Cybersecurity Checklist for Small NGOs
December 6, 2025
An Indian NGO holds a donor database with bank details, a beneficiary register with names, addresses, photographs and sometimes disability or health information, a finance team's access to a bank account, and a website with an admin panel. Small organisations in this sector are targeted routinely, and mostly they are not targeted by sophisticated attackers. They are targeted by automated scanning that costs an attacker almost nothing and finds whoever left a door open.
None of what follows requires a security specialist or a large budget. It requires a few hours of attention now, and the discipline to do the small things consistently. It is ordered by how long it takes, not by how important it is.
If you do nothing else this week
- Turn on two-factor authentication for your email accounts. Everywhere.
- Stop sharing logins. Shared inboxes only.
- Revoke access for anyone who has left, in every system, not just the one you remember.
- Check who has administrator access to your website and your cloud accounts.
- Back up your donor and beneficiary data, and test that you can restore it.
This week
- Two-factor authentication on email. Your email account is the master key. It contains password resets for everything else, your donor list, and your grant agreements. If you get one thing right this week, make it this. Use an authenticator app rather than SMS where you can.
- One login per person. Shared accounts should exist only for shared inboxes, where the shared address is the point. If your team shares a Gmail login, that login has no accountability and cannot be revoked for one person without revoking it for everyone.
- Your website admin is not the person who built it. Freelancers frequently retain administrator access on sites they built. Ask for it back, or change the credentials so nobody outside your organisation holds them.
- Revoke leaver access. Walk through every system: email, shared workspace, website, payment gateway, cloud storage, your MIS, your bank portal, your social accounts, your domain registrar. People who left in the last two years are the most common finding in audits we run.
- Back up, and verify the backup. A backup you have not restored from is a hope, not a backup. Copy your donor database and beneficiary register to encrypted storage you control, and once actually open the copy to confirm it works.
- Move finance off personal devices. The laptop that does your books should not also be the family laptop, the travel laptop, and the one the treasurer's nephew used once.
This month
- Device encryption and screen locks. FileVault on Mac, BitLocker on Windows, a PIN or biometric on the phone. An unlocked laptop in a taxi is a real risk in a city.
- Know what data you hold and where. One page. Every place you keep personal data about beneficiaries or donors, who has access, and whether it is encrypted. You cannot protect data you have not located.
- A shared password manager. Not a spreadsheet, and not a document called passwords. One vault, individual accounts, shared vaults for the team, and the master account held by two people.
- An incident contact list kept offline. Who to call internally, your bank, your lawyer, your IT person, the CERT-In helpline, your hosting provider. On paper, because you will not have signal during the incident.
- A short breach response note. One page saying what you do in the first hour, the first day, and what you tell people and when. Its main value is that everyone knows it exists, so nobody improvises during the panic.
- Separate the developer access from the owner access. On your website, your payment gateway and your cloud hosting: a day-to-day account and an owner account, with the owner one used rarely.
This quarter
- A quarterly access review. Thirty minutes. Read who has access to what, and remove what is stale. This catches the leaver problem again, four months before you would otherwise notice.
- A device replacement plan. Computers on your team should be four years old or less. Unpatched operating systems are the actual entry point far more often than anything exotic.
- A phishing briefing for staff and volunteers. Ninety minutes. Show real examples: a fake invoice attachment, a "your account will be suspended" SMS, a mail from your own director asking urgently for a bank change. That last one is the one that works, and it works on experienced staff.
- A data retention and deletion rule. Decide how long you keep beneficiary records after a programme closes, who approves deletion, and what happens to photographs. Most organisations have no answer, which usually means data is kept indefinitely.
- A written policy for AI tools. What may and may not be pasted into an AI assistant, at what level of data. Full detail in our post on using AI safely with beneficiary and donor data.
- A periodic restore test. Quarterly. If your backup has never been restored, it is not evidence of anything.
The risks specific to small Indian NGOs
Generic advice assumes a generic organisation. These are the ones we actually see.
| Risk | Likelihood | Cost to fix | Priority |
|---|---|---|---|
| Email account compromised through a phished link | High | Low, one afternoon | Do today |
| Shared login to a drive, bank portal or website admin | High | Low, but needs discipline | Do today |
| Freelancer retaining website or hosting access | High | Low | Do this week |
| Beneficiary data sitting on a personal phone, unencrypted | High | Low | Do this week |
| Access never revoked after someone leaves | Very high | Low | Do this week |
| Beneficiary data pasted into a consumer AI tool | High and rising | Low, a written policy fixes it | Do this month |
| Finance laptop is also the personal laptop | Common | Medium, hardware | This quarter |
| Shared office wifi with everyone on it | Very high | Low | This quarter |
| Cloud subscription renewing silently on one person's card | Common | Low | This quarter |
| No tested backup of donor and beneficiary data | Common | Low | Do today |
| Bank details changed by phone or email request without callback verification | Medium, high impact | Free, a written rule | Do today |
On Indian data protection law
India's Digital Personal Data Protection Act 2023 changed the framework rather than the practice, and its detailed rules have been notified in phases. Two concepts matter more than anything else for a small NGO. You are generally a data fiduciary in respect of the personal data you process, with obligations that include maintaining a record of processing and taking reasonable security safeguards. A vendor that processes personal data on your behalf, such as a CRM or a payment gateway, is generally a data processor, and your contract with them needs to reflect that relationship.
Please confirm the current status and applicability with a lawyer for your organisation rather than taking this paragraph as compliance advice. What is not in doubt is the direction: consent needs to be real and recorded, purpose limitation matters, and reasonable security safeguards are now an explicit expectation rather than good practice. Every item in the checklist above serves one of those three.
Separately, CERT-In has issued directions requiring organisations to report certain incidents within specified timelines and to maintain logs for a set period. Again, confirm the current requirements and your applicability with your own advisors, and note that the practical implication for a small organisation is the same as for a large one: you need to know when an incident happened and what you did about it.
The habit that matters most
None of this works if it lives in a document nobody reads. The organisations that handle this well are not more technical. They have one person, usually not the most senior, whose job includes this list, and a thirty-minute recurring slot in the calendar to work through it.
Everything above is a subset of "look after your access, your devices and your data the way you would look after a locked cupboard of cash". Most small organisations already understand the principle. They have simply not applied it to the files on the laptop.
Want someone to look at where your organisation actually stands? Ask digiSarathi about fractional CTO advisory and audits.