Pen testing · Nonprofit
Penetration Testing for Charities & Foundations
Penetration testing shows a charity how its own systems, not its vendors' marketing, hold up against a real attacker. The scoping question is the hard part: when donation pages run on CanadaHelps or Blackbaud, what remains yours to test is the website that links to them, the grant portal, the M365 tenant and everything volunteers log into. Charities book us before giving season or ahead of an insurer, funder or accreditation deadline that asks for testing evidence.
Reviewed by the Privacy Horizon team · Last reviewed
What you're protecting
What attackers can reach in a charity's own estate
Vendor platforms carry much of the fundraising load, but a surprising amount of attack surface still belongs to the charity itself, and that is where testing pays off.
The public website and its donation plugin
A WordPress site with an embedded giving form or checkout redirect is charity-owned attack surface. Compromise here lets an attacker skim card data or silently swap the destination of donations regardless of how secure the processor is.
Grant and application portals
Foundations expose SmartSimple-class portals holding applicant financials and grantee reports to the open internet. Authentication, session handling and file-upload behaviour all deserve adversarial attention.
The identity layer volunteers share
M365 or Google nonprofit tenants gate the CRM, finance files and case records. Password spraying, legacy protocols and permissive sharing links are classic paths a test exercises safely.
Integrations and API keys
Connectors moving data between forms, processors, the CRM and accounting each carry credentials. A test probes whether those keys are exposed in page source, repositories or misconfigured endpoints.
Remote access for staff and the MSP
VPNs, remote desktop and management tools that keep a lean team running are the same doors ransomware operators favour, so the external test enumerates them first.
Regulatory map
Why testing evidence keeps coming up for charities
No statute orders a charity to run penetration tests, yet three separate forces now ask for the results, and each shapes the scope differently.
Insurer questionnaires and the Cyber Centre baseline
Renewal forms increasingly probe whether technical controls have been independently exercised, and the national baseline for small organizations gives assessors their reference point for what should withstand attack.
Law 25 safeguard expectations
Charities caught by Quebec's enterprise test must protect personal information with measures proportionate to sensitivity. Testing the systems that hold Quebec donor data is a defensible way to demonstrate that proportionality.
Statutory safeguards in BC and for federal charities in Alberta
Where a PIPA applies to your organization, reasonable security arrangements are a legal duty, and an unexercised control is hard to call reasonable after an incident.
Funder and accreditation due diligence
Contribution agreements with security clauses and Imagine Canada re-accreditation reviews both go better when you can table a recent test report with remediation notes rather than assurances.
What goes wrong
Attack paths a charity pen test rehearses
The test imitates what has actually worked against Canadian nonprofit environments, then documents how far each path went before controls held.
Credential attacks on the tenant
Alberta OIPC files show charity mailboxes falling to phished or guessed credentials. The test measures whether MFA, lockouts and conditional access genuinely stop a determined password-spraying run.
Web application flaws on giving pages
Outdated plugins, injectable forms and weak admin panels on the charity's own site can undermine an otherwise secure payment chain, the gap the Blackbaud era taught the sector to stop assuming away.
Portal privilege escalation
Grant applicants should never see one another's files. Testing tries exactly that: crossing between accounts, roles and funds to expose authorization gaps before an applicant or attacker does.
Lateral movement after a foothold
From one compromised volunteer account, how close can an attacker get to the constituent database, payroll or backups? The internal phase answers that question in writing.
Our pen testing for charities & foundations
How we scope a test around vendor-hosted fundraising
The engagement follows the service's core activities, cut to fit an environment where key platforms are rented and change windows are seasonal.

Asset and boundary mapping
We establish what is yours to test, the website, portals, tenant and network, and what belongs to CanadaHelps, Blackbaud or another vendor, where contracts and their own attestations govern instead.
Vulnerability exploration of in-scope systems
Structured discovery across applications, network services and cloud configuration, prioritized by where donor, beneficiary and grantee data actually sits.
Response capability observation
We note whether your MSP or staff detected the activity, how alerts surfaced, and how long the window between foothold and discovery would have been in a real event.
Findings translated for your audiences
A technical annex for the MSP and a plain-language summary the board, insurer and funders can read, each finding tied to remediation guidance and priority.
Retest of corrected items
Once fixes land, we verify them, giving you a closed-loop report rather than a list of open questions before your renewal or accreditation date.
How the engagement runs
Running the test without disrupting fundraising
Every step is planned so donations, receipting and grant cycles keep flowing while the assessment proceeds.
Step 1
Scoping and rules of engagement
We agree targets, test windows, emergency contacts and exclusions, typically scheduling well clear of the November-to-February giving and receipting freeze.
Step 2
Coordinated notice where vendors touch scope
If testing brushes vendor-managed components, we align with each platform's testing policy so nobody trips a fraud response mid-campaign.
Step 3
Active testing with live safeguards
Exploitation stays controlled: no destructive actions against grant applications in flight, production donation flows or live case records, with a stop channel open throughout.
Step 4
Debrief, report and retest
Findings walkthrough with your finance director and MSP, prioritized remediation plan, and verification testing once changes are made.
What it costs
What a charity pen test costs depends on scope
Price follows the size of the attack surface: how many web applications and portals you run, whether the M365 tenant and internal network are included, the number of user roles in a grant portal, and whether you need retesting bundled for an insurer deadline. A single WordPress site with a donation plugin is a much smaller engagement than a foundation portal with applicant, reviewer and administrator roles.
Because scope varies this widely, we quote after a short scoping call rather than from a rate card, and we will tell you plainly if part of what you want tested is really your vendor's responsibility to evidence.
Charities & Foundations: Pen testing questions, answered
More than most boards expect. Your website that hosts or links to those pages, any WordPress plugins, your M365 or Google tenant, remote access, file shares, integrations carrying donor data into the CRM, and any portal you run yourselves all remain your attack surface. The vendors secure their platforms; nothing they do protects a spoofed admin login on your side or a compromised volunteer account with CRM access. We scope the test around exactly that boundary.
Yes, and early enough to fix what turns up. A test in late summer or early autumn leaves time to patch plugins, harden admin access and retest before the change freeze, when your site carries its highest traffic and the cost of compromise peaks. Testing during the campaign itself risks confusing fraud monitoring and leaves no remediation window, so we treat September and October as the practical deadline.
Preferably in a staging environment seeded with synthetic data; where only production exists, we use dedicated test accounts, avoid destructive actions, work in agreed windows outside application deadlines, and keep your administrator on a live channel. The valuable findings, authorization gaps between applicants, file-upload weaknesses, session flaws, emerge safely under those constraints without touching a real grantee's submission.
It is designed not to. Payment processing sits with your vendors and stays out of active scope, testing windows avoid campaign peaks, and anything that could degrade the site is flagged for an agreed maintenance period. In practice the riskiest moment is remediation, not testing, which is another reason to schedule the whole cycle before giving season rather than during it.
Three usable artifacts: an executive summary stating what was tested and the overall posture, a findings register with severity and remediation status, and a retest attestation once fixes are verified. Insurance questionnaires, contribution-agreement due diligence and Imagine Canada re-accreditation reviews each accept that package as evidence of independent technical diligence, which beats self-declared checkboxes every time.
More for charities & foundations
Other services for this niche
About this service
Answers & guides
- How much does a penetration test cost (and what affects the price)?
- What is a cybersecurity risk assessment, and how often should we do one?
- How do we prepare for a customer security questionnaire?
- Vulnerability Scan vs Penetration Test: Why You Probably Need Both
- How Often Should You Pen Test Your Web App?
What's Protecting Your Business from the Next Threat?
Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.