Topic 04

Technology and Data

Technology strategy for nonprofits with no IT department. The roadmap on one page, picking systems by criteria, free security basics, and what to budget.

You have no IT department, an operations manager who absorbed the job, a funder who wrote the CRM into the grant agreement, a spreadsheet everyone distrusts, and a board member whose cousin “does computers”. A nonprofit technology strategy here is not a 40-page plan. It is a short list of decisions, made once a year and written down. This page helps you make five of them: what you run today, which one system to fix or replace next, how to pick it without the demo picking for you, which security basics to switch on for free, and how much money to set aside.

What a technology strategy has to answer

Technology strategy here is a set of answers, not a document. Five questions cover it.

  1. What systems do you run, and who owns each one. Written down, one page.
  2. Which one system causes the most manual work or the most risk this year. One, not four.
  3. What you will do about it. Fix the setup, replace it, or leave it alone on purpose.
  4. What security controls are on. Multifactor authentication, backups, offboarding, and who can create an account.
  5. What you will spend. A number in the budget, not a line called “misc”.

The answers fit on one page. Nearly 40% of respondents to the 2024 NTEN Nonprofit Digital Investments Report include technology explicitly in their strategic plans and another 33% include it in general terms. A line that says “improve our systems” decides nothing.

The roadmap on one page

The roadmap is a table with four rows, one per quarter, and three columns: the system, the change, the owner. If you cannot fill it, you have a wish list, not a strategy.

QuarterSystemChangeOwner
Q1Donor databaseClean duplicates, retire the side spreadsheetDevelopment director
Q2Email, files, and identityTurn on multifactor authentication for everyoneOperations manager
Q3AccountingMove grant tracking from spreadsheet into the ledgerFinance lead
Q4NoneReview the year, write next year’s tableExecutive director

The Q4 row is deliberate. One quiet quarter makes the other three possible. The full method, with the questions to ask before each row, is in Nonprofit technology roadmap, which ships with the Technology roadmap one-pager as a fillable document.

Tie the roadmap to money you already plan. If your fundraising plan says you will grow monthly giving, the donor database row comes first. If it says you will chase two government grants, the accounting row does.

Data before tools

Most technology problems are data problems wearing a software costume. The donor report is wrong because three people enter gifts three ways, not because the database is bad.

Start with an inventory. One sheet, one row per system, six columns.

ColumnWhat goes in it
SystemThe product name and what you use it for
OwnerOne named person who can answer questions about it. Not a committee.
RecordsWhat lives there: donors, clients, volunteers, transactions
CostAnnual licence and any support contract
LoginsWho has admin access, whether it comes through single sign-on, and whether former staff still have it
TrustDoes staff believe its reports? Yes, no, or “we check it against a spreadsheet”

Any system with “we check it against a spreadsheet” in the Trust column is your first roadmap row. The fix is usually rules, not software: one way to enter a gift, one definition of “active donor”, one person who can create new fields.

One owner per system is the rule that holds everything else up. Shared ownership means nobody notices when the renewal lapses or a departed employee still has admin rights. The owner is the person who decides what the system is for, not the person who does the most data entry.

How to choose a system without a demo deciding it

Vendor demos are built to make you feel a gap. Write your criteria before you watch a single demo, score each product against them, and let the demo answer your questions instead of setting them.

CriterionWhat to askWeight
Fit to the three jobsCan it do the three tasks you do most, the way you do them, without a consultant?High
Data in, data outCan you export everything, in a usable format, without asking permission?High
Who runs itCan your ops person administer it, or does every change need a paid partner?High
Total cost over three yearsLicence, setup, migration, training, and the integration you will need in year twoMedium
Funder constraintsDoes a grant or a fiscal sponsor require or forbid it?Medium
Other nonprofits your sizeCan you call two that switched to it and two that switched away?Medium
Dashboards and AI featuresIgnore during selection. They rarely change the outcome.Low

Three jobs, not thirty features. A donor database has to record a gift, receipt it, and report on it by segment. Score those jobs on a live trial with your own data, not the vendor’s sample records. The full walk-through, including how to run the trial and what to put in the contract, is in How to choose a nonprofit CRM .

When a funder dictates the system, you are no longer choosing. You are deciding how much of your operation to run inside the mandated tool and how much to keep beside it. Keep it as the system of record for that program only, not your whole donor database by default.

Security basics that are free

Ransomware appeared in 88% of breaches at small and medium businesses (under 1,000 employees) compared with 39% at large ones, per the Verizon 2025 Data Breach Investigations Report small business snapshot. The same report puts the human element in around 60% of breaches across every organization it studied, which means a person clicked, reused a password, or approved a login prompt. Those are the failures the free controls stop.

