Your donors and beneficiaries hand over information because they trust you with it, and that trust is the asset funders care about most. A breach does not stay an IT problem for long. It becomes a mass-donor notification letter, a board meeting, and a funder who stops returning calls. So the case for security spend here is different from the private-sector one. Less about the insurance premium, more about who still gives next year.
Most not-for-profit (NFP) environments we assess share the same problems. Software that is under-licensed. Dozens of dormant volunteer accounts. A backup arrangement set up years ago and never tested since. The donor database has usually grown to hold far more sensitive information than anyone in the office realises. None of that is hard to fix. The work is in sequencing it against a budget that is already committed.
Money comes up early with charities, and we would rather have it out before you spend time on us. If your budget does not reach our minimums, we will say so and point you at providers who fit. You keep the baseline documentation either way. Better you succeed with another provider than run underserved with us.