risk management for nonprofits

A team formulating what the minimum cybersecurity controls for nonprofits are.

Minimum Cybersecurity Controls for Nonprofits (A Practical Baseline)

If your legal aid intake queue is exploding and a funder report is due, nonprofit cybersecurity can feel like a “later” problem. Until an account takeover locks you out of email, a ransomware note freezes a shared drive, or a data leak puts a client at risk. Minimum cybersecurity controls for nonprofits means the smallest […]

Minimum Cybersecurity Controls for Nonprofits (A Practical Baseline) Read More »

cyber insurance renewal

How To Simplify Your Cyber insurance renewal, a 30-day Plan that avoids premium spikes and coverage gaps

The renewal email lands in your inbox when intake is already backed up, a report is due, and a vendor just changed their portal again. Now your broker wants answers fast. Multifactor authentication? Backups? Incident response plan? Vendor controls? You know the work is happening, but proving it is another story. Cyber insurance renewal has

How To Simplify Your Cyber insurance renewal, a 30-day Plan that avoids premium spikes and coverage gaps Read More »

An image of a computer setup for ransomware communications plan for justice organizations

Ransomware Communications Plan for Justice Organizations (First 72 Hours + Templates)

The intake queue is already too long. A court deadline is already too close. Then someone says the words that make your stomach drop: files are locked, systems are down, a ransom note appeared. For legal aid, court self-help, navigator programs, and justice-support nonprofits, Ransomware Communications Plan for Justice Organizations, a critical component of a

Ransomware Communications Plan for Justice Organizations (First 72 Hours + Templates) Read More »

A nonprofit team navigating incident command structure roles for nonprofits

Incident Command Structure Roles for Nonprofits (Role Cards and Cadence for High-Pressure Weeks)

The intake queue is exploding. A key partner is asking for an update you don’t have yet. Your case management system is slow or down. A court deadline is coming fast. Everyone’s working hard, but work keeps bouncing between inboxes, spreadsheets, and hallway conversations That’s when incident command structure roles for nonprofits help. Drawn from

Incident Command Structure Roles for Nonprofits (Role Cards and Cadence for High-Pressure Weeks) Read More »

A board discussing a cybersecurity assessment for access to justice organizations

Cybersecurity Assessment for Access to Justice Organizations (real risks in 10 business days)

It’s 4:45 p.m. Intake is backed up. A partner asks for a file “right now.” Finance needs numbers for a funder update. Then someone forwards a strange email that looks like it came from a court address, underscoring the operational security challenges nonprofit organizations face every day. This is the real context for a cybersecurity

Cybersecurity Assessment for Access to Justice Organizations (real risks in 10 business days) Read More »

Stop privacy by design being an afterthought: A field memo on protecting vulnerable clients in justice nonprofits

The intake queue is exploding. A partner needs a same-day handoff. A funder report is due, and the numbers don’t reconcile. In that pressure, privacy turns into a cleanup job. A rushed form. A shared spreadsheet. A “temporary” folder that becomes permanent. For justice nonprofits serving people at real risk, that’s not just an IT

Stop privacy by design being an afterthought: A field memo on protecting vulnerable clients in justice nonprofits Read More »

A laptop showing a quarterly vendor scorecard

Build a quarterly vendor scorecard that spots underperformers and saves 15 percent on contracts in six months.

The intake queue is growing, the monthly close is late again, and a vendor ticket is stuck in “we’re looking into it.” You don’t have time for another vendor meeting that ends with polite promises and no change. A vendor scorecard gives you a calm, repeatable way to see what’s working, what’s failing, and what

Build a quarterly vendor scorecard that spots underperformers and saves 15 percent on contracts in six months. Read More »

A leadership team building a saas outage communication plan For nonprofits

A SaaS Outage Communication Plan For Nonprofits (Templates for Staff, Partners, Courts, and Funders)

The intake queue is climbing, a filing deadline is hours away, and the tool you depend on won’t load. In legal aid and justice-support work, Software as a Service (SaaS) failures happen. The bigger risk is what comes next: silence, mixed messages, and workarounds that scatter client data. A SaaS outage communication plan for nonprofits

A SaaS Outage Communication Plan For Nonprofits (Templates for Staff, Partners, Courts, and Funders) Read More »

A team working through a iso 42001 checklist for nonprofits

ISO 42001 Checklist for Nonprofits (Starter Governance and Oversight)

Your intake queue is growing, staff are tired, and a funder wants a clean answer: “How are you using AI, and how do you keep it safe?” Meanwhile, a well-meaning team member has already turned on an AI feature in a tool that touches client data. That’s where ISO/IEC 42001 helps. Published in December 2023,

ISO 42001 Checklist for Nonprofits (Starter Governance and Oversight) Read More »

An image that represents a team reviewing a data retention policy for legal services

Data Retention Policy for Legal Services: Keep What You Need, Delete What You Should, Defend What You Keep

Your team didn’t choose legal services because you love filing systems. You chose it to help people through high-stakes moments. But the intake queue grows, staff copy and paste notes across tools, and every year brings a new report, audit, or public records question. Meanwhile, old client data sits everywhere, quietly piling up. Keeping everything

Data Retention Policy for Legal Services: Keep What You Need, Delete What You Should, Defend What You Keep Read More »