
Tech & Main Presents · 2025-01-27 · 10 min
Key moments - from our scoring
Substance score
18 / 100
Five dimensions, 20 points each
Nonprofits often deprioritize cybersecurity, but protecting sensitive data is as critical to mission delivery as the work itself. Shaun St.Hill breaks down the NIST (National Institute of Standards and Technology) Cybersecurity Framework as a practical playbook for nonprofit organizations, not as a path to impenetrability but as a structured approach to managing risk. The framework operates as a five-function cycle: identify (cataloging where data lives), protect (implementing safeguards like encryption and multi-factor authentication), detect (monitoring for suspicious activity via firewalls and intrusion detection), respond (containing and investigating breaches), and recover (restoring operations and learning from incidents). The episode maps these functions against nonprofit-specific objectives - maintaining member-client data, donor financial information, employee-volunteer records, cybersecurity training, cyber insurance coverage, third-party vendor oversight, and physical asset security. Particular emphasis goes to donor data protection (a prime target for criminals) and vendor risk management, since a nonprofit's security is only as strong as its weakest vendor link. This conversation is essential for nonprofit leaders and operations staff responsible for data stewardship, fundraising infrastructure, or volunteer management.
NIST (National Institute of Standards and Technology) is a government agency that created a cybersecurity framework - essentially a playbook of guidelines and best practices - to help organizations of all types understand, manage, and reduce cybersecurity risks without requiring impenetrable security, just a solid plan for what could go wrong and how to react.
Encryption scrambles data so that only authorized people with a special key can read it, functioning like putting files in a lockbox to prevent unauthorized access.
The respond function is your action plan to contain damage, notify affected individuals, potentially engage law enforcement and cybersecurity professionals to investigate what happened, and work toward recovery.
A nonprofit's cybersecurity is only as strong as its weakest link, and that often includes third-party vendors like cloud storage providers and payment processors; if a vendor has weak security practices, it can compromise your entire organization regardless of your own defenses.
Cyber insurance can cover legal fees, notification expenses, credit monitoring services for affected individuals, and the costs of restoring compromised systems, acting as a safety net rather than a prevention tool.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode is almost entirely a surface-level walkthrough of the five NIST functions (Identify, Protect, Detect, Respond, Recover) with no novel claims or non-obvious ideas. Every point made - use strong passwords, train employees on phishing, vet vendors - is generic cybersecurity hygiene that any moderately informed person already knows.
We talking strong passwords We talking multi authentication which basically adds an extra layer of security on top of your passwords
So encryption basically means scrambling the data so that only authorized people with like a special key can read it
The episode recycles a well-known government framework verbatim with zero contrarian angles, first-principles arguments, or nonprofit-specific insights that go beyond the obvious. Even the framing device of 'I'm here to save the rainforest, not fight hackers' is a tired trope in nonprofit tech talks.
It's like that old saying, an ounce of prevention is worth a pound of cure
cybersecurity is not just about technology. It's really about a mindset
The presenter demonstrates only entry-level familiarity with the subject matter - explaining what NIST stands for and defining basic terms like encryption - with no evidence of having implemented these frameworks at scale inside an actual organization. There are no credentials, no war stories, and no demonstrated depth.
So NIST stands for the National Institute of Standards and Technology. So it's a government agency
So it's not necessarily about becoming, you know, impenetrable Fort Knox
There are zero real data points, named organizations, breach statistics, cost figures, or actual case studies. The only 'example' used is a fully hypothetical counseling nonprofit, and even that example is never developed with any concrete details.
So let's imagine a specific scenario. Let's say that we are a nonprofit that offers counseling services to families in need
it can help cover the costs that are associated with a data breach. And that might be, you know, legal fees, notification expenses
The host exclusively plays the role of a deliberately naive questioner to elicit basic definitions, never pushing back, never asking for evidence, and never probing beyond the surface. The format reads as a scripted explainer dressed as a conversation rather than genuine intellectual exchange.
Hold on Now you using big words Encrypting What does that mean
That sounds like a worst case scenario, but it's good to be prepared
Computed from the transcript - who did the talking, and the words that came up most.
