Cyber Liability Knowledge Center for Nonprofits | Chapter 2

The Quick Answer

Cyber Liability is easier to understand when leaders stop treating cyber risk as one large technical problem and instead organize it into four areas: Operational, Reputational, Regulatory, and Legal risk.

Each answers a different leadership question:

  • Operational: Can we continue carrying out our mission?
  • Reputational: Could this damage the trust others place in us?
  • Regulatory: What requirements or obligations apply to us?
  • Legal: Could this create responsibilities or exposure beyond the technology itself?

A single cyber event can affect more than one area at the same time.

That is why understanding the four risks helps nonprofit leaders move beyond asking, “Are we secure?” and toward a more useful question:

“What could this risk mean to our organization, our mission, and the people who depend on us?”

Four Cyber Liability risks for nonprofit leaders infographic

Why Nonprofit Leaders Need More Than a Cybersecurity Checklist

Cybersecurity checklists can be useful.

They may tell an organization to:

  • Enable multifactor authentication
  • Protect endpoints
  • Maintain backups
  • Patch systems
  • Train employees
  • Secure email
  • Monitor networks
  • Control administrative access

Those are important practices.

But a checklist does not automatically explain why one issue should receive attention before another.

Imagine that leadership receives five recommendations:

  1. Replace aging computers.
  2. Improve backup recovery.
  3. Require stronger authentication.
  4. Update cybersecurity policies.
  5. Review vendor access.

Which one comes first?

The answer cannot always be determined by looking at the technology alone.

Leadership needs to understand what happens if the weakness becomes a real event.

Could programs stop?

Could donor confidence be affected?

Could the organization fail to meet an obligation?

Could the issue create legal responsibilities?

That is where the four Cyber Liability risks become useful.

They give leadership a way to translate technical findings into organizational decisions.

1. Operational Risk: Can We Continue Carrying Out the Mission?

Operational risk is the possibility that a technology or cybersecurity issue could interfere with the organization’s ability to function.

For nonprofits, the consequences can reach far beyond an employee being unable to open a file.

Technology may support:

  • Program delivery
  • Fundraising
  • Donor management
  • Online donations
  • Payroll
  • Financial operations
  • Constituent records
  • Case management
  • Communications
  • Volunteer coordination
  • Publishing
  • E-commerce
  • Remote work
  • Collaboration with community partners

The leadership question is not simply:

“What technology could fail?”

It is:

“What part of our mission would be affected if it did?”

Think in Terms of Mission Dependencies

One way to understand operational risk is to identify the technology that important activities depend on.

For example:

Mission activity: Online fundraising

Technology dependency: Website, payment processing, donor platform, internet connectivity

Possible disruption: Donations cannot be processed

Organizational consequence: Lost revenue during a critical fundraising period

Or:

Mission activity: Delivering services to constituents

Technology dependency: Cloud-based case management platform

Possible disruption: Employees cannot access client information

Organizational consequence: Delayed services or inability to serve people who need assistance

Educational Example: Backup Does Not Automatically Mean Recovery

A nonprofit may know that backups occur every evening.

That is useful information.

But leadership may still need answers to several questions:

Has recovery been tested?

How much information could be lost between backups?

How long would restoration take?

Which systems would be restored first?

Who coordinates recovery?

How long can programs continue without those systems?

This changes the conversation from:

“Do we have a backup?”

to:

“Could we recover our mission-critical operations within a timeframe we can tolerate?”

2. Reputational Risk: Could We Damage the Trust Others Place in Us?

Trust is an operating asset for a nonprofit.

Organizations depend on trust from:

  • Donors
  • Constituents
  • Employees
  • Volunteers
  • Boards
  • Grantmakers
  • Community partners
  • Financial institutions
  • Vendors
  • Churches or member organizations
  • The public

Cyber incidents can place that trust under pressure.

But reputational risk is not limited to whether an incident becomes a news story.

Trust can also be affected by how prepared the organization appears to be and how well leadership responds.

Reputation Is Connected to Stewardship

Suppose an organization experiences unauthorized access to donor information.

Leadership may have to answer:

What information was involved?

How long did the exposure exist?

What safeguards were in place?

How did the organization discover it?

What actions were taken?

