving resources, understanding significant risks, overseeing vendors, and making sure cybersecurity issues do not fall into the gaps between the board, staff, IT, and outside providers. IT teams and security providers can manage the technical work. Employees can follow safe practices. Vendors can perform contracted services.

But a nonprofit cannot outsource responsibility for protecting its mission. And that distinction matters.

A cyber incident at a nonprofit is rarely just an “IT problem.” It can interrupt services, expose donor or client information, create compliance concerns, shake board confidence, damage the organization’s reputation, and make supporters question whether their trust has been well placed.

The goal is not to make the CEO responsible for every security control. The goal is to make sure everyone knows what they own—and that leadership has enough visibility to make responsible decisions before a problem threatens the mission.

What Does Cybersecurity Responsibility Mean for a Nonprofit?

Cybersecurity responsibility means clearly defining who protects the organization, who operates security controls, who responds when something goes wrong, and who makes decisions when cyber risk could affect the mission. That is different from simply assigning technical tasks.

Your IT team or cybersecurity provider may manage passwords, access, software updates, backups, monitoring, threat detection, or suspicious activity. Leadership still has to answer bigger questions:

  • How much risk is acceptable?
  • What information is most important to protect?
  • Are we investing enough to responsibly safeguard the organization?
  • Who needs to know when a serious problem is discovered?
  • What happens if systems go down during a critical program?
  • How would we respond if donor, employee, client, student, patient, or payment information were exposed?
  • Can we explain our cybersecurity approach to the board, an auditor, an insurer, a funder, or a regulator?

That governance role is reflected in the NIST Cybersecurity Framework, which emphasizes roles, responsibilities, policies, risk tolerance, and the integration of cybersecurity into broader organizational risk management.

For nonprofits, cybersecurity responsibility generally falls into four areas:

  • Governance: Who sets priorities and makes risk decisions?
  • Execution: Who operates and maintains security protections?
  • Behavior: What are staff and volunteers expected to do?
  • Oversight: Who confirms responsibilities are actually being fulfilled?

When those responsibilities are unclear, serious security gaps can exist even when a nonprofit has invested heavily in technology.

Who Is Responsible for Cybersecurity in a Nonprofit?

Cybersecurity is a shared responsibility, but it is not shared equally.

Role Main Responsibility Accountable For
Executive leadership Governance and mission-level risk decisions Priorities, resources, oversight, escalation, organizational risk
Board of directors Governance and oversight Asking appropriate questions, reviewing material risks, supporting responsible stewardship
IT and security teams Technical execution Systems, controls, access, patching, remediation, recovery
Employees and volunteers Secure behavior Following procedures, protecting credentials, reporting concerns
MSP or MSSP Contracted technology and security services Monitoring, support, response, reporting, remediation, guidance

The important distinction is between doing cybersecurity work and owning the organizational decisions behind it.

Executive Leadership Responsibility

For nonprofit CEOs and executive directors, cybersecurity is ultimately a leadership issue because technology risk can become mission risk very quickly. Executives do not need to understand every technical detail. They do need enough visibility to make responsible, defensible decisions.

Leadership typically owns:

  • Cybersecurity priorities
  • Budget and resource allocation
  • Risk tolerance
  • Vendor oversight
  • Compliance accountability
  • Escalation expectations
  • Business continuity priorities
  • Review of significant unresolved risks
  • Communication with the board

Think about what happens after a serious incident. The board is unlikely to ask the CEO which firewall setting failed. They are more likely to ask:

“Did we know this risk existed?”
“What were we doing about it?”
“Why wasn’t the board informed?”
“Could this have been prevented?”
“How will this affect the people we serve?”
“Do we have to notify donors, clients, regulators, insurers, or partners?”

Those are leadership questions. If a board member, funder, auditor, insurer, community partner, or regulator asks how a significant cybersecurity risk is being managed, leadership should be able to explain what the risk is, who owns it, what is being done, and whether further action is required.

Tracking a focused set of key risk indicators in cybersecurity can help nonprofit executives see changes in exposure without forcing them into technical detail.

The Board’s Cybersecurity Responsibility

The board is not there to run the nonprofit’s cybersecurity program. But it does have an important oversight role.

