SERVING VIRGINIA BEACH, VA ยท NORFOLK ยท CHESAPEAKE ยท TOWN CENTER ยท OCEANFRONT

Nonprofit IT Support in Virginia Beach That Protects Your Mission and Your Funding.

Every dollar lost to downtime or fraud is a dollar taken from your mission. We support Virginia Beach nonprofits with grant-friendly flat rates, Google Ad Grants, TechSoup discounts, and security funders can trust.

15+
YEARS
1,000+
BUSINESSES
<30 min
RESPONSE
4.9★
GOOGLE
  • 24/7 helpdesk & on-site Virginia Beach support
  • Industry compliance handled end to end
  • Vendor & line-of-business app management
  • A dedicated Success Manager who knows your world

Free · Takes 3 minutes · No sales call required

SOUND FAMILIAR?

If Any of These Hit Home, You Are Losing Money Right Now

Every IT Dollar Competes With the Mission

Downtime and overpriced licensing quietly tax your programs — most nonprofits leave thousands in discounts unclaimed.

Your Peers Are Quietly Using AI

Grant drafts in hours, donor insights on demand — Virginia Beach organizations using governed AI stretch lean staff further than any hire.

Donor Data in Public AI Tools

Donor lists and case notes pasted into free chatbots leave your control forever — a trust risk no board would approve.

AI

AI for Nonprofits — Done Safely

Grant drafting, donor insights, and knowledge assistants — with the governance funders expect.

  • AI grant-drafting & writing assistants
  • Donor data insights — governed & private
  • Staff AI policy & training

Book Your Free 15-Minute Strategy Call →

What We Do

Nonprofit IT and Cybersecurity: Nine Services Built Around Mission-First Constraints

Each service addresses a specific threat vector or compliance gap that Hampton Roads nonprofits face. We do not apply a corporate MSP template and bill you for what you cannot use. We build programs around the actual staff count, device inventory, data types, and compliance obligations your organization carries.

Microsoft Defender + DMARC

Business Email Compromise Prevention and Email Security

We deploy SPF, DKIM, and DMARC authentication on your organization’s domain so threat actors cannot send emails that appear to come from your executive director, development officer, or board chair. Microsoft Defender for Office 365 filters phishing emails, malicious attachments, and impersonation attempts before they reach staff inboxes. Multi-factor authentication is enforced on every account that sends financial approvals, wire transfer instructions, or donor acknowledgment communications — the three account types most targeted in nonprofit BEC attacks. For organizations receiving and disbursing grant funds, we implement wire transfer verification workflows that add a secondary confirmation step for any payment over a configurable threshold, breaking the BEC chain at the moment it is most dangerous.

What it prevents: grant disbursement wire fraud, payroll diversion, vendor payment fraud, and the account compromise that enables an attacker to monitor your email for months before striking at the moment a large payment is in motion.

Without it: your executive director’s name and grant programs are documented in public IRS filings. An attacker who has read your 990 can craft a wire transfer request your finance staff has no reason to doubt. DMARC and MFA together stop the majority of BEC attacks before any human judgment is required.

SentinelOne + Tested Backups

Ransomware Protection and Donor Database Recovery

SentinelOne endpoint detection and response monitors every device used to access your donor database, grant management system, client records, and financial files for ransomware behavior — and can isolate a compromised device in seconds before encryption spreads to shared drives and file servers. Immutable, offsite backups of your donor database, grant financial records, client intake files, and organizational data are maintained on a retention schedule appropriate to your federal grant record-keeping requirements (typically three years minimum under 2 CFR Part 200). Backups are tested regularly with documented recovery runs so that “untested backup” does not appear in your incident report. For Hampton Roads nonprofits running Salesforce Nonprofit Success Pack, Bloomerang, DonorPerfect, or similar CRMs, we configure backup coverage that captures the database in a recoverable format — not just the platform’s native export.

What it prevents: ransomware-driven operational shutdown, donor record loss, grant audit failures from missing financial documentation, and the forced choice between paying a ransom and rebuilding years of donor history from paper records.

Without it: the first indication of ransomware is often a staff member calling to say their files look strange. By then, encryption may have reached every shared drive on your network. A tested backup is the difference between a four-hour recovery and a three-week rebuild.

PCI DSS v4.0.1

Online Giving Platform Security and PCI Compliance

We assess the compliance scope of your online giving platform — whether you use a hosted payment page through Stripe, PayPal, Blackbaud, or a similar processor (reducing your scope to SAQ A), or whether your website embeds a payment form directly (expanding scope under SAQ A-EP or SAQ D). Under PCI DSS v4.0.1 Requirement 6.4.3 (mandatory since March 31, 2025), every script on a consumer-facing payment page must be authorized, integrity-verified, and inventoried with documented business justification. Under Req. 11.6.1, a tamper-detection mechanism must alert within seven days of any unauthorized modification to your giving page. We implement both requirements, document the evidence your payment processor requires at annual renewal, and monitor your giving page for script injection attacks that silently exfiltrate donor card data.

