Cyber Liability Knowledge Center for Nonprofits | Chapter 1

The Quick Answer

For a nonprofit organization, cybersecurity and Cyber Liability are connected, but they are not the same thing.

Cybersecurity is primarily concerned with protecting technology: systems, accounts, devices, networks, applications, and information.

Cyber Liability is the broader risk an organization carries because its mission depends on people, technology, data, vendors, and connected systems.

For nonprofit leaders, that risk can be understood through four areas: Operational, Reputational, Regulatory, and Legal risk.

Understanding the difference changes the conversation.

Cybersecurity versus Cyber Liability for nonprofits comparison graphic

Instead of asking only:

“Are we secure?”

Leadership can ask a more useful question:

“What could happen to our mission if one of our technology, people, data, or third-party risks becomes a real event?”

That is where Cyber Liability begins.

Cybersecurity Protects Technology. Cyber Liability Looks at What Is at Stake.

Cybersecurity is important.

A nonprofit may use safeguards such as multifactor authentication, endpoint protection, secure backups, email filtering, firewalls, access controls, employee education, vulnerability management, and security monitoring.

Each safeguard addresses part of the technology environment.

But nonprofit leadership is responsible for something larger.

Leadership is responsible for protecting the organization’s ability to carry out its mission.

That includes:

  • The people who depend on its services
  • Employees and volunteers
  • Donors and supporters
  • Sensitive organizational information
  • Financial resources
  • Community relationships
  • Regulatory and contractual responsibilities
  • The reputation and trust the organization has built

A cybersecurity weakness becomes a Cyber Liability issue when it can affect one or more of those responsibilities.

Consider a backup system.

From a cybersecurity perspective, the question might be:

“Do we have backups?”

From a Cyber Liability perspective, the questions become:

“Can we restore our information?”

“How long would restoration take?”

“What programs would stop while we recover?”

“How long can those programs remain unavailable before the people we serve are affected?”

The technology question matters.

But the mission question is ultimately more important.

The Four Areas of Cyber Liability

A practical way for nonprofit leaders to understand Cyber Liability is to organize risk into four categories.

1. Operational Risk

Operational risk asks:

What could prevent us from carrying out our mission?

Technology supports nearly every modern nonprofit in some way.

Organizations may depend on technology to communicate, process donations, maintain records, serve constituents, manage employees, coordinate volunteers, access financial information, operate programs, or work with outside partners.

A technology problem becomes an operational risk when it prevents those activities from happening.

For example, consider a nonprofit whose staff cannot access its primary cloud platform for an entire business day.

The technology issue may be an unavailable system.

But the operational consequences might include delayed services, employees who cannot work, missed communications, interrupted fundraising, or postponed program activities.

That is why leadership should think beyond whether a particular technology is “working.”

The better question is:

“Which parts of our mission depend on this technology, and what happens if it becomes unavailable?”

Educational Example: Backup and Recovery

A nonprofit may be told that its information is backed up every day.

That sounds reassuring.

But leadership still needs to understand whether the organization can actually restore that information, how long recovery is expected to take, and which operations receive priority.

A backup without a clear recovery expectation may reduce technical risk while leaving significant operational uncertainty.

2. Reputational Risk

Nonprofit organizations operate on trust.

A donor trusts an organization to use resources responsibly.

A constituent may trust the organization with personal information.

Employees and volunteers trust leadership to protect the systems they use.

Funders and community partners trust the organization to operate responsibly.

Boards trust executive leadership to identify and manage meaningful organizational risks.

A cyber incident can put that trust under pressure.

The reputational impact may come from the incident itself, but it may also come from how the organization responds.

Leadership may eventually need to answer questions such as:

What happened?

What information was affected?

What protections were in place?

How quickly did the organization respond?

Did leadership understand the risk before the event occurred?

This does not mean every cybersecurity problem becomes a public crisis.

It means reputation should be considered when evaluating Cyber Liability because trust is often one of a nonprofit’s most valuable assets.

Educational Example: Donor Trust

Imagine a nonprofit that processes online donations.

The organization may have excellent programs and responsible financial management. But if unauthorized access affects donor information, leadership may have to manage more than a technology incident.

It may also need to manage donor questions, board concerns, communication decisions, and uncertainty about whether supporters will continue to trust the organization with their information.

The Cyber Liability is therefore broader than the compromised technology.

3. Regulatory Risk

Not every nonprofit has the same regulatory responsibilities.

What applies to an organization can depend on factors such as the services it provides, the information it stores, its funding sources, contractual commitments, payment activity, geography, and the populations it serves.

