Skip to main content

New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs

Pen testing · Nonprofit

Penetration Testing for Charities & Foundations

Penetration testing shows a charity how its own systems, not its vendors' marketing, hold up against a real attacker. The scoping question is the hard part: when donation pages run on CanadaHelps or Blackbaud, what remains yours to test is the website that links to them, the grant portal, the M365 tenant and everything volunteers log into. Charities book us before giving season or ahead of an insurer, funder or accreditation deadline that asks for testing evidence.

Reviewed by the Privacy Horizon team · Last reviewed

What you're protecting

What attackers can reach in a charity's own estate

Vendor platforms carry much of the fundraising load, but a surprising amount of attack surface still belongs to the charity itself, and that is where testing pays off.

The public website and its donation plugin

A WordPress site with an embedded giving form or checkout redirect is charity-owned attack surface. Compromise here lets an attacker skim card data or silently swap the destination of donations regardless of how secure the processor is.

Grant and application portals

Foundations expose SmartSimple-class portals holding applicant financials and grantee reports to the open internet. Authentication, session handling and file-upload behaviour all deserve adversarial attention.

The identity layer volunteers share

M365 or Google nonprofit tenants gate the CRM, finance files and case records. Password spraying, legacy protocols and permissive sharing links are classic paths a test exercises safely.

Integrations and API keys

Connectors moving data between forms, processors, the CRM and accounting each carry credentials. A test probes whether those keys are exposed in page source, repositories or misconfigured endpoints.

Remote access for staff and the MSP

VPNs, remote desktop and management tools that keep a lean team running are the same doors ransomware operators favour, so the external test enumerates them first.

Regulatory map

Why testing evidence keeps coming up for charities

No statute orders a charity to run penetration tests, yet three separate forces now ask for the results, and each shapes the scope differently.

Insurer questionnaires and the Cyber Centre baseline

Renewal forms increasingly probe whether technical controls have been independently exercised, and the national baseline for small organizations gives assessors their reference point for what should withstand attack.

Primary source →

Law 25 safeguard expectations

Charities caught by Quebec's enterprise test must protect personal information with measures proportionate to sensitivity. Testing the systems that hold Quebec donor data is a defensible way to demonstrate that proportionality.

Primary source →

Statutory safeguards in BC and for federal charities in Alberta

Where a PIPA applies to your organization, reasonable security arrangements are a legal duty, and an unexercised control is hard to call reasonable after an incident.

Read our guide →

Funder and accreditation due diligence

Contribution agreements with security clauses and Imagine Canada re-accreditation reviews both go better when you can table a recent test report with remediation notes rather than assurances.

What goes wrong

Attack paths a charity pen test rehearses

The test imitates what has actually worked against Canadian nonprofit environments, then documents how far each path went before controls held.

  • Credential attacks on the tenant

    Alberta OIPC files show charity mailboxes falling to phished or guessed credentials. The test measures whether MFA, lockouts and conditional access genuinely stop a determined password-spraying run.

    Source →

  • Web application flaws on giving pages

    Outdated plugins, injectable forms and weak admin panels on the charity's own site can undermine an otherwise secure payment chain, the gap the Blackbaud era taught the sector to stop assuming away.

  • Portal privilege escalation

    Grant applicants should never see one another's files. Testing tries exactly that: crossing between accounts, roles and funds to expose authorization gaps before an applicant or attacker does.

  • Lateral movement after a foothold

    From one compromised volunteer account, how close can an attacker get to the constituent database, payroll or backups? The internal phase answers that question in writing.

Our pen testing for charities & foundations

How we scope a test around vendor-hosted fundraising

The engagement follows the service's core activities, cut to fit an environment where key platforms are rented and change windows are seasonal.

Business performance checklist, Businessman using laptop online survey filling out check digital form task, business performance monitoring and evaluation. online survey question f
  1. Asset and boundary mapping

    We establish what is yours to test, the website, portals, tenant and network, and what belongs to CanadaHelps, Blackbaud or another vendor, where contracts and their own attestations govern instead.