Has the risk been contained?

What is being done to prevent recurrence?

Those questions are about technology.

But they are also about stewardship.

A donor may not know the difference between endpoint detection, encryption, MFA, or vulnerability management.

They may understand a simpler question:

“Did the organization responsibly protect the information I trusted it with?”

That makes reputational risk a leadership concern.

Educational Example: Protecting Trust During an Incident

Consider a nonprofit that relies heavily on an annual giving campaign.

During the campaign, a cyber event causes uncertainty about whether donor information was exposed.

Even if the technical problem is resolved quickly, leadership may still need to determine:

What should donors be told?

When should they be told?

Who communicates the message?

What can leadership confidently say about the event?

What evidence supports those statements?

Could uncertainty reduce donor confidence during an important fundraising period?

The reputational exposure may therefore continue after the technical issue has been corrected.

3. Regulatory Risk: What Requirements and Obligations Apply to Us?

Regulatory risk is frequently misunderstood because nonprofit leaders may hear words such as “compliance” and assume there is one universal cybersecurity standard every organization must follow.

There is not.

The requirements relevant to a nonprofit may depend on factors such as:

  • The type of information it maintains
  • Payment processing
  • Services provided
  • Funding relationships
  • Contracts
  • Insurance requirements
  • Geography
  • Industry
  • Employee information
  • Donor or constituent information
  • Relationships with regulated organizations

A nonprofit may therefore have multiple overlapping expectations.

The important question is not:

“Are nonprofits compliant?”

It is:

“Which requirements apply to our organization, and what evidence do we have that we are addressing them?”

Compliance Is Not the Same as Cyber Liability

Compliance can be valuable.

It can provide structure, controls, documentation, and expectations.

But meeting a particular requirement does not necessarily mean every meaningful organizational risk has been addressed.

For example, a nonprofit could satisfy a required technical control while still having:

Weak disaster recovery planning

Poor vendor oversight

Excessive employee access

Undocumented decision-making

Inadequate executive ownership

Technology that is near failure

Risks that fall outside the scope of a specific standard

Compliance therefore answers one question:

“Are we meeting this requirement?”

Cyber Liability asks a broader question:

“What risks are we actually carrying?”

Educational Example: Having MFA Versus Demonstrating MFA

Assume an organization has a policy requiring multifactor authentication.

There are at least three separate questions:

Policy question:

Does the organization require MFA?

Technology question:

Has MFA been configured?

Evidence question:

Can the organization demonstrate that MFA is actually applied to the accounts and systems where it is required?

The third question becomes especially important when leadership needs to respond to a board, insurer, auditor, funder, regulator, or other stakeholder.

Cyber preparedness becomes stronger when the organization can answer from evidence rather than assumption.

4. Legal Risk: Could This Create Responsibilities Beyond the Technology?

A cybersecurity event may begin as a technical problem but eventually involve questions that should not be answered solely by the technology team.

Depending on the circumstances, those questions may involve:

  • Contracts
  • Privacy
  • Employee information
  • Incident notification
  • Financial transactions
  • Insurance
  • Donor or customer information
  • Vendor responsibilities
  • Records
  • Business relationships

This is where legal risk becomes part of Cyber Liability.

The goal is not for nonprofit leaders to become cybersecurity attorneys.

Nor should an IT provider try to act as legal counsel.

The important leadership skill is recognizing when an issue has consequences beyond technology and qualified legal advice may be appropriate.

A Helpful Boundary for Leadership

A technology professional may be able to answer:

“What happened to the system?”

A cybersecurity professional may be able to answer:

“How did the compromise occur?”

An independent assessor may be able to answer:

“What vulnerabilities or control weaknesses exist?”

Legal counsel may need to help answer:

“What responsibilities does the organization now have?”

Leadership needs enough clarity to know when each type of expertise belongs in the conversation.

That is one reason seeing the whole risk is so important.

One Cyber Event Can Affect All Four Risks

The four areas should not be viewed as separate boxes.

They often overlap.

Consider a hypothetical ransomware event affecting an organization’s primary systems.

Operational

Employees cannot access applications or information needed to work.

Reputational

Donors, constituents, partners, or board members may question whether the organization adequately protected its systems and information.

