An Independent Cyber Risk Assessment gives nonprofit leaders something that is often difficult to get from day-to-day technology management: an objective view of the organization’s current cyber risk.

The value of independence is straightforward.

The organization assessing the environment is separate from the organization responsible for managing, supporting, or selling the technology.

That separation can help leadership answer four important questions:

  1. What does the evidence actually show?
  2. Which protections are working as expected?
  3. Where are meaningful vulnerabilities or gaps?
  4. What decisions should leadership consider next?

The assessment does not make those decisions for leadership.

Its value is helping leaders make better decisions with clearer evidence.

Stormy seascape with a lighthouse beam illustrating the path from assumptions to informed decisions

Why Independence Matters

Most nonprofits already have people responsible for technology.

That may include:

  • An internal IT employee
  • A managed service provider
  • A cybersecurity vendor
  • A software provider
  • A consultant
  • A combination of several providers

Those people may be doing excellent work.

An independent assessment is not based on the assumption that they are doing something wrong.

The value comes from having someone outside the existing service relationship examine the environment.

That creates separation between two roles:

The people responsible for maintaining the environment

and

The people evaluating the environment

That distinction matters.

If the same organization installs a security control, manages it, and then evaluates whether it is effective, leadership may be relying on one perspective.

An independent assessment introduces another perspective.

Sometimes that assessment identifies problems.

Sometimes it confirms that existing protections are working properly.

Both outcomes are valuable.

Independent Does Not Mean Adversarial

The purpose of independence is not to catch someone making a mistake.

It is to improve visibility.

A strong assessment may validate the work of:

  • Internal IT staff
  • Managed service providers
  • Cybersecurity vendors
  • Cloud administrators
  • Leadership teams

That validation has value.

If an organization has invested time and money into cybersecurity, leadership should want evidence that those investments are producing the expected result.

An assessment may also identify something that was overlooked.

That does not automatically mean someone failed.

Modern technology environments are complicated.

Employees change.

Applications change.

Permissions accumulate.

Devices age.

Vendors gain and lose access.

Policies become outdated.

Configurations drift over time.

Independent review can help reveal changes that are difficult to see from inside the daily operating environment.

The Difference Between Believing and Knowing

Most nonprofit leaders hear reassuring statements about cybersecurity.

For example:

“We have MFA.”

“Our backups are working.”

“Our systems are patched.”

“Our employees receive cybersecurity training.”

“Our IT provider handles security.”

“We have cyber insurance.”

Those statements may all be correct.

But leadership still needs to ask:

What evidence supports them?

Consider multifactor authentication.

An organization may have implemented MFA several years ago.

Leadership may assume everyone is protected.

An independent assessment could help determine:

  • Whether MFA is enabled for appropriate users
  • Whether privileged accounts are protected
  • Whether exceptions exist
  • Whether new accounts were configured correctly
  • Whether old accounts remain
  • Whether the control is operating as leadership expects

The purpose is not to prove someone wrong.

It is to replace uncertainty with evidence.

Why Evidence Matters to Leadership

Cybersecurity decisions compete with many other nonprofit priorities.

A leader may be deciding between:

  • A technology upgrade
  • A new employee
  • Program funding
  • Building repairs
  • Fundraising investment
  • Cybersecurity improvements
  • Insurance costs
  • Compliance work

Those decisions are easier when the organization understands what is actually happening.

Without evidence, leadership may spend too much on a low-priority problem.

It may also spend too little on a risk that could seriously affect the mission.

An independent assessment helps create a clearer starting point.

It can help leadership distinguish between:

What we think is happening

and

What the evidence shows is happening

That difference is important.

What Should an Independent Cyber Risk Assessment Look At?

There is no single assessment that fits every nonprofit.

A 15-person community organization does not have the same environment as a 100-person nonprofit with multiple locations, regulated information, online payments, and complex vendor relationships.

Still, a meaningful assessment should look broadly enough to identify risk across the environment.

Areas may include:

  • Identity and access
  • Multifactor authentication
  • Endpoint protection
  • Software and patching
  • Network security
  • Email protection
  • Backup and recovery
  • Vulnerability management
  • Security awareness
  • Administrative access
  • Policies and governance
  • Incident response
  • Third-party access
  • Data protection
  • Cyber insurance requirements
  • Regulatory requirements
  • AI use and governance

The purpose is not to create the longest possible checklist.

It is to understand whether important safeguards exist, whether they are working, and where evidence suggests the organization may be exposed.

