Security awareness training for not-for-profits

Why charities and not-for-profits are targeted, the scams NFP teams actually face, and how to run security awareness training on a volunteer budget.

Not-for-profits are targeted for the same reason they succeed: they move money quickly on trust. Grant payments, donations and supplier invoices flow through small teams where the person answering email is often a volunteer or a part-time administrator. The Australian Cyber Security Centre maintains cyber security guidance specifically for charities and not-for-profits, and the ACNC — the national charities regulator — regularly warns registered charities about scams. Awareness training is the control that fits an NFP budget and an NFP threat model.

Key takeaways

Why not-for-profits get targeted

Four characteristics make NFPs attractive to attackers:

The scams your team will actually face

A training program that simulates these exact patterns teaches recognition where it matters. Generic corporate templates train people to spot scams that never arrive.

What to train, and on what cadence

Keep the curriculum short and recurring:

  1. Monthly micro-lessons — 5 to 10 minutes on one topic, rotated through the year: invoice fraud, verification rituals, password and MFA habits, reporting.
  2. Monthly phishing simulations using NFP-realistic templates: grant payment changes, donation receipts, internal requests from named senior staff.
  3. Automatic enrolment for new volunteers and staff in their first week — with volunteer churn, anything manual will miss people.
  4. Immediate refresher on click, delivered privately. Volunteers who feel blamed simply stop reporting.

Cyber Aware's training runs this cycle automatically — lessons, phishing simulations, click-triggered refreshers — and pricing is per seat with no minimum, so a five-person committee and a 200-volunteer organisation each pay only for who they have.

Evidence for boards, auditors and funders

Governance is where training pays a second dividend. Boards, auditors and increasingly funders ask what the organisation does about cyber risk. Human risk reporting answers with numbers rather than assurances: click rate trending down month over month, report rate climbing, completion records for every volunteer and staff member. That pack also satisfies the insurers who now expect training evidence before writing a cyber policy.

FAQ

Is security training worth it for a small charity? The scams that cost NFPs the most — payment diversion, CEO fraud — are stopped by trained people, not by tools a small charity can afford. Training is the highest-leverage control at any budget.

How do you train volunteers who come and go? Automatically: enrol every new volunteer in their first week, keep lessons under ten minutes, and repeat simulations monthly so people who left are replaced by people who are trained.

What does the ACNC expect on cyber security? The ACNC requires registered charities to manage risk responsibly and publishes scam warnings and guidance. Documented, recurring staff training is the most straightforward way to demonstrate that duty is being met.

Related guides

Ready to deploy

Same playbook.
Your brand.

Cyber Aware's Human Risk Score works the same way for every MSP partner - under your brand, on your cadence.