This episode was created in Notebook LM using a NIST based cybersecurity framework I created that focuses on nonprofits. This document outlines a cybersecurity framework for nonprofits, based on the NIST framework. It prioritizes the protection of various data types (member, donor, employee) and assets, emphasizing cybersecurity training and insurance. The framework addresses five core cybersecurity functions: identify, protect, detect, respond, and recover. Each function is mapped to specific organizational objectives and categorized by risk level (high, medium, low, or not applicable). The ultimate goal is to provide a structured approach to managing cybersecurity risks within nonprofit organizations. For more information please email me at info@techandmain.com or visit
Transcribed and scored by The B2B Podcast Index.
Okay, so today we're going to be diving deep into something that I think sometimes gets overlooked in the nonprofit world, and that's cybersecurity. Yes. We've got a great visual aid for today's deep dive. Okay.
And that is a slide from a presentation titled Tech and Main NIST Framework for Nonprofits. Oh, nice. So, you know, you might be thinking cybersecurity. I'm here to save the rainforest.
I'm here to help kids read. I'm here to rescue animals. What does this have to do with me? I'm not fighting off hackers.
But protecting your data is just as important as protecting those that you serve. Right. I mean, this is about protecting your mission, protecting your reputation, and protecting really your ability to even do good in the world. Yeah, for sure.
So let's take a look at this slide. What we have here is a mapping of the NIST cybersecurity framework categories against key nonprofit objectives. First of all, for listeners who might not be familiar, what exactly is this NIST framework that everyone keeps talking about? Yeah.
So NIST stands for the National Institute of Standards and Technology. So it's a government agency. And the NIST cybersecurity framework is basically like a set of guidelines or best practices. Think of it almost like a cybersecurity playbook to help organizations of all types.
But we're focusing on nonprofits today to help them kind of understand and manage and reduce their cybersecurity risks. Gotcha. So it's not necessarily about becoming, you know, impenetrable Fort Knox. Right.
But it's about having a solid plan in place, understanding what could go wrong and knowing how to react. Absolutely. So this slide is really great because it really tailors the framework specifically to what nonprofits need to be thinking about. Exactly.
Okay. So let's imagine a specific scenario. Let's say that we are a nonprofit that offers counseling services to families in need. You know, pretty sensitive information right there.
So sure. The slide lists our first objective is maintain member-client data. How does the NIST framework apply here? All right.
So we can think about the framework in terms of five different functions, and they all kind of work together in this cycle. And the functions are identify, protect, detect, respond, and recover. Good. So starting with identify, this is all about knowing what data you have, where is it stored, who has access to it.
So, you know, for our hypothetical counseling center, this might be things like, are we talking about physical files? Are we talking about databases? Is this in the cloud? Is it on our local servers?
So basically like step one is figuring out where all your data lives. Exactly. Taking inventory. That right Then what Then we move on to protect which is all about putting safeguards in place to prevent unauthorized access to that data OK so we talking strong passwords We talking multi authentication which basically adds an extra layer of security on top of your passwords and encrypting sensitive information Hold on Now you using big words Encrypting What does that mean So encryption basically means scrambling the data so that only authorized people with like a special key can read it.
So it's kind of like putting your files in a lockbox. Okay, got it. So we've identified our data. We've locked it up tight.
What's next? All right. So then we move on to detect. And this is all about having systems in place to monitor for suspicious activity or potential breaches.
Okay. So this might be things like firewalls, intrusion detection systems, and security software that can kind of flag unusual login attempts or any unusual data transfers. So even with all these precautions, you know, there's still a chance that something could slip through. Right.
So what happens then? Then we got to respond. Okay. So respond is your action plan if a breach does occur.
So it's about containing the damage, notifying any individuals that were affected by that data breach, you know, potentially working with law enforcement. Oh, wow. You might have to engage cybersecurity professionals to help investigate what happened and help recover. That sounds like a worst case scenario, but it's good to be prepared.
Absolutely. Yeah. And the last step is recover. So this is all about getting your systems back up and running, your operations back to a normal state as quickly and efficiently as possible.
Okay. So that might involve things like restoring data from backups, rebuilding systems that may have been compromised, and then really importantly, reviewing your security practices and seeing what can be improved to prevent a similar incident from happening again. Yeah. So not just bouncing back, but bouncing back stronger.
Exactly. Learning from that experience. Yeah. So it's really a cycle of continuous improvement.
Okay. So that all makes sense in the case of protecting like client data. But what about maintained donor data? I feel like the stakes are even higher, right?
Because now we're talking about financial information, people's generosity. Like a breach could really damage trust and future fundraising. Absolutely. Yeah.