Board members should have enough visibility to understand whether significant risks could affect the nonprofit’s mission, finances, reputation, legal obligations, or ability to serve the community. That does not mean flooding the board with technical reports.

Good cybersecurity reporting should help directors understand questions such as:

  • What are our most important cybersecurity risks?
  • Has our level of exposure increased or decreased?
  • Are there unresolved issues leadership needs to address?
  • Are we meeting applicable compliance requirements?
  • Can we recover if a major system becomes unavailable?
  • Are sensitive donor, employee, client, patient, student, or payment records adequately protected?
  • Are there decisions or investments that require board awareness?

The CEO’s job is not to turn directors into cybersecurity professionals. It is to give them enough clarity to fulfill their governance responsibilities.

When executive leadership can translate cybersecurity into mission impact, financial exposure, operational continuity, and organizational reputation, board conversations become much more productive.

Why Board Reporting Should Keep Material Cybersecurity Control Areas Separate

Clear reporting still matters. Boards need concise information tied to risk, mission impact, and decisions. But concise reporting should not hide meaningful differences between cybersecurity control areas.

Across 26 nonprofit cybersecurity assessments, 7tech observed that stronger findings in some control areas existed alongside weaker findings elsewhere. These were prospect assessment observations, not client outcomes, and the assessment set should not be treated as representative of the nonprofit sector.

The evidence supports a narrower conclusion: A favorable result in one cybersecurity control area should not be used to infer the health of another control area.

For nonprofit leadership, that distinction matters because several materially different security conditions can exist inside the same organization. An overall cybersecurity score can still be useful. But it should not replace visibility into important weaker areas.

Board reporting should preserve meaningful differences between material control areas so directors can understand where the organization is strong and where attention is still required.

For each important area, leadership reporting should show:

  • Current condition
  • Material gaps
  • Business impact
  • Required action
  • Responsible owner
  • Current status

The purpose is not to make directors review every individual security control. It is to prevent simplicity from hiding a distinction that could matter to governance.

Can leadership see which important control areas are strong and which still need attention?

If several materially different controls are summarized into one rating, leadership should determine whether stronger findings could be masking weaker ones.

The 26 assessments do not prove that nonprofit boards were misled, that overall cybersecurity scores are inherently misleading, or that this pattern is prevalent across the nonprofit sector. They do support keeping material control-level differences visible when cybersecurity information reaches leadership.

A structured cyber risk assessment can help leadership examine security conditions separately, prioritize material gaps, and translate findings into an actionable risk picture instead of relying only on one overall rating.

IT or Internal Technology Team Responsibility

Internal IT and security teams usually handle much of the daily execution. Their responsibilities may include:

  • User access
  • Software patching
  • Endpoint protection
  • Network security
  • Microsoft 365 administration
  • Backups
  • Vulnerability remediation
  • Security tools
  • Device management
  • Incident response
  • Employee onboarding and offboarding
  • Technology vendor coordination

But operational responsibility does not make IT solely accountable for organizational risk. Your IT team cannot independently decide how much risk the nonprofit should accept. It cannot decide whether a major investment is justified compared with competing program priorities. And it should not be left alone to determine whether a significant issue needs to be elevated to executive leadership or the board.

Internal technology teams need clear priorities, appropriate resources, executive support, and defined escalation paths. They may also need specialized outside expertise when security needs become broader than the internal team’s available time or experience.

That matters because protecting a nonprofit requires more than securing individual computers. Understanding how different cybersecurity layers work together can help leadership see how security connects across the organization’s entire technology environment.

Employee and Volunteer Responsibility

Your employees are part of the nonprofit’s cybersecurity defense because some decisions cannot be automated.

Imagine someone in your finance or development department receives an email late Friday afternoon. It appears to come from the executive director:

“I’m heading into a meeting. Can you send me the updated banking information for the new vendor before you leave?”

The name looks right. The writing style seems believable. Everyone is trying to finish the week. And the request sounds urgent.

Security technology may block many malicious messages, but it cannot make every judgment for your staff.

Employees should know:

  • Who to contact when something seems suspicious
  • How to verify unusual financial or data requests
  • When not to open a link or attachment
  • How to protect passwords and authentication methods
  • How to report suspected phishing
  • What to do after an accidental click
  • What to do if information was sent to the wrong person
  • Why reporting a mistake quickly is more important than hiding it

The goal is not to turn your program staff, fundraisers, case managers, administrative employees, or volunteers into cybersecurity specialists. The goal is to remove uncertainty.

