Our Cybersecurity Risk Mitigation Recommendations for Nonprofit associations in Ottawa and Throughout Canada
Cybersecurity has traditionally been treated as an IT problem. For associations, that framing no longer holds. A ransomware attack that locks a membership database, a phishing email that authorizes a fraudulent wire transfer, or a breach that exposes donor records is not a server issue. It is a governance issue with legal, financial, and reputational consequences that land squarely with the board.
Boards do not need to become technical experts. They do need to ask the right questions, understand where the organization's actual exposure sits, and make sure management has a credible plan. This guide covers the five areas every association board should be paying attention to.
Questions Boards Should Be Asking
Most board cybersecurity conversations, when they happen at all, stop at "do we have antivirus software." That is not a governance-level question. Boards should be asking things that surface actual risk and accountability:
- Who currently has administrative access to our systems, and when was that access last reviewed?
- What would happen tomorrow if our membership database, email, or financial systems became unavailable?
- Do we have a written incident response plan, and has anyone actually read it?
- What is our cyber insurance policy designed to cover, and has anyone outside IT reviewed it in the past year?
- How would we know if a breach occurred, and how quickly would we find out?
If management cannot answer these clearly and specifically, that is itself the finding. Larger corporations have increasingly embedded cyber risk into board-level strategy with dedicated incident response teams and structured risk quantification. Associations operating with lean staff and volunteer boards are well behind that curve, and the gap is exactly where risk accumulates. This is also where having an IT company for nonprofit associations makes sense. If they understand the realities of nonprofit association governance, these conversations are far easier for a board to have with confidence.
Insurance Considerations
Cyber insurance has become a standard line item for businesses generally, but Canadian small and medium organizations remain significantly underinsured. Only about 12% of Canadian small businesses carry a standalone cyber insurance policy, and broader surveys put overall cyber coverage uptake at just 22%, even though most respondents already understand they could be targeted.
For boards, three things matter more than the premium:
- Coverage gaps are common and often discovered too late. One Canadian nonprofit believed its cyber insurance had no gaps, only to find through a third-party review that the policy excluded phishing, social engineering, and invoice manipulation incidents, which are among the most common ways associations actually get breached.
- Standard business insurance does not cover cyber incidents. Regular liability or property coverage typically does not pay for forensic investigators, legal counsel, breach notification costs, or public relations support after an incident. Standalone cyber policies are built specifically to cover these costs along with income disruption and recovery expenses.
- Basic cyber hygiene is now a condition of coverage, not a suggestion. Insurers increasingly require multi-factor authentication, regular backups, and documented employee training as conditions of the policy. In at least one documented Canadian case, an insurer denied a claim after a major cyberattack because MFA had not been implemented, despite the organization otherwise believing it was covered.
Boards should ask for a plain-language summary of what the policy actually excludes, not just what it covers, and should have that reviewed at renewal every year rather than assuming it still fits. A cyber liability insurance review is a reasonable place to start if your board has never had one done independently.
Ransomware Realities
Ransomware remains the threat most likely to bring association operations to a complete stop, and the trend in Canada is moving in the wrong direction. Among Canadian businesses that report cybersecurity incidents, the share identifying ransomware as the attack method has been climbing, and the Canadian Centre for Cyber Security names ransomware as the top cybercrime threat facing the country's critical infrastructure, a category that increasingly extends to the service providers and supply chains associations depend on.
A few realities boards should sit with:
- Mid-sized organizations are the sweet spot for attackers, not an afterthought. Recent ransomware data shows organizations in the 51 to 200 employee range, with revenue between $5 million and $25 million, absorbed the highest volume of attacks, a profile that describes many associations and the businesses in their membership.
- Recovery costs dwarf the headlines about ransom payments. Total recovery costs tied to cybersecurity incidents in Canada have run into the billions annually, reflecting downtime, emergency IT response, and reputational cleanup that far exceed any ransom figure.