What it prevents: payment card skimming attacks that harvest donor card numbers for months before discovery, PCI forensic investigation by card brands, payment processor account suspension, and notification obligations to card-issuing banks covering every donor whose payment was compromised.

Without it: a single unauthorized script on your giving page can silently collect every donor’s payment card data for as long as it remains undetected. PCI DSS v4.0.1 Req. 11.6.1 now requires detection within seven days. Without a monitoring mechanism, you may not know for months.

Microsoft 365 Nonprofit

Microsoft 365 Nonprofit Licensing and Security Configuration

We handle TechSoup nonprofit eligibility verification, Microsoft 365 tenant setup and migration from legacy email platforms, security configuration aligned to the Center for Internet Security (CIS) Microsoft 365 Foundations Benchmark, MFA and conditional access enforcement across all staff and volunteer accounts, SharePoint and Teams configuration for secure document management, and ongoing administration of the Microsoft 365 environment. Microsoft 365 Business Premium through the nonprofit program provides Defender for Business (EDR), Defender for Office 365 (email security), Intune (device management), and Azure AD Premium P1 (MFA and conditional access) — the full enterprise security stack at nonprofit pricing. For Hampton Roads nonprofits that currently operate on Google Workspace, personal email accounts, or outdated on-premises Exchange, the migration to Microsoft 365 Business Premium is typically the single largest security improvement achievable within a nonprofit IT budget.

What it prevents: account compromise from unprotected email, data loss from unmanaged personal devices, compliance gaps from unapproved cloud storage, and the perpetual IT troubleshooting that consumes staff time when technology is patched together from free and donated tools.

Without it: a shared Gmail account and a Google Drive folder are not an IT infrastructure — they are a liability with no access controls, no audit logging, no breach notification capability, and no path to satisfying grantor security requirements or cyber insurance underwriting.

vCISO Advisory

Grantor and Funder Security Requirements Documentation

We review your active grant agreements for security requirements and data protection representations, map your current IT environment against those requirements, identify gaps that create clawback or audit exposure, and produce remediation documentation in the format grantor program officers request during site reviews. Federal grants subject to 2 CFR Part 200 Uniform Guidance require documented financial controls, data retention for three years minimum, and information security practices appropriate to the sensitivity of federal program data. For Virginia state grants administered through DHCD, DMAS, DSS, or DCJS, we identify the applicable data security addenda and build the controls documentation required for contract compliance. For major private foundation funders that include data security representations in grant agreements, we produce a controls attestation package that satisfies the representation without requiring your executive director to have a cybersecurity background.

What it prevents: grant audit failures from undocumented data security practices, clawback demands for undocumented expenditures, and the loss of funder relationships when a data incident reveals that grant-funded data was not protected as the agreement required.

Without it: your grant agreement says you will protect the data. Your IT environment may not support that representation. The gap is invisible until a program officer asks for documentation or an incident triggers an audit.

KnowBe4 + IR Plan

Security Awareness Training and Breach Notification Readiness

Annual security awareness training for all staff and key volunteers through KnowBe4’s nonprofit-accessible training library, with simulated phishing campaigns targeting the social engineering techniques most commonly used against nonprofit staff: executive impersonation BEC, grant-themed phishing, fake donor acknowledgment requests, and Microsoft 365 credential harvesting. Training completion records are documented in a format that satisfies cyber insurance carrier requirements and grantor security expectations. Separately, we build a documented incident response plan and breach notification workflow that covers both Va. Code 18.2-186.6 requirements (notification to affected Virginia residents and the Virginia AG Computer Crime Section without unreasonable delay) and VCDPA obligations for organizations that process data of 100,000 or more consumers. The workflow includes a pre-drafted notification letter template and AG notification package so that if a breach occurs, notification execution begins within hours rather than days.

What it prevents: phishing-driven account compromise, the human error that delivers ransomware, the notification deadline miss that compounds a breach into a regulatory violation, and the reputational damage of an incident handled slowly and poorly.

Without it: a volunteer who clicks a phishing link on a Tuesday afternoon and a breach notification that goes out three months late are both foreseeable outcomes when training and incident response planning are deferred to “when we have time.”

$

Google Ad Grants: $10,000 a Month

We make eligible nonprofits qualify for the Google Ad Grants program: up to $10,000 per month in free Google search advertising to reach donors, volunteers, and program participants. We handle eligibility, account setup, and the compliance rules that keep the grant active.

Money back in your pocket: up to $120,000 a year in advertising your budget never has to cover.

%

TechSoup Software Discounts

We are part of the TechSoup preferred vendor network. We get your organization validated and approved for donated and steeply discounted software: Microsoft 365 nonprofit grants, Adobe, QuickBooks, and more.

Typical savings: 50 to 90 percent off commercial pricing across your software stack.

AI

Knowledge Base & AI Assistants

We build a private, searchable knowledge base for your policies, programs, and procedures, and deploy AI assistants that answer staff and volunteer questions instantly, with your data staying yours.

Why it matters: volunteer and staff turnover stops costing you institutional knowledge.

