
It's 4:17 on a Friday. A staff member gets an email that looks like it's from you: "Can you send the updated banking info before you head out?"
The name is right. The tone sounds familiar. And with everyone rushing to close out the week, the easiest thing to do is just hit reply. There's only one problem. You never sent it.
Your IT provider can put strong protections in place. But even the best tools can't catch every scam. Some of it still comes down to one person, in one moment, deciding what feels right.
An Assumption That's Easy To Make
It's easy to assume cybersecurity is fully taken care of behind the scenes. The IT provider has tools in place. The computers are protected. Surely that's enough.
The truth is, your organization's safety is tested every time someone on your team decides whether to trust an email, a link or a request that feels slightly off. In a non-profit, that happens all day long. Staff, volunteers, everyone pitching in to keep your programs running.
To protect your donors, your clients and the people you serve, your whole team needs to know what to do the moment something doesn't feel right.
Good Tools Can't Make Every Call
Think of your security software like a smoke detector. It can warn you the moment something's wrong. But it can't put out the fire, and it can't walk everyone outside. That part still takes a person.
Today's scams don't look like scams anymore. They sound like your own team. They mention a vendor you really do work with, or a grant deadline you're actually racing to meet. When something unusual shows up, a changed bank account, a link to "review" a file, a volunteer asking for access they've never needed, someone has to decide, right then, if it's real.
"Just be careful" Isn't a Plan
Most organizations tell their team to watch for suspicious emails. But then what? Every person on your team, staff and volunteers alike, should know:
- Who to tell
- How to check if a request is real
- Not to click a link or open a file they weren't expecting
- What to do if they already did
- How to report it without fear of getting in trouble
Saying "be careful" without giving people a next step puts a lot of weight on whoever happens to be at their desk that day. In a non-profit, that's often someone already juggling five other jobs.
Hesitation is the real danger here. Someone unsure if they're overreacting may stay quiet. Someone afraid of blame may wait before saying anything. That short pause is often what turns a small mix-up into a real crisis.
Leadership Sets the Tone
Your team takes its cues from the top. Skip a verification step because you're busy, and people learn speed matters more than caution. Make it awkward to flag something odd, and people stop flagging it. Embarrass someone for clicking the wrong link, and mistakes start hiding instead of getting reported.
The good news is the opposite is just as true. When double-checking is normal, your team takes it seriously too. When someone raises a concern and feels backed up instead of brushed off, everyone feels safer speaking up. That trust is what catches small problems while they're still small.
Everyone Has a Part to Play
Back to that email at 4:17 on a Friday.
The goal was never to make your team afraid of their inbox. It's to make sure that when something feels off, they know exactly what to do, who to ask and how to check. Speaking up should always feel like the right call, never an overreaction.
Your staff and volunteers don't need to become tech experts. They just need clear expectations, a few good habits and the confidence to say something when it counts. That's what actually keeps your mission safe.
Building that kind of culture takes more than one training a year. It takes steady support as things change, and that's exactly where we come in.
We work alongside BC non-profits every day. We know your priorities aren't the same as a typical business's. You're protecting donor trust on a budget with no room for surprises, all while trying to keep your eyes on the mission instead of the inbox.
That's what we're here for. Finding the gaps. Strengthening your protections. Helping your whole team understand the part they play in keeping your mission, and the people you serve, safe.
Cybersecurity is everyone's job. But you don't have to carry it alone. If you're curious where the gaps might be in your own organization, we'd love to talk it through with you, and show you how we support mission-driven groups like yours every day.

