Services
Fractional CISOFractional CIOAI Readiness & Security AuditStrategic Implementation
Who we serve
NonprofitsChurches & ministriesSmall businessesMSP partners
Company
AboutCase studiesInsightsContactStart with a conversation →
Home/Who we serve/Nonprofits

For nonprofits

The CIO and CISO your funders assume you have.

Grant applications, insurers, and larger partners now ask for security policies, incident plans, and AI guidelines. ForEffect gives a nonprofit a part-time executive who can answer those questions truthfully — and who understands that every dollar spent on technology is a dollar not spent on the mission.

Typical size10–150 staff, one IT person or an MSP
FrameworksNIST CSF 2.0 · HIPAA · PCI DSS · grant terms
Start withThe 30-day audit or a retainer
RegionWashington-based, nationwide remote

What we hear

Four sentences we hear from executive directors.

Heard often

“The grant asks for a cybersecurity policy.”

Funders and government programs increasingly require a written security program. We write one you can honestly attest to, mapped to the terms of the award.

Heard often

“Our insurer sent a forty-question form.”

Cyber-insurance renewals now hinge on multi-factor authentication, backups, and training. We answer once, fix what is missing, and keep the evidence for next year.

Heard often

“Staff are already using AI with donor data.”

A ban does not work and a free-for-all is a breach waiting to happen. We write an acceptable-use policy, inventory the tools, and put guardrails on the workflows that matter.

Heard often

“We have an MSP. Are we actually protected?”

An independent look at what your provider is and is not doing, followed by a relationship where they have a peer to work with instead of a client to manage.

Where ForEffect fits

Inside the budget, not on top of it.

Because we hold both the CIO and CISO chairs, the security recommendation and the budget decision happen in the same meeting. Unused licenses fund the missing control. The technology roadmap becomes a line in the grant narrative rather than an unfunded wish.

We also help nonprofit clients position technology and security work inside grant applications — including funders and state programs with dedicated cybersecurity dollars — so the executive is paid for by the award, not the general fund.

“What stood out about working with Mike and ForEffect was that they took the time to understand how our church actually operates before writing a line of code.”

AJ
Alex JohnsonExecutive Pastor, Gold Creek Community Church

Questions we hear

Frequently asked

Can a grant pay for this?
Often. State and local cybersecurity grant programs, foundation capacity-building grants, and some federal awards allow security and technology governance as an eligible expense. We help position the work inside the application.
We are small — is this too much for us?
The retainer is sized to the organization. A ten-person nonprofit does not need the same cadence as a hundred-person one, and we say so in the first conversation.
Do you work with our existing IT volunteer or provider?
Yes, and they usually like it. A fractional executive gives them priorities, a budget, and someone to share the responsibility with.

One call, no deck

Start with a conversation.

Tell us what keeps you up at night. We read and reply to every note — usually within one business day — and the first conversation is about your organization, not our services.

info@foreffectai.comMill Creek, WA · Remote-first

Book a 20-minute conversation

Pick a time that suits you. No slides, no pitch — twenty minutes on what your organization is dealing with and whether a fractional executive is the right shape of help.

Choose a time
or
Send a short note instead