CISA’s phishing guidance reinforces the importance of helping employees recognize and report suspicious activity.

More focused resources, such as these ransomware prevention strategies for nonprofit organizations, can also help organizations address specific threats without shifting technical responsibility onto employees.

MSP or MSSP Responsibility

Many nonprofits rely on a managed IT provider or managed security services provider because maintaining all the necessary expertise internally can be expensive and difficult. A qualified provider should own the responsibilities defined in its agreement with your organization.

Depending on the engagement, that could include:

  • IT support
  • Security monitoring
  • Threat detection
  • Vulnerability management
  • Patch management
  • Backup monitoring
  • Microsoft 365 administration
  • Endpoint security
  • Incident response
  • Security reporting
  • Compliance guidance
  • Strategic technology planning

Nonprofits may use managed security services to gain deeper expertise and broader coverage without building a large internal security department.

But hiring an MSP or MSSP does not transfer all responsibility away from the nonprofit. Leadership still needs to know:

  • What the provider owns
  • What internal staff owns
  • What is not covered
  • How incidents are escalated
  • Who can authorize emergency actions
  • What risks have been identified
  • What recommendations remain unresolved
  • How provider performance is reviewed

CISA guidance on shared responsibility with managed service providers emphasizes that organizations and MSPs need transparent discussions and a shared commitment to securing sensitive systems and data.

The FTC’s vendor security guidance similarly reinforces the need to define security expectations and maintain oversight.

Your provider may operate the controls. Your nonprofit still owns the consequences of the decisions made around them.

Cybersecurity Responsibility Is Not the Same as Cybersecurity Ownership

A nonprofit can distribute cybersecurity work without losing clarity about who ultimately owns the risk.

Ownership identifies who has organization-level authority and visibility. Accountability identifies who makes sure necessary action happens. Administration covers the day-to-day technical work. Support adds specialized expertise, capacity, and coverage.

For many nonprofits, one executive should have clear visibility across all four areas. That may be the CEO, executive director, COO, CFO, CIO, or another senior leader. The title matters less than the clarity.

That person does not need to operate every security control. Their responsibility is to make sure an important risk does not disappear between:

  • The CEO and the board
  • Finance and IT
  • Internal staff and an outside provider
  • A cybersecurity provider and another technology vendor
  • Leadership priorities and limited budget
  • A technical finding and the person authorized to make a decision

Role clarity is a central part of effective cybersecurity governance. Leadership needs to know not only who is doing the work, but who has authority when a decision affects the organization.

Why Cybersecurity Responsibility Matters More for Nonprofits

Nonprofits operate under a different kind of pressure. Every dollar spent on technology competes with programs, people, fundraising, and direct mission work. That can make cybersecurity spending uncomfortable.

The question is rarely, “Would stronger security be nice to have?” It is usually, “Can we responsibly justify this expense when those dollars could be used somewhere else?”

That is exactly why cybersecurity responsibility must be clear. Good governance helps leadership distinguish between unnecessary technology spending and investments needed to protect the organization.

A security failure can create costs far beyond replacing a computer. Depending on the organization, an incident could affect:

  • Donor confidence
  • Grant requirements
  • Fundraising systems
  • Credit card information
  • Client records
  • Patient information
  • Student data
  • Children’s information
  • Payroll
  • Financial accounts
  • Staff productivity
  • Community services
  • Partner relationships
  • Insurance coverage
  • Regulatory obligations

For some nonprofits, requirements such as HIPAA, PCI DSS, COPPA, FERPA, contractual requirements, or other privacy and security obligations may add another layer of responsibility.

The point is not that every nonprofit faces every regulation. The point is that leadership should know which requirements apply and who is responsible for meeting them. Responsible stewardship includes protecting the organization from avoidable risk.

What Changes When a Nonprofit Outsources Cybersecurity?

Outsourcing changes who performs certain cybersecurity functions. It does not eliminate the nonprofit’s responsibility for oversight.

