For nonprofits
The CIO and CISO your funders assume you have.
Grant applications, insurers, and larger partners now ask for security policies, incident plans, and AI guidelines. ForEffect gives a nonprofit a part-time executive who can answer those questions truthfully — and who understands that every dollar spent on technology is a dollar not spent on the mission.
What we hear
Four sentences we hear from executive directors.
“The grant asks for a cybersecurity policy.”
Funders and government programs increasingly require a written security program. We write one you can honestly attest to, mapped to the terms of the award.
“Our insurer sent a forty-question form.”
Cyber-insurance renewals now hinge on multi-factor authentication, backups, and training. We answer once, fix what is missing, and keep the evidence for next year.
“Staff are already using AI with donor data.”
A ban does not work and a free-for-all is a breach waiting to happen. We write an acceptable-use policy, inventory the tools, and put guardrails on the workflows that matter.
“We have an MSP. Are we actually protected?”
An independent look at what your provider is and is not doing, followed by a relationship where they have a peer to work with instead of a client to manage.
Where ForEffect fits
Inside the budget, not on top of it.
Because we hold both the CIO and CISO chairs, the security recommendation and the budget decision happen in the same meeting. Unused licenses fund the missing control. The technology roadmap becomes a line in the grant narrative rather than an unfunded wish.
We also help nonprofit clients position technology and security work inside grant applications — including funders and state programs with dedicated cybersecurity dollars — so the executive is paid for by the award, not the general fund.
“What stood out about working with Mike and ForEffect was that they took the time to understand how our church actually operates before writing a line of code.”
Services for nonprofits
Start where the pressure is.
Fractional CISO
Security strategy, risk register, compliance, incident leadership — a few days a month.
Fractional CISO →OngoingFractional CIO
Technology roadmap, budget, vendor and MSP oversight, board reporting.
Fractional CIO →30 daysAI Readiness & Security Audit
A fixed-scope assessment that ends in a prioritized roadmap your board can read.
The audit →ProjectStrategic Implementation
Governed AI workflows, security program build-outs, automation on the tools you own.
Implementation →Questions we hear
Frequently asked
Can a grant pay for this?
We are small — is this too much for us?
Do you work with our existing IT volunteer or provider?
One call, no deck
Start with a conversation.
Tell us what keeps you up at night. We read and reply to every note — usually within one business day — and the first conversation is about your organization, not our services.
Book a 20-minute conversation
Pick a time that suits you. No slides, no pitch — twenty minutes on what your organization is dealing with and whether a fractional executive is the right shape of help.
Choose a time