Four controls cost nothing beyond the licences you already pay.

  1. Multifactor authentication on email and every system with donor or client data. CISA states that MFA makes an account 99% less likely to be hacked. Turn it on for every staff account, board members included, and use an authenticator app rather than text messages where the system allows it.
  2. A written offboarding step. The day someone leaves, one person disables every login on the inventory sheet. The inventory’s Logins column is the checklist.
  3. Backups you have restored once. A backup nobody has tested is a hope. Restore one file from last month, on purpose, and note the date.
  4. Admin accounts separated from daily accounts. Whoever administers your email or database uses a second login for that job, so a phished daily account cannot change everyone’s settings.

For a longer list, CISA publishes a catalog of free cybersecurity services and tools, including vulnerability scanning of your public systems at no cost. Nothing on this list needs a security vendor, and none of it is a job for the board member’s cousin.

Budgeting technology as a share of expenses

The most recent benchmark that breaks out technology spend by budget size is old but still the best one available. NTEN’s 2017 Nonprofit Technology Staffing and Investments Report found an average technology budget of 5.7% of operating budget across all respondents, with medians well below the averages.

Operating budgetAverage tech spendMedian tech spend
Under $1M13.2%2.6%
$1M to $5M4.8%1.7%
$5M to $10M2.8%2.0%
Over $10M1.5%1.0%

Source: NTEN, 2017, with the size bands as NTEN defined them. Read the median as the typical organization and the average as the ones mid-replacement. At $3M and 1% you are probably deferring a replacement. At 5% you are in a project year or paying for licences nobody uses.

In the 2024 NTEN report, 45% of respondents said they spend too little on technology and 77% of those named available budget as the barrier. The same report found training at roughly 1% of technology budgets, which explains a lot of distrusted spreadsheets. The cheapest line to raise is training on what you already own.

Budget it in three lines: licences and subscriptions, one project (the roadmap row you will replace this year), and training at a real figure. Put the project in the year you will spend it.

Where to start this quarter

Build the inventory sheet. Fill the six columns for every system, name one owner per row, and mark the Trust column truthfully. Then turn on multifactor authentication for every account on the sheet. Those two steps take under a month. Do not choose a new system, hire a consultant, or form a board technology committee before the sheet exists.

When not to do this

Do not replace a system in the same year you replace the executive director, the finance lead, or the person who runs the current system. Migrations fail on people, not data, and the person who knew the old field names is the migration.

Do not buy a new system to fix a data problem. If the reports are wrong because entry is inconsistent, they will be wrong in the new system by month three. Fix the entry rules and rerun the report before you shop.

Do not start a roadmap when cash is under 60 days. Turn on MFA, test a backup, and come back when the reserve allows a project year.

Questions people ask

What is a nonprofit technology strategy?

A short set of written decisions about the systems you run, who owns each, which one you will change next, which security controls are on, and what you will spend. It fits on one page and gets rewritten once a year. It does not need a consultant to draft.

How much should a nonprofit spend on technology?

Medians in NTEN’s 2017 benchmark run from 2.6% of operating budget under $1M to 1.0% over $10M, with averages higher because of replacement years. Budget licences, one project, and training as separate lines. If training is near zero, raise that line before any other.

Does a nonprofit need a technology roadmap?

Yes, if you run more than eight systems or more than one person administers them. The roadmap is a four-row table, one change per quarter with an owner. Below that, an inventory sheet with named owners does the same job.

How do I choose a CRM for a nonprofit without getting sold to?

Write the three jobs the system must do, score candidates against criteria before any demo, and run a trial with your own data. Insist on full export rights, check that your own staff can administer it, and call two organizations your size that left the product.

What cybersecurity does a nonprofit need at minimum?

Multifactor authentication on every account, an offboarding checklist tied to your system inventory, a backup you have restored at least once, and separate admin logins. CISA reports MFA alone makes accounts 99% less likely to be hacked. None of the four requires a paid security product.

Who should own technology decisions in a nonprofit?

One named staff member per system, with the executive director owning the roadmap. Not the board, not a committee, and not a volunteer. The board approves the budget line and asks once a year whether the roadmap table was completed.

Start with these

Nonprofit technology roadmap on one page

A one-page technology roadmap you can write in two weeks. Every system with an owner and a renewal date, three moves for the year, a stop list, and a free template.

1 October 2026

All articles in this topic

Templates in this topic

Nonprofit technology roadmap template, one page

A one-page technology roadmap template with a system inventory, three moves, a stop list, five security checks, a budget line, and a sign-off. Docs and Word files.

Google Docs, Word (DOCX)