

Cyber security isn’t just an IT issue anymore—it’s a business risk. For Australian not-for-profit organisations, a cyber incident can disrupt services, expose donor information, affect funding, and damage trust with the communities you support.
Many charities assume they’re “too small” to be targeted. Unfortunately, that’s not how cybercriminals operate. Automated attacks constantly scan the internet looking for vulnerable organisations, regardless of size.
At STW, we’ve found that the organisations with the strongest security aren’t necessarily the ones spending the most—they’re the ones following a structured approach. One of the best frameworks available is the Australian Cyber Security Centre’s Essential Eight.
The Essential Eight is a set of eight practical security strategies developed by the Australian Cyber Security Centre (ACSC). They are designed to help organisations reduce the risk of cyber attacks and recover more effectively if an incident occurs.
The eight strategies are:
You don’t need to implement everything overnight. Even improving a few areas can significantly reduce your cyber risk.
Not-for-profit organisations often manage sensitive information, including:
A successful cyber attack can result in:
For many organisations, maintaining trust is just as important as protecting data.
Outdated software is one of the easiest ways for attackers to gain access.
Ensure that:
Automated patch management can greatly reduce the workload.
Passwords alone are no longer enough.
MFA adds a second layer of protection by requiring a code from an authenticator app, hardware key, or trusted device.
Every organisation should enable MFA for:
Not every staff member needs administrator rights.
Using separate administrator accounts and applying the principle of least privilege helps prevent malware from spreading if a user account is compromised.
Backups are your safety net.
Good backups should be:
Remember: a backup is only useful if it can be restored successfully.
Microsoft 365 is the primary platform for many Australian charities, making it a common target.
Important security measures include:
Technology alone won’t stop every attack.
Regular cyber awareness training helps staff recognise:
Building a culture where staff report suspicious activity without fear of blame is one of the most effective defences.
If you’re unsure of your current security posture, begin with a simple assessment:
If the answer is “no” to several of these questions, those areas are good starting points.
At STW, we work with Australian not-for-profit organisations to strengthen their cyber security using practical, cost-effective solutions.
Our approach includes:
Rather than implementing technology for its own sake, we focus on solutions that suit each organisation’s size, budget, and operational needs.
Cyber security doesn’t have to be overwhelming. By following the Essential Eight, not-for-profit organisations can make meaningful improvements that reduce risk and improve resilience.
Whether your organisation has five staff or several hundred, taking steady, practical steps today can help protect your people, your data, and the communities you serve.
If you’d like to understand how your organisation compares against the Essential Eight, STW can help assess your current environment and recommend practical improvements based on your goals and budget.
Written by Mark Churchward
Director, STW
20+ years helping Victorian organisations with Microsoft 365, cybersecurity, and managed IT.
Stuff That Works (STW) is a Melbourne-based Managed IT Services Provider specialising in supporting Australian not-for-profit organisations. We help charities, churches, community organisations and NDIS providers with Microsoft 365, cyber security, managed IT support, cloud solutions and business continuity.
Need help improving your cyber security?
Contact STW for an Essential Eight assessment and practical recommendations tailored to your organisation.
