Cyber Risk & Insurance

The Results

“More than half of non-profits are not confident their cyber security is a well-managed risk”

  • NetHope 2024 Cyber Security Report

The insurance industry agrees! That’s why many cyber-crime insurers no longer offer coverage for non profits or charities!

Nonprofit organizations tend to have less stringent IT security protocols than for-profit businesses and suffer a higher frequency of cyber-crimes and claims. 

Cyber-attacks are the fastest growing crime in the world.  However, many church and charitable organization leaders have a false sense of security in thinking that because they have never experienced a cyber incident, they don’t have to be concerned; or that because they are a non-profit, they’re not a target for cyber-attacks.

However, our experience from working with faith-based charities indicates otherwise.  We continue to see a steadily rising trend in cyber-attacks against non-profits amongst our client organizations.

WHY NON-PROFITS ARE AT RISK?

Non-profits are prime targets because they:
  • Store sensitive data (donors, volunteers, beneficiaries)
  • Transfer or receive funds online
  • Offer online programs or fundraising
  • Have limited IT security budgets

Cyber Coverage 

Cyber Coverage 

Cyber Coverage 

Cyber Coverage 

Cyber Coverage 

TOP 3 CYBER-CRIMES AFFECTING  NONPROFITS.

Following are the three (3) most common cyber incidents suffered among our clients, none of which are covered under a standard property, crime, or liability insurance policy!

What we want to Prevent:

  • Theft or exposure of personal info (PI):  bank data, health info, employment records
  • Each notification can cost $75–$100 per person
  • 500-member data breach = $50,000 in costs
  • Not covered by standard insurance!

Prevent with:

  • Identify and protect PI that you must collect and retain
  • Delete PI that is no longer required
  • Limit or restrict PI posted online
  • Periodic audits and system penetration tests
  • Multi-Factor Authentication (MFA) including for ANY connected devices

What we want to Prevent:

• Malware locks or destroys your data until ransom is paid
• Common entry: phishing emails

Prevent with:

  • Ongoing cyber training
  • Multi-Factor Authentication (MFA)
  • Updated antivirus + secure giving platforms (e.g., Tith.ly, PushPay)

What we want to Prevent:

• Criminals impersonate leaders or vendors to trick staff into sending money
• Often through fake urgent emails or altered invoices

Prevent with:

  • Callback verification for all fund transfers
  • Dual authorization for payments
  • Confirm vendor banking info by phone
  • Train staff to spot red flags

CYBER INSURANCE

OPTIONS

Most general policies exclude cyber-crime coverage.

Specialized Cyber Insurance can protect against:

• Privacy Breach Costs
• Ransomware Attacks
• Social Engineering Fraud
• Data loss & business interruption
Read the Article

Specialized Cyber Insurance also usually includes:

• Cyber breach 24/7 support including proactive advice and training, and professional emergency response team to minimize damage, restore data and systems sooner, and provide advice about privacy notifications required to avoid uninsurable fines and penalties under privacy law.
Read the Article

Example Coverage (Robertson Hall Clients):

• $250K Privacy Breach Liability (included)
• Option to increase up to $1M
• Broader cyber protection available via specialty insurers
Learn More

Cyber risk isn’t about if — it’s about when.
Protect your charity’s mission, reputation, and community trust through proactive training, secure systems, and the right insurance coverage.