Volunteering is my middle name. Ask my husband — he’ll tell you, with a sigh, that I’ve spent the last fifteen years in one volunteer leadership seat or another. Right now that includes co-president of our band boosters. And every year, without fail, someone tries to phish us — an email or text pretending to be a board member, a vendor, a parent, asking someone to move money or share information they shouldn’t. So every year, I send out a reminder to the exec board about what phishing actually looks like, so people can catch it before they act on it.

I know how that sounds. Phishing attempts against a volunteer band board? But here’s the thing: phishing doesn’t check your org chart before it hits send. It doesn’t care that everyone on your board has a full-time job somewhere else and is doing this work for free, at night, between kids’ homework and everything else life throws at them. A scammer sees a group of people who move money, and that’s all they need to see.
And that’s really the heart of it. Whether it’s a booster club, a small nonprofit, or a growing small business, the question is the same: are you being a good steward of what people have trusted you with?
Nonprofits and small businesses have more in common than you’d think
I’ve spent years both running a business and sitting on volunteer boards, and the parallel is hard to unsee. Each organization is unique — different mission, different budget, different risk tolerance — but every single one of them has to reckon with the same short list of questions:
- Who has access to our money, and how do they get in?
- Who has access to our data — donor lists, member info, financial records — and how do they get in?
- What happens if one of those people clicks the wrong link?
- Do we have a plan, or are we hoping it never happens to us?
The difference is that small businesses usually have someone whose job title includes the word “operations” or “finance.” Nonprofits, especially small and volunteer-run ones, often don’t. The treasurer is a parent who’s great with spreadsheets. The person managing the donor database learned it on the fly. Nobody signed up to be the IT department — but somebody has to be, because the money still needs protecting.
Why nonprofits are actually a bigger target than people think
There’s a myth that nonprofits are too small or too mission-driven to be worth a criminal’s time. It’s backwards. Nonprofits are often more attractive targets, not less:
- Volunteer turnover means inconsistent access control. People rotate on and off boards every year or two. If nobody’s cleaning up old logins and shared passwords, you’ve got more open doors than you think.
- Trust runs high and skepticism runs low. Boards operate on goodwill. An email that looks like it’s from the treasurer or the executive director doesn’t get the same scrutiny it might in a corporate inbox with a trained security team behind it.
- The money is needed, not extra. When a business loses money to fraud, it hurts. When a nonprofit loses money to fraud, that’s the money that was going to fund the program, sponsor the kid who couldn’t otherwise afford the trip, keep the lights on for the mission. There’s no cushion.
That last point is the one that keeps me up at night, honestly. It’s not abstract. It’s real dollars that were earmarked for real kids, real families, real communities — gone because someone clicked a link they shouldn’t have.
What good stewardship actually looks like
You don’t need a full-time security team to take this seriously. What you need is a habit of asking the right questions and closing the obvious gaps. A few places to start:
- Send a phishing reminder at least once a year — for everyone, not just staff. You don’t need a simulated test to justify this. If real attempts are landing in your board’s inbox (and they are — yours too, even if no one’s said so out loud), a plain-language refresher on what phishing looks like is enough. Board members, volunteers, anyone with access to funds or data. If they touch money or data, they get the reminder. It doesn’t have to be fancy. It has to happen.
- Get serious about who has access to what. When someone rotates off the board, their access should rotate off too — bank logins, shared drives, donor databases, all of it. This is the single most overlooked step in volunteer-run organizations, because nobody owns it as a job.
- Separate duties around money movement. One person requesting a payment and a different person approving it isn’t bureaucracy for its own sake — it’s the single easiest way to stop both fraud and honest mistakes before money leaves the account. Honestly, needing two signatures on checks seems like a pain but is worth it to overcome fraud.
- Know where your sensitive data actually lives. Donor lists, financial records, member information — if you can’t answer “where is this stored and who can see it,” that’s your starting point.
- Write down what happens if something goes wrong. You don’t need a 40-page incident response plan. You need to know who gets called first, how you shut off access fast, and who talks to the bank. Write it down before you need it.
Leave it better than you found it
My daughter Ash has a phrase they use constantly, in the business and out of it: we leave things better than we found it. It comes from our Scouting background and the idea of “Leave No Trace” but we use it for everything. That’s really what this comes down to. You didn’t necessarily build the systems you inherited when you joined that board or took over that program. But you get to decide whether you hand it off in better shape than you received it.

That’s what stewardship means to me — not perfection, not a flashy security program, just consistently doing the unglamorous work of protecting what people trusted you to protect. For fifteen years that’s meant volunteer boards for me. For plenty of small business owners, it means the same instinct applied to a company instead of a cause.
Either way, the mission deserves a bodyguard, not a locked door you forgot to check.
Need a second set of eyes on your nonprofit’s or small business’s security basics? That’s exactly what PDRM is for. Call me before you’re hacked, not after.







Leave a Reply