< Back to Thought Leadership

4 Cybersecurity Tips For Not-for-profits On A Budget

by Ashley Jones, CPA, Manager

Following the headlines from any news source these days, it seems that cyber security is just about always trending. While this is not a new topic, with attacks becoming more common, cyber security is something every organization should be seriously addressing.

Not-for-profits need to be prepared as much as any type of business organization. However, we know that budget constraints can make staying protected especially challenging for the not-for-profit world.

Some cost effective solutions for not-for-profits include the following:

Enforce strong passwords for all people accessing systems.

This costs nothing other than some cultural change management. A six-character password that is all lower case letters can be cracked in about two minutes. A 10-character password with upper and lower case, and alpha/numeric characters, would take months to crack.

Get religious about patching your software.

When updates are sent from the vendor, apply them. A majority of these patches are addressing identified security vulnerabilities from the vendor. Don’t let these patches back up.

Train, train, train.

That is, train your employees in the do’s and do not’s of good information handling practices. Do not open emails from suspicious addresses, and especially, never click on suspicious links or attachments. Do not give your password to ANYONE, EVER!

Expand the team.

If possible, add a board member who has strong information technology and cyber security skills who can work with your management team in his/her board capacity to ensure you are doing everything reasonable to protect your information. Use them as a free consultant.

The AICPA has recently released the cybersecurity risk management reporting framework to assist organizations as they communicate relevant and useful information about the effectiveness of their cybersecurity risk management programs.

As a business’s most trusted advisor, the CPA is now getting involved to help clients stay protected and can help by examining and reporting on an organization’s cybersecurity.

Blue & Co. has recently made some big moves to be a resource for our clients in this area. If you have concerns about your entity’s risks and current security situation, please contact your engagement partner or Blue & Co.’s Cybersecurity and Data Management Practice Leader, Tom Skoog at tskoog@blueandco.com.


Read More Thought Leadership Articles Like what you read? Subscribe to our newsletter. Click Here.


Blue & Co., LLC Announces New Partnership With Vsimple | Vsimple and Blue and Co logo

Blue & Co., LLC Announces New Partnership With Vsimple

CARMEL, Ind. (May 5, 2022) – Blue & Co., LLC is excited to announce our new partnership with Vsimple, a workflow management software company based in New Albany, IN.  Blue & Co and Vsimple will be working closely together to address the workflow and process improvement challenges of manufacturers throughout the Midwest. “At Blue & […]

Learn More
Proposed Rule FY 2023 for Skilled Nursing Facilities

Proposed Rule FY 2023 for Skilled Nursing Facilities

It is that time of year again! The Center for Medicare and Medicaid Services (CMS) has issued the proposed rule that would update Medicare payment policies and rates for the fiscal year (FY) 2023’s Skilled Nursing Facility (SNF) Prospective Payment System (PPS). The Patient Driven Payment Model (PDPM) was implemented on October 1, 2019. This […]

Learn More
Coverage Scheduling Solutions for Physician Practices and Hospital Systems

Scheduling Solutions for Clinician Work-Life Balance

One of the most challenging conversations in any multi-physician practice or specialty-based hospital employed group is about how to create a fair distribution of on-call and/or inpatient hospital service coverage while balancing the duties of an outpatient practice. The COVID-19 pandemic has contributed to clinician burnout, and physicians and Advanced Practice Providers (APPs) place significant […]

Learn More