Attackers do not discriminate by mission. They target vulnerability.
Nonprofit organizations occupy a unique position: deeply trusted by the communities they serve, holding extraordinarily sensitive data, and defended by budgets and teams a fraction of the size their exposure warrants. Healthcare nonprofits hold protected health information. Social service organizations hold Social Security numbers, housing histories and immigration status. Advocacy groups hold the identities of people who could face serious consequences if their affiliations became public. Donor databases hold financial records for hundreds of thousands of individuals.
The persistent belief that charitable organizations are too small to be targeted is not just incorrect — it is precisely the assumption attackers rely on.
What this book is
Cybersecurity Strategy & Risk Management grew directly out of Dr. Yawo O. Kondo’s doctoral research into the strategies Information System Security Managers at nonprofit organizations use to defend against cyberattacks. It carries that research into practice, written for people who have to make decisions rather than cite literature.
Every recommendation is made with constraint in view: volunteer-driven governance, legacy technology, competing priorities, and the reality that security often feels like a luxury rather than a necessity.
What it covers
Part I — The Nonprofit Under Siege Why nonprofits are prime targets · Mapping the threat landscape · The regulatory and compliance landscape
Part II — Governance and Risk Cybersecurity governance for nonprofits · Risk management frameworks · Security architecture on a budget
Part III — Protecting Data and Access Data protection and privacy · Identity and access management · Endpoint and network security
Part IV — When Prevention Fails Building an incident response capability · Ransomware response and cyber insurance · Business continuity and disaster recovery
Part V — The Human Layer Security awareness training · Insider threats and privileged user management · Third-party and vendor risk management
Part VI — Building Forward Building your cybersecurity roadmap · Securing funding for cybersecurity · The future of nonprofit cybersecurity
Working appendices
- NIST Cybersecurity Framework reference
- Sample incident response plan
- Core security policy templates
- Cybersecurity assessment instrument
- Free and low-cost security tooling
- Glossary of key terms
Who it is for
Nonprofit executives and executive directors · Board members with fiduciary responsibility · IT and security staff at mission-driven organizations · Grantmakers assessing organizational risk · Consultants and advisors serving the nonprofit sector
Details
194 pages · First Edition, 2026 · Lausey Technology Press ISBN (eBook/PDF) 979-8-9968055-4-9 · ISBN (Paperback) 979-8-9968055-7-0
Delivered instantly via BookFunnel to your preferred device or reading app.




Reviews
There are no reviews yet.