Who We Serve

Nonprofit IT Support for Every Type of Hampton Roads Organization

Hampton Roads nonprofit sector spans human services, faith communities, arts and culture, advocacy, and grant-funded program delivery. Each vertical has a distinct mix of data types at risk, compliance obligations, staff and volunteer structure, and technology constraints that general-purpose IT providers have not encountered before.

Foundations and Grantmakers

Community Foundations and Private Foundations — Norfolk and Virginia Beach

Hampton Roads community foundations and family foundations manage grant portfolios, donor advised fund records, investment data, and grantee financial reporting that make them high-value BEC targets. An executive director impersonation that redirects a $200,000 grant disbursement wire is operationally possible without a single IT control failure — if email authentication and MFA are not in place. Foundations also hold confidential grantee financial records and donor identity information that trigger Va. Code 18.2-186.6 notification obligations if breached. Capital Techies builds email security, MFA enforcement, and financial workflow verification controls for Hampton Roads foundations that protect the disbursement process without adding administrative friction to grantmaking operations. We also produce the data security documentation that foundation audit committees and independent auditors increasingly request as part of governance reviews.

Human Services and Social Services

Social Service Agencies, Food Banks, and Housing Nonprofits

Hampton Roads social service agencies, food banks, and homeless services organizations hold some of the most sensitive data in the nonprofit sector: Social Security numbers from benefits eligibility screening, domestic violence client location data, child welfare records, and financial account information from emergency assistance programs. A breach of this data creates immediate Va. Code 18.2-186.6 notification obligations and — for organizations receiving federal funding — potential Uniform Guidance compliance failures. These organizations also tend to operate with the leanest IT budgets in the sector, the highest volunteer turnover, and the most inconsistent access control practices. Capital Techies builds IT security programs for Hampton Roads human services organizations that prioritize client data protection, implement the access controls required to limit sensitive record visibility to authorized staff only, and produce the breach notification workflow that can execute within hours of a confirmed incident.

Faith-Based Organizations

Churches, Mosques, Synagogues, and Faith-Based Charities

Faith-based organizations in Hampton Roads face a specific BEC threat pattern: impersonation of the senior pastor, priest, imam, or rabbi to divert online giving receipts, redirect payroll, or authorize fraudulent vendor payments. This attack is effective because congregants and staff have high trust in senior leadership communications, and because faith communities often lack the verification protocols that commercial organizations implement for financial approvals. Online giving platforms used by Hampton Roads faith communities — Planning Center Giving, Pushpay, Realm, Breeze ChMS, and similar tools — all process payment card transactions subject to PCI DSS v4.0.1. Congregant data including giving records, contact information, and pastoral counseling notes can trigger breach notification obligations if exposed. Capital Techies builds email authentication, MFA, and giving platform security programs for Hampton Roads faith-based organizations that respect limited budgets and volunteer-dependent operations while closing the gaps attackers exploit most.

Arts and Cultural Organizations

Arts Organizations, Museums, and Cultural Institutions

Hampton Roads arts organizations, including performing arts companies, museums, galleries, and cultural institutions concentrated in Norfolk’s arts district and Virginia Beach’s cultural corridor, hold donor databases, membership records, online ticketing payment data, and grant financial records that create multiple simultaneous compliance obligations. Online ticket sales and membership payments are subject to PCI DSS v4.0.1. Donor and member PII creates Va. Code 18.2-186.6 notification exposure. Grant financial records must be retained per the terms of NEA, Virginia Commission for the Arts, and private foundation grant agreements. Capital Techies builds IT security programs for Hampton Roads arts organizations that map to the specific platforms you use, the compliance obligations your funding mix creates, and the donor trust your institution depends on for annual support.

Veterans Services Nonprofits

Veterans Service Organizations and Military Family Nonprofits

Hampton Roads hosts one of the densest concentrations of active-duty military, veterans, and military families in the United States, and the nonprofit sector that serves that population — VSOs, transition assistance nonprofits, military family support organizations, and veteran housing programs — handles sensitive data including DD-214 discharge records, VA benefits documentation, mental health service records, and Social Security numbers. Many of these organizations operate programs funded by DoD, VA, and state veteran affairs agencies, creating data security requirements that flow from federal program agreements in addition to Virginia state law. Capital Techies has experience building IT programs for nonprofits serving Hampton Roads’ military and veteran community — including the data protection controls required for VA and DoD-funded programs, and the breach notification workflows that apply when veteran personal information is compromised.

Grant-Funded Nonprofits

Workforce Development, Advocacy, and Multi-Funder Nonprofits

Hampton Roads workforce development nonprofits, policy and advocacy organizations, and multi-funder program nonprofits face a compliance challenge that compounds with each funding source: federal grants bring 2 CFR Part 200 data security requirements, Virginia state contracts bring applicable data security standards for state agency data, private foundations bring individual grant agreement security representations, and the overall organization’s donor database and financial records sit under Va. Code 18.2-186.6. Managing these overlapping requirements with a part-time operations manager and no dedicated IT staff is the standard operating model for most organizations in this category. Capital Techies acts as the fractional IT and compliance function that maps all of these requirements, builds the controls that satisfy the most demanding framework, produces the documentation each funder needs, and maintains the IT program on an ongoing basis so your program staff can focus on the work funders actually funded you to do.

