Human Services

Cybersecurity for the mission.

Protect case and donor data, and the systems your mission runs on, without overhead a nonprofit cannot carry.

The requirements come with the work

You hold some of the most sensitive records anyone holds, from case notes to children's records, on a budget where every dollar spent on operations is a dollar not spent on the mission. OrbitalFire helps smaller nonprofits protect case and donor data, meet the security conditions in their contracts and grants, and answer the funders who ask for proof.

There is rarely one statute with your name on it. The requirements come attached to the work. HIPAA follows the data if you deliver behavioral health or care management. NYSDFS Part 500 may apply if you handle financial services. Take a state contract, a federal grant, or a foundation award, and the security conditions sit in an agreement you have already signed.

What we help with

  • What you actually committed to

    Reading the security conditions across your contracts and grants, and turning them into one set of work rather than a separate scramble for each funder.

  • Where you stand today

    An Assessment mapped to whichever rules and funder conditions apply to you, with a roadmap ordered by risk so the first quarter is the quarter that matters most.

  • The documents funders name

    Policy and Plan Development, including the written information security policy and incident response plan your agreements ask for by name.

  • Training for ten minutes, not an afternoon

    Awareness Training and Phishing Testing sized for staff and volunteers who are between appointments.

  • The platforms holding your data

    Third Party Risk Management for the case management, payment, and fundraising systems holding records for the people you serve.

  • Running quietly in the background

    Vulnerability Management and Intrusion and Threat Detection, which need to keep working without adding to anyone's day.

  • So a bad morning stays a morning

    Incident Response planning and Incident Response Tabletops, rehearsed before they are needed.

  • Someone your board can hear from

    A vCISO who keeps the roadmap moving and can sit in front of your board with an independent read on it.

Progress, not a perfect score

Nobody expects a thirty person agency to look like a bank. What funders, auditors, and boards are looking for is that you know your risks, you have decided what to do about them, and you are making visible progress. Chasing every control at once is the fastest way to spend a grant on something that does not move.

We help you decide what comes first, and show the progress in a form your board and your funders can read.

  • Which rules actually apply to us?

    It depends on the work rather than on the sector. Behavioral health or care management brings HIPAA with the data, and our Healthcare page covers what that involves. Financial services can bring NYSDFS Part 500. Beyond that, most of what you owe sits in the contracts and grant agreements you have already signed. Working out which is part of the Assessment.

  • What do funders usually ask for?

    The list has been getting more specific: a written information security policy, an incident response plan, evidence that workforce training happened, and a named person responsible for security. Those four cover most of what shows up in grant conditions now.

  • We have one IT person. Do you replace them?

    No. We work alongside whoever handles your IT rather than instead of them. They keep the systems running and make the changes. We keep the risk picture, the documentation, and the roadmap current. That separation is also what several of these rules expect.

  • Can we do this on a nonprofit budget?

    That is the premise. Services are priced per user and month to month, and the roadmap is ordered by risk, so you are never paying to chase every control at once. Chasing all of them is the fastest way to spend a grant on something that does not move.

Tell us about your business.

A half-hour conversation about what you're being asked for and where you actually stand. If we can help, you'll have a proposal usually within a day.

Not ready to talk? Check your readiness in five minutes and see where to start.