"No-one will target us" is empirically wrong.
Pareto Phone cascaded across up to 70 charities. The ICRC lost data on 515,000 vulnerable people. ACNC Governance Standard 5 places a duty of care and diligence on responsible persons — with ACNC enforcement powers behind it. The "we're too small" assumption is the sector's biggest risk.
Why Not-for-Profits are in the crosshairs
Five shifts shaping the Not-for-Profit threat environment — why "no-one will target us" is empirically wrong, and why the regulatory floor is rising.
The "we're too small to be a target" assumption is empirically wrong
Infoxchange's 12% annual incident rate, applied across tens of thousands of sector organisations, puts the real annual incident count in the thousands. MSF's Tom Duggan captured the position plainly: charities and their supply chains are now on notice that they are just as much a target as their commercial colleagues. Pareto Phone and ICRC are the headline proofs.
Third-party and fundraising-vendor risk is the dominant cascade pattern
Pareto Phone was a shared telemarketing vendor whose compromise cascaded across up to 70 charities — including WWF Australia, the Australian Conservation Foundation, Plan International Australia, MSF, and Amnesty International. Charity operations depend extensively on outsourced fundraising agencies, donor-management CRMs, payment processors, and email providers. Each vendor is a potential cascade point.
Data retention is a primary risk multiplier
A central controversy of the Pareto Phone incident was that the company had retained donor data from as far back as 2007 — more than a decade beyond operational need. Many charities' own systems exhibit the same pattern: legacy donor databases, volunteer records, event registration histories, grant application data. The attack surface includes data that should have been deleted years ago.
Beneficiary data sensitivity creates safety risk, not just reputational risk
The ICRC breach compromised data on people separated from families by conflict, missing persons, and people in detention. Australian charities working with domestic violence survivors, refugees, people experiencing homelessness, or minors hold data whose exposure creates immediate safety risk. Director-General Mardini's appeal to the attackers — "do not share, sell, leak or otherwise use this data" — captures what is at stake when this class of data is exposed.
The regulatory floor is rising, and directors now carry personal exposure
Under ACNC Governance Standard 5, directors have a duty to act with reasonable care and diligence — a duty that is not diminished by a lack of specialised cyber knowledge. The ACNC can issue directions, accept enforceable undertakings, or deregister charities for breaches. Mandatory ransomware payment reporting (from 30 May 2025 for entities over $3M turnover), the Privacy Act NDB scheme, and the ASD's March 2024 charities cyber guide together set the direction of travel.
What regulators and experts are saying
I urge directors of all charities and not-for-profits, no matter how small, to make it a priority to strengthen their strategies and procedures to reduce potential harm from cyber attacks, such as data breaches.
The impacts will reverberate through 2024 and beyond. Charities and their supply chains are now on notice that they are just as much a target as their commercial colleagues. This will require ensuring they have properly invested in appropriate infrastructure and skills to keep their data and their donors' data secure.
An attack on the data of people who are missing makes the anguish and suffering for families even more difficult to endure. We are all appalled and perplexed that this humanitarian information would be targeted and compromised. This cyber-attack puts vulnerable people, those already in need of humanitarian services, at further risk.
ACNC Commissioner urging and mandatory ransomware reporting
ACNC Commissioner Sue Woodward has publicly urged charity directors — regardless of size — to prioritise cybersecurity under Governance Standard 5. Mandatory ransomware payment reporting under the Cyber Security Act 2024 took effect on 30 May 2025 for NFPs with turnover over $3M.
The NFP and charities regulatory stack is principles-based rather than prescriptive. ACNC Governance Standards apply to registered charities (basic religious charities are exempt from the Governance Standards, though other obligations still apply). Governance Standard 3 captures compliance with Australian laws including the Privacy Act, Cyber Security Act, and NDB scheme. Governance Standard 5 places a duty of reasonable care and diligence on responsible persons — a duty that is not diminished by a lack of specialised cyber knowledge. The Privacy Act applies directly to NFPs over $3M turnover, and to smaller NFPs that provide health services, are government-contracted, or trade in personal information. The Cyber Security Act 2024's mandatory ransomware reporting applies to NFPs over $3M turnover from 30 May 2025. The ASD's March 2024 cyber security guide for charities and NFPs sets a practical baseline. Many NFPs voluntarily adopt the Essential Eight as a structured framework. Charities operating overseas must also meet the ACNC External Conduct Standards. Sector-specific regulation (aged care, NDIS, child safety, health services) compounds where applicable.