A capable MSSP can give a nonprofit access to:

  • Specialized cybersecurity expertise
  • 24/7 monitoring
  • Threat detection
  • Security tooling
  • Incident response capabilities
  • Vulnerability management
  • Executive reporting
  • Strategic guidance

Those capabilities may be difficult or expensive to maintain entirely in-house. But the nonprofit still needs to understand:

  • Who is protecting what
  • Where provider responsibility ends
  • Where internal responsibility begins
  • How serious problems reach leadership
  • Who approves major remediation work
  • How quickly incidents are addressed
  • Whether recommendations are actually being implemented

Nonprofits considering outside support should understand what managed security services include without assuming the provider becomes accountable for every cybersecurity decision.

For organizations with internal technology staff, understanding how MSSP support works with internal IT is particularly important. The best co-managed relationships eliminate ambiguity rather than adding another layer of it.

When the missing capability is executive-level security strategy, virtual CISO services can help translate technical findings into priorities, roadmaps, governance decisions, and board-ready reporting.

A Simple Cybersecurity Responsibility Framework for Nonprofit Leaders

You do not need a complicated governance program to improve cybersecurity accountability. Start with five questions.

1. Who owns organization-level cybersecurity decisions?

Name the executive who has responsibility for visibility, escalation, and risk decisions. That person should understand enough about the organization’s cybersecurity position to know when action is required.

2. Who operates each critical cybersecurity function?

Clarify ownership for areas such as:

  • User access
  • Microsoft 365
  • Endpoint protection
  • Software patching
  • Backups
  • Network security
  • Vulnerability management
  • Security monitoring
  • Incident response
  • Employee onboarding and offboarding
  • Vendor access
  • Recovery

Avoid assumptions. If internal IT thinks the provider owns something while the provider believes internal IT owns it, nobody truly owns it.

3. What are employees expected to do?

Define simple, practical expectations. Employees should know how to:

  • Protect their accounts
  • Verify unusual requests
  • Handle sensitive information
  • Report suspicious activity
  • Respond after making a mistake

The process should be easy enough that staff will actually follow it.

4. What exactly does your provider own?

Review your IT and cybersecurity agreements. Document what the provider:

  • Monitors
  • Manages
  • Maintains
  • Reports
  • Responds to
  • Escalates
  • Advises on

Then identify what remains the nonprofit’s responsibility.

5. How does leadership review cybersecurity risk?

Executive reporting should not be a pile of technical data. It should help leadership answer:

  • What changed?
  • What matters?
  • What remains unresolved?
  • Who owns the next step?
  • Is the organization becoming more or less exposed?
  • Which material control areas are strong?
  • Which material control areas still need attention?
  • Could stronger results in one area be obscuring weaker results somewhere else?
  • Does leadership need to make a decision?
  • Does the board need to know?

An overall score can still be useful, but it should not replace visibility into important weaker areas.

For organizations that want to review these areas more systematically, a cybersecurity assessment checklist can provide a more structured starting point.

Warning Signs Cybersecurity Responsibility Is Unclear

Responsibility gaps often appear before a serious incident. Watch for warning signs such as:

  • Nobody can clearly explain who owns cybersecurity at the leadership level.
  • The board only hears about cybersecurity when something goes wrong.
  • Executive reports are too technical to support decisions.
  • Materially different cybersecurity control areas are reduced to one overall rating without showing where important weaknesses remain.
  • Critical security knowledge depends on one employee.
  • Your IT team believes the provider owns something the provider believes IT owns.
  • Security findings are identified, but nobody owns follow-up.
  • Employees do not know where to report suspicious activity.
  • Old employee accounts remain active longer than they should.
  • Nobody regularly confirms backups can actually be restored.
  • Audit or insurance questionnaires trigger a scramble for answers.
  • Compliance questions depend entirely on one employee or vendor.
  • Security projects repeatedly stall because nobody has authority to approve the next step.
  • Leadership knows there are cybersecurity concerns but cannot clearly explain which risks are most important.

Those are not simply technology problems. They are governance problems. And the solution may not be another cybersecurity tool.

The first step may be clarifying ownership, reporting, escalation, decision authority, and accountability.

When Should a Nonprofit Bring in Outside Cybersecurity Leadership or MSSP Support?

