
We take that seriously. Non-profit pricing on the software you're probably already overpaying for, and an honest answer about what you genuinely need versus what would just be nice.Non-Profit IT Assessment
Including if you just want to know what grants and non-profit pricing you qualify for.
We won't sell your data or send you marketing you didn't ask for.
Charities and community organizations we support
Microsoft, Google, and most major vendors run substantial non-profit programmes — including grants of free licensing for eligible registered charities. A great many organizations either don't know, or applied years ago and never revisited it as they grew.
We check your eligibility as part of the initial review. For a lot of the organizations we've worked with, the licensing savings alone cover a meaningful share of what managed IT costs.
Eligibility rules and grant terms change and vary by programme — we'll check your specific situation rather than promise a discount you may not qualify for.
Donor giving histories, beneficiary records, and in many cases information about vulnerable people. A breach here doesn't just cost money — it costs the trust the organization runs on.
Names, addresses, payment details, and giving patterns — attractive to attackers and devastating to leak.
For social services agencies, records about vulnerable individuals — often the most sensitive data any organization holds.
Funder reporting, restricted fund accounting, and audit trails your auditor and funders both rely on.
Including police checks and vulnerable sector screening, which carry their own handling expectations.
Non-profits run on people who join for a season and move on. That's a strength operationally and a genuine weakness in access control — most organizations we audit have active accounts for people who left years ago.For a multi-branch Ontario youth employment charity we connected identity and email to Microsoft 365 with directory sync, so a departure is one action rather than several.
A volunteer coordinator from three years ago still has an active login. Nobody removed it because nobody owned the process.
The reception or info@ account is shared so anyone can cover. Convenient, and it means no action can be attributed to a person.
Volunteers use their own laptops and phones, so organizational data ends up on equipment you have no control over.
The fundraising database lives on a single desktop under someone's desk, backed up to a USB drive when remembered.
The person who knew how everything worked was a long-serving volunteer who has now retired.
Funder reports assembled by hand each cycle, consuming days of staff time that should go to programme delivery.
Set up properly — email, files, Teams, and the security features included in your licence that usually go unused.
A repeatable process so a new volunteer gets the right access in minutes and loses it the day they finish.
Backed up, access-controlled, and moved off that one desktop — with a restore that has actually been tested.
MFA, encryption, and email filtering configured so they protect you without needing someone to administer them daily.
Programme staff working from community sites, homes, and the office with the same access and the same controls.
Automating the repetitive assembly of funder reports and data entry, so staff time goes to the mission instead.
Directors of registered charities carry fiduciary duties, and cyber risk has moved onto board agendas. "Our IT person handles it" is no longer an adequate answer to a governance committee.
Funders are asking too — larger grants increasingly include questions about data protection and continuity planning.When an Ontario member association's single server was crashing daily, we moved the workload onto private cloud and replaced VPN access with Zero Trust.
Something your board can actually read and act on, rather than a technical report nobody discusses.
What happens if systems are unavailable for a week — increasingly a question on larger grant applications.
A record that controls were assessed and implemented, which is what protects directors as much as data.
Risk changes as you grow. A yearly review keeps the board's answer current rather than historical.
NFD runs a community and philanthropy programme, and we sponsor local initiatives each year. If you're running something worthwhile, that conversation is separate from any commercial one.
Yes, and more importantly we check what vendor non-profit pricing and grants you qualify for — which is often worth considerably more than any discount we could give. For several organizations the licensing savings we identified covered a meaningful part of our fee.
It's the defining feature of non-profit IT rather than a complication. The answer is a repeatable onboarding and offboarding process with time-limited access, so high turnover stops being a security problem.
Urgent. A single machine with no tested backup holding your entire fundraising history is one hard drive failure away from a crisis that also damages donor trust. It's usually the first thing we'd address, and it's not expensive to fix.
Sometimes the honest answer is that you should spend on two or three specific things rather than a full managed contract — tested backup, MFA, and claiming your licensing grants. We'll tell you if that's the better use of your money this year.
Yes. Larger grants increasingly ask about data protection, continuity, and security controls. We'll provide the technical answers and the documentation, so the application isn't held up by a section nobody can complete.
Yes — churches, dioceses, and faith-based charities are part of our client base. The needs are similar to other non-profits, with the addition of multi-site coordination and often a large volunteer base.
Tell us what you're running and what you're paying for it. We'll check what non-profit pricing you qualify for and be straight about what you actually need.
We'll reply within one business day.