top of page

8 Steps Every Nonprofit Can Take to Reduce Third-Party Vendor Risk



Third-party vendors are essential to the daily operations of most nonprofits. From payroll and accounting to fundraising platforms, cloud storage, and IT support, these trusted partners help organizations operate more efficiently.

However, every vendor with access to your systems, data, or financial information also introduces potential cyber risk. Criminals increasingly target these relationships through social engineering, phishing, and business email compromise because they know trust is often easier to exploit than technology.

The good news is that a few proactive steps can significantly reduce your organization's exposure.


1. Verify Changes to Payment Instructions


Never rely solely on an email to change banking information or payment instructions. Always verify requests using a trusted phone number or another independent method of communication.


2. Educate and Train Your Employees


Employees are your first line of defense. Regular cybersecurity awareness training helps staff recognize phishing emails, fraudulent vendor requests, and other common social engineering tactics.


3. Limit Vendor Access


Provide vendors with access only to the systems and information necessary to perform their work. Review permissions regularly and immediately remove access when a contract ends.


4. Perform Vendor Due Diligence


Before engaging a vendor, evaluate their cybersecurity practices, ask about their incident response procedures, and confirm they maintain appropriate cyber liability insurance.


5. Review Vendor Contracts


Understand who is responsible if a cyber incident occurs. Pay close attention to indemnification provisions, breach notification requirements, cybersecurity obligations, and insurance requirements.


6. Strengthen Financial Controls


Require dual approval for wire transfers, ACH changes, and other significant financial transactions. Segregating financial responsibilities can prevent a single mistake from becoming a costly loss.


7. Enable Multi-Factor Authentication (MFA)


Require MFA for email accounts, financial platforms, cloud applications, and remote access. This simple control can stop many unauthorized access attempts.


8. Review Your Cyber Insurance Annually


Not all cyber policies provide the same protection. Work with your insurance advisor to review your coverage and confirm it includes protection for social engineering, funds transfer fraud, third-party vendor incidents, ransomware, business interruption, and data breach response.

Cybersecurity is no longer just an IT issue—it's an organizational responsibility. By combining strong internal controls, employee training, careful vendor management, and comprehensive cyber insurance, nonprofits can better protect their finances, operations, and the trust of the communities they serve.

The best time to identify a vulnerability is before it becomes a claim.


If you would like more information or to continue the conversation we are more than happy to.


 
 
 

Comments


bottom of page