Home / Blog / Donor data security

Security · for small nonprofits

Keeping donor data safe when you don't have an IT department

By the Ember team · August 8, 2026

The short version

You don't need an IT department to keep donor data safe — you need a handful of habits that stop the most common problems. Here's the calm, no-panic checklist.

Why small nonprofits are targets

It's not personal — it's easy. Small orgs hold real data (names, emails, giving history, sometimes payment details) and often have the lightest defenses. The 2020 Blackbaud ransomware attack, which exposed data held by thousands of nonprofits and schools, made the point: you don't have to be big to be hit. The good news is that most breaches come through a few predictable gaps, and closing them doesn't take an expert.

The basics that stop most problems

Choose tools that protect you

Where donor data lives matters. Prefer tools that offer two-factor login, role-based permissions, and encryption, and that let you export your data anytime. A tool that treats your data as yours — clear on how it's stored and easy to leave — is safer than a cheaper one that's vague about both.

Have a simple "what if" plan

  1. Know what you hold and where

    You can't protect data you've forgotten is in an old spreadsheet.

  2. Keep backups

    Ransomware is far less scary when you have a clean copy.

  3. Know who you'd tell

    Many states require notifying affected people after a breach. Know your obligation before you need it.

None of this requires an IT team. Two-factor on, unique passwords, least-access, updates, and a little phishing awareness will put a small nonprofit ahead of most. Calm and prepared beats worried and exposed.

The Ember tool for this

Ember Donors

Keep donor records in one place with secure login and role-based access — and your data always yours to export. Built only for nonprofits.

Common questions

What's the single most important security step for a small nonprofit?

Turn on two-factor authentication, starting with your email. It blocks the large majority of account break-ins and takes minutes to set up.

Do we have to tell donors if we have a data breach?

Often yes. Many states require notifying affected people after a breach of personal data. Know your state's rule before an incident, not during one.

Is our donor data safer in a spreadsheet or in software?

Well-chosen software is usually safer — it can offer two-factor login, permissions, encryption, and backups that a shared spreadsheet can't. The key is choosing a tool that's clear about how it protects and exports your data.

One calm place for all of it

Ember brings your programs, grants, volunteers, and donors into one place — built only for nonprofits, with a free plan and no credit card.

No credit card · No trial clock · Unlimited users included

Keep reading

Sources: Donor Data Security After Blackbaud; NonProfitPRO — protecting donor data. Verified August 2026.

General information, not legal or security advice. For a serious incident, consult a professional.