Regulatory

The organization may need to determine whether affected information or contractual obligations create specific requirements.

Legal

Leadership may need advice about notification, contracts, insurance, liability, or other responsibilities.

It is still one event.

But leadership may need to manage four different kinds of consequences.

That is the value of the four-part framework.

It helps an executive team avoid treating a cyber incident as only an IT problem.

Educational Scenario: One Event, Four Questions

Imagine an employee account is compromised and an unauthorized individual gains access to organizational information.

Leadership could examine the event this way:

Operational question:

Did the compromise interfere with staff, systems, services, or financial operations?

Reputational question:

Could the event affect the confidence of donors, constituents, employees, or partners?

Regulatory question:

Was information involved that creates regulatory, contractual, or other compliance responsibilities?

Legal question:

Does the organization need qualified guidance regarding notification, contractual duties, insurance, employment matters, or another legal obligation?

Notice what the framework does.

It does not tell leadership what the answer must be.

It helps leadership know which questions need to be answered.

That is a much more useful starting point.

A Real Nonprofit Experience: The Same Environment Can Carry Different Types of Risk

The following nonprofit experience is intentionally anonymized.

An established nonprofit with publishing, e-commerce, employee information, payment activity, and mission-critical business systems had made substantial improvements to its technology environment.

Documented progress included:

  • Eliminating Windows 7
  • Continuing migration toward Windows 11
  • Establishing a 3-5 year hardware lifecycle
  • Deploying next-generation endpoint protection
  • Improving password management
  • Conducting recurring vulnerability assessments
  • Advancing employee security awareness
  • Reviewing encryption
  • Reducing unnecessary administrative privileges
  • Evaluating server and cloud decisions
  • Improving internet resiliency

Those improvements strengthened the organization’s operational environment.

But looking at the organization through the four-risk framework created a broader picture.

Operational

Technology modernization, endpoint protection, hardware lifecycle management, resiliency, and backup/recovery considerations helped support ongoing operations.

Reputational

The organization recognized that an incident could affect customer confidence, ministry relationships, order fulfillment, and trust developed over decades.

Regulatory

Its online payments, customer information, e-commerce systems, and other activities meant that leadership also needed to consider frameworks and requirements that extended beyond basic IT management.

Legal

Although the source reports no legal claims or regulatory penalties resulting from a cyber incident to date, leadership continued considering contractual, privacy, employment, financial, governance, and documentation risks.

What This Example Teaches

The educational lesson is that the same technology environment can carry multiple categories of Cyber Liability at the same time.

A hardware upgrade may primarily improve operations.

A reduction in administrative access may reduce operational, regulatory, and legal exposure.

Employee education may help reduce the likelihood of an incident while also supporting reputational preparedness.

Governance and documentation may contribute to regulatory and legal maturity even though they are not cybersecurity “products.”

The value of the four-risk framework is that it helps leadership understand the organizational reason behind the technology decision.

How Should a Nonprofit Prioritize the Four Risks?

The four areas do not automatically have equal priority.

For one nonprofit, operational continuity may require immediate attention.

For another, regulatory complexity may be the greater concern.

For another, a major dependency on donors or community partners may make reputational consequences especially important.

Instead of assigning a universal order, leadership can use a simple four-question test.

Question 1: What could have the greatest mission impact?

If a system failed tomorrow, which disruption would most affect your ability to serve?

Question 2: What could create the greatest loss of trust?

Which information, systems, or relationships would be most sensitive if compromised?

Question 3: Where do we have responsibilities that must be demonstrated?

What regulatory, contractual, insurance, funding, or other expectations apply?

Question 4: Where could an event create responsibilities beyond IT?

Which risks might require legal, insurance, executive, board, or communications involvement?

Those questions help leadership establish context.

Then the organization can consider:

  • Severity
  • Likelihood
  • Current safeguards
  • Available evidence
  • Cost
  • Complexity
  • Resources
  • Time required
  • Consequences of deferring action

Not Every Risk Has to Be Fixed Today

This point is especially important for nonprofit organizations.

Resources are finite.

Money allocated to cybersecurity is money that cannot simultaneously be spent on programs, people, facilities, fundraising, or another mission priority.