FUNDING & DISCOUNTS

Put Money Back Into Your Mission

Most Virginia Beach nonprofits leave free money on the table. We fix that as part of onboarding.

$10,000/mo
Google Ad Grants eligibility we set up and keep compliant
50–90%
Off software via TechSoup validation and nonprofit grants
$0
Microsoft 365 nonprofit licensing for eligible organizations
Definition

What Nonprofit IT Support Means — and Why It Is Different from Standard Business IT

Nonprofit IT support is managed technology and cybersecurity specifically structured for organizations operating under 501(c)(3) and related tax-exempt status, where technology spending competes directly with mission delivery, volunteer and part-time staff are a significant part of the workforce, donor and grant-funder trust is a primary organizational asset, and compliance obligations span federal grant requirements, state data protection law, and payment card industry standards simultaneously. It is not a discounted version of corporate IT. The threat surface, the data types at risk, the compliance frameworks in play, and the budget constraints are all materially different from what a commercial business faces — and a general-purpose IT provider who has never managed a nonprofit’s grant data, donor database, or online giving platform will not recognize those differences until after something goes wrong.

Why nonprofits are a primary cybercrime target, not a secondary one: The FBI’s 2024 Internet Crime Complaint Center report recorded 859,532 cybercrime complaints nationally with $16.6 billion in total reported losses — a 33% increase in complaint volume from the prior year (FBI IC3 2024 Annual Report, ic3.gov). Nonprofits attract a disproportionate share of business email compromise attacks because the information needed to impersonate nonprofit leadership — executive director names, board composition, grant programs, payment vendors — is publicly disclosed in IRS Form 990 filings that anyone can download from ProPublica or the IRS website. BEC attackers use this public data to craft hyper-targeted impersonation emails that bypass spam filters and fool finance staff who have no reason to distrust an email that references the right grant program, the right vendor, and the right internal contact.

What nonprofit IT support includes: email security and authentication (SPF, DKIM, DMARC) to stop domain spoofing and impersonation; multi-factor authentication on every account that sends financial approvals, wire transfers, or donor communications; endpoint detection and response (EDR) on all staff and volunteer-accessible devices; immutable, tested backups of donor databases, grant financial records, and client files; PCI DSS v4.0.1 compliance for online giving platforms; Microsoft 365 Nonprofit licensing and security configuration; grantor security requirement documentation and compliance evidence; Virginia breach notification readiness under Va. Code 18.2-186.6; and security awareness training sized for staff teams that include part-time employees and rotating volunteers.

What nonprofit IT support is not: a consumer-grade antivirus subscription, a shared password list on a sticky note, a personal email account used for organizational business, or a “HIPAA compliant” cloud storage service that satisfies one compliance checkbox while leaving every other gap open. Many Hampton Roads nonprofits operate with technology that was donated, inherited, or patched together over years of underfunded IT budgets. Capital Techies builds programs that start from where your organization actually is, not from a corporate baseline that your budget cannot reach.

Who this serves in Hampton Roads: the nonprofit sector in Hampton Roads and Virginia Beach spans community foundations, human services organizations, veterans service nonprofits serving the region’s military population, arts and cultural institutions, food banks and hunger-relief organizations, faith-based charities, homeless services providers, workforce development nonprofits, environmental advocacy groups, and grant-funded research and policy organizations. Each has different data types at risk, different compliance obligations, and a different mix of staff, volunteers, and board members with varying levels of technology sophistication. Capital Techies builds IT programs that map to what each organization actually handles — not a one-size-fits-all MSP contract that ignores the nonprofit’s specific operational reality.

Microsoft 365 Nonprofit advantage: Microsoft provides qualifying 501(c)(3) organizations with Microsoft 365 Business Premium at deeply reduced pricing through the Microsoft nonprofit program administered by TechSoup. Business Premium includes Microsoft Defender for Business (endpoint detection and response), Defender for Office 365 (email security, anti-phishing, and safe links), Microsoft Intune (device management and MFA enforcement), and Azure AD Premium P1 (conditional access policies). For a Hampton Roads nonprofit that currently operates on free consumer email and personal devices, transitioning to Microsoft 365 Business Premium through the nonprofit licensing program provides enterprise-grade security capabilities that satisfy cyber insurance requirements, grantor security expectations, and PCI DSS technical controls — at a cost that a mission-driven budget can absorb. Capital Techies handles the TechSoup verification, tenant migration, security configuration, and ongoing administration.

The Numbers

Six Statistics Every Hampton Roads Nonprofit Leader Needs to Understand

Every figure below is sourced and attributable. These are the numbers your executive director, development officer, board treasurer, and major funders need to understand before a cybersecurity incident resets your organizational priorities.