Source: ACNC Governance Toolkit — Cyber SecurityApplies to NFPs over $3M turnover and to smaller NFPs providing health services, government-contracted services, or trading in personal information. APP 11 is the direct cyber hook — "active steps" to protect personal information.
Not mandatory for NFPs, but commonly adopted as the structured cyber framework of choice — aligned with the ASD's March 2024 Charities Cyber Security Guide. ML1 is a practical target for most charities; ML2 where grant-funded or enterprise-customer requirements apply.
Mandatory ransomware payment reporting within 72 hours for NFPs over $3M turnover. Captures thousands of Australian NFPs directly.
Where NodeZero appliesIncreasingly held by large NFPs and fundraising/donor-management platforms serving charity customers — particularly post-Pareto, where the sector is sharpening vendor assurance expectations.
Where NodeZero appliesExpected of fundraising agencies, donor-management CRMs, payment processors, and grants management platforms delivering into Australian charities.
Where NodeZero appliesA cascade of new obligations
Multiple new regulatory requirements are hitting simultaneously — each increasing the compliance burden and the consequences of failure.
ACNC Governance Standard 5 — cyber interpretation
2024–2025 focusUnder Governance Standard 5, directors have a duty to act with reasonable care and diligence that is not diminished by a lack of specialised cyber knowledge. The ACNC's 2024–25 enforcement priorities include cybersecurity. Commissioner Sue Woodward has publicly urged directors of all charities, regardless of size, to prioritise cybersecurity. The ACNC can issue directions, accept enforceable undertakings, or deregister charities in extreme cases.
Source: ACNC Governance StandardsCyber Security Act 2024 — mandatory ransomware reporting
30 May 2025Mandatory 72-hour reporting of ransomware payments to ASD for NFPs with annual turnover over $3 million — a threshold thousands of Australian charities and NFPs exceed. The Cyber Incident Review Board may conduct no-fault reviews of significant incidents. "Limited use" protection means information provided cannot generally be used against the reporter in civil, criminal, or regulatory proceedings.
Source: Cyber Security Act 2024Privacy Act APP 11 — active steps and NDB
OngoingAPP 11 requires active steps to protect and secure personal information. OAIC increasingly interprets this as requiring demonstrated control effectiveness, not just documented policy. Notifiable Data Breaches must be notified to the OAIC and affected individuals "as soon as practicable" where serious harm is likely. Applies to NFPs over $3M turnover, plus health service providers, government-contracted providers, and certain smaller NFPs.
Source: OAIC — Notifiable Data Breaches SchemeASD / ACSC Cyber Security for Charities and Not-for-profit Organisations
Mar 2024Non-binding guidance from the Australian Signals Directorate addressed specifically to charities and NFPs. Released March 2024. Covers prevention (MFA, patching, backups, access control), preparation (incident response planning), and response. A practical baseline you can measure your charity against.
Source: ASD / ACSCNodeZero produces defensible evidence. Drochaid wraps a sector-aware delivery around it.
The NFP sector is under-served by enterprise-focused cybersecurity providers. Drochaid's positioning is a deliberate, sector-shaped offering — appropriately priced, appropriately scoped, and aligned with the ACNC, OAIC, and ASD guidance that already exists. NodeZero produces the defensible evidence; Drochaid wraps it in the delivery context charities and their Boards actually need.
Find your organisation
See how the changes affect you specifically
Large charities
Charities with annual revenue of $3M or more — the ACNC's "large" tier, roughly a tenth of the sector. Directly captured by the Privacy Act and Cyber Security Act, and carrying full ACNC Governance Standard exposure.
View details →Fundraising agencies & donor platforms
Fundraising agencies, donor-management CRMs, payment processors, and grants platforms — the vendor layer the sector now scrutinises directly post-Pareto.
View details →International humanitarian
Australian-headquartered humanitarian and international development organisations — ICRC-benchmark sensitivity, overseas operational risk, and ACNC External Conduct Standards on top of the standard stack.
View details →The only autonomous pentesting platform that is:
References
Everything cited on this page — regulator reports, incident coverage, and official framework documentation.
Give your Board the cyber evidence GS5 expects
Book a charity baseline mapped to ACNC Governance Standards, APP 11, and the ASD Charities Cyber Security Guide


