Grant ProgramsCyber Grants Alliance Blog

Ten Minutes On The Agenda: What A Nonprofit Board Should Ask About Cybersecurity

August 31, 2026 Cyber Grants Alliance 7 min read

Cybersecurity belongs on your board agenda as an oversight item, not a technology update. The board does not need to understand firewalls, it needs to know who is accountable, what would happen on the worst day, and whether anything is written down.

Most small nonprofit boards handle this badly in one of two directions. Either they never raise it at all, or they ask one alarming question, hear a reassuring answer from the one person who manages the laptops, and move on. Neither is oversight.

Hierarchy diagram showing board oversight at the top branching into five standing questions, each pointing down to one written artifact staff must own.
Board oversight sits above five standing questions. Each question points to one written artifact staff must own.

Why is this landing on boards right now?

Two pressures are converging on small organizations at once.

The first is governance itself. When NIST released version 2.0 of its Cybersecurity Framework in 2024, the headline change was a new function called Govern, which sits alongside Identify, Protect, Detect, Respond and Recover. Govern is explicitly about organizational context, roles, responsibilities, policy and oversight. In plain language, the most widely used cyber framework in the country now says that leadership accountability is part of the control set, not a nice extra.

The second is federal money. If your organization receives federal awards, you are already subject to internal control obligations under the Uniform Guidance at 2 CFR 200.303, which requires recipients to establish and maintain effective internal control over the federal award and to take reasonable measures to safeguard protected personally identifiable information. That language has been there for years. What is changing is how specifically agencies are asking about it.

There is also movement on the risk side of federal programs. The National Institutes of Health published guidance in August 2026 on how small business program applicants should address foreign risk in their applications, following legislation enacted earlier in 2026. That guidance is aimed at small business program applicants rather than at nonprofits generally, so do not assume it binds you. Do assume the direction of travel: agencies are asking award recipients to describe risk in writing rather than to promise it verbally.

What does the board actually owe here, and what does it not?

The board owes duty of care. That means informed oversight of a material organizational risk, documented in the minutes.

The board does not owe technical judgment. You are not approving a tool. You are asking whether a named human being is accountable, whether the organization knows what data it holds, and whether there is a plan for the day the finance email account is compromised.

Here is the honest question for your board: if your executive director were unreachable for a week and your accounts payable inbox received a convincing request to change a vendor's banking details, who catches it, and what written procedure do they follow?

Not Sure Where Your Organization Stands?

If your board is ready to ask these questions and your team needs help producing the answers, Cyber Grants Alliance can help you get there, including in-kind support built for nonprofits.

See Cybersecurity Grants for Nonprofits →

What are the five questions to put on the agenda?

Ask these in this order. They build on each other.

  1. Who is accountable for cybersecurity by name, and who is their backup? Not a vendor. A person on your staff or board who owns the answer.
  2. What sensitive data do we hold, where does it live, and who can reach it? Donor records, client records, health information, personnel files, payroll. If nobody can answer this in one page, that is the finding.
  3. What happens in the first twenty four hours after we discover a breach? Who calls counsel, who calls the insurer, who decides whether to notify, and where is that written down.
  4. What are we contractually or legally required to do that we are not doing? Grant agreements, donor agreements, HIPAA if you are a covered entity, state breach notification statutes, and any flow down clauses if you subcontract on federal work.
  5. When did we last test a restore from backup? Not whether backups run. Whether someone has actually restored data and watched it work.

What answers should worry a board member?

Some answers are red flags regardless of how confident they sound.

  • "Our IT provider handles all of that." Ask what the agreement actually obligates them to do. Managed service agreements frequently exclude incident response, security monitoring and user training.
  • "We are too small to be a target." Attacks on small organizations are overwhelmingly automated and opportunistic. Nobody chose you.
  • "We have cyber insurance." Ask whether anyone has read the application answers your organization submitted. Coverage often depends on controls the organization claimed to have.
  • "It is all in the cloud." Cloud providers secure their infrastructure. Your configuration, your accounts and your data are yours.
  • Silence, followed by a promise to look into it. That is fine once. Ask for a date.

What should be written down before the next audit or grant report?

Four artifacts get a small organization most of the way there, and none of them require a security team.

  • A one page data inventory. What you hold, where, and who can access it.
  • A one page incident response plan with names and phone numbers, printed, because it will be needed when systems are down.
  • An access list review, done twice a year, confirming that departed staff and former volunteers no longer have accounts.
  • A short board resolution naming the accountable person and setting a review cadence.

If your organization touches defense work as a subcontractor or partner, the bar is higher and more specific. The Department of Defense CMMC program rule took effect in December 2024, and the acquisition rule that puts CMMC requirements into contracts followed in late 2025, which means requirements now flow through contract clauses rather than good intentions. Nonprofits are not automatically exempt if they handle covered information under a federal contract. What does your organization actually hold on behalf of a federal customer? Our CMMC guide walks through what that means in practice.

Frequently Asked Questions

Does a nonprofit board need a cybersecurity expert on it?

No. Boards oversee risk in many areas without holding the underlying expertise, and cybersecurity is no different. What the board needs is a standing agenda item, a named accountable person, and the willingness to ask follow up questions when an answer is vague. An expert advisor can be useful, but the absence of one is not an excuse to skip oversight.

How often should cybersecurity appear on the board agenda?

Quarterly is a reasonable default for most small nonprofits, with an annual deeper review. The quarterly item can be ten minutes: any incidents, any changes to systems or vendors, status of the access review. The annual review should revisit the data inventory and the incident response plan.

Are nonprofits legally required to have cybersecurity controls?

It depends entirely on what you hold and where your money comes from. Recipients of federal awards have internal control and personally identifiable information safeguarding obligations under 2 CFR 200.303. Health information may trigger HIPAA, and every state has a data breach notification statute that applies regardless of organization type. There is no single national cybersecurity law that covers all nonprofits.

What is the difference between directors and officers insurance and cyber insurance?

They cover different things and neither reliably covers the other. Directors and officers policies address claims against individual board members and officers for their decisions. Cyber policies address incident response, notification, business interruption and liability arising from a data incident. Ask your broker to state in writing what is excluded.

Our IT is handled by a volunteer. Is that a problem?

It is common and it is workable, but it becomes a problem when it is undocumented. The risk is not the volunteer's skill, it is that knowledge and access live in one head with no succession. Make sure a second person, ideally a staff member, holds administrative access and knows where credentials are stored.

What is the single first step for a board that has never discussed this?

Ask for the one page data inventory at the next meeting. It is the artifact that makes every other conversation possible, it can be produced by existing staff, and the difficulty of producing it tells you more about your posture than any assessment would.

Sources: NIST Cybersecurity Framework 2.0; 2 CFR 200.303, Internal controls; CISA Cyber Essentials, Yourself, The Leader; Department of Defense CMMC program; NIH Extramural Nexus, How Do I Address Potential Foreign Risks in My Small Business Program Application, August 2026.

Share this article: LinkedIn X Email