$16.6B
Total reported cybercrime losses nationally in 2024 — a record high, representing a 33% increase in complaint volume over 2023. BEC remains the highest-dollar loss category and nonprofits are among its most targeted victims because grant and donor payment data is publicly disclosed in IRS filings.
Source: FBI IC3 2024 Annual Report, published April 2025 (ic3.gov)

44%
Share of all data breaches in 2025 in which ransomware appeared — up from 32% the prior year, now the most common action type in breaches. For small organizations, the exposure is even higher: ransomware appeared in 88% of breaches at small and mid-size organizations, compared to 39% for large enterprises.
Source: Verizon Data Breach Investigations Report (DBIR) 2025

$1.53M
Average ransomware recovery cost in 2025 excluding any ransom payment. This covers IT recovery, lost productivity, legal fees, notification costs, and reputational remediation. Few Hampton Roads nonprofits carry operating reserves sufficient to absorb a fraction of this figure without interrupting services to the communities they serve.
Source: Sophos State of Ransomware 2025 (published June 2025)

$10.22M
Average cost of a US data breach in 2025 — the highest in the world for the 15th consecutive year. Even a fraction of this figure, applied to a Hampton Roads nonprofit with a $2M annual budget, represents an existential financial event that most organizations could not survive without emergency board intervention.
Source: IBM Cost of a Data Breach Report 2025

$150K
Maximum civil penalty the Virginia Attorney General may seek per breach under Va. Code 18.2-186.6. Nonprofits that hold Social Security numbers, financial account numbers, or payment card data for donors, clients, or program participants are subject to this law — regardless of organizational size or tax-exempt status.
Source: Va. Code 18.2-186.6; Virginia OAG Data Breach Notification Requirements

Mar. 2025
Deadline after which all 51 PCI DSS v4.0.1 previously “best practice” requirements became mandatory — including Req. 6.4.3 (script authorization for payment pages) and Req. 11.6.1 (tamper-detection on giving pages within seven days). Nonprofits accepting online donations must now meet these requirements or risk forensic investigation by card brands.
Source: PCI Security Standards Council; PCI DSS v4.0.1 (pcisecuritystandards.org)

Compliance Frameworks

Compliance Frameworks That Apply to Hampton Roads Nonprofits

Most Hampton Roads nonprofits operate under multiple simultaneous compliance obligations they are not fully aware of. The frameworks below are not optional — they are legal and contractual requirements that flow from accepting donations, holding donor data, processing online payments, and receiving government grants.

Framework Who Needs It What Capital Techies Does Deliverable
PCI DSS v4.0.1 Any Hampton Roads nonprofit that accepts credit or debit card donations online, at events, or through third-party giving platforms (Stripe, PayPal, Blackbaud, Planning Center Giving, Pushpay, Tessitura, and similar). PCI DSS v3.2.1 retired March 31, 2024; v4.0.1 is now the sole active standard. Req. 6.4.3 and 11.6.1 became fully mandatory March 31, 2025. SAQ scope assessment (A vs. A-EP vs. D) based on giving platform architecture; script inventory and authorization under Req. 6.4.3; tamper-detection monitoring on giving page under Req. 11.6.1; MFA implementation for all access to cardholder data; annual SAQ completion and evidence documentation for payment processor renewal Completed SAQ with evidence package, script authorization inventory, tamper-detection monitoring active on giving page, PCI controls evidence folder for processor renewal
IRS Data Safeguard Expectations (IRS Pub. 4557) All nonprofits handling employee payroll data, donor Social Security numbers (in gift acknowledgment or estate planning contexts), Form 1099 vendor payments, or operating VITA volunteer income tax assistance sites. IRS Publication 4557 governs safeguarding of taxpayer information handled by tax professionals and organizations. Data security plan documentation per IRS Pub. 4557 requirements; access controls on systems holding taxpayer information; staff and volunteer training on taxpayer data handling; VITA site security program support including background check tracking and annual training documentation for IRS site authorization Written data security plan per IRS Pub. 4557, VITA site security documentation package, training records for IRS authorization, access control evidence for systems holding taxpayer data
Virginia Breach Notification Law (Va. Code 18.2-186.6) Any Hampton Roads nonprofit that holds computerized personal information of Virginia residents — including donor contact and payment records, client intake files with SSNs or financial account numbers, employee payroll records, or program participant data. Applies regardless of organizational size or tax-exempt status. Civil penalties up to $150,000 per breach. Incident response plan with Virginia-specific notification workflow; pre-drafted notification letter for affected Virginia residents; Virginia AG Computer Crime Section notification package; breach response coordination covering both state notification and any federal program notification requirements simultaneously Incident response plan with dual-track notification workflow, pre-drafted AG notification package, affected individual notification letter template, breach response runbook with notification timeline checklist
Grantor and Funder Security Requirements (2 CFR Part 200 and Grant Agreements) Hampton Roads nonprofits receiving federal grants administered through HHS, HUD, DOJ, USDA, NEA, or other federal agencies; Virginia state grants with data security addenda; and private foundation grants with data security representations in grant agreements. Federal awards of $750,000 or more in a fiscal year trigger Uniform Guidance requirements including data security expectations for federal program information. Grant agreement security requirement review and gap analysis; controls documentation mapped to specific grantor requirements; evidence package for funder site reviews and audits; 2 CFR Part 200 record retention implementation (three-year minimum); data security plan documentation for state and federal program officers Grant security requirements gap analysis, controls evidence folder per grantor, 2 CFR Part 200 compliant record retention configuration, data security plan for federal and state program officer review
Virginia Consumer Data Protection Act (VCDPA) Hampton Roads nonprofits that process personal data of 100,000 or more Virginia consumers in a calendar year, or process data of 25,000 or more consumers and derive more than 50% of gross revenue from data sales. Larger nonprofits with substantial program participant databases, statewide membership rolls, or large donor files may reach the 100,000-consumer threshold. Effective January 1, 2023; enforced by Virginia AG only; no private right of action. VCDPA threshold assessment based on data processing volume; data inventory mapping for consumer data subject to the Act; consumer rights response workflow (access, correction, deletion, portability, opt-out rights with 45-day response timeline); privacy notice review; data processing agreement review for vendors handling in-scope consumer data VCDPA threshold assessment report, data inventory, consumer rights response workflow and templates, privacy notice gap analysis, vendor data processing agreement checklist
Cyber Insurance Requirements Every Hampton Roads nonprofit carrying or seeking cyber liability coverage — or seeking renewal at standard premiums. Carriers now require documented MFA on all email and remote access, EDR on all endpoints, tested and immutable backups, privileged account controls, and security awareness training as conditions of coverage and claim payment. Nonprofits without these controls face coverage denial or substantially higher premiums. MFA implementation and documentation across all accounts; EDR deployment and management (SentinelOne); immutable backup with documented recovery testing; security awareness training records (KnowBe4); privileged access management; patch management documentation — all maintained in a format that survives post-claim carrier audit and satisfies renewal questionnaires Controls attestation package with evidence documentation, renewal-ready questionnaire support for nonprofit-specific cyber insurance applications, gap remediation for coverage requirements before renewal

