Mission-driven organizations are not too small to be targeted. In fact, they are often preferred targets precisely because they tend to underinvest in security while holding sensitive donor, client, and operational data.
The good news is that the vast majority of breaches are preventable with fundamentals—not expensive enterprise tools. Here are five practices that cost almost nothing and eliminate most risk.
First, enable multi-factor authentication on every account that supports it. This single step blocks the overwhelming majority of automated account takeover attempts. It is free and takes minutes.
Second, stop reusing passwords. A password manager costs a few dollars per user per month and eliminates the single most common breach vector: credential reuse across services.
Third, keep systems updated. Unpatched software is the entry point for most ransomware. Turn on automatic updates wherever possible and assign someone to own it.
Fourth, back up your data in a way that is disconnected from your network. If ransomware encrypts your primary systems, a clean offline backup is your recovery path.
Fifth, train your team. Most breaches start with a human clicking something they should not have. A short, regular training cadence beats a once-a-year compliance video.
