How Nonprofits Can Stay Aligned and Adapt as Conditions Change
Stronger alignment and shorter planning cycles help organizations stay focused on what matters most while adjusting more effectively to changing conditions.
Digital viruses and hackers are nothing new, but the severity and prominence of cyber attacks is growing. Is the impact of breaches greater? Or are there truly more breaches now than in the past? The answer is “yes” to both,...
Digital viruses and hackers are nothing new, but the severity and prominence of cyber attacks is growing. Is the impact of breaches greater? Or are there truly more breaches now than in the past?

The answer is “yes” to both, as leaks and breaches were thrust into the spotlight during the recent election cycle. Hackers have increased their reach into even the most sophisticated of organizations, capitalizing on lax security to gain access to sensitive information.
Companies are caught in a tech quandary. Technology advances bring outstanding efficiency to organizations of all shapes and sizes, including electronic funds transfers (EFTs), electronic time sheets and expense reimbursements and “bring your own device” policies… With each new element comes an increase in complexity. Companies must evaluate how to manage the intrinsic risks to find the right balance of security and effectiveness.
No easy task, and cyber security often takes a back seat to revenue-generating activities. According to a recent survey, 80 percent of companies have a medium-level of vulnerability and 10 percent are at high risk for breaches. As the Wall Street Journal [subscriber content] noted, “Among the highly vulnerable companies, 91% of non-executive directors cannot read a cyber security report and nearly 100% of those companies don’t track devices on their network. Among this group, only 9% said their systems were regularly updated in response to cyber threats, and 87% of them don’t consider their malware, antivirus software and patches to be 100% up-to-date at all times.”
Too many organizations consider themselves to be in a low-risk category – but nearly all companies have information on hand for hackers to extort, whether in the form of donor records, credit card data, or healthcare records.
Indeed, healthcare providers are increasingly found in the cross hairs of attackers. A 2016 incident at Hollywood Presbyterian Medical Center underscores the risk, as the hospital was forced to acquiesce to ransom demands from hackers. The cyber attack locked the staff out of hospital technology, and the results were felt immediately.
“While the employees were shut out, they were forced technologically back in time: writing down patient orders, exchanging paper, and using faxes,” reported Nonprofit Quarterly. “Area hospitals accepted diverted patients who would have otherwise been accepted at Hollywood Presbyterian’s emergency room.”
Companies looking to improve their cyber security posture should be guided by three proven realities:
At a higher level, business leaders should be aware that critical security elements such as firewalls will not maintain themselves. If IT resources leave them unattended even for a three- or six-month window, that gap can wreak havoc on the environment. Organizations can buy the best firewall on the market – but if not routinely updated, it will not provide the intended safety measures.
There is no doubt that cyber threats are increasing in frequency and impact. But at the same time, organizations can equip themselves by proactively securing their systems and staying at the ready to react quickly if a breach occurs. The right training around the right controls will go a long way to bringing companies some cyber-peace-of-mind.
For more information about cyber security and IT risk assessment, please contact your AAF Partner, or James Jumes, leader of AAFCPAs’ integrated business & IT advisory practice at: 774.512.4062 or jjumes@aafcpa.com.
Stronger alignment and shorter planning cycles help organizations stay focused on what matters most while adjusting more effectively to changing conditions.
Management is responsible for maintaining internal controls that support reliable financial reporting. A disciplined approach to SOX 404(a) reinforces governance, reliability, and confidence in public...
Nonprofit organizations continue to innovate and rethink how they plan, operate, and report. AAFCPAs’ 2026 Nonprofit Seminar sessions offer experienced perspectives you can employ across...