An Assessment Should Look Beyond Technology Products

One of the weaknesses of some cybersecurity reviews is that they focus heavily on products.

Does the organization have a firewall?

Does it have endpoint security?

Does it have backup software?

Those are useful questions.

They are not enough.

A nonprofit may have strong technology and still carry significant Cyber Liability.

Leadership also needs to understand issues such as:

  • Who has access to sensitive information
  • Whether former employees still have access
  • Whether backups can actually be restored
  • Whether vendors have unnecessary permissions
  • Whether security policies reflect actual practices
  • Whether responsibilities are clearly assigned
  • Whether important recommendations were deferred
  • Whether leadership understands the risks it has chosen to carry

A useful assessment should help reveal both technical weaknesses and organizational gaps.

Educational Example: Having a Backup Versus Knowing You Can Recover

Imagine a nonprofit that backs up its data every evening.

Leadership may reasonably believe backup risk has been addressed.

An independent review asks a different set of questions.

  • What information is being backed up?
  • Are all mission-critical systems included?
  • When was the last successful backup?
  • Has restoration been tested?
  • How long would recovery take?
  • Who is responsible for initiating recovery?
  • Which systems would be restored first?

This creates an important distinction:

A backup is a technology control.

Recovery is an operational capability.

The organization may discover that its backup technology is working exactly as designed.

That is valuable confirmation.

It may also discover that recovery expectations have never been tested.

That is valuable information too.

An Assessment Should Validate What Is Working Too

A useful assessment should not only report problems.

It should also help leadership understand which safeguards appear to be working.

That matters for several reasons.

First, leadership gains confidence that previous investments are producing value.

Second, the organization can avoid spending money replacing controls that are already effective.

Third, strong areas can help leadership focus resources where they are actually needed.

For example, an assessment might determine that:

  • Endpoint protection is properly deployed
  • MFA coverage is strong
  • Devices are being patched consistently
  • Administrative access is appropriately limited
  • Backups are healthy
  • Employees are completing security awareness training

That information matters just as much as a list of weaknesses.

A good assessment should provide a balanced picture.

The Most Important Output Is Not a Score

Many assessments produce a cybersecurity score.

Scores can be useful.

They can help establish a baseline.

They can make progress easier to measure.

They can help leadership see whether conditions are improving.

But a score should not become the entire conversation.

Imagine two organizations both receive a score of 72.

One may have a relatively simple environment with several low-risk technical gaps.

The other may have a serious backup issue affecting mission-critical operations.

The same score does not mean the same risk.

Leadership needs context.

A useful assessment should explain:

What was found?

Why does it matter?

How could it affect the organization?

How significant is the risk?

What options are available?

That information is more valuable than the number alone.

A Technical Finding Becomes Useful When It Leads to a Business Question

Imagine an assessment identifies an administrative account with unnecessary privileges.

The technical finding might be:

“Excessive administrative access identified.”

Leadership may not know what to do with that statement.

A better conversation asks:

Who has this access?

Why do they have it?

What could happen if that account were compromised?

Could the access be reduced without interfering with the employee’s work?

What risk remains if we decide not to change it?

The technical finding becomes useful when leadership understands the consequence and the decision.

That is where a cyber assessment becomes a risk-management tool instead of simply a technical report.

Diagram tracing a backup recovery finding through evidence and business questions to leadership options

Educational Example: Two Findings Do Not Always Deserve Equal Attention

Suppose an assessment identifies two findings.

Finding 1

Several employee computers need routine software updates.

Finding 2

The organization has backups, but no recent recovery test can be confirmed.
Both deserve attention.

But they may not deserve the same priority.

If routine patching is slightly behind schedule, the issue might fit naturally into the existing maintenance process.

If the organization cannot confirm that mission-critical systems can be restored, leadership may want to understand that issue sooner.

The point is not that backup is always more important than patching.

The point is that findings should be considered in context.

Good prioritization looks at potential impact, existing protections, likelihood, cost, and the consequences of waiting.

A Good Assessment Should Create Priorities, Not Panic

A technical assessment can easily produce dozens of findings.

That does not mean leadership suddenly has dozens of emergencies.

A useful assessment should help separate findings into practical groups.

For example:

Address Now

The potential impact is significant and the organization has a practical opportunity to reduce the risk.

Plan

The issue matters, but it can reasonably be included in an upcoming technology, budget, or operational plan.

Investigate

More evidence is needed before leadership can make a responsible decision.

