Each service addresses a specific threat vector or compliance gap that Hampton Roads nonprofits face. We do not apply a corporate MSP template and bill you for what you cannot use. We build programs around the actual staff count, device inventory, data types, and compliance obligations your organization carries.
Microsoft Defender + DMARC
Business Email Compromise Prevention and Email Security
We deploy SPF, DKIM, and DMARC authentication on your organization’s domain so threat actors cannot send emails that appear to come from your executive director, development officer, or board chair. Microsoft Defender for Office 365 filters phishing emails, malicious attachments, and impersonation attempts before they reach staff inboxes. Multi-factor authentication is enforced on every account that sends financial approvals, wire transfer instructions, or donor acknowledgment communications — the three account types most targeted in nonprofit BEC attacks. For organizations receiving and disbursing grant funds, we implement wire transfer verification workflows that add a secondary confirmation step for any payment over a configurable threshold, breaking the BEC chain at the moment it is most dangerous.
What it prevents: grant disbursement wire fraud, payroll diversion, vendor payment fraud, and the account compromise that enables an attacker to monitor your email for months before striking at the moment a large payment is in motion.
Without it: your executive director’s name and grant programs are documented in public IRS filings. An attacker who has read your 990 can craft a wire transfer request your finance staff has no reason to doubt. DMARC and MFA together stop the majority of BEC attacks before any human judgment is required.
SentinelOne + Tested Backups
Ransomware Protection and Donor Database Recovery
SentinelOne endpoint detection and response monitors every device used to access your donor database, grant management system, client records, and financial files for ransomware behavior — and can isolate a compromised device in seconds before encryption spreads to shared drives and file servers. Immutable, offsite backups of your donor database, grant financial records, client intake files, and organizational data are maintained on a retention schedule appropriate to your federal grant record-keeping requirements (typically three years minimum under 2 CFR Part 200). Backups are tested regularly with documented recovery runs so that “untested backup” does not appear in your incident report. For Hampton Roads nonprofits running Salesforce Nonprofit Success Pack, Bloomerang, DonorPerfect, or similar CRMs, we configure backup coverage that captures the database in a recoverable format — not just the platform’s native export.
What it prevents: ransomware-driven operational shutdown, donor record loss, grant audit failures from missing financial documentation, and the forced choice between paying a ransom and rebuilding years of donor history from paper records.
Without it: the first indication of ransomware is often a staff member calling to say their files look strange. By then, encryption may have reached every shared drive on your network. A tested backup is the difference between a four-hour recovery and a three-week rebuild.
PCI DSS v4.0.1
Online Giving Platform Security and PCI Compliance
We assess the compliance scope of your online giving platform — whether you use a hosted payment page through Stripe, PayPal, Blackbaud, or a similar processor (reducing your scope to SAQ A), or whether your website embeds a payment form directly (expanding scope under SAQ A-EP or SAQ D). Under PCI DSS v4.0.1 Requirement 6.4.3 (mandatory since March 31, 2025), every script on a consumer-facing payment page must be authorized, integrity-verified, and inventoried with documented business justification. Under Req. 11.6.1, a tamper-detection mechanism must alert within seven days of any unauthorized modification to your giving page. We implement both requirements, document the evidence your payment processor requires at annual renewal, and monitor your giving page for script injection attacks that silently exfiltrate donor card data.
What it prevents: payment card skimming attacks that harvest donor card numbers for months before discovery, PCI forensic investigation by card brands, payment processor account suspension, and notification obligations to card-issuing banks covering every donor whose payment was compromised.
Without it: a single unauthorized script on your giving page can silently collect every donor’s payment card data for as long as it remains undetected. PCI DSS v4.0.1 Req. 11.6.1 now requires detection within seven days. Without a monitoring mechanism, you may not know for months.
