BoardEffect Logo
Blog / Cyber resilience starts with board readiness

Cyber resilience starts with board readiness

Jill Holtz

September 01, 2026

fb logox logolinkedin logo

Cybersecurity is no longer a specialist concern that boards can leave entirely to IT. For nonprofits, a cyber incident can quickly become a governance challenge, affecting service delivery, stakeholder trust and the board’s ability to access the information it needs.

This month, we’re focusing on the practical habits that help boards stay better prepared, from understanding cyber oversight responsibilities and assessing vulnerabilities to keeping essential governance information secure, accessible and ready when it matters.

Make your volunteer board cyber-ready

Cyber-ready trustees are better positioned to oversee significant organization-wide risks and support clear conversations with management. Our guide to making your volunteer board cyber-ready explores common risks, the value of training existing board members and practical steps for building stronger cyber awareness.

It also covers phishing awareness, data protection, incident response planning and why cyber-readiness means avoiding reputational risk.

Start with a security assessment

A security assessment can help your organization identify vulnerabilities before they become larger problems. Our freeSecurity Assessment Checklist offers practical questions and next steps to help boards and leadership teams strengthen their overall security posture.

4 tips to fine tune BoardEffect for top security

  1. Use only BoardEffect for distributing sensitive board documents — skip email or shadow IT systems. Make sure your security features like role-based permissions, single sign-on (SSO), two-factor authentication, audit trails and encrypted storage are activated.
  2. Review your organization's security policies with your IT team to ensure alignment with established password criteria and automatic password resets as needed for all users to help avoid cyber incidents.
  3. Set up a “Profile update email” for alerts when user profiles change.
  4. Review user lists, passwords and connected devices frequently, disabling accounts for rotating board and committee members.

If you have any questions or need support implementing these best practices, don’t hesitate to reach out to your customer success manager.

How Hospital Sisters Health System kept governance moving during a cyber incident

Hospital Sisters Health System relied on an outdated homegrown system that made document sharing, board member updates and meeting preparation difficult. During a 15-day cyber incident that took down its other systems, BoardEffect remained accessible and secure, helping board members retrieve information and communicate confidentially.

As Dani Glascock, System Director of Governance, explained:

“During the cyber-incident, BoardEffect was secure and reliable. Knowing we could access it while everything else was down gave us a great sense of security.”

Read the full Hospital Sisters Health System story.

Run a cybersecurity tabletop exercise with your board

Knowing what to do during a cyber incident is easier when the board has already practiced the conversation. Scenario-based exercises can help trustees clarify roles, test response plans and strengthen oversight before a real incident occurs. Read the blog here.

Upcoming seasonal events to plan around

October is a useful moment to connect Cybersecurity Awareness Month with practical board conversations about data protection, incident response and trustee responsibilities. Breast Cancer Awareness Month can also provide a timely prompt for health, community and advocacy organizations to review how they protect sensitive information while supporting the people they serve. Consider using 5 October, World Teacher’s Day, 11 October, International Day of the Girl and 16 October, International Credit Union Day, as additional moments to connect mission-led work with responsible governance.

Find more nonprofit events for your calendar for the rest of the year here.

What’s trending

Until next month

We hope this month’s resources help your board build cyber confidence without adding unnecessary complexity to its governance work.

As always, we’d love to hear how your board is evolving.

Follow us and join the wider BoardEffect community on LinkedIn.

Jill is a Content Strategy Manager at Diligent. Her strategy background and content expertise working across a variety of sectors, including education, non-profit and with local government partners, allows her to provide unique insights for organizations looking to achieve modern governance.

Interested in learning more ?

Learn why 180k+ users are using BoardEffect for their board portal solution!

SHARE THIS POST

fb logox logolinkedin logo

Popular Links