All insights

What IT does a not-for-profit need?

6 min readBy Brendon Whiting, Founder · 1 July 2026

The same foundations as any organisation of the same size, with two differences that matter: much of it is available at nonprofit pricing that many organisations never claim, and the data you hold is often more sensitive than a comparable business would handle.

Not-for-profits are frequently sold either too little or too much. Too little because budget pressure encourages consumer-grade arrangements and volunteer goodwill, which works until it does not. Too much because a vendor treats a charity like a corporate. The honest answer is that a fifteen-person not-for-profit needs roughly what a fifteen-person business needs, bought at a price the sector is entitled to and configured around the specific realities of volunteers, funders and vulnerable data.

Start with the money, because it changes what is affordable. Registered charities and eligible not-for-profits can access substantially discounted and sometimes donated licensing from major vendors, Microsoft included, and the difference is large enough to reshape a budget. A great many eligible organisations have never claimed it, not because they were refused but because nobody told them it existed. Checking eligibility is an afternoon's work and it is the highest-return hour in this whole article.

The foundations themselves are unremarkable and worth stating plainly. Email and identity on a business platform rather than a mixture of personal accounts. Files in structured cloud storage rather than a server nobody maintains or a folder on someone's laptop. Devices that are managed, encrypted and can be wiped. Multi-factor authentication everywhere. Backups that have been restored. None of that is exotic, and the sector's problem is usually that it was never funded rather than that it was rejected.

The data question is where not-for-profits genuinely differ. Many hold donor details including payment information, participant or client records, and in disability, health, youth and community services, information about vulnerable people whose exposure would cause real harm. The Privacy Act applies to organisations holding personal information according to its own tests, and beyond the legal position there is the plain reality that the people you serve did not consent to their circumstances being disclosed. That raises the standard rather than lowering it because funds are tight.

Volunteers and turnover are the second structural difference. A workforce that includes volunteers, casual staff, students and board members changes what access management has to handle: many accounts, created quickly, often by different people, and rarely removed with the same enthusiasm. The failure mode in this sector is almost never a sophisticated attack; it is a live account belonging to somebody who stopped volunteering in 2022. Access by role and a genuine offboarding step fix most of it.

Funder and grant obligations are increasingly a technology matter, which surprises organisations the first time it appears. Government-funded programmes and larger philanthropic funders now ask about data handling and security as part of acquittal or contracting, and being unable to answer can affect funding rather than merely being awkward. That is another argument for the Essential Eight as a framework, because it produces a dated report that answers most of what is asked.

TAPS, a group training organisation for apprentices and trainees, is a useful example of what consolidation looks like in this sector. A fragmented and ageing IT and phone setup was brought under one partner: files moved to the cloud, identity and cyber security modernised to Essential Eight, telephony virtualised, the network refreshed, and Zero Trust security applied across both organisation computers and staff-owned mobiles. That last detail matters in a sector where personal devices are widely used because equipment budgets are thin.

On the phone side, not-for-profits often carry legacy arrangements longer than businesses do, because a phone system that works is rarely anybody's priority. Virtualising telephony usually reduces the recurring bill while making the service better, particularly for organisations with multiple sites or staff working across locations, and it removes a box in a cupboard that nobody can support.

The honest caveats. Budget is a real constraint rather than an attitude, and the right sequence for a constrained organisation is nonprofit licensing first, then identity and backups, then everything else. Volunteer goodwill is valuable and is not a substitute for someone accountable, particularly for security. And a board that has never been briefed on technology risk cannot govern it, which is a conversation worth having before an incident rather than after. If you want an arrangement built around the sector's actual constraints, call 1800 456 567.

Get more from a constrained budget

We help Australian not-for-profits claim the nonprofit pricing they are entitled to and spend what remains where it matters.

Frequently asked questions

Yes, and it is substantial. Registered charities and eligible not-for-profits can access heavily discounted and in some cases donated licensing from major vendors including Microsoft. A surprising number of eligible organisations have never claimed it, usually because nobody mentioned it rather than because they were refused.

Yes, and arguably more than a comparable business, because of what you hold. Donor financial details, participant and client records, and in many organisations information about vulnerable people. The obligation follows the sensitivity of the data rather than the size of the organisation or its budget.

With accounts that are easy to create and, more importantly, easy to remove, and access granted by role rather than individually. The common failure in this sector is not weak passwords; it is accounts belonging to people who left two years ago that nobody ever disabled.

Questions? Let's talk.

Call 1800 456 567 or fill out the form.

  • 30-minute discovery — no jargon, no pressure
  • Plain-English Essential Eight Cyber Security Scorecard
  • A clear plan tailored to your business

Prefer to talk?

Call 1800 456 567

Powered by Calendly — your data is handled securely.

Our office · Level 2, 25 Grenfell Street, Adelaide

By submitting, you agree to our terms and privacy policy. No spam — ever.