Industries

Enterprise obligations. Nothing like an enterprise budget.

A nonprofit holds donor records, payment details and often information about vulnerable people, with a fraction of the staff and none of the slack. The obligations do not scale down to match the budget. What can change is how much you pay to meet them, and how much of it you have to think about.

$163
Per user, per month
24/7
Threat monitoring
Under 2 hrs
First response, business hours
$0
Trip charges

What actually goes wrong in a nonprofit

The people problem

  • Volunteer and staff turnover with no offboarding, so accounts accumulate for years and nobody can say who still has access
  • Shared logins for a front desk, a donation station or a shared inbox, which makes every log useless
  • One person who set everything up and has since left, taking the passwords with them

The money and trust problem

  • A spoofed email from the executive director asking finance to move money, often timed to a board meeting or a campaign
  • Donor records — names, addresses, giving history — in a spreadsheet that has been emailed around
  • A gift processing page or terminal handling card data that nobody has ever assessed
  • A grant or funder questionnaire asking security questions nobody in the building can answer

The reputational maths here is unusual. A business that suffers a breach loses customers. An organisation that exists on trust and voluntary giving can lose the thing that makes it viable.

Where the obligations actually come from

Nonprofits are rarely regulated as an industry, which leads people to assume there is nothing to meet. The obligations arrive by other routes.

Your payment processor

Any organisation that stores, processes or transmits cardholder data falls within the scope of PCI DSS. It is enforced through your acquirer or payment brand agreement rather than by statute, which means the obligation is contractual and real. The cheapest way to meet it is almost always to arrange things so your systems never touch card data at all.

Your funders

Grant agreements and institutional funders increasingly include security and data-handling terms, and questionnaires that expect specific answers. These arrive with a deadline attached and are far easier to answer when the controls already exist.

Your programmes

Organisations running youth, health, housing or counselling programmes hold sensitive personal information about the people they serve, and sometimes fall under sector rules as a result. Faith-based organisations often hold pastoral and safeguarding records with no formal classification at all, which does not make them less sensitive.

Your own promises

Most nonprofits publish a privacy commitment to donors. That is a statement you can be held to, and it is worth knowing whether your systems actually support it.

The controls we run

All included in the monthly rate. The two that matter most for a nonprofit are unglamorous.

Identity and access

  • Multi-factor authentication and identity hardening
  • Named accounts instead of shared logins, so records mean something
  • Access reviewed on a schedule, and a real offboarding step when someone leaves

The human layer

  • Security awareness training and simulated phishing, for staff and volunteers
  • Email security and quarantine, which catches most of the executive-impersonation attempts before anyone sees them

Protection and recovery

  • Managed detection and response, 24/7
  • Backup verification and recovery testing for donor and programme data
  • Patch and vulnerability management, DNS and web filtering, dark web credential monitoring

Getting the budget further

  • Nonprofit pricing and grant programmes from major software vendors change regularly; we track them and pass through what you qualify for
  • Quarterly planning, so capital purchases land in the right fiscal year
  • Audit evidence collection for funder questionnaires

Where our responsibility stops

  • We are not your privacy counsel and we do not determine what your programmes are obliged to do with participant information.
  • We do not assess or certify your PCI compliance. We will help you arrange things so the scope is as small as possible, which is the actually useful move.
  • Your donor database, accounting and programme systems keep their own vendor support. We manage the environment they run in.
  • We do not sell attestations or seals.

What it costs

The same published rates apply, and we do not run a separate nonprofit price list — the published one is already the price. $163 per user, $19 per computer, $100 per server, $17 per mailbox and $179 per additional location, per month, or $199 for a fully equipped seat. No minimum, no setup fee, no automatic annual escalator, so an organisation with eight staff pays for eight. The pricing page has a calculator.

We support organisations across Northeast Ohio and the Greater Houston area. Iconium’s founder serves on local nonprofit boards, which is the main reason this is a category we know rather than a category we list.

Questions nonprofits ask us

There is no minimum here, no seat minimum and no setup fee, so an organisation with eight staff pays for eight. We also do not operate a separate nonprofit rate card, because the published rate is already the rate — you can see it without asking. Where we genuinely save nonprofits money is elsewhere: the nonprofit pricing and grant programmes the major software vendors run, which change often enough that most organisations are either missing them or still assuming an old one applies.

By making offboarding a step rather than an intention. Named accounts instead of shared logins, a documented process when someone leaves, and access reviewed on a schedule so the list is checked by someone rather than accumulating quietly. This is the single most common gap we find in nonprofits and it is also one of the cheapest to close.

Layered, and the last layer is not technical. Email security and quarantine catch most impersonation attempts before anyone sees them. Multi-factor authentication means a stolen password is not enough on its own. Simulated phishing means the person on the receiving end has seen the pattern in a safe setting. Then a callback rule on a known number for any payment change, which we will help you write but your team has to actually follow — and the board should back them when they use it on the director.

You are in scope if your systems store, process or transmit cardholder data. The useful move is to arrange things so they do not: a hosted donation page or a redirect keeps the card data with the processor and keeps your scope as small as it can be. The obligation reaches you through your acquirer or payment brand agreement rather than through a statute, so check what yours says. We help with the arrangement; we do not assess or certify compliance.

We can tell you exactly what is deployed and show the evidence behind each answer, which is the hard part. The form goes in over your organisation’s signature because the funder is contracting with you. Send it over before the deadline rather than the week of it — these questionnaires usually surface one or two things worth fixing first, and a fixed answer is better than an explained one.

Mostly, with one difference worth naming. Congregations hold pastoral, membership and often youth programme records that carry no formal regulatory classification, which sometimes leads to them being treated as less sensitive than they are. A membership directory with addresses and family details is a valuable file, and a safeguarding record is a serious one. The controls are the same; the conversation about what you hold is worth having explicitly.

With an inventory, and without blame — this is extremely common and it is not anyone’s failure. We work out what exists, what it does, who has access and what nobody has the password for. That last category is usually the urgent one. From there it is a prioritised list rather than a rebuild, and most organisations need far less replaced than they fear.

We plan for a clean handover and never withhold data or organisational intellectual property. We work with whoever comes next, including a volunteer, and we hand over documentation rather than a shrug. Onboarding in the other direction takes about a week, with terms of twelve, twenty-four or thirty-six months and no setup fee.

Can you say who still has access to your donor database?

Call (440) 991-9980 or book a thirty minute call. For most organisations that one question opens the whole conversation, and the answer is usually fixable in an afternoon.

See also: every industry we serve and our written answers.