

Cyber security doesn’t have to be complicated. Many successful cyber attacks happen because organisations overlook simple, practical security measures rather than sophisticated technology.
For Australian not-for-profit organisations, protecting donor information, client records, volunteer data and Microsoft 365 environments is essential. Every organisation—whether it has five staff or five hundred—can take practical steps to reduce cyber risk.
At Stuff That Works (STW), we regularly perform cyber security reviews for organisations across Victoria. While every environment is different, the same weaknesses appear time and time again.
This checklist brings together the key areas every not-for-profit should review.
Not-for-profit organisations are increasingly targeted because they often:
A simple checklist helps ensure the basics aren’t overlooked.
☐ Multi-Factor Authentication enabled for every user
☐ Security Defaults or Conditional Access enabled
☐ Administrator accounts reviewed
☐ Legacy authentication disabled
☐ Microsoft Defender configured
☐ Windows updates installed
☐ Third-party software updated
☐ BitLocker enabled
☐ Devices protected with Microsoft Defender
☐ Local administrator access reviewed
☐ Anti-phishing policies enabled
☐ Safe Links configured
☐ Safe Attachments enabled (where licensed)
☐ SPF, DKIM and DMARC configured
☐ Microsoft 365 backup solution implemented
☐ Backup restore testing completed
☐ Backup copies stored separately
☐ Staff complete cyber awareness training
☐ Password manager used
☐ Phishing reporting process documented
☐ Incident Response Plan documented
☐ Disaster Recovery Plan tested
☐ Essential Eight assessment completed
When conducting reviews, we commonly discover:
Many of these can be resolved quickly with the right configuration.
If your organisation is just starting, prioritise these five actions:
These steps significantly reduce the likelihood of a successful cyber attack.
The Australian Cyber Security Centre’s Essential Eight provides a structured framework for improving cyber resilience.
This checklist complements that framework by highlighting practical day-to-day controls that organisations can review regularly.
If you haven’t already read our guide, we recommend starting with:
The Essential Eight Explained for Australian Not-for-Profit Organisations (2026)
To make implementation easier, STW has created a printable checklist that your organisation can use during internal IT reviews.
It can also be used before your annual cyber insurance renewal or technology audit.
Stuff That Works (STW) helps Australian not-for-profit organisations improve cyber security through:
Our goal is to provide practical, cost-effective security solutions that allow organisations to focus on their mission with confidence.
At least every six months, or after any major IT changes.
Yes. It is designed for organisations of all sizes.
Many are included with Microsoft 365 Business Premium, although correct configuration is essential.
Yes. We can perform a cyber security assessment and provide practical recommendations tailored to your organisation.
Cyber security isn’t about achieving perfection—it’s about consistently improving your defences.
By regularly reviewing your systems, training your staff and following recognised frameworks such as the Essential Eight, Australian not-for-profit organisations can significantly reduce cyber risk while making the best use of limited budgets.
Written by Mark Churchward
Director | Stuff That Works (STW)
Mark Churchward is the Director of Stuff That Works (STW), a Melbourne-based Managed IT Services Provider specialising in supporting Australian not-for-profit organisations. With over 20 years of experience in IT, Mark helps charities, NDIS providers, churches and community organisations improve cybersecurity, strengthen Microsoft 365 environments and implement practical technology solutions that support their mission.
His areas of expertise include Microsoft 365, cybersecurity, cloud infrastructure, business continuity, backup and disaster recovery, Microsoft Intune, Microsoft Defender and the Australian Cyber Security Centre’s Essential Eight framework.
