A weekend volunteer at your fundraising gala gets a text that looks like it came from your executive director, asking them to quickly buy gift cards for auction winners. Another volunteer plugs a USB drive from home into the front desk PC to print the program. Neither means any harm, and either one can start an incident. That is nonprofit cybersecurity in practice: people come and go, and it is easy to skip the steps you would never skip for staff.
62%
Share of breaches in Verizon’s 2026 Data Breach Investigations Report that involved a human element, such as a mistake, a phishing click or misused credentials
In short
- Mistake one is skipping security training because volunteers aren’t employees or only work a few hours.
- Mistake two is access without control: shared logins, personal USB drives and accounts that never get removed.
- Under HIPAA, volunteers working under your direction count as workforce, so the rules apply to them.
- Individual accounts with MFA, an expiration date and a short onboarding session prevent most problems.
Why volunteers are a nonprofit cybersecurity blind spot
Staff go through onboarding, sign policies and hear regular reminders. Volunteers often get a quick tour and a shared password. They may work sporadically, use their own phones and laptops, and leave without anyone noticing their access is still active. Meanwhile they handle donor names and giving history, payment details at events, client records, children’s information or, in health and human services, patient data. Attackers know nonprofits run lean.
Mistake 1: skipping security training for volunteers
Training someone who works four hours a month can feel like overkill. A phishing message doesn’t care how many hours someone works. If a volunteer has an email address, access to a shared drive or a login to your donor system, they need the basics.

Phishing has moved beyond email, too. Verizon’s 2026 report found that in phishing simulations, people clicked on mobile-based lures such as texts and voice calls at a median rate 40% higher than email lures. Volunteers, who often hear from you by text, are a natural target.
Keep the session short, ideally 15 to 30 minutes, and repeat the key points each season or event. Cover:
- How to spot phishing emails, texts and calls, including messages that impersonate your leaders or board members.
- The rule that nobody at your organization will ask for passwords, gift cards or urgent payments by text or email.
- Who to contact when something looks wrong, and that reporting a mistake quickly is always the right call.
- What donor, client and patient information they can share, where it can be stored, and what never leaves the building.
- Your rules on personal devices and USB drives.
For volunteers who get an organization account, ongoing practice helps more than one session. Our clients run continuous phishing simulations, and anyone who clicks gets a short lesson on the spot, with the result reported to the organization. Our guide to cybersecurity training that works has more.
Mistake 2: giving volunteers access without control
The second mistake is about access, and it usually looks like one of these:
- One shared “volunteer” login, so you can’t tell who did what and the password never changes.
- Too much access, such as an event check-in volunteer who can open the whole donor database or the finance folder.
- Personal USB drives that carry malware in or carry sensitive files out.
- Accounts, shared-folder links and app logins that stay active for years after someone moves on.
How to fix it
- Give each volunteer their own account or guest access, never a shared login, and turn on MFA for every account that can reach email, files or donor and client systems.
- Grant the least access the role needs, using separate folders or Teams channels for volunteer work.
- Share files through the cloud instead of USB drives, and block or restrict USB storage on organization computers where it isn’t needed. In Microsoft 365, administrators can set guest access to SharePoint and OneDrive to expire automatically after a set number of days, and Google Workspace for Nonprofits includes its own security and management controls.
- Offboard every volunteer: disable accounts, remove guest access and change shared passwords when someone leaves, and review all volunteer access at least quarterly. Our offboarding checklist works for volunteers too.
This matters most when an organization grows fast. After Hurricane Ida, we supported a nonprofit’s disaster case management program for 18 months, including devices, systems and onboarding for staff. Programs like that bring people in quickly and see them leave just as quickly, and individual accounts with a clear end date are what keep that turnover from turning into open doors.
Volunteers and compliance
If your organization is a HIPAA covered entity or business associate, such as a community health clinic or a nonprofit that provides services for one, volunteers are no exception. HIPAA defines workforce as employees, volunteers, trainees and others working under your direct control, paid or not. The Security Rule’s requirements apply to them, including security awareness training for all workforce members and procedures to end access when someone’s arrangement with you ends.
Payment card data from events and online donations falls under PCI DSS through your payment processor, so volunteers taking payments should use only approved card readers or forms, never write card numbers down and never store them in spreadsheets. Where no specific law applies, donors still expect careful handling, and a breach can damage trust that took years to build. Our compliance services page explains how these obligations fit together.
A volunteer security checklist
- Short security training completed before access is granted.
- Signed acceptable use and confidentiality agreement on file.
- Individual account or guest access, with MFA, limited to what the role needs.
- Expiration date set on guest access and shared links.
- An approved way to share files, and no personal USB drives on organization computers.
- A clear contact for reporting suspicious messages or mistakes.
- Access removed the day the volunteer’s role ends, and reviewed quarterly.
None of this needs an enterprise budget, and most of it uses tools you already have. If you want help setting up volunteer accounts and a simple way to close them out, book a 20-minute call. We work with nonprofit organizations on exactly this, backed by layered security for your devices and data.
Sources: Verizon 2026 Data Breach Investigations Report; eCFR, 45 CFR 160.103 (HIPAA definitions, workforce); eCFR, 45 CFR 164.308 (HIPAA administrative safeguards); Microsoft Learn, Plan sharing and collaboration options in SharePoint and OneDrive; Google for Nonprofits, Google Workspace for Nonprofits.




