Who we work with

Not-for-Profit & Member Organisations

Not-for-profits carry the same privacy obligations as any other organisation holding personal information, usually without anyone whose job it is to meet them.

The defining constraint is that there is often no internal IT function at all — there is a person who is good with computers and a great deal of other work. Everything below has to work without a systems administrator watching it, because there is not one.

Donor and member data is the exposure. It is personal information under the Privacy Act, it is frequently the organisation’s most valuable asset, and it typically lives across a CRM, a mailbox, several spreadsheets and a volunteer’s laptop. A breach here costs the thing the organisation runs on, which is trust.

Budget shape matters as much as budget size. Grant funding rewards predictable operating cost and penalises unplanned capital spend, which favours managed services over owning infrastructure — provided the service is scoped to what is actually needed rather than to an enterprise template.

Where the work goes

What we focus on in this sector

Scope is agreed per engagement. These are the areas that consistently carry the most value here.

01

Managed without an admin

An environment that stays patched, backed up and monitored without depending on somebody internal remembering to check it.

02

Volunteers on their own devices

A work boundary on personally owned devices that protects organisational data and can be removed cleanly, without claiming access to anything personal.

03

Donor data with a boundary

Access to member and donor records granted by role, logged, and removed when someone stops volunteering — not left in a shared login.

04

Recovery that has been tested

Backup of Microsoft 365 and business systems with a restore that has actually been performed, because retention policies are not backup.

05

Cost that fits a grant cycle

Predictable monthly operating cost, scoped to the organisation’s actual size rather than an enterprise baseline.

Outcomes

What changes once it is running properly

  • An environment that does not depend on one person’s spare time
  • Volunteer devices that can be offboarded in a minute
  • Donor data with role-based access and an audit trail
  • A restore you have watched work
Services

What usually applies

A few of the organisations we have delivered for

Department of Defence
Department of Defence
Royal Australian Air Force
Royal Australian Air Force
Department of the Prime Minister and Cabinet
Department of the Prime Minister and Cabinet
Department of Foreign Affairs and Trade
Department of Foreign Affairs and Trade
Department of Home Affairs
Department of Home Affairs
Attorney-General’s Department
Attorney-General’s Department
Parliament of Australia
Parliament of Australia
Parliament of New South Wales
Parliament of New South Wales

Common questions

We are small. Is a managed service overkill?

It is the opposite — the smaller the internal team, the more of the environment depends on one person being available. The scope should match the organisation, and a small organisation should not be sold an enterprise baseline.

Volunteers use their own laptops and phones. What can we do?

Put a managed work boundary on the personal device. Organisational applications and data sit inside it and can be removed entirely when someone stops volunteering, while the personal side stays out of the organisation’s reach — and you can say that to volunteers truthfully.

Isn’t our Microsoft 365 data already backed up?

Not in the sense people mean. Microsoft protects the platform; retention policies and the recycle bin are not a backup, and they will not help against a deletion you only discover months later. That gap has an inexpensive answer, and it is worth closing before you need it.

Next step

Talk to us about Not-for-Profit & Member Organisations

Tell us what the environment looks like today. We will tell you honestly whether this is the right place to start.