nonprofit risk management

The 2-hour Nonprofit Systems Inventory workshop: capture every workflow, owner, and risk in one living document

At 4:45 p.m., someone asks a simple question: “How many people did we actually serve this quarter?” The number doesn’t reconcile. Intake is in one place. Referrals are in someone’s inbox. Program notes are in a shared drive. The report is due tomorrow, and staff are already carrying too much. This is how the justice […]

The 2-hour Nonprofit Systems Inventory workshop: capture every workflow, owner, and risk in one living document Read More »

Cybersecurity strategy for capacity building organizations (security priorities funders will respect)

At capacity building organizations focused on workforce development, your training team is onboarding another cohort. A partner sends a spreadsheet of contacts. A funder wants a progress update, and the numbers don’t reconcile. Then someone forwards a “DocuSign” email that wasn’t DocuSign at all. Capacity building organizations sit in a tricky middle. You’re not always

Cybersecurity strategy for capacity building organizations (security priorities funders will respect) Read More »

A team discussing a MFA rollout plan for justice nonprofits

A 14-day MFA rollout plan for justice nonprofits, cut account takeovers without locking out staff or partners

It’s 4:45 p.m. Intake is still climbing. A partner is waiting on a referral handoff. Tomorrow’s court deadline is already too close. Then someone can’t sign in, again, because a password was reset and the reset email went to an old inbox no one checks. This is how account takeovers become a justice problem, not

A 14-day MFA rollout plan for justice nonprofits, cut account takeovers without locking out staff or partners Read More »

A team discussing cybersecurity requirements for legal aid grantees

Cybersecurity Requirements for Legal Aid Grantees (What Funders Expect in Practice)

It’s 8:12 a.m. A program manager forwards a message that looks like it came from the ED. “Urgent, please review this invoice.” Someone clicked. Now intake is down, staff can’t reach case notes, and the board chair is asking the question nobody wants to answer out loud: Are we meeting our grant cybersecurity requirements? As

Cybersecurity Requirements for Legal Aid Grantees (What Funders Expect in Practice) Read More »

A scene of a 60-Day Tech Triage Plan

A 60-Day Tech Triage Plan for Justice Nonprofits, Stop the Fire Drills Without Freezing Work

If you support frontline legal advocates, your tech problems don’t show up politely. They show up on deadline days. During audits. Right before a board meeting. Or when a partner can’t get the data they need to serve someone at risk. A 60-tech triage plan gives you a way out of the loop. Not with

A 60-Day Tech Triage Plan for Justice Nonprofits, Stop the Fire Drills Without Freezing Work Read More »

Featured data classification guide for justice nonprofits image of data being sorted into different categories.

A Practical Data Classification Guide for Justice Nonprofits (Public, Internal, Sensitive, Restricted)

If your organization supports legal advocates, you already know the feeling: information is everywhere. Case notes in shared drives. Training rosters in spreadsheets. Partner lists in email threads. A “final” report living in five versions. A data classification policy (which is a key part of our data classification guide for justice nonprofits) is the simple

A Practical Data Classification Guide for Justice Nonprofits (Public, Internal, Sensitive, Restricted) Read More »

A team reviewing a AI Vendor Due Diligence Checklist

AI Vendor Due Diligence Checklist (Privacy, Bias, and Explainability)

Your intake queue is already loud. A report is due. A partner wants answers. Then a generative AI vendor promises to serve as your strategic technology partner and “save time” with summaries, triage, or a chatbot. That tool might also touch intake notes, safety plans, immigration status, or donor records. The risk isn’t abstract. It’s

AI Vendor Due Diligence Checklist (Privacy, Bias, and Explainability) Read More »

A team performing a SaaS cleanup for justice nonprofits

The 30-Day SaaS Cleanup for Justice Nonprofits, Find every tool, cut duplicates, and stop shadow IT

It’s 4:45 pm. A funder report is due tomorrow. Program says the numbers are in the case system. Development says they’re in the CRM. Finance says the invoice list doesn’t match either. Someone opens a spreadsheet named “FINAL_v7_REAL.xlsx” and hopes it’s the right one. This isn’t a “tech problem.” It’s a capacity problem. When your

The 30-Day SaaS Cleanup for Justice Nonprofits, Find every tool, cut duplicates, and stop shadow IT Read More »

A team that has the correct access to justice technology solutions to help them accomplish their mission

Access to Justice Technology Solutions That Actually Reduce Wait Times (and Risk)

The intake queue is exploding again. A partner referral fell through because the handoff email went to the wrong place. A funder report is due, and the numbers don’t match what staff know happened on the ground. That’s the justice gap in day-to-day form: too many people need help, too few legal resources, and too

Access to Justice Technology Solutions That Actually Reduce Wait Times (and Risk) Read More »

Taming the Chaos: A Practical Guide to Vendor Management for Justice Organizations

You’re running a justice organization that’s grown fast. Your mission is clear, your team is dedicated, and the stakes for the communities you serve couldn’t be higher. But behind the scenes, things feel… fragile. Case data is scattered across tools that don’t talk to each other. Grant reporting is a recurring fire drill. And the

Taming the Chaos: A Practical Guide to Vendor Management for Justice Organizations Read More »