Skip to main content

Security Awareness Training for Non-Profit

Interactive simulations for non-profit staff, volunteers, and distributed teams. Donor-fund BEC, gift-card fraud, ransomware on small NGOs, and phishing for donor-database credentials, calibrated for budget-constrained workforces that carry outsized donor trust.

Why Non-Profits Carry Donor Trust That Attackers Target

Non-profits hold something attackers want and something funders watch closely: donor trust. The 2020 Blackbaud ransomware incident exposed donor records at thousands of charities, museums, and universities, and the reputational fallout reached every annual report and grant application that followed. Attackers continue to target the year-end giving rush, disaster-response drives, and any moment when donations spike and staff are stretched thin.

Most non-profits operate as PCI Level 4 merchants for online donations, hold international donor data subject to GDPR, and sit under state charity registration rules that increasingly require breach notification. Major foundations such as Gates and Ford explicitly include donor-data confidentiality clauses in grant agreements. The training expectation is real even when the budget is not.

RansomLeak delivers training that fits the realities of distributed, volunteer-supported, often-underfunded teams. Interactive 3D simulations rehearse the decisions that protect donor trust: refusing a gift-card request from a "CEO," verifying a vendor invoice change before redirecting funds, recognizing a phishing email targeting your CRM credentials, and reporting a suspected breach within state notification windows.

Non-Profit-Specific Threat Patterns

1

Donor-fund BEC and wire redirection

Attackers monitor public foundation directories and impersonate executive directors during year-end giving and disaster drives. A single redirected wire can wipe out a quarterly fundraising goal. Finance and development staff need scenario practice, not generic anti-phishing reminders.

2

Gift-card scams against junior staff and volunteers

A "quick favor" text from the executive director asking for Amazon or Apple gift cards is one of the highest-volume frauds against non-profits. Junior staff and volunteers who rarely interact with leadership are common targets and need explicit refusal patterns.

3

Vendor invoice fraud against thin AP teams

Many non-profits run accounts payable with one or two staff and limited segregation of duties. Attackers compromise vendor mailboxes and submit changed banking details. Training rehearses out-of-band verification before any banking change.

4

Phishing for donor-database credentials

Blackbaud, Salesforce NPSP, Bloomerang, and Donor Perfect logins are high-value targets. A compromised CRM session can exfiltrate donor records, payment instruments, and pledge schedules. Development staff need MFA discipline and phishing literacy.

5

Ransomware on small NGOs with thin backups

Small non-profits frequently run unmaintained backups on the same network as production. Ransomware that encrypts both ends grant cycles and donor outreach for weeks. Workforce reporting culture is often the only early warning.

Compliance Frameworks This Page Covers

Mapping to the regulations that drive most non-profit buying decisions.

PCI DSS for online donations

Most non-profits accepting online donations qualify as PCI Level 4 merchants. PCI DSS Requirement 12.6 calls for a formal security awareness program with documented training for all staff with access to cardholder data.

Read the article

GDPR for international donor data

Non-profits with EU donors are GDPR controllers. Article 32 (security of processing) and Article 39 (DPO duties) flow into staff training expectations, especially around DSAR handling and breach notification.

Read the article

State breach-notification laws

All 50 US states have breach-notification statutes, and non-profits are not exempt. Several states layer charity-registration data privacy expectations on top. Training drives correct, timely incident reporting.

Funder and grant data clauses

Major foundations such as Gates, Ford, and MacArthur include donor-data confidentiality and breach-notification clauses in grant agreements. Funders increasingly request training evidence at renewal.

IRS rules for fundraising data

IRS Form 990 and related guidance push non-profits toward documented data-handling practices. Workforce awareness training is the foundation that makes those practices stick.

Threats this program covers

Read the pillar guide for each attack type and the exercises that train against it.

Frequently Asked Questions

Do you offer non-profit pricing?

Yes. RansomLeak offers discounted pricing for registered 501(c)(3) and equivalent international non-profit entities. Volunteer seats are accommodated separately so you only pay for staff and active long-term volunteers, not every one-day event helper.

How does this help during year-end giving?

Year-end giving is peak BEC season. Attackers know finance and development teams are stretched and impersonate executives, vendors, and major donors. The BEC exercise rehearses the wire-verification discipline that protects December and January receipts.

Can volunteers complete the training?

Yes. SCORM packages run in any LMS, and the standalone cloud platform supports volunteer accounts with reduced-friction onboarding. Volunteer-specific assignments cover gift-card scams, social engineering, and basic phishing without requiring the full staff curriculum.

How does this satisfy grant-agreement training clauses?

Grant agreements from Gates, Ford, MacArthur, and similar funders frequently require documented training. RansomLeak supplies per-employee completion records, scores, and topic coverage maps in formats funders accept at renewal and audit.

What about international donor data and GDPR?

Non-profits with EU donors are GDPR controllers. The catalogue covers GDPR breach response, DSAR handling, cross-border transfer awareness, and consent management. Audit evidence maps to Article 32 and Article 39 expectations.

Does it integrate with our LMS?

Every exercise exports as SCORM 1.2 and 2004 packages, tested with 50+ LMSes including Cornerstone, Workday, Moodle, Canvas, and the LMS modules in Salesforce NPSP. For non-profits without an LMS, the standalone cloud platform offers SSO, MFA, and audit-ready reporting.

How often should non-profit staff and volunteers run training?

PCI DSS Requirement 12.6 calls for at-hire training plus annual refresh. Most non-profits run a full refresh once per year plus short micro-modules ahead of peak fundraising windows and after public incident bulletins. RansomLeak supports both rhythms.

See RansomLeak in Action

Try the free exercises or book a demo to see analytics, SCORM export, SSO, and custom content in your environment.