risk management for nonprofits

Board Member Offboarding Checklist After Board Turnover

A board seat on a nonprofit board can change hands in one meeting. Access can linger for weeks. If you don’t have a board member offboarding checklist, board member transitions can leave old permissions, stale contacts, and quiet exposure behind. Most of the time, the problem is not bad intent. It’s weak follow-through. That is […]

Board Member Offboarding Checklist After Board Turnover Read More »

The 30-Day Service Account Register for Justice Nonprofits

A forgotten service account can sit in your systems for years, retaining authentication privileges that let it keep moving data, calling APIs, or giving a vendor quiet access long after the original project ended. That is a real risk for justice nonprofits, because your systems often hold sensitive client, case, and partner data. A simple

The 30-Day Service Account Register for Justice Nonprofits Read More »

Client Texting Policy for Justice Nonprofits Using Personal Phones

A personal phone feels harmless until it becomes a pocket archive of client risk. If your staff text clients from their own devices, speed goes up, but so do risks to client confidentiality, recordkeeping gaps, and leadership blind spots. That tension is common in justice nonprofits. You want fast, humane communication. At the same time,

Client Texting Policy for Justice Nonprofits Using Personal Phones Read More »

Finding operational resilience assessment for legal aid organizations

Operational resilience assessment for legal aid organizations (keep intake and casework moving)

An operational resilience assessment for legal aid organizations, centered on legal aid operational resilience, is a plain-language review of what keeps services running when something goes wrong. It focuses on the real chain of work, from first contact to case outcomes, and conducts a business impact analysis by asking a practical question: where would a

Operational resilience assessment for legal aid organizations (keep intake and casework moving) Read More »

A team learning about cybersecurity for civil justice organizations

Cybersecurity for Civil Justice Organizations (Board-Ready Oversight for Sensitive Data)

The intake queue is exploding. A partner needs records today. A funder report is due, and your team is already stretched thin. In the middle of that, digital security can feel like an extra project. For civil justice system organizations and civil society organizations (legal aid, court self-help, navigator programs, justice-support nonprofits), it isn’t. Cybersecurity

Cybersecurity for Civil Justice Organizations (Board-Ready Oversight for Sensitive Data) Read More »

A leadership team performing a third party risk assessment for capacity building organizations

Third Party Risk Assessment for Capacity Building Organizations (Funder-Ready Findings)

Your intake queue is exploding, a training partner needs an export by Friday, and a funder report is due with numbers that don’t reconcile. Then a vendor emails, “We updated our platform with new AI features.” Your team didn’t ask for that. Now it’s your problem, especially amid cybersecurity threats in the evolving digital landscape.

Third Party Risk Assessment for Capacity Building Organizations (Funder-Ready Findings) Read More »

A leader working with a Fractional CISO for Capacity Building Organizations

Fractional CISO for Capacity Building Organizations (Security Governance Funders Can Trust)

Your intake queue is overflowing. A partner needs access to a shared platform today. A funder due diligence form lands in your inbox, asking about encryption, vendor risk, and incident response, with a deadline you can’t move. In capacity building organizations, you’re not only protecting your own systems and ensuring data protection. You’re protecting the

Fractional CISO for Capacity Building Organizations (Security Governance Funders Can Trust) Read More »