  2. Vulnerability exploration of in-scope systems

    Structured discovery across applications, network services and cloud configuration, prioritized by where donor, beneficiary and grantee data actually sits.

  3. Response capability observation

    We note whether your MSP or staff detected the activity, how alerts surfaced, and how long the window between foothold and discovery would have been in a real event.

  4. Findings translated for your audiences

    A technical annex for the MSP and a plain-language summary the board, insurer and funders can read, each finding tied to remediation guidance and priority.

  5. Retest of corrected items

    Once fixes land, we verify them, giving you a closed-loop report rather than a list of open questions before your renewal or accreditation date.

How the engagement runs

Running the test without disrupting fundraising

Every step is planned so donations, receipting and grant cycles keep flowing while the assessment proceeds.

  1. Step 1

    Scoping and rules of engagement

    We agree targets, test windows, emergency contacts and exclusions, typically scheduling well clear of the November-to-February giving and receipting freeze.

  2. Step 2

    Coordinated notice where vendors touch scope

    If testing brushes vendor-managed components, we align with each platform's testing policy so nobody trips a fraud response mid-campaign.

  3. Step 3

    Active testing with live safeguards

    Exploitation stays controlled: no destructive actions against grant applications in flight, production donation flows or live case records, with a stop channel open throughout.

  4. Step 4

    Debrief, report and retest

    Findings walkthrough with your finance director and MSP, prioritized remediation plan, and verification testing once changes are made.

What it costs

What a charity pen test costs depends on scope

Price follows the size of the attack surface: how many web applications and portals you run, whether the M365 tenant and internal network are included, the number of user roles in a grant portal, and whether you need retesting bundled for an insurer deadline. A single WordPress site with a donation plugin is a much smaller engagement than a foundation portal with applicant, reviewer and administrator roles.

Because scope varies this widely, we quote after a short scoping call rather than from a rate card, and we will tell you plainly if part of what you want tested is really your vendor's responsibility to evidence.

Charities & Foundations: Pen testing questions, answered

More than most boards expect. Your website that hosts or links to those pages, any WordPress plugins, your M365 or Google tenant, remote access, file shares, integrations carrying donor data into the CRM, and any portal you run yourselves all remain your attack surface. The vendors secure their platforms; nothing they do protects a spoofed admin login on your side or a compromised volunteer account with CRM access. We scope the test around exactly that boundary.

Yes, and early enough to fix what turns up. A test in late summer or early autumn leaves time to patch plugins, harden admin access and retest before the change freeze, when your site carries its highest traffic and the cost of compromise peaks. Testing during the campaign itself risks confusing fraud monitoring and leaves no remediation window, so we treat September and October as the practical deadline.

Preferably in a staging environment seeded with synthetic data; where only production exists, we use dedicated test accounts, avoid destructive actions, work in agreed windows outside application deadlines, and keep your administrator on a live channel. The valuable findings, authorization gaps between applicants, file-upload weaknesses, session flaws, emerge safely under those constraints without touching a real grantee's submission.

It is designed not to. Payment processing sits with your vendors and stays out of active scope, testing windows avoid campaign peaks, and anything that could degrade the site is flagged for an agreed maintenance period. In practice the riskiest moment is remediation, not testing, which is another reason to schedule the whole cycle before giving season rather than during it.

Three usable artifacts: an executive summary stating what was tested and the overall posture, a findings register with severity and remediation status, and a retest attestation once fixes are verified. Insurance questionnaires, contribution-agreement due diligence and Imagine Canada re-accreditation reviews each accept that package as evidence of independent technical diligence, which beats self-declared checkboxes every time.

What's Protecting Your Business from the Next Threat?

Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.

(647) 622-2644

Free, no obligation

Get a quote

Tell us what you need and we'll come back within one business day with a tailored quote.

We only use your details to respond to this request.