GivingTuesday Cybersecurity Checklist for Nonprofits: Secure the Accounts Behind Your Campaign

GivingTuesday brings more attention to your nonprofit.

More people visit your website. More donors click your links. More staff members log into platforms. More emails go out. More questions come in. That activity is good, but it also puts pressure on the accounts and systems behind the campaign.

Your donation page, email platform, website, social media accounts, fundraising tools, and donor data all need to be protected before campaign day. A well-planned GivingTuesday campaign can still create problems if the wrong people have access, MFA isn’t turned on, your staff uses shared passwords, or no one knows what to do when something looks suspicious.

We put this checklist together from the cybersecurity questions we review with our nonprofit clients before busy campaign moments like GivingTuesday.

 

Start With the Accounts That Control the Campaign

Most GivingTuesday campaigns depend on several platforms at once. 

Your team may use a website, donation platform, email tool, CRM, design tool, social media accounts, payment processor, analytics platform, and shared drive.

Before the campaign goes live, take time to identify the accounts your team depends on most, especially the platforms that control donations, website updates, email, social media, and donor records.

  • Website admin access
  • Donation platform access
  • Email marketing platform
  • CRM or donor database
  • Social media accounts
  • Payment processor
  • Shared campaign folder
  • Design or content tools
  • Analytics and tracking tools

For each account, your team should know who can log in, who can make changes, who can reset access, and who can remove users if something looks wrong. If no one knows who has admin access, who can reset passwords, or who can remove a user, the campaign is already carrying risk.

 

Turn On MFA Before Campaign Traffic Increases

Multi-factor authentication should be enabled on the accounts that support the campaign. That includes your donation platform, email system, website, social accounts, CRM, and any tool that stores donor or payment-related information.

The Cybersecurity and Infrastructure Security Agency (CISA) recommends MFA because it adds another layer of protection beyond a password. For a GivingTuesday campaign, that extra step is especially important because staff may be logging in more often, working faster, and responding to more activity than usual. 

The accounts tied to donations, communications, website updates, and donor data should be reviewed before campaign activity increases.

  • Donation platform admins
  • Website admins
  • Email platform admins
  • CRM or donor database users
  • Social media managers
  • Payment processor accounts
  • Shared file storage
  • Any account with donor data

If MFA has not been fully rolled out within your organization yet, make time to review your multi-factor authenticator setup process before campaign activity increases.

 

Remove Old Users Before the Campaign Goes Live

GivingTuesday is not the time to find out that former staff, old vendors, past interns, or inactive volunteers still have access to important platforms.

A quick access cleanup can help your team spot people or accounts that no longer need to be active before donation activity increases.

  • Former employees
  • Past contractors
  • Old agency users
  • Vendors who no longer support the campaign
  • Volunteers with outdated access
  • Duplicate admin accounts
  • Personal emails used for work tools
  • Shared accounts that should be replaced

Access should match current responsibilities. If someone no longer works on your website, donor platform, CRM, email tool, or social accounts, their access should be removed.

This is especially important for admin-level accounts. Admins can usually edit settings, change payment information, export data, add users, or remove other users.

 

Replace Shared Passwords With Named Users

Shared passwords are common in nonprofits, especially when teams are small. They are also hard to manage.

When several people use the same login, it becomes difficult to know who changed something, who accessed donor information, or who still has the password after leaving the organization. The campaign tools that control donations, outreach, files, and reporting should not depend on one shared password passed from person to person.

  • Website access
  • Donation platforms
  • Email tools
  • Social media accounts
  • CRM or donor database
  • File storage
  • Design tools
  • Event or campaign tools

Whenever possible, each person should have their own account with the right level of access.

Named users make it easier to remove access, track activity, reset passwords, and keep the campaign secure without locking everyone out at once.

 

Watch for Phishing During Donation Season

GivingTuesday creates urgency, and urgency is exactly what scammers like to use.

Your team may see emails about donation issues, fake invoices, password resets, payment alerts, platform updates, or urgent requests from someone pretending to be leadership, a vendor, or a donor.

The Federal Trade Commission (FTC) notes that phishing scammers may ask for account information or create urgent requests that appear to come from a trusted source. 

During campaign season, your staff should be extra careful with messages that ask them to act quickly, share access, update payment details, or bypass the normal process.

