Stuff That Works logo
Stuff That Works logo

Cyber Security Checklist for Australian Not-for-Profit Organisations

Cyber security doesn’t have to be complicated. Many successful cyber attacks happen because organisations overlook simple, practical security measures rather than sophisticated technology.

For Australian not-for-profit organisations, protecting donor information, client records, volunteer data and Microsoft 365 environments is essential. Every organisation—whether it has five staff or five hundred—can take practical steps to reduce cyber risk.

At Stuff That Works (STW), we regularly perform cyber security reviews for organisations across Victoria. While every environment is different, the same weaknesses appear time and time again.

This checklist brings together the key areas every not-for-profit should review.


Why Every Not-for-Profit Needs a Cyber Security Checklist

Not-for-profit organisations are increasingly targeted because they often:

  • Have limited IT resources
  • Manage sensitive personal information
  • Use cloud services extensively
  • Depend on volunteers and casual staff
  • Cannot afford extended downtime

A simple checklist helps ensure the basics aren’t overlooked.


Your 20-Point Cyber Security Checklist

Microsoft 365

☐ Multi-Factor Authentication enabled for every user

☐ Security Defaults or Conditional Access enabled

☐ Administrator accounts reviewed

☐ Legacy authentication disabled

☐ Microsoft Defender configured


Devices

☐ Windows updates installed

☐ Third-party software updated

☐ BitLocker enabled

☐ Devices protected with Microsoft Defender

☐ Local administrator access reviewed


Email Security

☐ Anti-phishing policies enabled

☐ Safe Links configured

☐ Safe Attachments enabled (where licensed)

☐ SPF, DKIM and DMARC configured


Backups

☐ Microsoft 365 backup solution implemented

☐ Backup restore testing completed

☐ Backup copies stored separately


Staff Awareness

☐ Staff complete cyber awareness training

☐ Password manager used

☐ Phishing reporting process documented


Business Continuity

☐ Incident Response Plan documented

☐ Disaster Recovery Plan tested

☐ Essential Eight assessment completed


Common Problems We Find

When conducting reviews, we commonly discover:

  • Administrator accounts without MFA
  • Former employees still enabled
  • Missing Microsoft 365 backups
  • Shared passwords
  • Unsupported Windows devices
  • Unmanaged personal computers
  • Missing Conditional Access policies

Many of these can be resolved quickly with the right configuration.


What Should You Fix First?

If your organisation is just starting, prioritise these five actions:

  1. Enable Multi-Factor Authentication.
  2. Update every computer.
  3. Review administrator accounts.
  4. Verify backups.
  5. Train staff to recognise phishing emails.

These steps significantly reduce the likelihood of a successful cyber attack.


How This Relates to the Essential Eight

The Australian Cyber Security Centre’s Essential Eight provides a structured framework for improving cyber resilience.

This checklist complements that framework by highlighting practical day-to-day controls that organisations can review regularly.

If you haven’t already read our guide, we recommend starting with:

The Essential Eight Explained for Australian Not-for-Profit Organisations (2026)


Download Your Free Checklist

To make implementation easier, STW has created a printable checklist that your organisation can use during internal IT reviews.

It can also be used before your annual cyber insurance renewal or technology audit.


How STW Can Help

Stuff That Works (STW) helps Australian not-for-profit organisations improve cyber security through:

  • Microsoft 365 security reviews
  • Essential Eight assessments
  • Managed IT support
  • Cyber awareness training
  • Backup and disaster recovery
  • Microsoft Intune deployment
  • Microsoft Defender configuration
  • Ongoing cyber security monitoring

Our goal is to provide practical, cost-effective security solutions that allow organisations to focus on their mission with confidence.


Frequently Asked Questions

How often should we complete this checklist?

At least every six months, or after any major IT changes.

Is this checklist suitable for small charities?

Yes. It is designed for organisations of all sizes.

Does Microsoft 365 include these security features?

Many are included with Microsoft 365 Business Premium, although correct configuration is essential.

Can STW perform this review for us?

Yes. We can perform a cyber security assessment and provide practical recommendations tailored to your organisation.


Final Thoughts

Cyber security isn’t about achieving perfection—it’s about consistently improving your defences.

By regularly reviewing your systems, training your staff and following recognised frameworks such as the Essential Eight, Australian not-for-profit organisations can significantly reduce cyber risk while making the best use of limited budgets.

About the Author

Written by Mark Churchward
Director | Stuff That Works (STW)

Mark Churchward is the Director of Stuff That Works (STW), a Melbourne-based Managed IT Services Provider specialising in supporting Australian not-for-profit organisations. With over 20 years of experience in IT, Mark helps charities, NDIS providers, churches and community organisations improve cybersecurity, strengthen Microsoft 365 environments and implement practical technology solutions that support their mission.

His areas of expertise include Microsoft 365, cybersecurity, cloud infrastructure, business continuity, backup and disaster recovery, Microsoft Intune, Microsoft Defender and the Australian Cyber Security Centre’s Essential Eight framework.

Subscribe to our email updates
Melbourne
Office
Suite 16, 476 Canterbury Road
Forest Hill, Victoria 3131
Australia
We acknowledge the Traditional Custodians of the land on which we work and we pay our respects to Elders past and present.
Stuff That Works logo
Copyright © 2026