Home  /  Research  /  Doctoral Research
Doctoral Dissertation

Cyberattacks Strategy for Nonprofit Organizations

Design
Qualitative Multiple Case Study
Participants
5 Information System Security Managers
Scope
Maryland · D.C. · Virginia
Analysis
Thematic Analysis
Section 1

Research Problem

General IT problem

Nonprofit organizations regularly face security risks.

Specific IT problem

Some Information System Security Managers (ISSMs) at nonprofit organizations lack strategies to protect against cyberattacks.

Section 2

Purpose & Research Question

The purpose of this qualitative multiple case study was to explore strategies ISSMs at nonprofit organizations employ to protect against cyberattacks.

Research question

What are the strategies that ISSMs at nonprofit organizations employ to protect against cyberattacks?

Section 3

Theoretical Framework

General Systems Theory. The study viewed cybersecurity within the broader organizational system, recognizing the interaction among technology, people, processes, organizational strategy, and external dependencies.

Examining any one of these elements in isolation offers a partial account at best — which is part of why technically sound controls still fail inside real organizations.

Section 4

Methodology & Study Design

Design
Qualitative multiple case study
Participants
5 Information System Security Managers
Geographic scope
Maryland, District of Columbia and Virginia (the DMV region)
Data sources
Semi-structured interviews and archival documents
Analytical approach
Thematic analysis
Section 5

Key Findings

The study identified three core operational pillars essential for organizational protection.

  1. Cybersecurity Awareness

    People remain the operating surface of any security programme. Awareness determines whether controls are used as intended or quietly worked around.

  2. Cybersecurity Strategy

    A deliberate, documented approach rather than accumulated tooling — the difference between defending an organization and reacting to events within it.

  3. Third-Party Dependence

    Nonprofits rely heavily on external providers. That dependence is simultaneously a capability and an exposure, and requires governing as such.

Section 6

Practical Implications

The research provides actionable guidance for enterprise security leaders and nonprofit ISSMs through a four-stage execution framework.

  1. Assess

    Establish the real exposure, the dependencies, and what the organization cannot afford to lose.

  2. Strategize

    Turn that picture into a deliberate, documented approach with defensible priorities.

  3. Build / Acquire

    Develop capability internally or source it deliberately, including the third-party relationships already relied upon.

  4. Educate

    Sustain awareness across the organization so the strategy survives contact with daily operations.

Section 7

Contribution & Social Change

The study documents transferable strategies drawn from practitioners directly responsible for security in nonprofit organizations — a population that holds sensitive data and serves vulnerable people, yet rarely commands the budgets or in-house expertise that enterprises take for granted.

Social change impact. Effective cybersecurity strategies can help nonprofits mitigate and prevent cybersecurity attacks, protect organizational information, and maintain their ability to fulfil their missions without disruption to vital public services.

Section 8

Full Dissertation

Cyberattacks Strategy for Nonprofit Organizations
Walden University · ScholarWorks · Open Access

The complete dissertation is publicly available through Walden University's ScholarWorks repository, including the full literature review, methodology, participant findings and appendices.

Read More

For universities, think tanks and researchers working on cybersecurity, nonprofit resilience or organizational security strategy.

Research Collaboration