Cyberattacks Strategy for Nonprofit Organizations
Dr. Yawo O. Kondo, DIT — Doctor of Information Technology
Research Problem
Nonprofit organizations regularly face security risks.
Some Information System Security Managers (ISSMs) at nonprofit organizations lack strategies to protect against cyberattacks.
Purpose & Research Question
The purpose of this qualitative multiple case study was to explore strategies ISSMs at nonprofit organizations employ to protect against cyberattacks.
What are the strategies that ISSMs at nonprofit organizations employ to protect against cyberattacks?
Theoretical Framework
General Systems Theory. The study viewed cybersecurity within the broader organizational system, recognizing the interaction among technology, people, processes, organizational strategy, and external dependencies.
Examining any one of these elements in isolation offers a partial account at best — which is part of why technically sound controls still fail inside real organizations.
Methodology & Study Design
Key Findings
The study identified three core operational pillars essential for organizational protection.
-
Cybersecurity Awareness
People remain the operating surface of any security programme. Awareness determines whether controls are used as intended or quietly worked around.
-
Cybersecurity Strategy
A deliberate, documented approach rather than accumulated tooling — the difference between defending an organization and reacting to events within it.
-
Third-Party Dependence
Nonprofits rely heavily on external providers. That dependence is simultaneously a capability and an exposure, and requires governing as such.
Practical Implications
The research provides actionable guidance for enterprise security leaders and nonprofit ISSMs through a four-stage execution framework.
-
Assess
Establish the real exposure, the dependencies, and what the organization cannot afford to lose.
-
Strategize
Turn that picture into a deliberate, documented approach with defensible priorities.
-
Build / Acquire
Develop capability internally or source it deliberately, including the third-party relationships already relied upon.
-
Educate
Sustain awareness across the organization so the strategy survives contact with daily operations.
Contribution & Social Change
The study documents transferable strategies drawn from practitioners directly responsible for security in nonprofit organizations — a population that holds sensitive data and serves vulnerable people, yet rarely commands the budgets or in-house expertise that enterprises take for granted.
Social change impact. Effective cybersecurity strategies can help nonprofits mitigate and prevent cybersecurity attacks, protect organizational information, and maintain their ability to fulfil their missions without disruption to vital public services.
Full Dissertation
The complete dissertation is publicly available through Walden University's ScholarWorks repository, including the full literature review, methodology, participant findings and appendices.
Read MoreDerived Publications
For universities, think tanks and researchers working on cybersecurity, nonprofit resilience or organizational security strategy.
Research Collaboration