  • Password reset emails they did not request
  • Unexpected donation platform alerts
  • Payment or bank change requests
  • Messages asking for login codes
  • Attachments from unknown senders
  • Links that do not match the platform’s real website
  • Emails pretending to come from leadership
  • Urgent vendor requests
  • Messages asking staff to bypass the normal process

Everyone in your organization should also know how to spot the warning signs of a fake email before they click, reply, or share account information.

 

Confirm Donation Links Before People Start Sharing Them

Donation links move quickly during GivingTuesday. They appear on your website, emails, social posts, QR codes, board member messages, partner updates, and campaign graphics.

Before anything is published, confirm that every donation link points to the right place and that donors can clearly recognize the official path to give.

  • Website donation buttons
  • Email links
  • Social media bios
  • Scheduled posts
  • QR codes
  • Board member sharing links
  • Partner links
  • Paid or boosted posts
  • Thank-you email links
  • Recurring donation links

The Federal Trade Commission advises donors to be careful with unexpected donation requests and avoid using information from unexpected text messages when deciding where to give. 

For nonprofits, that is a reminder to keep donation paths clear, official, and easy to verify.

Donors should not have to wonder if the link is real.

 

Protect Donor Data After the Campaign

The cybersecurity work does not end once donations come in.

After GivingTuesday, your organization may have new donor records, recurring gifts, declined payments, email signups, exported spreadsheets, thank-you lists, reports, and campaign notes. 

That information should not sit across inboxes, personal desktops, old spreadsheets, and shared folders with unclear access. 

The post-campaign cleanup should include the places where donor information, reports, and temporary files may have been saved during the campaign.

  • Where donor records are stored
  • Who can export donation data
  • Whether spreadsheets were downloaded
  • Who has access to campaign reports
  • Whether donor information synced correctly
  • Whether temporary users still have access
  • Where thank-you lists are saved
  • Whether payment issues need follow-up
  • Whether duplicate records were created

After the campaign, clean up temporary files and remove access that was only needed for GivingTuesday.

 

Create a Simple Day-Of Security Plan

GivingTuesday moves quickly. Your team should know who to contact if something goes wrong. 

A simple day-of plan can help staff respond faster if someone gets locked out, a donation alert looks suspicious, a link breaks, or a platform needs urgent attention.

  • Who can reset staff access?
  • Who can contact the donation platform?
  • Who can make urgent website updates?
  • Who monitors suspicious emails?
  • Who reviews donation platform alerts?
  • Who handles donor-reported payment issues?
  • Who can remove access if an account looks compromised?
  • Who communicates with leadership if there is a problem?

Keep the plan simple enough for the team to use during a busy day.

A campaign problem becomes harder to manage when staff is trying to figure out access, approvals, and support contacts in the middle of the issue.

 

Review Vendor and Volunteer Access

Vendors and volunteers often help with GivingTuesday. They may support social media, email, website updates, design, donor outreach, reporting, or campaign operations.

Before giving access, decide what they actually need. A volunteer helping with social posts may not need donation platform access. A designer may not need donor records. A consultant reviewing campaign copy may not need website admin access.

Use limited access whenever possible. If access is only needed for the campaign, remove it after the campaign ends.

 

Use GivingTuesday as a Cybersecurity Checkpoint

GivingTuesday is a good moment to review how your nonprofit handles access, passwords, donation tools, staff support, and donor data.

The campaign may last one day, but the systems behind it support your organization all year.

If your team finds old users, shared passwords, unclear admin access, weak MFA, scattered donor files, or no plan for suspicious emails, those are signs that your cybersecurity process needs more structure.

You do not need to fix everything at once. Start with the accounts and tools that carry the most risk during the campaign.

 

A Safer Campaign Starts Before GivingTuesday

Your GivingTuesday campaign depends on more than a donation page. It depends on secure accounts, clear access, protected donor data, staff awareness, and a support plan for the tools your team uses.

DeepTech works with nonprofits to strengthen the IT and cybersecurity foundations behind campaigns, programs, and daily operations, including access control, MFA, website support, phishing awareness, donation tools, staff workflows, and data protection.

When more people are paying attention to your mission, your systems should be ready too.

Nonprofits that want to strengthen the systems behind their programs, campaigns, and daily operations can use our IT and cybersecurity resource page as a practical next step.

Explore More Insights