Cyber Security for
Not-for-Profits & Charities

Donor, client and volunteer data deserves the same protection as any corporate system. We help charity boards secure their websites and platforms without enterprise budgets.

Pixelbird client
Pixelbird client
Pixelbird client

Over a decade of website security expertise

The Sector Is Exposed

Infoxchange’s 2025 survey of Australian and New Zealand not-for-profits found only 23% had a documented cyber security plan, and 14% had experienced a cyber breach in the previous 12 months.

Some of the sector’s largest incidents came through third parties. A Brisbane telemarketing contractor’s ransomware attack exposed donor details from around 70 charities, after it kept data for years beyond its contracts.

The ACNC made cyber security a compliance focus in 2024–25 and treats it as a governance responsibility of the people who run a charity.

Businessman Wearing Headset Talking To Caller In Busy Customer Services Centre

Practical

Security on

a Charity

Budget

Practical Security

on a Charity Budget

Practical Security

on a Charity Budget

Most charities don’t need an enterprise security program. They need their website, donation pages, client portals and volunteer systems patched, their vendors under control and old data deleted.

We start with a fixed-price audit that finds the issues that matter, written in plain English for your board. Then we fix them, or keep your platform maintained on a care plan, so you’re not paying for a big rebuild you don’t need.

It gives your Responsible People documented evidence that cyber risk is being managed with reasonable care and diligence.

Smiling mature confident professional executive manager at office.

Why Charities

Choose

Pixelbird

Why Charities

Choose Pixelbird

Why Charities

Choose Pixelbird

Donor & Client Data Focus

We map where donor, client and volunteer data lives, including fundraising platforms and contractors.

Vendor Offboarding

Ended contracts shouldn’t leave your data behind. We check which past and present vendors still hold it.

Plain-English Reporting

Reports your board and treasurer can read, with fixes prioritised by risk and cost.

0 %

Of NFPs Have a Documented Cyber Security Plan (2025)

0 %

Of NFPs Breached in the Past 12 Months (2025)

0

Charities Affected by One Contractor’s Breach

0 +

Years Shipping Production Software

How It Works

We confirm your website, donation, client and volunteer systems, and give you a fixed price.

Young African businessman looking at data on computer screen

Step 2: Audit Your

Platforms

Our engineers review your platforms, vendors and data handling, focused on what matters most.

Group of young happy business people looking at laptop screen, communocating and discussing work

Step 3: Fix

& Maintain

You get a board-ready report, and we can fix the issues and keep your platform patched.

Brands We Have Helped

What People Say

Makes the Magic Happen

“Love the professional finishes . Dustin and the team know how to make the magic happen.”

Sam Hunter

Sam Hunter

Corporate Headshot Photographer

Always Shows Up

“I have hired Pixelbird many times to build websites and to host. I recommend Dustin and his team without question.”

Kym Bolger

Kym Bolger

Social Media Marketing

Responsive Professionalism

“Dustin is friendly and good to work with. He is good at finding better ways to provide solutions and automate the processes.”

Ivan Huang

Ivan Huang

CPA

What You Can Expect

What’s Covered

Pixelbird

Generic IT Check

Website & Donations

With Us

Platform, plugins and payment scripts reviewed

With Them

Not in scope

Client Portals

With Us

Logins, access and data exposure checked

With Them

Not covered

Volunteer Systems

With Us

Access and offboarding reviewed

With Them

Ignored

Fundraising Vendors

With Us

Data held by contractors mapped

With Them

Not covered

Old Data

With Us

Retention and deletion reviewed

With Them

Kept forever

Email Authentication

With Us

SPF, DKIM and DMARC for appeals

With Them

Not checked

End-of-Life Software

With Us

Unsupported platforms flagged

With Them

Rarely mentioned

Board Reporting

With Us

Plain-English summary for Responsible People

With Them

Technical jargon

Remediation

With Us

We can fix what we find

With Them

You’re on your own

Pricing

With Us

Fixed, quoted up front

With Them

Hourly, open-ended

Frequently Asked Questions

Charities are covered if they meet the usual tests, such as annual turnover over $3 million, providing a health service or trading in personal information, and some opt in. Get advice on your own position.

The ACNC treats cyber security as a governance responsibility, consistent with Responsible People acting with reasonable care and diligence, and publishes a cyber security governance toolkit.

Yes. We review how your website and systems connect to fundraising, CRM and payment platforms, and what data each one holds.

The audit is a fixed price, from $1,950, and focuses on the issues that matter most. Fixes are quoted up front so your board can prioritise.

You own the report. Many organisations move onto a care plan so their platforms stay patched, but there’s no obligation.

Protect Your Donors, Clients and Volunteers