Logo of Centium
Contact Us

Cyber security with a budget: A practical approach for not-for-profit leaders

Category:
September 10, 2026

By: Stephen Calder

Director

Not-for-profit organisations are increasingly operating in a challenging environment. Funding pressures, growing service demand and workforce constraints mean leaders are constantly making decisions about where limited resources should be invested.

At the same time, cyber security, privacy and digital governance expectations continue to increase.

For many organisations, this creates a difficult tension. Boards and executive teams recognise the importance of protecting sensitive information, maintaining service continuity and meeting stakeholder expectations. However, they also know that every dollar spent on technology is a dollar that cannot be spent directly on delivering community outcomes.

The challenge is not whether to invest in cyber security. It is how to invest wisely.

Why NFPs are targets for cyber crimes

A common misconception is that cyber criminals focus exclusively on large corporations and government agencies. In reality, not-for-profit organisations often hold significant volumes of sensitive information, including client records, donor information, financial data, employee details and operational systems. Many also provide critical services that communities depend upon.

The consequences of a cyber incident can extend well beyond technology. Service disruption, loss of stakeholder trust and reputational damage can all affect an organisation's ability to achieve its mission.

More spending doesn't always mean better security

When organisations begin their cyber security journey, there can be a temptation to search for a single technology solution that will solve the problem. Unfortunately, cyber security rarely works that way.

Some organisations underinvest and leave themselves exposed to significant risks. Others invest heavily in complex tools and technologies that create administrative burden without meaningfully reducing risk.

The most effective organisations take a different approach. They focus first on understanding their most significant risks and then direct their investment towards controls that deliver the greatest practical benefit. Cyber security should be proportionate to an organisation's size, complexity, risk profile and operating environment. It should strengthen resilience without creating unnecessary compliance burden.

The biggest cyber risk is often not technology

While technology plays an important role in protecting organisations, many cyber incidents still involve people.

Phishing attacks, weak passwords, inappropriate information handling practices and a lack of cyber awareness continue to be some of the most common causes of security breaches. This means strong cyber security is not simply about systems and software. It is also about culture. Organisations that build cyber awareness across their workforce are often better positioned to identify threats early, respond effectively and reduce the likelihood of incidents occurring in the first place.

Importantly, fostering a culture of accountability does not require large budgets. It requires consistent leadership, practical education and clear expectations.

Focusing on what matters most

For not-for-profit organisations, the goal should not be perfection. The goal should be resilience.

A practical cyber security program helps organisations:

  • Protect critical client and donor information
  • Maintain trust with stakeholders and funding bodies
  • Reduce the likelihood of operational disruption
  • Support informed decision-making by boards and executives
  • Strengthen organisational resilience

Most importantly, it enables organisations to continue focusing on their mission.

Every organisation will face constraints. The key is ensuring that cyber security investments are directed towards the areas that matter most, rather than chasing every possible threat or technology trend.

How Centium can help

Centium's Digital Assurance team helps organisations build confidence in how they govern, protect and use technology, information and data. Our practical, risk-based approach focuses on strengthening cyber security, digital governance and organisational resilience without creating unnecessary compliance burden.

Our services include:

  • Digital governance and technology risk reviews to strengthen oversight, accountability and decision-making.
  • Information security and control assurance, including cyber security maturity assessments, Essential Eight assessments and security governance reviews.
  • ISO 27001 and information security management system (ISMS) assurance, helping organisations assess readiness, maturity and ongoing effectiveness.

We focus on practical outcomes, helping organisations identify their most significant digital risks and invest in controls that are proportionate, effective and sustainable.

Meet Stephen Calder at the Third Sector Leaders Forum

Centium's Stephen Calder, Director Risk & Assurance, will be attending the Third Sector Leaders Forum, where he'll be discussing the cyber security and digital governance challenges facing not-for-profit organisations today.

Stephen is passionate about helping NFPs strike the right balance between protecting critical information and making the most of limited resources. His work focuses on helping boards and executive teams understand their most significant cyber and IT risks, right-size their investment in security and build practical, sustainable approaches to resilience.

Stephen will be attending the Third Sector Leaders Forum on Sept 15-16, 2026 and welcomes the opportunity to connect with fellow not-for-profit leaders. If you'd like to discuss cyber security, digital governance or organisational resilience in a practical, resource-conscious way, be sure to say hello at the event or connect with him on LinkedIn.

Top