DrochaidHorizon3.ai
NodeZero/Industries/Not-for-Profit & Charities
The state of play — Not-for-Profit & Charities, 2026

"No-one will target us" is empirically wrong.

Pareto Phone cascaded across up to 70 charities. The ICRC lost data on 515,000 vulnerable people. ACNC Governance Standard 5 places a duty of care and diligence on responsible persons — with ACNC enforcement powers behind it. The "we're too small" assumption is the sector's biggest risk.

12%
of Australian not-for-profits suffered a cyber security incident in the past year. Fewer than a quarter have introduced processes to manage cyber risks.
Infoxchange research, via Institute of Community Directors Australia
~50,000
donor records from up to 70 charities across Australia and NZ placed on the dark web via the Pareto Phone breach. The vendor collapsed into liquidation owing $17.3 million.
Institute of Community Directors Australia
70 days
dwell time before the ICRC detected its November 2021 breach. Industry dwell times routinely run into months. Most NFPs have no continuous monitoring capability.
ICRC — Cyber-attack on ICRC: What we know
The trend

Why Not-for-Profits are in the crosshairs

Five shifts shaping the Not-for-Profit threat environment — why "no-one will target us" is empirically wrong, and why the regulatory floor is rising.

The "we're too small to be a target" assumption is empirically wrong

Infoxchange's 12% annual incident rate, applied across tens of thousands of sector organisations, puts the real annual incident count in the thousands. MSF's Tom Duggan captured the position plainly: charities and their supply chains are now on notice that they are just as much a target as their commercial colleagues. Pareto Phone and ICRC are the headline proofs.

Third-party and fundraising-vendor risk is the dominant cascade pattern

Pareto Phone was a shared telemarketing vendor whose compromise cascaded across up to 70 charities — including WWF Australia, the Australian Conservation Foundation, Plan International Australia, MSF, and Amnesty International. Charity operations depend extensively on outsourced fundraising agencies, donor-management CRMs, payment processors, and email providers. Each vendor is a potential cascade point.

Data retention is a primary risk multiplier

A central controversy of the Pareto Phone incident was that the company had retained donor data from as far back as 2007 — more than a decade beyond operational need. Many charities' own systems exhibit the same pattern: legacy donor databases, volunteer records, event registration histories, grant application data. The attack surface includes data that should have been deleted years ago.

Beneficiary data sensitivity creates safety risk, not just reputational risk

The ICRC breach compromised data on people separated from families by conflict, missing persons, and people in detention. Australian charities working with domestic violence survivors, refugees, people experiencing homelessness, or minors hold data whose exposure creates immediate safety risk. Director-General Mardini's appeal to the attackers — "do not share, sell, leak or otherwise use this data" — captures what is at stake when this class of data is exposed.

The regulatory floor is rising, and directors now carry personal exposure

Under ACNC Governance Standard 5, directors have a duty to act with reasonable care and diligence — a duty that is not diminished by a lack of specialised cyber knowledge. The ACNC can issue directions, accept enforceable undertakings, or deregister charities for breaches. Mandatory ransomware payment reporting (from 30 May 2025 for entities over $3M turnover), the Privacy Act NDB scheme, and the ASD's March 2024 charities cyber guide together set the direction of travel.

On the record

What regulators and experts are saying

I urge directors of all charities and not-for-profits, no matter how small, to make it a priority to strengthen their strategies and procedures to reduce potential harm from cyber attacks, such as data breaches.
Sue Woodward
Commissioner, Australian Charities and Not-for-profits Commission (ACNC)
2024·ACNC
The impacts will reverberate through 2024 and beyond. Charities and their supply chains are now on notice that they are just as much a target as their commercial colleagues. This will require ensuring they have properly invested in appropriate infrastructure and skills to keep their data and their donors' data secure.
Tom Duggan
Head of Fundraising, Médecins Sans Frontières Australia (after the Pareto Phone breach)
2023
An attack on the data of people who are missing makes the anguish and suffering for families even more difficult to endure. We are all appalled and perplexed that this humanitarian information would be targeted and compromised. This cyber-attack puts vulnerable people, those already in need of humanitarian services, at further risk.
Robert Mardini
Director-General, International Committee of the Red Cross
January 2022·ICRC
What is now required

ACNC Commissioner urging and mandatory ransomware reporting

ACNC Commissioner Sue Woodward has publicly urged charity directors — regardless of size — to prioritise cybersecurity under Governance Standard 5. Mandatory ransomware payment reporting under the Cyber Security Act 2024 took effect on 30 May 2025 for NFPs with turnover over $3M.

