All insights

What should a not-for-profit board know about IT risk?

2 min readBy Brendon Whiting, Founder · 6 July 2026

Four things, none of which requires technical expertise to ask about. What personal data does the organisation hold and about whom. What protects it. When was that last assessed by somebody independent of the people who set it up. And what would happen, in practice, if it were breached tomorrow.

Those questions matter here more than in a comparable business because of who is affected. A not-for-profit holds donor payment details and participant records, and in disability, health, youth, family and community services those records describe circumstances that people would be harmed by having disclosed. The board's governance responsibility for risk extends squarely to that, whether or not anyone around the table considers themselves technical.

The quality of the answers is as informative as their content. Specific answers with dates attached indicate the risk is being managed. Reassurance that everything is fine, or a technical explanation that does not answer the question asked, indicates it is not being managed so much as hoped about. A board is entitled to specifics, and asking for them is the whole of the governance function here.

Make it an annual item rather than a reaction to something. One page to the board covering data held, controls in place, the date of the last independent assessment and what remains outstanding, plus immediate reporting of any material incident. That is enough to make the oversight genuine, and it means the conversation happens when everyone is calm rather than during an incident. If you want a report a board can actually read, the Cyber Security Scorecard is free, or call 1800 456 567.

Give the board something to govern

The free Cyber Security Scorecard produces a dated report a board can read and act on, rather than a technical document nobody discusses.

Frequently asked questions

Boards carry governance responsibility for organisational risk, and for an organisation holding participant and donor data, technology risk is squarely within that. It does not require technical expertise on the board; it requires the board being able to ask whether the risk is understood and managed.

Annually is enough for most organisations, with an exception for material incidents which should be reported when they happen. One page covering what data is held, what protects it, when it was last assessed and what remains outstanding gives a board what it needs without becoming a technical briefing.

That is normal and it is not a barrier. The four questions below require no technical knowledge to ask, and the quality of the answers is itself informative. A board that receives vague answers to specific questions has learned something important about how the risk is being managed.

Questions? Let's talk.

Call 1800 456 567 or fill out the form.

  • 30-minute discovery — no jargon, no pressure
  • Plain-English Essential Eight Cyber Security Scorecard
  • A clear plan tailored to your business

Prefer to talk?

Call 1800 456 567

Powered by Calendly — your data is handled securely.

Our office · Level 2, 25 Grenfell Street, Adelaide

By submitting, you agree to our terms and privacy policy. No spam — ever.