Free Nonprofit IT Assessment

Find Out Where Your Nonprofit’s IT and Security Program Has Gaps — In 15 Minutes

Most Hampton Roads nonprofits are operating with IT gaps they do not know exist — in email security, donor data protection, online giving compliance, and breach notification readiness. Our free Nonprofit IT Assessment identifies your specific exposure areas and gives you a written summary with no obligation and no sales pressure.

  • 15-minute call with a Capital Techies nonprofit IT advisor, not a salesperson
  • We map your current IT environment against your actual compliance obligations
  • We identify your highest-risk gaps: BEC exposure, donor database security, PCI DSS giving page compliance, grantor requirements
  • You receive a written gap summary whether or not you become a client
  • We help you maximize Microsoft 365 Nonprofit pricing through TechSoup — reducing software costs before you commit to anything
  • No contract required. No sales pressure — ever. Serving all seven cities of Hampton Roads.

Start My Free Nonprofit IT Assessment

For Hampton Roads nonprofits, foundations, social service agencies, faith-based organizations, arts groups, and grant-funded organizations. Response within 30 minutes.













No spam. No contract required. Your information is used only to prepare for your assessment call and is never sold or shared.

Client Feedback

What Our Clients Say

Real reviews from Capital Techies clients on Google.

FAQ

Nonprofit IT and Cybersecurity Questions from Hampton Roads Organizations

Authoritative answers to the questions Hampton Roads nonprofit executive directors, development officers, finance managers, and board members ask most often about cybersecurity, compliance, and managed IT for mission-driven organizations.