The NFP and charities regulatory stack is principles-based rather than prescriptive. ACNC Governance Standards apply to registered charities (basic religious charities are exempt from the Governance Standards, though other obligations still apply). Governance Standard 3 captures compliance with Australian laws including the Privacy Act, Cyber Security Act, and NDB scheme. Governance Standard 5 places a duty of reasonable care and diligence on responsible persons — a duty that is not diminished by a lack of specialised cyber knowledge. The Privacy Act applies directly to NFPs over $3M turnover, and to smaller NFPs that provide health services, are government-contracted, or trade in personal information. The Cyber Security Act 2024's mandatory ransomware reporting applies to NFPs over $3M turnover from 30 May 2025. The ASD's March 2024 cyber security guide for charities and NFPs sets a practical baseline. Many NFPs voluntarily adopt the Essential Eight as a structured framework. Charities operating overseas must also meet the ACNC External Conduct Standards. Sector-specific regulation (aged care, NDIS, child safety, health services) compounds where applicable.

Source: ACNC Governance Toolkit — Cyber Security
Frameworks that apply
Australian Privacy Act 1988 — Australian Privacy Principles

Applies to NFPs over $3M turnover and to smaller NFPs providing health services, government-contracted services, or trading in personal information. APP 11 is the direct cyber hook — "active steps" to protect personal information.

ASD Essential Eight Maturity Level 2

Not mandatory for NFPs, but commonly adopted as the structured cyber framework of choice — aligned with the ASD's March 2024 Charities Cyber Security Guide. ML1 is a practical target for most charities; ML2 where grant-funded or enterprise-customer requirements apply.

Also in effect

A cascade of new obligations

Multiple new regulatory requirements are hitting simultaneously — each increasing the compliance burden and the consequences of failure.

ACNC Governance Standard 5 — cyber interpretation

2024–2025 focus

Under Governance Standard 5, directors have a duty to act with reasonable care and diligence that is not diminished by a lack of specialised cyber knowledge. The ACNC's 2024–25 enforcement priorities include cybersecurity. Commissioner Sue Woodward has publicly urged directors of all charities, regardless of size, to prioritise cybersecurity. The ACNC can issue directions, accept enforceable undertakings, or deregister charities in extreme cases.

Source: ACNC Governance Standards

Cyber Security Act 2024 — mandatory ransomware reporting

30 May 2025

Mandatory 72-hour reporting of ransomware payments to ASD for NFPs with annual turnover over $3 million — a threshold thousands of Australian charities and NFPs exceed. The Cyber Incident Review Board may conduct no-fault reviews of significant incidents. "Limited use" protection means information provided cannot generally be used against the reporter in civil, criminal, or regulatory proceedings.

Source: Cyber Security Act 2024

Privacy Act APP 11 — active steps and NDB

Ongoing

APP 11 requires active steps to protect and secure personal information. OAIC increasingly interprets this as requiring demonstrated control effectiveness, not just documented policy. Notifiable Data Breaches must be notified to the OAIC and affected individuals "as soon as practicable" where serious harm is likely. Applies to NFPs over $3M turnover, plus health service providers, government-contracted providers, and certain smaller NFPs.

Source: OAIC — Notifiable Data Breaches Scheme

ASD / ACSC Cyber Security for Charities and Not-for-profit Organisations

Mar 2024

Non-binding guidance from the Australian Signals Directorate addressed specifically to charities and NFPs. Released March 2024. Covers prevention (MFA, patching, backups, access control), preparation (incident response planning), and response. A practical baseline you can measure your charity against.

Source: ASD / ACSC
Beyond the platform

NodeZero produces defensible evidence. Drochaid wraps a sector-aware delivery around it.

The NFP sector is under-served by enterprise-focused cybersecurity providers. Drochaid's positioning is a deliberate, sector-shaped offering — appropriately priced, appropriately scoped, and aligned with the ACNC, OAIC, and ASD guidance that already exists. NodeZero produces the defensible evidence; Drochaid wraps it in the delivery context charities and their Boards actually need.

GS5 evidence pack for Boards
Findings structured against ACNC Governance Standard 5 — concrete, defensible evidence that directors have acted with reasonable care and diligence on cyber risk oversight.
Sector-specific scoping and pricing
Scope tailored to typical NFP IT estates — cloud-heavy, limited on-premise, third-party CRM, fundraising agency integrations. Tiered pricing by ACNC size classification. Consortium and peak-body-brokered procurement supported.
Vendor-ecosystem validation (Pareto pattern)
Testing of fundraising agency, donor CRM, and payment processor integration points — the exact cascade pattern the 2023 Pareto Phone incident exposed.
Platform credentials

The only autonomous pentesting platform that is:

Essential Eight
Mapped ML1–3
ASD baseline
Privacy Act
Reachability proof
Donor & client data
Gartner Peer Insights
4.7 / 5
Customers' Choice (Oct 2025)
310,332
Pentests run
7,013 orgs
Trusted by 7,013 organisations worldwide
Powers the NSA's CAPT program310,332 pentests4.7 Gartner

Give your Board the cyber evidence GS5 expects

Book a charity baseline mapped to ACNC Governance Standards, APP 11, and the ASD Charities Cyber Security Guide