Responsible Cyber Liability management should not create the expectation that leadership must approve every recommendation immediately.

Instead, leaders should understand:

What is the risk?

What could happen?

How significant could the impact be?

What protection already exists?

What would improvement require?

What happens if we wait?

A decision to defer action can still be an informed decision.

The important distinction is whether leadership understands the risk it is choosing to carry.

That is different from being unaware of the risk.

The Four-Risk Board Conversation

The four Cyber Liability categories can also give boards and executive teams a practical way to discuss cyber risk without turning the meeting into a technical presentation.

A quarterly discussion could use four questions.

Operational

What technology or cybersecurity risks could materially interrupt our mission today?

Reputational

What risks could most seriously affect the trust of donors, constituents, employees, funders, or partners?

Regulatory

What obligations apply to us, and what evidence shows how we are addressing them?

Legal

Are there risks or decisions that should involve legal, insurance, or other specialized guidance?

Leadership does not need a 50-page technical report to begin this conversation.

It needs clarity.

A Simple Four-Part Cyber Liability Review

A nonprofit leader can begin with a simple exercise.

Take a sheet of paper or create four columns.

Label them:

Operational

Reputational

Regulatory

Legal

Then identify the organization’s major technology dependencies and known cybersecurity concerns.

For each one, ask:

Where could this affect us?

Some issues may appear in one column.

Others may appear in all four.

The goal is not to create a perfect risk register.

The goal is to change the way the organization thinks about cyber risk.

Instead of seeing:

“A technical problem.”

Leadership begins seeing:

“An organizational risk that technology may create or influence.”

That is the beginning of Cyber Liability awareness.

What Should a Nonprofit Leader Take Away From This Chapter?

Cyber Liability is not one risk.

It is a way of understanding how technology and cybersecurity can affect the broader organization.

The four areas give leadership a practical framework.

Four-part nonprofit Cyber Liability framework showing each risk category

The four areas of Cyber Liability help nonprofit leaders translate technology issues into mission and business questions they can understand, explain, and act on.

Operational Risk

Can we continue carrying out our mission?

Reputational Risk

Could we damage the trust others place in us?

Regulatory Risk

What requirements and obligations must we understand and demonstrate?

Legal Risk

Could this create responsibilities or exposure beyond the technology itself?

The framework is useful because leaders do not have to become cybersecurity experts to use it.

They need to understand what questions to ask.

Good Cyber Liability management begins by creating clarity before action.

It avoids using fear as a substitute for understanding.

It teaches before asking leaders to make decisions.

And it looks at the whole organizational risk instead of focusing only on technology.

Applying the Education: How MTS Uses the Four-Risk Framework

At MTS, the four Cyber Liability areas are used to help translate technical evidence into business understanding.

The goal is not to tell leadership:

“You need this technology because we recommend it.”

The process begins with a different question:

“What does the evidence show, and what could it mean to your organization?”

That reflects the principle:

Evidence before opinion.

When an objective view of the environment is needed, an Independent Cyber Risk Assessment can provide evidence about current vulnerabilities.

The assessment referenced by MTS is performed by an independent third-party security company that is not affiliated with MTS. Its independence allows it to evaluate the environment objectively, including protections that MTS itself may already have implemented.

MTS then helps leadership interpret the evidence through questions such as:

  • What is the potential operational impact?
  • Could trust or reputation be affected?
  • Are regulatory obligations involved?
  • Could the issue create legal considerations?
  • How should the risk be prioritized?
  • What choices does leadership have?
  • What happens if action is deferred?

The independent third party provides evidence.

MTS educates, interprets, guides, and helps prioritize.

The client remains the responsible decision-maker.

That distinction matters because Cyber Liability management should create informed leadership, not dependence on a technology provider.

Continue Learning

Previous Chapter

What Is Cyber Liability for a Nonprofit, and How Is It Different From Cybersecurity?

Next Chapter

Chapter 3: How Do People, Technology, Donor Data, and Third-Party Systems Create Cyber Liability for a Nonprofit?

The next chapter moves from the types of Cyber Liability to the places where Cyber Liability originates.

We will look at four common sources:

  • People
  • Technology
  • Sensitive and donor information
  • Vendors and third-party systems

and show how risk can move from one area to another.