Monitor

The issue does not currently justify major action, but it should remain visible.

Accept the Risk

Leadership understands the issue and consciously decides not to address it at this time.

This kind of prioritization can be especially important for nonprofits because resources are limited.

The purpose is not to make everything urgent.

The purpose is to make the important things clear.

Choosing Not to Fix Something Can Still Be a Responsible Decision

A cybersecurity assessment does not mean leadership must approve every recommendation.

Nonprofit leaders make tradeoffs every day.

An organization may decide that a particular recommendation:

  • Costs too much right now
  • Can wait until the next budget year
  • Depends on another project
  • Needs more research
  • Has a relatively low potential impact
  • Can be partially mitigated another way

That can be a reasonable decision.

The key is understanding the risk being carried.

There is an important difference between:

“We did not know about the risk.”

and

“We understand the risk and have decided to accept it for now.”

The second is an informed leadership decision.

The risk should remain visible so it can be reconsidered later rather than simply disappearing.

What Should Leadership Receive From an Independent Assessment?

A useful assessment should leave leadership with more clarity than it had before.

At minimum, leaders should expect to understand several things.

1. Where the Organization Stands Today

The assessment should provide a baseline view of the current environment.

2. What the Evidence Shows

Leadership should understand which findings are supported by actual evidence rather than assumption.

3. What Is Working

Strong safeguards should be identified as well as weaknesses.

4. Where Important Gaps Exist

Leadership should understand the vulnerabilities or control gaps that may deserve attention.

5. Why Those Findings Matter

Technical issues should be translated into potential organizational impact.

6. What Should Be Prioritized

Not every finding should be treated equally.

7. What Decisions Leadership Needs to Make

The assessment should create useful questions, not simply technical data.

That is the point where the assessment becomes valuable to leadership.

What an Independent Assessment Should Not Become

Understanding what an assessment should not do is equally important.

It Should Not Be a Sales Presentation Disguised as an Assessment

If every finding immediately leads to a product sold by the assessor, leadership should ask whether the evaluation and sales process are sufficiently separated.

This does not automatically mean the recommendations are wrong.

It does mean independence should be understood clearly.

It Should Not Use Fear as a Decision Tool

Cyber risks are real.

That does not mean fear produces better leadership decisions.

An assessment should create clarity, not panic.

It Should Not Treat Every Finding as an Emergency

The purpose of risk management is prioritization.

If everything is critical, nothing is truly prioritized.

It Should Not Promise Perfect Security

No assessment can eliminate all cyber risk.

The goal is better visibility and better decisions.

It Should Not Replace Leadership

An assessor can identify and explain risk.

Leadership still determines what the organization will do.

Why Independent Assessment Can Be Especially Valuable When You Already Have an IT Provider

Some leaders may wonder:

“If we already have an IT provider, why would we need another organization to assess the environment?”

The answer is not necessarily because the IT provider is failing.

Independent assessment can create another layer of accountability.

Think of the roles separately.

Your IT provider may be responsible for:

  • Supporting users
  • Maintaining devices
  • Managing Microsoft 365
  • Installing security controls
  • Patching systems
  • Managing networks
  • Supporting applications

An independent assessor has a different job.

Its role is to look at the environment and ask:

What does the evidence show?

That independent viewpoint can:

  • Validate your provider’s work
  • Identify gaps that need attention
  • Challenge assumptions
  • Give leadership greater visibility
  • Create clearer conversations with the provider

A strong IT provider should not be threatened by independent verification.

Independent evidence can help good providers demonstrate the value of the work they are already doing.

Educational Example: Independent Evidence Confirms Good Work

Imagine a nonprofit has worked with the same technology provider for several years.

Leadership agrees to an independent assessment.

The results confirm that:

  • MFA is broadly implemented
  • Endpoint security is active
  • Patching is consistent
  • Backups are healthy
  • Major systems are current

The assessment also identifies two smaller areas where improvement may be appropriate.

That is a successful outcome.

The assessment did not need to uncover a disaster to be valuable.

Leadership now has independent evidence that many existing protections are working.

It also has a short list of improvements to consider.

One Assessment Is a Snapshot

An assessment shows leadership what the environment looks like at a point in time.

But the environment will change.

New employees will join.

Other employees will leave.

New software will be adopted.

Vendors will change.

Devices will age.

New vulnerabilities will be discovered.

The organization itself may grow or change its programs.

For that reason, assessment is more useful when leadership treats it as part of a cycle.

