What do funders ask not-for-profits about data security?
Increasingly specific questions, and increasingly early. Whether participant data is stored securely, whether multi-factor authentication is in place, how access is controlled, whether backups exist and have been tested, and what would happen in a breach. Being unable to answer can affect funding rather than merely reading poorly.
The shift has been noticeable and it follows the sensitivity of what the sector handles. Government-funded programmes involving participant data ask most consistently, because the funder carries its own obligations for the information collected on its behalf. Larger philanthropic funders and corporate partners have followed. The questions have moved from whether you have a privacy policy to whether specific technical controls are in place, which is a different kind of question requiring a different kind of answer.
The questions cluster into four areas. Where participant and donor data is stored and who can reach it. Whether identity is protected, meaning multi-factor authentication and access appropriate to role. Whether the data would survive an incident, meaning backups that have been restored rather than merely configured. And what happens if something goes wrong, meaning an incident plan and an understanding of your notification obligations.
Answering well requires evidence rather than description, and this is where organisations struggle. Saying that access is limited to authorised staff is a statement of intent. Producing a list of roles and who holds them, dated, is an answer. Saying backups run nightly is a description of a configuration. A restore log with dates is evidence. Funders have learned the difference, largely because the sector has had incidents where the description and the reality diverged.
This is why an Essential Eight assessment is efficient for a not-for-profit rather than an additional burden. It produces exactly what these questions are reaching for: a dated, control-by-control report with evidence behind each score, which can be attached to an application or acquittal rather than composed from scratch each time. Australia's leading not-for-profit accounting firm reached Maturity Level 1 alongside replacing ageing physical servers with AWS Remote Desktop and deploying Microsoft 365, ThreatLocker and device management.
Where you cannot answer well, say so and attach a plan with dates. Funders deal with resource-constrained organisations constantly and respond reasonably to a true position with a credible trajectory, particularly where you can show what has already been done. An answer that turns out to be inaccurate after an incident is a governance failure rather than a capability gap, and it damages a funding relationship far more than an honest admission would.
Ask about funding the improvements, because organisations routinely assume the answer is no without asking. Some grant programmes allow reasonable infrastructure and capability costs within the funded activity, particularly where the funder is imposing the requirement. Some funders will consider a specific request where security is a condition of delivering the work. The worst outcome is a requirement imposed and unfunded because nobody raised it.
Keep the answer current, because these documents age. Staff change, systems change, and a report from two years ago describes an organisation that no longer exists in that form. An annual reassessment is enough for most not-for-profits and means the evidence attached to a funding application is defensible rather than merely available. Diarise it alongside your other annual governance obligations so it happens without anyone remembering.
There is a board dimension worth connecting here. Boards carry governance responsibility for organisational risk, and a funder asking about data security is effectively asking whether that governance exists. A short annual briefing to the board covering what data is held, what protects it, when it was assessed and what remains outstanding turns an awkward funder question into a summary of something already being managed.
The honest caveats. Requirements vary considerably between funders, so read what each specifically asks rather than working from a general standard. An assessment measures rather than protects, so a report with no remediation behind it documents your exposure carefully and changes nothing. And the underlying obligation is to the people whose data you hold rather than to the funder, which is the better reason to do it. If you want the report that answers most of these questions, the Scorecard is free, or call 1800 456 567.
Write the answers once and keep them in a short standing document, since the same four areas come up across every funder and most organisations rebuild the response from scratch each time under deadline pressure.
Have the answers before the acquittal
The free Cyber Security Scorecard gives your organisation a dated, control-by-control report to attach to funding applications and acquittals.
Frequently asked questions
Questions? Let's talk.
Call 1800 456 567 or fill out the form.
- 30-minute discovery — no jargon, no pressure
- Plain-English Essential Eight Cyber Security Scorecard
- A clear plan tailored to your business