I mean, donor data is a prime target for cyber criminals. And I think, you know, while all five of these NIST functions are still relevant, I think protect takes on an even greater significance when we're talking about donor information. We're talking about rigorous access controls, encryption of all financial data and regular security audits to make sure that your systems are really up to snuff Because you know you entrusted with people hard money Right Absolutely So security needs to be top Now, what about protecting staff and volunteers?
Yeah. It's easy to focus on external threats, but what about internal risks? Yeah. You've hit upon a critical point.
Maintain employee volunteer data isn't just about hackers. It's about, you know, protecting this data from misuse or unauthorized access from within your organization as well. Oh, interesting. So we're talking strict access controls that are, you know, based on job roles.
We're talking clear policies about how data should be handled and ongoing training for all your staff and your volunteers. It's like that old saying, an ounce of prevention is worth a pound of cure. Exactly. Exactly.
And let's not forget the legal and ethical obligations that nonprofits have to safeguard their employee and volunteer information. Right. So this is not just best practice. It's often, you know, the law.
Speaking of best practices, the slide also lists maintain employee cybersecurity training. And I have a feeling this goes, you know, way beyond telling people to choose a strong password. Right. You'd be surprised how many data breaches actually result from very simple human error.
Yeah. So this is why ongoing cybersecurity training is so important in today's world. We're talking about educating staff on how to recognize things like phishing attempts. Those emails, you know, they look real, but they're designed to trick you into giving away your information.
Yeah. And, you know, how to create passwords that are both strong and unique and safe browsing habits. I feel like it's a constant game of cat and mouse, right? Like as soon as you figure out what to look for, the bad guys are like two steps ahead.
Exactly. Exactly. And that's why, you know, this training needs to be ongoing. It can't just be a one-time thing.
It needs to be, you know, part of the culture, this awareness. Yeah, absolutely. Okay, let's talk about something a bit less glamorous, but just as important. Maintain proper cyber insurance coverage.
I'll admit, insurance isn't the most thrilling topic to talk about, but I feel like in this context, it's pretty crucial. It absolutely is. You know, think of cyber insurance as a safety net for your organization. It can help cover the costs that are associated with a data breach.
And that might be, you know, legal fees, notification expenses, credit monitoring services for the individuals that were affected. Wow. And potentially even the cost of restoring your system So it not a you know it not a magic bullet It not going to prevent everything but it can really be a lifesaver if the worst happens Okay so an investment worth considering Okay this next one really caught my eye Maintain third supplier oversight Why is this so important for nonprofits Yeah So a nonprofit cybersecurity is only as strong as its weakest link right And often that weak link can be a third vendor You know nonprofits work with a lot of different vendors You got your cloud storage providers you have payment processors fundraising platforms email marketing services all of these different services And so if one of those vendors has weak security practices it can put your entire organization at risk It's kind of scary to think that a breach could originate from a vendor that you might not even directly interact with.
Right. And that's why due diligence is so important. You know, nonprofits really need to carefully vet their vendors. Make sure that they have strong cybersecurity practices in place and include specific security requirements in their contracts with those vendors.
And it's also wise to, you know, monitor your vendor's security posture over time because things change. Things change. All right. Last but not least, maintain physical assets.
Now, this might seem a little bit out of place in a conversation about cybersecurity. Yeah. Help me connect the dots here. Right.
It's easy to get caught up in the digital world, but physical security still matters. You know, you could have the best cybersecurity software in the world, but if someone can just walk into your office and steal a server or steal a laptop with sensitive information, you know, all of those defenses are useless. Oh, wow. Yeah.
I hadn't even thought about it that way. Right. So we're talking basic security measures, locks, cameras, controlling access to like server rooms. Exactly.
Exactly. So, you know, it's about securing your physical spaces, your equipment, just as diligently as you secure your data networks. OK. So wrapping up, I think what's really resonating with me is that cybersecurity is not just about technology.
It's really about a mindset. It's about kind of weaving security into every aspect of how a nonprofit operates. Couldn't have said it better myself. And remember, you don't have to be a tech expert to get started with this.
The NIST framework gives you that roadmap, and there are tons of resources available to help nonprofits navigate this complex landscape. Great advice. So for our listeners out there, even if you're focused on, you know, saving the world one pause at a time, whatever cause you're passionate about, take a moment to consider your cybersecurity. It's an investment in your mission.
It's an investment in your reputation. And it's an investment in the people that you serve. Thanks for joining us for this deep dive. And remember, stay safe out there online and off.
Stay safe. See ya.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.