By: Stephen Calder
Director
Not-for-profit organisations are increasingly operating in a challenging environment. Funding pressures, growing service demand and workforce constraints mean leaders are constantly making decisions about where limited resources should be invested.
At the same time, cyber security, privacy and digital governance expectations continue to increase.
For many organisations, this creates a difficult tension. Boards and executive teams recognise the importance of protecting sensitive information, maintaining service continuity and meeting stakeholder expectations. However, they also know that every dollar spent on technology is a dollar that cannot be spent directly on delivering community outcomes.
The challenge is not whether to invest in cyber security. It is how to invest wisely.
A common misconception is that cyber criminals focus exclusively on large corporations and government agencies. In reality, not-for-profit organisations often hold significant volumes of sensitive information, including client records, donor information, financial data, employee details and operational systems. Many also provide critical services that communities depend upon.
The consequences of a cyber incident can extend well beyond technology. Service disruption, loss of stakeholder trust and reputational damage can all affect an organisation's ability to achieve its mission.
When organisations begin their cyber security journey, there can be a temptation to search for a single technology solution that will solve the problem. Unfortunately, cyber security rarely works that way.
Some organisations underinvest and leave themselves exposed to significant risks. Others invest heavily in complex tools and technologies that create administrative burden without meaningfully reducing risk.
The most effective organisations take a different approach. They focus first on understanding their most significant risks and then direct their investment towards controls that deliver the greatest practical benefit. Cyber security should be proportionate to an organisation's size, complexity, risk profile and operating environment. It should strengthen resilience without creating unnecessary compliance burden.

While technology plays an important role in protecting organisations, many cyber incidents still involve people.
Phishing attacks, weak passwords, inappropriate information handling practices and a lack of cyber awareness continue to be some of the most common causes of security breaches. This means strong cyber security is not simply about systems and software. It is also about culture. Organisations that build cyber awareness across their workforce are often better positioned to identify threats early, respond effectively and reduce the likelihood of incidents occurring in the first place.
Importantly, fostering a culture of accountability does not require large budgets. It requires consistent leadership, practical education and clear expectations.
For not-for-profit organisations, the goal should not be perfection. The goal should be resilience.
A practical cyber security program helps organisations:
Most importantly, it enables organisations to continue focusing on their mission.
Every organisation will face constraints. The key is ensuring that cyber security investments are directed towards the areas that matter most, rather than chasing every possible threat or technology trend.

Centium's Digital Assurance team helps organisations build confidence in how they govern, protect and use technology, information and data. Our practical, risk-based approach focuses on strengthening cyber security, digital governance and organisational resilience without creating unnecessary compliance burden.
Our services include:
We focus on practical outcomes, helping organisations identify their most significant digital risks and invest in controls that are proportionate, effective and sustainable.
Centium's Stephen Calder, Director Risk & Assurance, will be attending the Third Sector Leaders Forum, where he'll be discussing the cyber security and digital governance challenges facing not-for-profit organisations today.
Stephen is passionate about helping NFPs strike the right balance between protecting critical information and making the most of limited resources. His work focuses on helping boards and executive teams understand their most significant cyber and IT risks, right-size their investment in security and build practical, sustainable approaches to resilience.
Stephen will be attending the Third Sector Leaders Forum on Sept 15-16, 2026 and welcomes the opportunity to connect with fellow not-for-profit leaders. If you'd like to discuss cyber security, digital governance or organisational resilience in a practical, resource-conscious way, be sure to say hello at the event or connect with him on LinkedIn.