Outside support becomes valuable when cybersecurity responsibilities exceed your internal team’s available time, expertise, capacity, or coverage. That often happens when:

  • The nonprofit has grown faster than its IT processes.
  • Staff depends increasingly on cloud technology.
  • Remote or distributed employees need secure access.
  • Internal IT spends most of its time responding to daily support needs.
  • The organization handles sensitive donor, client, health, payment, or student information.
  • Cyber insurance requirements are becoming more demanding.
  • Grant, contractual, or regulatory requirements are increasing.
  • Leadership cannot get a clear view of cybersecurity risk.
  • Security monitoring needs to happen outside normal business hours.
  • Too much organizational knowledge depends on one IT employee.
  • The board is asking more cybersecurity questions.
  • Leadership wants stronger oversight without hiring a full internal security team.

The purpose of outside support should not be to remove accountability from leadership. It should make accountability easier.

The right partner helps nonprofit leaders understand what matters, what needs attention, what can wait, and what action is required—without burying them in technical language.

A cyber risk assessment can help identify where exposure is concentrated, while broader managed cybersecurity services can provide the ongoing protection and support needed to address those risks.

Frequently Asked Questions About Nonprofit Cybersecurity Responsibility

Who is ultimately responsible for cybersecurity at a nonprofit?

Cybersecurity responsibility is shared across executive leadership, the board, IT, employees, volunteers, and outside providers. Executive leadership owns organization-level accountability for priorities, resources, oversight, escalation, and risk decisions.

Is cybersecurity the nonprofit CEO’s responsibility?

The CEO or executive director does not need to personally manage cybersecurity operations. However, executive leadership is responsible for making sure cybersecurity risk is appropriately governed.

Depending on the organization, a COO, CFO, CIO, IT director, CISO, or another senior leader may manage parts of the responsibility. What matters is that ownership is explicit rather than assumed.

What cybersecurity responsibility does the board have?

The board provides governance and oversight. Directors should have enough information to understand material cybersecurity risks that could affect the organization’s mission, finances, reputation, compliance obligations, or continuity.

They do not need to manage technical controls. Reporting should preserve meaningful differences between material control areas so stronger findings in one area do not create assumptions about another.

Does outsourcing cybersecurity transfer responsibility away from the nonprofit?

No. Outsourcing transfers defined operational duties. The nonprofit still owns vendor oversight, organizational risk decisions, governance, resource allocation, and responsibility for acting when significant cybersecurity issues require leadership attention.

Are nonprofit employees responsible for cybersecurity too?

Yes. Employees are responsible for following security procedures, protecting credentials, verifying unusual requests, handling sensitive information appropriately, and reporting suspicious activity quickly. They should not be expected to make technical cybersecurity decisions.

What is the difference between cybersecurity governance and cybersecurity operations?

Cybersecurity governance defines ownership, priorities, accountability, risk decisions, reporting, and oversight. Cybersecurity operations put those decisions into practice through access management, patching, backups, monitoring, threat detection, response, vulnerability remediation, and other technical activities.

How should nonprofit leaders explain cybersecurity spending to the board?

Connect the investment to what the organization is protecting. Instead of leading with technical products, explain how the investment reduces risk to mission continuity, donor trust, sensitive information, staff productivity, compliance obligations, finances, and the people the nonprofit serves.

The board does not need every technical detail. It needs enough information to understand the risk, the consequences of inaction, the recommended response, and the cost of addressing it.

Clear Cybersecurity Responsibility Helps Protect the Mission

Your nonprofit exists to serve people, strengthen communities, advance a cause, or solve a problem that matters. Cybersecurity exists to help protect your ability to keep doing that work.

Leadership governs the risk. The board provides oversight. IT and security teams handle technical execution. Employees and volunteers follow secure practices and speak up when something does not look right. Outside providers contribute expertise, monitoring, response, and strategic support.

The objective is not to make one person responsible for everything. It is to make sure nothing important gets lost between people, departments, vendors, budgets, and competing priorities.

Because ultimately, nonprofit leaders are not trying to protect servers. They are protecting trust. They are protecting the people who depend on them. And they are protecting the mission they have been entrusted to lead.

Get a clear view of your cybersecurity responsibilities and risk gaps with a practical cybersecurity assessment. Clarify where ownership currently sits, where responsibilities overlap or remain undefined, and where stronger oversight or outside support could give leadership better control.