For that reason, regulatory risk cannot be reduced to a universal cybersecurity checklist.

Leadership should understand the difference between:

“This is considered a good security practice.”

and

“Our organization has a responsibility or obligation to address this.”

Those may overlap, but they are not always the same.

A nonprofit working with particularly sensitive information may face different requirements from an organization whose systems contain less regulated data.

Likewise, a funding agreement, insurance policy, contract, or business relationship may create expectations that do not apply to every nonprofit.

This is why regulatory complexity can significantly change the level of cybersecurity governance an organization needs.

The educational goal is not for nonprofit executives to become regulatory experts.

It is for leadership to know enough to ask:

“What obligations apply to our organization, and what evidence do we have that we are meeting them?”

Educational Example: A Control Versus Evidence of the Control

Suppose an organization requires multifactor authentication.

The policy may say MFA is required.

The technology team may believe it is enabled.

The regulatory question may be different:

Can the organization demonstrate that MFA is consistently applied where it is supposed to be?

The distinction is between having a control and having evidence that the control is actually operating as intended.

4. Legal Risk

Cyber incidents can also create legal questions.

Those questions may involve contracts, privacy, notification responsibilities, employee information, insurance, financial transactions, records, third-party relationships, or other obligations.

Technology teams should not be expected to provide legal advice.

Likewise, nonprofit executives should not be expected to become cybersecurity attorneys.

The leadership responsibility is different.

Leaders need enough visibility to recognize when a technology or cybersecurity issue may have legal implications and when qualified legal advice should be brought into the conversation.

One of the practical benefits of understanding Cyber Liability is that it helps leadership recognize when an issue has moved beyond IT.

A technical vulnerability may begin with a server, employee account, cloud application, or vendor.

But the consequences may eventually involve executive leadership, legal counsel, insurance professionals, the board, communications personnel, regulators, funders, or other stakeholders.

This is why looking at the whole risk matters.

Technology may be where the issue begins.

It is not always where the consequences end.

Why Having Cybersecurity Tools Does Not Automatically Mean the Organization Understands Its Cyber Liability

Consider a nonprofit that has already implemented several good cybersecurity practices.

It has:

  • Endpoint protection
  • Multifactor authentication
  • A firewall
  • Backups
  • Employee security awareness training
  • An outsourced technology provider

At first glance, leadership might reasonably feel that cybersecurity is being addressed.

But there are still important questions to ask.

Is MFA actually enabled everywhere it should be?

Can backups be restored within a timeframe the organization can tolerate?

Do former employees still have access?

Which outside vendors have access to systems or information?

Who has administrative privileges?

Are those privileges necessary?

Are known vulnerabilities being identified and prioritized?

Do policies match what employees actually do?

Who in leadership is responsible for decisions about cyber risk?

If a recommendation is postponed, does leadership understand the risk it is choosing to carry?

Those questions are not designed to create fear.

They are designed to create clarity.

The point is not that something must be wrong.

The point is that responsible decisions are easier when they are based on evidence instead of assumptions.

A Real Nonprofit Experience: Security Maturity Is a Journey

The following example is intentionally anonymized.

An established nonprofit organization relied heavily on technology to support publishing, online activity, information management, employees, and mission delivery.

Over time, the organization made documented improvements that included eliminating Windows 7, continuing migration toward Windows 11, creating a 3-5 year hardware lifecycle, deploying more advanced endpoint protection, using recurring independent vulnerability assessments, improving password management, increasing security awareness, reviewing encryption, reducing unnecessary administrative access, strengthening governance, and evaluating resiliency and redundant connectivity.

The important educational lesson is not the individual technologies.

It is that improvement happened in stages.

There was not one product that suddenly made the organization “secure.”

The organization continued moving from individual technology improvements toward a more structured understanding of governance, risk, responsibility, and preparedness.

What Can We Learn From This Example?

A reasonable lesson from the documented experience is:

Cybersecurity maturity and Cyber Liability maturity are related, but they are not the same thing.

An organization may have strong cybersecurity tools and still need to improve:

  • Governance
  • Documentation
  • Risk ownership
  • Recovery expectations
  • Regulatory understanding
  • Executive visibility
  • Decision-making
  • Ongoing review

The underlying improvements are documented in MTS source material. The conclusion above is an educational interpretation of that experience and should not be presented as a direct quotation from the nonprofit.

Five Questions Nonprofit Leaders Can Ask Without Becoming Cybersecurity Experts

A nonprofit executive does not need to understand every technical control.

A board member does not need to know how to configure a firewall.

But leadership should be able to ask informed questions.

