December 29, 2025

Featured data classification guide for justice nonprofits image of data being sorted into different categories.

A Practical Data Classification Guide for Justice Nonprofits (Public, Internal, Sensitive, Restricted)

If your organization supports legal advocates, you already know the feeling: information is everywhere. Case notes in shared drives. Training rosters in spreadsheets. Partner lists in email threads. A “final” report living in five versions. A data classification policy (which is a key part of our data classification guide for justice nonprofits) is the simple

A Practical Data Classification Guide for Justice Nonprofits (Public, Internal, Sensitive, Restricted) Read More »

A team reviewing a AI Vendor Due Diligence Checklist

AI Vendor Due Diligence Checklist (Privacy, Bias, and Explainability)

Your intake queue is already loud. A report is due. A partner wants answers. Then a generative AI vendor promises to serve as your strategic technology partner and “save time” with summaries, triage, or a chatbot. That tool might also touch intake notes, safety plans, immigration status, or donor records. The risk isn’t abstract. It’s

AI Vendor Due Diligence Checklist (Privacy, Bias, and Explainability) Read More »

A team reviewing a post incident public statement checklist.

Post Incident Public Statement Checklist: Truth Discipline for Credibility and Harm Reduction

After an incident, your first public statement, rather than a scripted public relations statement, is either a seatbelt or a spark. It can protect your security posture and reduce harm, or it can multiply it. Mission-driven orgs feel pressure from every direction at once following a cybersecurity incident. The board wants confidence. Funders want reassurance.

Post Incident Public Statement Checklist: Truth Discipline for Credibility and Harm Reduction Read More »

A team discussing how tool sprawl is a governance problem

Tool Sprawl Is a Governance Problem in Disguise: Fix It with Clear Ownership & Guardrails

You look at your monthly spend and see a growing wall of SaaS subscriptions, “must‑have” security tools, and point solutions. Yet outages keep happening, access requests drag on, and the board is asking sharper questions about cyber risk and resilience. On paper, you have more tools than ever. In practice, you have less confidence. Tool

Tool Sprawl Is a Governance Problem in Disguise: Fix It with Clear Ownership & Guardrails Read More »

An image of Information Security Compliance for justice organizations

Information Security Compliance: A Practical Guide for Justice-Focused Leaders

Information security compliance, at its core, is about protecting your organization’s digital information by following established laws and industry standards. It's the set of controls and processes you build to stop data breaches, protect sensitive information, and prove to funders, regulators, and the communities you serve that you're a responsible steward of their data. For

Information Security Compliance: A Practical Guide for Justice-Focused Leaders Read More »