What is business email compromise and why are Hampton Roads nonprofits targeted?
Business email compromise (BEC) is a cyberattack in which an attacker either hijacks a legitimate email account or spoofs a trusted sender’s address to trick an employee, volunteer, or board member into wiring money, redirecting a payment, or disclosing sensitive credentials. Nonprofits are attractive BEC targets for three structural reasons. First, they regularly move large sums tied to grant disbursements, donor gifts, and vendor payments — and those wire transfers are time-sensitive, which discourages the verification that might catch a fraudulent request. Second, nonprofit finance and operations are often run by small teams with limited IT oversight, meaning a single compromised account goes undetected longer. Third, the executive director or development officer emails that authorize payments are frequently impersonated because those individuals are publicly named in 990 filings, grant reports, and board rosters available to anyone. Capital Techies deploys email authentication (SPF, DKIM, DMARC), multi-factor authentication on every account that sends or approves wire transfers, and security awareness training specifically designed for nonprofit staff who process grant funds and donor payments.
Does my nonprofit need to be PCI DSS compliant if we accept online donations?
Yes. Any nonprofit that accepts credit or debit card donations online — whether through its own website, a third-party giving platform, or a peer-to-peer fundraising tool — is subject to PCI DSS v4.0.1, the current active standard as of January 2025. The compliance requirements depend on how your donation page is structured. Nonprofits that redirect donors to a hosted payment page (such as Stripe, PayPal, or Blackbaud’s payment portal) have a substantially reduced scope — primarily the SAQ A self-assessment — but are still required to meet PCI DSS requirements for their website environment under Requirement 6.4.3, which mandates that every script running on a consumer-facing payment page must be authorized, integrity-checked, and inventoried. Nonprofits that embed payment forms directly in their websites have a larger compliance scope. Capital Techies assesses which SAQ applies to your giving platform, remediates gaps under Req. 6.4.3 and 11.6.1, and produces the documentation your payment processor or acquirer requires at renewal.
What are grantor and funder IT security requirements and do they apply to us?
Major government and private grantors increasingly require grant recipients to demonstrate baseline cybersecurity controls as a condition of funding or contract renewal. Federal grants administered through agencies such as HHS, HUD, DOJ, and USDA may require compliance with NIST SP 800-171 controls, documented incident response plans, and evidence of data protection practices for any grant-related data handled by the nonprofit. Virginia state grants administered through DHCD, DMAS, or DSS may carry their own data security addenda. If your organization has received federal funding of $750,000 or more in a fiscal year, you are subject to Uniform Guidance (2 CFR Part 200), which includes data security expectations for federal program information. Capital Techies reviews your grant agreements for security requirements, maps your current IT environment against those requirements, and produces a gap remediation plan with documentation that satisfies funder audit requests.
What is Virginia’s breach notification law and what does it mean for a nonprofit that has a data breach?
Virginia Code Section 18.2-186.6 requires any entity — including nonprofits — that owns or licenses computerized personal information of Virginia residents to notify affected individuals and the Virginia Attorney General’s Computer Crime Section without unreasonable delay after a breach of unencrypted personal information. Virginia does not set a fixed number of days — the standard is without unreasonable delay, and the only permitted delay is at law enforcement’s written request when notification would impede a criminal investigation. The AG must be notified for every reportable breach regardless of how many individuals are affected. Civil penalties can reach $150,000 per breach. For a Hampton Roads nonprofit whose donor database, volunteer records, or program participant files include Social Security numbers — common in social service, workforce development, and housing nonprofits — a ransomware incident or BEC attack that exposes those records triggers this law immediately. Capital Techies builds breach notification workflows that produce the required notifications for both affected individuals and the Virginia AG within the required timeframe.
Does the Virginia Consumer Data Protection Act (VCDPA) apply to nonprofits?
The VCDPA, effective January 1, 2023, applies to persons that control or process personal data of at least 100,000 Virginia consumers, or control or process personal data of at least 25,000 consumers and derive more than 50% of gross revenue from the sale of personal data. Most Hampton Roads nonprofits do not sell personal data, so the revenue threshold is rarely triggered. However, larger nonprofits — particularly those with substantial program participant databases, statewide membership rolls, or large donor files — may process personal data of 100,000 or more individuals and would fall within VCDPA scope. Capital Techies assesses whether your nonprofit meets VCDPA thresholds and, where applicable, builds the data inventory and consumer rights response workflow required for compliance.
How does ransomware typically hit a nonprofit and what does recovery actually cost?
Ransomware reaches nonprofit networks through phishing emails that deliver malicious attachments or links, compromised remote access credentials (often from staff or volunteers working from home), and unpatched software vulnerabilities in servers or workstations. Nonprofits face compounding risk factors: high volunteer turnover means credentials are frequently created and rarely deprovisioned; limited IT budgets mean older operating systems and software remain in use longer; and remote and hybrid work arrangements expand the attack surface significantly. According to Sophos State of Ransomware 2025, the average ransomware recovery cost excluding any ransom payment was $1.53 million across all affected organizations. For a Hampton Roads nonprofit, recovery from ransomware without a tested backup means either paying the attacker or attempting to reconstruct donor records, program data, financial histories, and grant documentation from paper — if paper records exist. Capital Techies deploys immutable, tested backups that enable same-day recovery from ransomware without negotiating with an attacker, and endpoint detection that catches ransomware behavior before encryption completes.
What is Microsoft 365 Nonprofit and does Capital Techies help nonprofits get it?
