Not-for-profits are targeted for the same reason they succeed: they move money quickly on trust. Grant payments, donations and supplier invoices flow through small teams where the person answering email is often a volunteer or a part-time administrator. The Australian Cyber Security Centre maintains cyber security guidance specifically for charities and not-for-profits, and the ACNC — the national charities regulator — regularly warns registered charities about scams. Awareness training is the control that fits an NFP budget and an NFP threat model.
Key takeaways
- The scams that actually hit NFPs are payment diversion on grants and supplier invoices, donation-themed phishing, and payroll changes attributed to senior staff.
- Volunteer turnover means annual training fails by design — training has to reach new people automatically, every month.
- Boards and funders increasingly ask for evidence: completion records, simulation results and reporting satisfy governance without a security team.
- Per-seat pricing with no minimums makes this affordable for teams of any size.
Why not-for-profits get targeted
Four characteristics make NFPs attractive to attackers:
- Money in motion. Grants and donations arrive on deadlines, and urgency is the social engineer's favourite tool. A fake email about changed grant payment details lands at exactly the moment nobody wants to delay.
- Small, rotating teams. Volunteers and casual staff churn through mailboxes without the accumulated suspicion a permanent finance officer builds.
- Valuable data. Donor databases, client records and beneficiary details carry real resale and reputational value — and a charity breach damages donor trust in a way a corporate breach does not.
- Thin IT. Many NFPs run on a part-time IT contractor or an enthusiastic board member, which means the human layer carries more of the defence.
The scams your team will actually face
- Payment diversion. A fake email from a supplier or program manager changes the bank details on an invoice or a grant acquittal. This is the single most expensive scam pattern for small organisations — the ACSC's own charity case studies show losses of $30,000 and more from exactly this pattern.
- Donation-themed phishing. Fake donation receipts, end-of-financial-year tax receipts and payment failure notices, timed to giving seasons when donors expect such emails.
- CEO fraud. An urgent request from the director — gift cards, a quick transfer, staff records — sent while the real director is travelling.
- Payroll and supplier change requests. Especially effective against teams where the person processing the change may be a volunteer.
A training program that simulates these exact patterns teaches recognition where it matters. Generic corporate templates train people to spot scams that never arrive.
What to train, and on what cadence
Keep the curriculum short and recurring:
- Monthly micro-lessons — 5 to 10 minutes on one topic, rotated through the year: invoice fraud, verification rituals, password and MFA habits, reporting.
- Monthly phishing simulations using NFP-realistic templates: grant payment changes, donation receipts, internal requests from named senior staff.
- Automatic enrolment for new volunteers and staff in their first week — with volunteer churn, anything manual will miss people.
- Immediate refresher on click, delivered privately. Volunteers who feel blamed simply stop reporting.
Cyber Aware's training runs this cycle automatically — lessons, phishing simulations, click-triggered refreshers — and pricing is per seat with no minimum, so a five-person committee and a 200-volunteer organisation each pay only for who they have.
Evidence for boards, auditors and funders
Governance is where training pays a second dividend. Boards, auditors and increasingly funders ask what the organisation does about cyber risk. Human risk reporting answers with numbers rather than assurances: click rate trending down month over month, report rate climbing, completion records for every volunteer and staff member. That pack also satisfies the insurers who now expect training evidence before writing a cyber policy.
FAQ
Is security training worth it for a small charity? The scams that cost NFPs the most — payment diversion, CEO fraud — are stopped by trained people, not by tools a small charity can afford. Training is the highest-leverage control at any budget.
How do you train volunteers who come and go? Automatically: enrol every new volunteer in their first week, keep lessons under ten minutes, and repeat simulations monthly so people who left are replaced by people who are trained.
What does the ACNC expect on cyber security? The ACNC requires registered charities to manage risk responsibly and publishes scam warnings and guidance. Documented, recurring staff training is the most straightforward way to demonstrate that duty is being met.