Community organisations rarely see themselves as a cyber target. The mission is to help people, the budget is tight, and IT is whatever keeps the laptops running. Security feels like a corporate concern, something for the businesses you sit alongside rather than for a not-for-profit.
That is exactly why the sector gets caught. Community organisations hold some of the most sensitive data there is, run on volunteers and casual staff who change often, and handle grants and donations that move real money. They also tend to run on ageing equipment and stretched resources, which is precisely the soft target an attacker looks for. If you want the wider picture, start with our guide to IT for community services. Here are the seven gaps we find most often, and the practical fix for each.
Gap 1: Vulnerable Client Data Is Exposed
Community organisations often hold the most sensitive personal information of anyone: case notes, health details, family circumstances, records about people who are already at risk. A breach here is not just a privacy fine, it can put vulnerable clients in real danger.
We routinely find this data spread across spreadsheets, email attachments, and shared drives where far too many people can see it. The fix is to know exactly where client data lives, restrict it to the staff who genuinely need it for their role, and protect those systems properly. The duty of care you have to your clients in person extends to their information, and it deserves the same standard.
Gap 2: Volunteer Access Sprawl
The sector runs on volunteers, and access tends to spread with every new helper who needs to log in to something. Over time, far more people can reach client records, the donation system, or shared drives than anyone realises, and much of it belongs to volunteers who left months or years ago.
Every active login is a potential way in, and a former volunteer’s forgotten account is a quiet one. The fix is to grant access by role, keep it to what each person actually needs, and switch it off promptly when someone stops volunteering. A simple register of who has access to what, reviewed regularly, turns sprawl back into something you control.

Gap 3: Grant and Donation Payment Fraud
Money moves through community organisations in ways attackers love to exploit: grant payments, donor transfers, supplier invoices, and reimbursements, often handled by a small finance team or a single bookkeeper.
An attacker who gets into one mailbox can watch the money flow and then send a request that looks genuine, asking to update bank details before a grant lands or a payment goes out. Because it comes from a real-looking account, it passes the usual checks. The defence is multi-factor authentication on every mailbox to make the break-in harder, plus a firm rule that any change to payment details is confirmed by a phone call to a known number, never by replying to the email.
Gap 4: Ageing, Unpatched Equipment
Tight budgets mean equipment gets kept long past its prime. We often find community organisations running computers on a version of Windows that stopped receiving security updates, or machines that are years behind on patches because money for replacements never quite arrives.
An unsupported or unpatched machine is an open door, because most attacks use a flaw that already had a fix available. The good news is that closing this gap rarely means buying everything new at once. It means actively managing updates on the machines you have, and replacing the few that can no longer be protected, in priority order rather than all at once.
Gap 5: No Multi-Factor Authentication
Almost every organisation has a password on its email and its key systems. Far fewer have a second lock. We regularly find multi-factor authentication switched on for nothing, leaving the accounts that hold client data and control the money protected by a single password that may already have leaked.
Attackers look for the one account with only a password in front of it. The fix is to inventory every system that holds sensitive data or money and turn on a second verification step everywhere, starting with email. It is the single control that blocks most account takeovers, and it costs nothing to switch on in tools you already use.
Gap 6: Untested Backups
Backups are “running”, the dashboard is green, and everyone assumes the client records and case files are safe. Then a device fails or ransomware hits, someone tries to restore, and the files are incomplete, corrupted, or encrypted along with everything else.
For an organisation that holds irreplaceable client histories, this is not a gap you can afford. A backup nobody has restored from is a guess. The fix is to test restores on a schedule and keep at least one copy an attacker cannot alter or delete, so a bad day means a few hours of recovery rather than the permanent loss of records people depend on.
Gap 7: Donated Security Licensing Left Unused
This one is almost unique to the sector, and it is good news. Many community organisations qualify for heavily discounted or donated software through programs for not-for-profits, and a lot of that licensing includes serious security features that are simply never switched on.
We routinely find organisations already paying for, or entitled to, protections like multi-factor authentication, advanced email filtering, and device controls that sit unused because nobody set them up. The fix is the cheapest one on this list: turn on the security you already have access to. Closing this gap is often a configuration job, not a purchase.
Closing the Gaps
None of these are exotic. They are the everyday shortfalls that turn a stretched but well-run organisation into a breach victim, with vulnerable clients paying the price. Most of them are settings you can tighten or protections you already qualify for, not a budget you do not have.
The hard part is knowing which gaps apply to you, because most are invisible until someone looks. That is the value of an honest assessment.
Where to Start
If you recognised your organisation in more than one of these, you are normal, and you are in a good position, because every gap here has a clear fix. The starting point is the same for everyone: get a clear picture, then close the biggest gaps in order.
Our IT maturity assessment takes a few minutes and gives you a plain-English read on where you stand. For the structured version of the basics, it is worth reading what Essential Eight is, the baseline published by the Australian Cyber Security Centre.
We are a Sydney-based team in Bella Vista, and we work with community services organisations across the metro area. We understand tight budgets and a duty of care to vulnerable people, and we help you protect both. Talk to our team when you are ready.