Microsoft 365 Nonprofit is a licensing program that provides qualifying 501(c)(3) organizations with Microsoft 365 Business Premium and related products at steeply discounted or no-cost pricing through Microsoft’s nonprofit eligibility program administered by TechSoup. Business Premium includes Microsoft Defender for Business (endpoint detection and response), Microsoft Intune (device management), Azure Active Directory Premium P1 (multi-factor authentication, conditional access), and Defender for Office 365 (email security and anti-phishing). For a Hampton Roads nonprofit that currently operates on consumer-grade email, shared passwords, and unmanaged personal devices, Microsoft 365 Business Premium through the nonprofit program provides enterprise-grade security at a fraction of the commercial cost. Capital Techies handles the TechSoup eligibility verification, Microsoft 365 tenant setup and migration, security configuration, and ongoing management so nonprofit staff spend their time on mission, not on IT troubleshooting.
What IRS data safeguard expectations apply to nonprofits?
The IRS expects that tax-exempt organizations protect any sensitive tax information, Social Security numbers, and financial data they handle — including donor information used for gift acknowledgment letters, Form 1099 filings for vendors or contractors, payroll records, and W-2 data for employees. IRS Publication 4557, “Safeguarding Taxpayer Data,” provides the framework the IRS uses when evaluating whether an organization has appropriate safeguards for taxpayer information. For nonprofits that prepare tax returns for program participants — such as VITA (Volunteer Income Tax Assistance) sites and financial coaching programs common among Hampton Roads social service nonprofits — the IRS requires a specific data security plan, background checks for volunteers, and annual training on data security practices as conditions of VITA site authorization. Capital Techies builds data protection programs that satisfy IRS safeguard expectations and the state breach notification requirements that arise when payroll or employee benefit data is compromised.
What cyber insurance requirements do nonprofits face and can we actually get coverage?
Cyber insurance carriers have significantly tightened underwriting requirements since 2021, and nonprofits are not exempt from those requirements. Carriers now require documented multi-factor authentication on all email accounts and remote access systems, endpoint detection and response (EDR) on all workstations and servers, tested and immutable backups with documented recovery testing, privileged account controls limiting administrative access, and security awareness training with records of completion — as minimum conditions for coverage and claim payment. Nonprofits that cannot demonstrate these controls face either coverage denial or substantially higher premiums. The same Microsoft 365 Business Premium nonprofit licensing that provides email security and endpoint detection also satisfies most of the technical controls carriers require. Capital Techies has helped Hampton Roads nonprofits reduce insurance premiums by implementing the required controls before renewal — producing the controls documentation in the format carriers need for the renewal questionnaire.
How does Capital Techies price IT services for nonprofits with limited budgets?
Capital Techies structures nonprofit IT engagements around the reality that most nonprofits operate with constrained IT budgets and cannot absorb unpredictable per-incident bills. Our managed IT programs for nonprofits are flat-rate monthly engagements that cover help desk support, Microsoft 365 administration, endpoint monitoring, backup management, and security patching — so your finance team can budget predictably without surprises. We help nonprofits maximize Microsoft’s nonprofit licensing discounts (which can reduce software costs by 75% or more compared to commercial pricing) and apply those savings directly to the managed services budget. For Hampton Roads nonprofits with 10 to 100 staff and volunteers, we size programs that include the security controls required for cyber insurance, grantor compliance, and PCI DSS without the overhead of a full-time IT director. The assessment is free and no contract is required to get a written cost estimate and gap summary.
What happens to donor PII if our nonprofit has a data breach?
A data breach that exposes donor personal information — names, addresses, payment card numbers, Social Security numbers used in gift acknowledgment or estate planning contexts, or bank account numbers from EFT/ACH giving records — creates several simultaneous obligations. Under Virginia Code 18.2-186.6, affected Virginia resident donors must be notified without unreasonable delay, and the Virginia AG must be notified for every reportable breach regardless of size. If payment card numbers were exposed, your PCI DSS obligations require notifying your payment processor and potentially card brands, which may initiate a forensic investigation of your giving platform. The reputational damage to donor trust is the compounding cost that statistics do not capture: major donors who receive a breach notification letter often redirect their giving. Capital Techies builds breach prevention and rapid-response programs so that Hampton Roads nonprofits never have to send that letter.
Do faith-based organizations and churches need cybersecurity the same as other nonprofits?
Yes, and faith-based organizations face a specific threat pattern that makes cybersecurity particularly urgent. Churches, mosques, synagogues, and faith-based charities in Hampton Roads are routinely targeted by BEC attacks that impersonate the senior pastor, executive director, or board chair to redirect online giving receipts, divert payroll, or authorize fraudulent vendor payments. Faith-based organizations typically rely on volunteers for finance and administration, creating gaps in the consistent verification practices that catch BEC before money moves. Online giving platforms used by faith communities — including Planning Center, Pushpay, and Breeze ChMS — require PCI DSS compliance for the card transactions they process. And congregant data including contact information, giving records, and counseling notes can trigger Va. Code 18.2-186.6 notification obligations if breached. Capital Techies builds IT security programs for Hampton Roads faith-based organizations that respect limited budgets while implementing the email authentication, MFA, and endpoint protection that stop the most common attacks before they succeed.
Can you get our nonprofit $10,000 a month in Google Ad Grants?
Yes. We qualify eligible nonprofits for the Google Ad Grants program, up to $10,000 per month in free Google search advertising, and we manage setup and ongoing compliance so the grant stays active. That is up to $120,000 a year back in your mission.
Can you get us discounted nonprofit software?
Yes. We are part of the TechSoup preferred vendor network and get organizations validated for donated and discounted software, including Microsoft 365 nonprofit grants, Adobe, and QuickBooks, typically saving 50 to 90 percent off commercial pricing.

How Exposed Is Your Business Right Now?

Get your free Cyber Risk Score in under 3 minutes. We check for exposed credentials, email spoofing gaps, dark web leaks, and unpatched systems. You get a letter grade and a plain-English report. No sales call required.

Get Your Free Cyber Risk Score →

Free · Takes 3 minutes · No sales call required