- Paying does not guarantee resolution. A growing share of ransomware groups steal data and threaten to publish it regardless of whether encryption succeeds or a ransom is paid, meaning a clean backup restore no longer fully closes out an incident.
- Tested backups remain the single most reliable defence. Organizations that can restore from isolated, tested backups consistently fare better than those negotiating with an attacker, but a backup that has never been tested is not a real recovery option.
The board's role here is not to manage the technical response. It is to confirm that backups are actually tested on a schedule, and that someone, internally or through an IT partner, owns that responsibility in writing. Where backups live also matters: associations increasingly rely on cloud storage built to support hybrid and remote teams, and that infrastructure needs to be evaluated with backup resilience specifically in mind, not just convenience.
Member Data Protection
Associations hold more sensitive data than many boards realize: membership records, payment information, event registrations, donor histories, and sometimes professional credentials or licensing data.
There is an important legal nuance here that boards should understand clearly. Not-for-profit associations are generally exempt from Canada's federal privacy law (PIPEDA) for activities central to their non-commercial mandate. However, that exemption narrows quickly. The moment an association engages in commercial activity, such as selling sponsorships, processing membership dues as a transaction, running ticketed events, or operating an online store, personal information tied to those activities typically falls back under PIPEDA's protection requirements.
In practice, this means most associations cannot assume they are categorically exempt. Where PIPEDA or a substantially similar provincial law applies:
- Organizations must report breaches that pose a real risk of significant harm to the Office of the Privacy Commissioner and affected individuals, "as soon as feasible."
- Records of every breach, reportable or not, must be retained for 24 months.
- Penalties for failing to report or maintain records can reach $100,000 per violation.
Boards do not need to become privacy lawyers, but they do need a clear answer to one question: which parts of our data and activities fall under PIPEDA or provincial privacy law, and does our breach response plan actually account for that. This is precisely the kind of gap a focused cybersecurity review for associations is designed to catch before it becomes a regulatory problem rather than after.
Incident Response Basics
The biggest gap between organizations that recover quickly from a cyber incident and those that spend months in crisis mode is rarely technology. It is whether a plan existed before the incident happened.
A workable incident response plan does not need to be long. It needs to answer, in advance:
- Who is contacted first internally, and who has authority to make operational decisions during an incident?
- How will staff and board members communicate if email and primary systems are down?
- At what point are legal counsel and the cyber insurance provider notified?
- What is the process for determining whether member or donor data was affected, and who makes that call?
- How and when will members be informed, if notification becomes necessary?
This matters in practice, not just in theory. Among Canadian organizations surveyed about ransomware response, the majority that had an incident response plan and used it during an actual attack restored their systems within a month. Having a plan in place is consistently the difference between a contained incident and a prolonged operational crisis.
A Note on AI and Emerging Risk for Nonprofit Associations in Ottawa and Throughout Canada
One area boards are increasingly being asked about, and one most have not yet addressed formally, is how staff and volunteers are using AI tools. Unsanctioned AI tools used to draft member communications, summarize meeting notes, or process registration data can quietly create new data exposure points outside any policy the board has actually approved. A basic AI governance framework does not need to be restrictive, but it does need to exist, and most associations currently have nothing in writing on this at all.
Your Board's Role Going Forward
None of this requires the board to become technical. It requires the board to treat cybersecurity the way it already treats financial oversight: ask direct questions, expect clear answers, and hold management accountable for closing identified gaps. Cyber risk for associations is not a hypothetical future problem. It is an active and growing one, and the boards that get ahead of it now will spend far less time managing the consequences of not having done so.
Need help keeping your nonprofit association secure against cyber threats? Get in touch with us.

Gabriel Rapacz
He believes IT is ultimately about supporting people, not just technology. Gabriel focuses on making systems approachable and effective for each client and their team, adapting to different levels of comfort and experience.
With a strong interest in cybersecurity, Gabriel stays current on emerging threats and attacker tactics, helping clients stay protected in an evolving landscape.



