> ## Content Index
> Fetch the complete content index at: https://www.cybrsecmedia.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Nonprofit Cybersecurity Won’t Be Fixed With Another Checklist
- URL: https://www.cybrsecmedia.com/nonprofit-cybersecurity-wont-be-fixed-with-another-checklist/
- Published: 2026-10-02T19:05:38.000Z
- Updated: 2026-10-02T19:05:38.000Z
- Description: Nonprofit cybersecurity doesn't improve with more checklists and portals. Real change starts with conversations that expose hidden risks, build trust and turn advice into action.
- Author: Kelley Misata
- Tags: Adventures in Non-Profit Cyber, Non-Profit Cybersecurity, CYBR.SEC.Community, blog

Our industry has gotten very good at building things to hand nonprofits: surveys, checklists, self-assessment portals, resource libraries. We send them out, count the responses, and report the numbers, like 800 organizations assessed, 5,000 downloads, or 1,200 portal accounts. Funders like those numbers, and so do boards.

I've spent the past few weeks on onboarding calls with nonprofits getting ready to start work with Sightline. Every one of them reminded me that the number was never the point. Change happens in conversation, and honestly, so does most of my own learning.

**What a tool can't tell you**

On one call, a staffer had set up time with me after an earlier assessment showed security gaps well beyond her own program. She brought a colleague from operations because, as she put it, she knew the history but someone else would have to carry the work. No form would have told me that. But it told me almost everything about how our work together needed to run. It showed me who holds the institutional memory and who holds the capacity. It also showed me that the person who raised her hand first isn't necessarily the one who will make it stick.

On another call, a staff member told me her organization uses a password manager. A checklist would have marked that as done. Then she mentioned that about a third of staff don't use it consistently. Then, more quietly, she said they'd done digital security training before, and it stalled. It wasn't because people didn't care. It was because nobody had time to follow through.

That's the finding. They'd tried, it hadn't stuck, and they were wary of trying again.

A survey measures only what an organization can report about itself, through whoever opens the email. A checklist assumes they already know which items matter for them. A portal assumes someone has the time to log in, find the right resource, and act on it alone. None of them catch the disconnects inside an organization. The program side thinks security is operations' job, operations thinks it's IT's job, and IT is a volunteer who comes in on Tuesdays. Those disconnects are where the risk lives.

**What a conversation does**

When you're live with people, they ask questions, and their questions tell you what they're worried about. On one call, I was asked right away whether I'd call immediately if I found something urgent, and whether I'd be looking at staff's personal accounts. Those were trust questions. They were deciding whether to let me in.

In a conversation, you can correct misunderstandings before they turn into bad decisions. You hear the words people use for their own work, so your guidance comes back in language they'll act on. And sometimes you learn they need a listening ear as much as a social media policy. That matters more than it sounds. An organization that feels heard follows through, while one that feels graded files the report away.

**Who's teaching whom**

Here's something I don't hear our field say out loud: I've learned more from conversations with our nonprofit members than from almost anything else in my career. They teach me their reality. They show me what a Monday actually looks like when the grant report is due, and the executive director is out. They explain why the "right" control is wrong for a twelve-person organization with three part-time staff. They push back, and they push me to find a path that works for them rather than one that works for a generic checklist.

That's how our recommendations get better, and change happens. It doesn't come from more data points. It comes from people telling us where our advice doesn't fit their lives. If all we ever do is send tools, we never hear that, and we keep building the same tools.

**Being honest about the tradeoff**

To be fair, our own KickStart process uses questionnaires too. Structured questions are useful. The problem isn't the tool. It's sending one into an organization with no relationship around it and calling the answers help.

Conversation is slower, and my "organizations reached" number will always look smaller than it could. I've made peace with that. I'd rather know ten organizations well enough to help them change something than hand a thousand of them a checklist that changes nothing.

**For the rest of us**

If you work with nonprofits, small businesses, local governments, or other struggling sectors, whether as a vendor, volunteer, funder, or researcher, here's my ask. Before you send the survey, the checklist, or the portal link, get on a call. Listen more than you present. Ask what they've tried before and what happened. Find out who actually carries the work.

They'll be more likely to act on what you tell them, and you'll walk away knowing something you didn't. That's where the real work starts.