Back to case studies

Nonprofit

Nonprofit Cybersecurity Services

How a resource-constrained nonprofit improved donor data protection without building an internal IT department.

The organization is anonymized to avoid exposing security details for a community nonprofit.

Client

Anonymized Montana nonprofit

Timeline

30 days

Primary need

Nonprofit IT and security

Challenge

The nonprofit had staff, volunteers, board members, shared files, donor records, and grant documents spread across multiple accounts. Access reviews were informal, former volunteers sometimes retained access too long, and leadership needed better protection without adding a full-time IT hire.

What PBM implemented

  • Audited Microsoft 365 users, groups, shared files, and administrator roles to remove stale access.
  • Enabled MFA and tightened sign-in expectations for staff, board members, and high-risk accounts.
  • Separated staff and volunteer access patterns to reduce unnecessary exposure to donor and grant records.
  • Added endpoint security, backup monitoring, and a short incident response checklist leadership could follow.
  • Delivered plain-English phishing training built around donation scams, invoice fraud, and executive impersonation.

Results

  • Former-user access cleaned up
  • Donor data exposure reduced
  • Board and staff MFA improved
  • Phishing readiness increased
  • Backup visibility improved
  • No internal IT hire required

Need similar support?

PBM helps Montana businesses reduce downtime, document cybersecurity controls, and recover faster when technology fails.