Start with these five:

1. What evidence tells us where our most important technology and cybersecurity risks are today?

Not what do we assume. Not what someone thinks.

What does the evidence show?

2. Which risks could most seriously interrupt our mission?

This brings the conversation back to operations and the people the organization exists to serve.

3. Which systems, data, vendors, or relationships could create significant reputational, regulatory, or legal consequences?

This helps leadership see beyond individual technology tools.

4. Who is responsible for making Cyber Liability decisions?

The technology provider may advise.

Security professionals may provide evidence.

Legal or insurance professionals may contribute expertise.

But someone inside the organization still needs to own the decision.

5. When we decide not to address a recommendation immediately, do we understand the risk we are choosing to carry?

Not every recommendation can or should be completed at once.

Nonprofits have budgets, staffing limitations, competing priorities, and mission responsibilities.

Responsible Cyber Liability management does not mean fixing everything immediately.

It means understanding the tradeoffs well enough to make an informed decision.

The Goal Is Not Perfect Security

No nonprofit can eliminate every cyber risk.

Even well-funded organizations with mature cybersecurity programs continue to face risk.

The goal should therefore not be:

“Eliminate all cyber risk.”

A more practical goal is:

Understand the risks that matter.

Prioritize them based on impact.

Make informed decisions about what to do.

Document important decisions.

Continue reviewing the environment as conditions change.

That approach helps leadership avoid two extremes.

The first is complacency:

“We have an IT provider, so cybersecurity is handled.”

The second is fear:

“Cyber threats are everywhere, so we need to buy everything.”

Neither creates good decision-making.

Clarity does.

A Simple Educational Framework: Understand, Prioritize, Prepare

A nonprofit can begin thinking about Cyber Liability through three practical steps.

Understand Where You Stand

Start by establishing what is actually known about the environment.

What is working?

What vulnerabilities exist?

Which assumptions have been verified?

Where is more evidence needed?

Understanding comes before action because solving the wrong problem wastes both money and time.

Build an Informed Plan

Once the risks are understood, prioritize them.

Consider:

  • Potential operational impact
  • Reputational impact
  • Regulatory complexity
  • Legal implications
  • Likelihood
  • Cost
  • Available resources
  • The consequences of waiting

A plan should help leadership understand not only what should be done but why it matters.

Stay Prepared

Cyber risk does not stand still.

Employees change.

Technology changes.

Vendors change.

Programs change.

Threats change.

Requirements may change.

Preparedness therefore requires ongoing review rather than a one-time project.

What Should a Nonprofit Leader Take Away From This Chapter?

Cybersecurity protects systems and information.

Cyber Liability asks a larger question:

What could happen to the organization if the people, technology, information, vendors, or safeguards it depends on fail or are compromised?

For nonprofit leaders, the answer should be considered through four lenses:

Operational

Can we continue carrying out our mission?

Reputational

Could we damage the trust others place in us?

Regulatory

Are there requirements or obligations we need to understand and demonstrate?

Legal

Could the event create responsibilities or exposure that extend beyond the technology itself?

You do not have to become a technology or cybersecurity expert to ask those questions.

But asking them can help you become a more informed steward of your organization’s mission, resources, data, and trust.

Applying the Education: How MTS Thinks About Cyber Liability

At MTS, the education in this chapter is applied through a simple principle:

Evidence before opinion.

That means starting by understanding what the evidence actually shows before recommending what should happen next.

When an organization wants an objective view of its current environment, an Independent Cyber Risk Assessment can provide evidence about vulnerabilities and existing protections.

The assessment referenced by MTS is performed by an independent third-party security company that is not affiliated with MTS. It can therefore evaluate the environment objectively, including protections that MTS itself may already have implemented.

Once the independent evidence exists, MTS’s role is educational.

MTS helps leadership understand:

What does the evidence mean?

Which part of our Cyber Liability does it affect?

Why does it matter?

What options do we have?

What should we prioritize?

The client remains the decision-maker and responsible leader. That separation between independent evidence, MTS guidance, and client decision-making is key to MTS operations.

If you would like to understand how that process works in practice, the next step is not to buy a product.

It is to learn how an Independent Cyber Risk Assessment can help an organization better understand where it stands.

Continue Learning

Next Chapter

Chapter 2: What Are the Four Cyber Liability Risks Every Nonprofit Leader Should Understand?

Chapter 2 takes a deeper look at:

Operational Risk

Reputational Risk

Regulatory Risk

Legal Risk

and explains how nonprofit leadership can use the four categories to organize conversations about cybersecurity and organizational risk.