Skip to content

IT and cybersecurity for Australian not-for-profits.

Donors trust you with their data. Beneficiaries trust you with theirs. The board is watching every dollar, and grant funders are writing security conditions into the deed. Your budget is tighter than a private company's; the data you hold is not less sensitive. We scope to the risk in front of you, not to a template price.

What's actually different

What a data breach costs a charity.

Your donors and beneficiaries hand over information because they trust you with it, and that trust is the asset funders care about most. A breach does not stay an IT problem for long. It becomes a mass-donor notification letter, a board meeting, and a funder who stops returning calls. So the case for security spend here is different from the private-sector one. Less about the insurance premium, more about who still gives next year.

Most not-for-profit (NFP) environments we assess share the same problems. Software that is under-licensed. Dozens of dormant volunteer accounts. A backup arrangement set up years ago and never tested since. The donor database has usually grown to hold far more sensitive information than anyone in the office realises. None of that is hard to fix. The work is in sequencing it against a budget that is already committed.

Money comes up early with charities, and we would rather have it out before you spend time on us. If your budget does not reach our minimums, we will say so and point you at providers who fit. You keep the baseline documentation either way. Better you succeed with another provider than run underserved with us.

Live right now

The 2026 pressure points we're actively working on with clients.

The specific asks, deadlines and enforcement actions shaping 2026 conversations in your sector.

ACNC compliance focus now names cyber security

The Australian Charities and Not-for-profits Commission (ACNC) names cyber security and terrorism-financing misuse in its current compliance focus. Its Governance Toolkit on cyber security has stopped being optional reading. Treat it as the baseline your board is expected to meet, and if nobody can produce a written IT policy, start there.

Grant funders are writing security into the deed

Paul Ramsay, Minderoo, several state health departments and federal grant programs now put security conditions in the funding agreement. Multi-factor authentication (MFA), tested backups and a documented incident response plan are the usual three. Have the evidence ready before contracting, so a funded program does not stall while you go looking for it.

Privacy Act Tranche 2 has not passed yet

Tranche 1 reforms are live. Tranche 2 would remove the small-business exemption and bring roughly 100,000 organisations into full coverage of the Australian Privacy Principles (APPs). Many charities under $3M turnover are in that group. No bill has passed and no start date is set. If you hold sensitive client or beneficiary data, work as though the rules already apply rather than wait for a date that keeps moving.

External Conduct Standards cover your offshore software

If you operate internationally, the ACNC's External Conduct Standards require documented controls over funds, personnel and data sent offshore. Cloud and software-as-a-service (SaaS) platforms hosted or supported overseas are in scope. The register doesn't build itself.

Frameworks and regulators

Industry frameworks, regulations and audit standards for not-for-profit in Australia.

ACNC Governance Standards
Privacy Act 1988 and the APPs
Grant and funding conditions
Fundraising regulation, state by state
ACSC Essential Eight

Common questions

The things not-for-profit clients ask us first.

We're small and donor-funded. Is this level of security really necessary?
Our board wants to keep IT spend low. How do we argue for proper investment?
We run a mix of volunteers and paid staff. Can both access our systems?
What about donor data in our CRM (Salesforce NPSP, Raiser's Edge, DonorTec)?

The qualifier

Let's see if we're a fit.

Seven questions, one moment of your time. We'd rather tell you now than three months in.

Step 1 of 7

How big is your team?

Counting everyone: staff, contractors, anyone with an account.

See if we're a fit