Employee Owned Since 2022  |  Serving Chicagoland since 1996Support: 630-523-0220Sales: 630-526-8030Remote support

Cybersecurity whitepaper | Non Profit Organizations

Security Awareness Training for Staff and Volunteers

Build safe habits across staff, volunteers, and board members without overwhelming anyone

  • Published September 25, 2026
  • 4 min read

Most cyberattacks on nonprofits start with a person, not a machine. A convincing email, a fake login page, or a phone call can get past the best technology. Security awareness training gives staff and volunteers the habits to spot these tricks and report them quickly.

However, training only works when it fits how nonprofits actually operate. This guide explains how to build a program that busy people will finish and remember.

Why nonprofits need a different approach

Nonprofit teams mix full-time staff, part-time workers, seasonal volunteers, interns, and board members. Each group has different access and different amounts of time to give.

As a result, a single long annual course rarely works. Volunteers may never finish it, and staff may forget it within weeks. Instead, aim for short, frequent lessons matched to each role.

In addition, turnover means new people arrive all the time. So training has to be ongoing, not a single event each year.

Board members deserve attention too. They often use personal email and devices, yet they receive sensitive financial and strategic information.

Design security awareness training by role

Everyone needs the basics, such as spotting phishing, using strong passwords, and locking screens. Beyond that, tailor topics to the risks each group faces.

  • Finance staff: Payment verification, invoice fraud, and wire requests.
  • Development staff: Donor data handling, fake donor inquiries, and payment portal logins.
  • Program staff: Client confidentiality, field devices, and safe sharing with partners.
  • Front desk and volunteers: Phone scams, visitors who ask for information, and shared computers.
  • Leadership and board: Impersonation of executives, and the risks of personal email for board business.

For example, a finance lesson might walk through a fake invoice step by step. Meanwhile, a program lesson might show how to send a referral securely instead of attaching files to regular email.

Keep lessons short and frequent

Monthly videos of a few minutes fit busy schedules far better than one long session. Also, frequent reminders keep security top of mind.

For volunteers, add a brief segment to orientation before they receive any system access. Cover the few rules that matter most, such as never sharing logins and never taking client data home.

In addition, use real examples from your own inbox when possible. Staff pay closer attention when they recognize a scam that targeted them.

Then reinforce lessons at natural moments. For instance, send a quick reminder before a major fundraising campaign, when scammers know donations are flowing.

Use phishing simulations the right way

Simulated phishing emails let people practice spotting threats in a safe setting. However, the goal is learning, not catching people out.

So when someone clicks, show a short lesson right away instead of a scolding message. Also, track trends across the organization rather than naming individuals. Most importantly, celebrate reports, because a staff member who reports a suspicious email protects everyone.

Also, vary the simulations. Include fake shipping notices, shared document alerts, and donation receipts, because real attackers use the same themes.

Build a reporting culture

Training only helps if people speak up. Therefore, make reporting easy with a single button or a clear email address. This checklist helps build the habit.

  1. Give every user a one-click way to report suspicious email.
  2. Respond to each report, so people know someone read it.
  3. Thank reporters, even when the email turns out harmless.
  4. Tell staff that reporting a mistake early never leads to punishment.
  5. Share a short monthly note on recent scams your team caught.
  6. Ask leaders to model the behavior by reporting too.

Measure what matters

Completion rates show who finished the lessons, but they do not show whether behavior changed. Instead, watch how many people report simulated and real phishing, and how quickly they do it.

Also look at trends over several months. If click rates drop and reports rise, your program works. If not, adjust the topics or the format.

Finally, share results with leadership and the board. A short summary shows progress and helps justify the time staff spend on training.

How WEBIT helps

WEBIT includes security awareness training in our Security Advanced add-on, along with email security and dark web monitoring. We help you set up short lessons, run phishing simulations, and review results with your team.

Our help desk is also unlimited, so staff can forward anything suspicious for a quick answer. See our cybersecurity services, or visit our nonprofit IT page to learn more.

Key takeaways

  • Nonprofit security awareness training must fit staff, volunteers, and board members with limited time.
  • Role-based topics address the real risks each group faces.
  • Short, frequent lessons beat one long annual course.
  • Phishing simulations should teach, not shame.
  • Reporting rates show progress better than completion rates.

Talk to an owner

Want help putting this guide into practice? A 30-minute discovery call gets you honest advice for your environment.

Schedule a discovery call

Non Profit Organizations IT services

See how WEBIT supports non profit organizations organizations across Chicagoland.

Explore Non Profit Organizations IT →

More Non Profit Organizations whitepapers

Browse the full library of guides for your industry.

All Non Profit Organizations whitepapers →

Two new clients per month. Maximum.

Ready to talk to an owner?

Every conversation starts with an honest look at where you are today. No pressure, no pitch deck, and no obligation.