Assess

Understand the current environment.

Prioritize

Determine which risks matter most.

Decide

Choose what to address, plan, investigate, monitor, or accept.

Improve

Make the appropriate changes.

Verify

Confirm that the changes produced the intended result.

Reassess

Review the environment again as conditions change.

This creates an ongoing process of learning and improvement rather than a one-time cybersecurity project.

Five Questions to Ask Before Choosing an Independent Assessment

Nonprofit leaders do not need to understand technical scanning tools to evaluate whether an assessment is likely to be useful.

Start with these questions.

1. Is the Assessor Truly Independent?

Understand whether the organization performing the assessment also sells or manages the technologies being evaluated.

Independence should be clear.

2. What Will the Assessment Actually Examine?

Will it look broadly at the environment or focus only on one security tool?

3. Will We Receive Evidence or Just Opinions?

Ask what information supports the findings.

4. Will Leadership Understand the Results?

A report may be technically accurate and still be useless to a nonprofit executive.

The findings should be explained in language leadership can understand.

5. How Will Findings Become Decisions?

Ask whether the assessment helps identify priorities, consequences, options, and the risks associated with waiting.

If those five questions receive clear answers, leadership is more likely to receive an assessment that supports real decision-making.

How Can a Board Use the Results?

A board generally does not need every technical detail.

It needs an understandable view of organizational risk.

A useful board-level conversation might include:

  • What did the assessment identify?
  • Which findings have the greatest potential mission impact?
  • What protections are working well?
  • Which risks should leadership address first?
  • Which recommendations have been deferred?
  • What risks has leadership consciously accepted?
  • Are there regulatory, legal, insurance, or governance considerations?
  • When will the organization review these issues again?

That gives the board meaningful oversight without turning the meeting into a technical briefing.

What Should a Nonprofit Leader Take Away From This Chapter?

The greatest value of an Independent Cyber Risk Assessment is not the report.

It is the perspective.

Independent assessment gives leadership another source of evidence about the environment it is responsible for.

It can help answer:

What is actually happening?

What protections are working?

Where are the meaningful gaps?

What should we address first?

What can reasonably wait?

What risk are we choosing to carry?

The assessment should not create fear.

It should create clarity.

It should not replace leadership decisions.

It should improve them.

And it should not begin with the assumption that the organization is failing.

Sometimes independent evidence identifies serious risks.

Sometimes it confirms that the organization is doing many things well.

Either way, knowing is more useful than assuming.

Applying the Education: How MTS Makes an Independent Cyber Risk Assessment Available

MTS believes leadership decisions should begin with evidence.

That is why MTS makes an Independent Cyber Risk Assessment available to clients and prospects through an independent third-party security company.

The company performing the assessment is not affiliated with MTS.

It also helps monitor MTS’s own environment and assists MTS with managing its vulnerabilities.

Because the assessment is independent, it can objectively evaluate an organization’s environment, including cybersecurity protections MTS may already have implemented.

That separation is intentional.

The independent third party evaluates the environment and documents the evidence.

MTS does not conduct the assessment.

Once the findings are available, MTS can help leadership understand:

  • What the findings mean
  • How they may affect Cyber Liability
  • Which issues deserve attention
  • What options are available
  • What could happen if action is delayed
  • What decisions leadership may need to make

The client remains the decision-maker.

That follows the MTS educational process:

Understand where you stand.

Build an informed plan.

Stay prepared together.

MTS calls the principle behind this approach:

Evidence before opinion.

Interested in Understanding Where Your Organization Stands?

If your nonprofit would benefit from an objective view of its current cyber risk, you can learn more about the Independent Cyber Risk Assessment available through MTS.

The assessment is performed by the unaffiliated third-party security company, not by MTS.

Its purpose is simple:

Give leadership clearer evidence so it can make better decisions.

Continue Learning

Previous Chapter

How Do People, Technology, Donor Data, and Third-Party Systems Create Cyber Liability for a Nonprofit?

Next Chapter

Chapter 5: How Should a Nonprofit Prioritize Cyber Risks When Every Dollar Matters?

An assessment may identify more opportunities for improvement than an organization can address immediately.

Chapter 5 will focus on the next question:

How do nonprofit leaders decide what comes first?

We will look at how to weigh:

  • Mission impact
  • Operational risk
  • Reputational risk
  • Regulatory complexity
  • Legal considerations
  • Existing safeguards
  • Evidence
  • Cost
  • Timing
  • The consequences of waiting