> ## Content Index
> Fetch the complete content index at: https://www.cybrsecmedia.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# AI and Nonprofits: The Monster Under the Bed Uses the Same Old Doors
- URL: https://www.cybrsecmedia.com/ai-and-nonprofits-the-monster-under-the-bed-uses-the-same-old-doors/
- Published: 2026-09-25T18:42:32.000Z
- Updated: 2026-09-25T18:44:52.000Z
- Description: AI is changing the threat landscape. For nonprofits and other under-resourced organizations, panic is a bigger risk than the technology.
- Author: Kelley Misata
- Tags: Adventures in Non-Profit Cyber, non-profit security, Agentic AI, CYBR.SEC.Community, blog

Almost every conversation I have with a nonprofit leader eventually gets to AI. Sometimes it's curiosity. More often it's dread. They've read about deepfaked executives on video calls and AI-written phishing emails that look like a perfect donor or someone in need, and they come to the conversation already convinced they've lost. Nevermind trying to think thru the risks and rewards of their staff, volunteers, and board members using AI - what organizational guardrails do they need?

I understand why. The organizations I work with, along with small businesses and many state and local governments, were living below what, Sightline Advisor, Wendy Nather called "the security poverty line" long before anyone had heard of ChatGPT. They have little or no IT staff, aging equipment, and volunteers with access to things they probably shouldn't have. Now they're being told there's a new, faceless, tireless attacker, and that it gets smarter every month.

What worries me more than the attacker is what that fear does. Overwhelmed organizations don't act. They freeze, or they decide security is for organizations with bigger budgets and put it back on the shelf. I've watched it happen. Fear doesn't make people safer. It makes them stop.

So let's put the monster in perspective.

**What the data actually says**

This year's Verizon Data Breach Investigations Report is refreshingly calm on AI. The amount of AI-assisted text showing up in malicious emails has doubled, yet the report notes this hasn't led to a measurable increase in how often phishing actually succeeds against organizations. Fewer than 2.5 percent of AI-assisted malware observations involved techniques that were new or rare. Meanwhile, the human element showed up in 62% of breaches, and exploiting vulnerabilities became the top way in, at 31 percent. 

In other words, AI is making old attacks cheaper and more polished. It isn't inventing new ways in. Attackers are walking through the same doors we've been talking about for twenty years: unpatched systems, reused passwords, and a human-like convincing message that gets someone to act before they think.

That's good news for under-resourced organizations, because it means the fundamentals still work.

**We've gotten better too**

We don't give ourselves enough credit. Ten years ago, many of the people I talked with had never heard the word phishing. Today most nonprofit staff know not to click a strange link. They know multi-factor authentication exists, even if it isn't turned on everywhere yet. Attackers got better tools, but users got better too.

The lessons from the last era still apply almost exactly. "Is that email really from our executive director?" becomes "Is that voice really our executive director?" The defense is the same: slow down and check through another channel. A request to change payment details gets a phone call to a number you already have. That worked against wire fraud emails in 2016, and it works against a cloned voice in 2026.

**Where AI does change the picture**

To be honest about it, AI isn't nothing. About a third of AI-assisted initial access involved exploiting vulnerabilities, which means the gap between a flaw being found and being used is shrinking, and patching matters more than ever. There's also a quieter risk inside the organization. Most people using unapproved AI tools on work devices do it through personal accounts. For a nonprofit, that might look like a program manager pasting client case notes into a free chatbot to draft a grant report, with no attacker required.

Neither problem needs a new security program. They need automatic updates turned on, and a simple, sensible conversation with staff about which AI tools to use and what should never go into them.

**What we owe them**

Those of us in the security field have contributed to the panic. AI threats make great conference talks and even better marketing. But every time we lead with the scariest scenario, a small organization somewhere decides this isn't for them.

Next time you talk with a nonprofit, a small business, or a town IT department about AI, try starting somewhere else. Yes, this is a new era, and here's what hasn't changed. Patch your systems. Use a password manager and MFA. Verify any request for money or access through a second channel. Talk with your staff about the tools they're using. None of those four things are new.

The monster under the bed is real enough, but it's using the same old doors, and we know how to lock those.