Microsoft 365 Nonprofit
Microsoft 365 Nonprofit Licensing and Security Configuration
We handle TechSoup nonprofit eligibility verification, Microsoft 365 tenant setup and migration from legacy email platforms, security configuration aligned to the Center for Internet Security (CIS) Microsoft 365 Foundations Benchmark, MFA and conditional access enforcement across all staff and volunteer accounts, SharePoint and Teams configuration for secure document management, and ongoing administration of the Microsoft 365 environment. Microsoft 365 Business Premium through the nonprofit program provides Defender for Business (EDR), Defender for Office 365 (email security), Intune (device management), and Azure AD Premium P1 (MFA and conditional access) — the full enterprise security stack at nonprofit pricing. For Hampton Roads nonprofits that currently operate on Google Workspace, personal email accounts, or outdated on-premises Exchange, the migration to Microsoft 365 Business Premium is typically the single largest security improvement achievable within a nonprofit IT budget.
What it prevents: account compromise from unprotected email, data loss from unmanaged personal devices, compliance gaps from unapproved cloud storage, and the perpetual IT troubleshooting that consumes staff time when technology is patched together from free and donated tools.
Without it: a shared Gmail account and a Google Drive folder are not an IT infrastructure — they are a liability with no access controls, no audit logging, no breach notification capability, and no path to satisfying grantor security requirements or cyber insurance underwriting.
vCISO Advisory
Grantor and Funder Security Requirements Documentation
We review your active grant agreements for security requirements and data protection representations, map your current IT environment against those requirements, identify gaps that create clawback or audit exposure, and produce remediation documentation in the format grantor program officers request during site reviews. Federal grants subject to 2 CFR Part 200 Uniform Guidance require documented financial controls, data retention for three years minimum, and information security practices appropriate to the sensitivity of federal program data. For Virginia state grants administered through DHCD, DMAS, DSS, or DCJS, we identify the applicable data security addenda and build the controls documentation required for contract compliance. For major private foundation funders that include data security representations in grant agreements, we produce a controls attestation package that satisfies the representation without requiring your executive director to have a cybersecurity background.
What it prevents: grant audit failures from undocumented data security practices, clawback demands for undocumented expenditures, and the loss of funder relationships when a data incident reveals that grant-funded data was not protected as the agreement required.
Without it: your grant agreement says you will protect the data. Your IT environment may not support that representation. The gap is invisible until a program officer asks for documentation or an incident triggers an audit.
KnowBe4 + IR Plan
Security Awareness Training and Breach Notification Readiness
Annual security awareness training for all staff and key volunteers through KnowBe4’s nonprofit-accessible training library, with simulated phishing campaigns targeting the social engineering techniques most commonly used against nonprofit staff: executive impersonation BEC, grant-themed phishing, fake donor acknowledgment requests, and Microsoft 365 credential harvesting. Training completion records are documented in a format that satisfies cyber insurance carrier requirements and grantor security expectations. Separately, we build a documented incident response plan and breach notification workflow that covers both Va. Code 18.2-186.6 requirements (notification to affected Virginia residents and the Virginia AG Computer Crime Section without unreasonable delay) and VCDPA obligations for organizations that process data of 100,000 or more consumers. The workflow includes a pre-drafted notification letter template and AG notification package so that if a breach occurs, notification execution begins within hours rather than days.
What it prevents: phishing-driven account compromise, the human error that delivers ransomware, the notification deadline miss that compounds a breach into a regulatory violation, and the reputational damage of an incident handled slowly and poorly.
Without it: a volunteer who clicks a phishing link on a Tuesday afternoon and a breach notification that goes out three months late are both foreseeable outcomes when training and incident response planning are deferred to “when we have time.”
$
Google Ad Grants: $10,000 a Month
We make eligible nonprofits qualify for the Google Ad Grants program: up to $10,000 per month in free Google search advertising to reach donors, volunteers, and program participants. We handle eligibility, account setup, and the compliance rules that keep the grant active.
Money back in your pocket: up to $120,000 a year in advertising your budget never has to cover.
%
TechSoup Software Discounts
We are part of the TechSoup preferred vendor network. We get your organization validated and approved for donated and steeply discounted software: Microsoft 365 nonprofit grants, Adobe, QuickBooks, and more.
Typical savings: 50 to 90 percent off commercial pricing across your software stack.
AI
Knowledge Base & AI Assistants
We build a private, searchable knowledge base for your policies, programs, and procedures, and deploy AI assistants that answer staff and volunteer questions instantly, with your data staying yours.
Why it matters: volunteer and staff turnover stops costing you institutional knowledge.