Protecting member and donor data: cyber security for trade unions and NPOs
Membership and donor databases hold exactly the kind of information attackers want — identity details, banking information, contact histories — often protected by a fraction of a typical corporate security budget.
Trade unions and non-profits are attractive targets for a simple reason: the data they hold is just as valuable to an attacker as a bank's or a retailer's, but the budget and staffing behind it usually isn't. Surveys of the sector consistently find that a meaningful share of non-profits have already experienced a cyberattack, and that cybersecurity spend is one of the first things cut when budgets are tight, because donors and members understandably want funds going toward the mission rather than overhead.
Why membership and donor records are such a draw
A union's membership database or an NPO's donor list typically includes ID numbers, banking or payment details, addresses, and years of contact history in one place. Compromising a single system can hand an attacker everything needed for identity theft or fraud at scale — a far higher return per breach than many corporate targets offer, for far less effort.
The gaps that show up again and again
Ageing donated hardware, volunteer or part-time staff filling IT roles without formal security training, and a general assumption that a smaller organisation is too insignificant to be worth targeting. Fewer than half of non-profits surveyed have a formal, written policy for responding to a cyberattack, and a similar share provide no regular security training to staff at all. None of that reflects a lack of care — it reflects the same overhead-versus-mission tension that shapes every other budget line.
Where to focus first on a limited budget
Strong cyber security doesn't require a large-organisation budget. Multi-factor authentication is the single highest-value control available, closing off account compromise even when a password is stolen or reused. A basic data inventory — what you hold, where it lives, who can access it — routinely surfaces old exports sitting in shared folders or former staff accounts that were never deactivated. Cloud platforms built for this kind of organisation increasingly bundle security controls in at no extra cost, which is often a faster win than trying to build equivalent protection in-house.
POPIA doesn't grant a size exemption
Trade unions and NPOs are responsible parties under POPIA in exactly the same way a business is, with the same breach-notification obligations and the same exposure if member or donor data is compromised. Smaller size doesn't reduce that obligation — if anything, it makes a plan drafted in advance more valuable, since there's less spare capacity to absorb the disruption of improvising one mid-incident.