MCR Business Tech Solutions

Services

Managed IT

The Volunteer Who Built Our Network in 2019 Just Moved to Charlotte

MCR Business Tech SolutionsSeptember 8, 20269 min read

The agency occupies the second floor of a building in Sharon, fifteen staff, a food pantry on the ground level, and housing case management funded by a mix of county contracts, state pass-through dollars, and a spring fundraiser. In 2019 a board member's brother-in-law, a retired engineer with time on his hands, set up their server, their wifi, their backups, and their email. He did it for free, he did it well enough, and he did it entirely in his own head.

In June he moved to Charlotte to be near his grandchildren. The executive director found out the domain renewal notice was going to an email address nobody could open, the backup drive in the closet had last written a file in February, and the only person who knew the server password was now nine hours away and, understandably, done.

That is the moment most nonprofits in Western Pennsylvania start looking for nonprofit IT support. Not a technology strategy. Not a digital transformation. Somebody who will answer the phone and actually own the thing that has been running on goodwill for six years.

Why is nonprofit IT support different from ordinary small business IT support?

The usual answer is that nonprofits have less money, which is true and also the least interesting part.

A fifteen person nonprofit carries obligations that a fifteen person plumbing company does not. It reports to funders who can ask for documentation. It often handles protected health information (behavioral health programs, home visiting, recovery services, anything billing a managed care organization), which puts it squarely under HIPAA with the same obligations as a medical practice and usually a fraction of the infrastructure. It takes donations online, which puts card data in scope. It keeps client records that are frequently more sensitive than anything a for-profit small business stores, because they describe housing status, family circumstances, and medical need.

It also has a workforce shape that no business has. Full-time staff, part-time staff, AmeriCorps or intern placements that turn over on a schedule, contractors, and volunteers who need enough access to be useful and no more. People arrive and leave constantly, and every one of them gets an account.

Then there is the board. A nonprofit's technology spending is visible in a way a company's is not. It appears in a budget that gets reviewed line by line by volunteers who are personally liable for the organization's governance, some of whom will ask why the IT number went up, and all of whom deserve an answer better than "it just did."

So nonprofit technology support is not a discounted version of business IT. It is business IT plus compliance, plus high turnover access control, plus the requirement that every dollar can be explained to a room.

What does donated equipment actually cost a nonprofit?

Every nonprofit we have worked with has a closet. Inside the closet are laptops a law firm cleaned out three years ago, a couple of desktops from a bank branch that closed, monitors of four different vintages, and a printer nobody can find a driver for.

Donated hardware is not free. It is prepaid, and the bill arrives later.

A five year old laptop out of a corporate refresh has a battery near the end of its life, a drive with real wear on it, and often an operating system version that is either out of support or about to be. The staff member who receives it loses fifteen minutes a day to slowness, which across a year is roughly a working week of a caseworker's time that funders paid for. When the drive fails, the failure lands mid-week on the person with the most client contact.

The mixed fleet is the deeper cost. Nine different machines in nine different configurations means nothing can be standardized, patching cannot be verified in one place, and every support call starts with an inventory question. That is exactly the environment where patch management stops being a checkbox and becomes the difference between a monitored fleet and a hopeful one.

The right answer is not refusing donations. It is setting a floor. Accept hardware above a defined age and specification, decline what falls below it (gracefully, with thanks), and price the alternative honestly: a standardized refurbished machine bought through a nonprofit hardware program usually costs less over three years than a free laptop that consumes support hours and dies in eighteen months.

Which technology grant programs should a nonprofit check before spending anything?

Before a nonprofit buys a single license, somebody should check what it is already entitled to.

Registered 501(c)(3) organizations qualify for nonprofit programs from most of the major software vendors, and for discounted or donated licensing and hardware through nonprofit technology marketplaces. The catch, and it is a real one, is that the terms of these programs have changed meaningfully in the last couple of years. Grant tiers that used to be free are now discounted, seat counts have moved, and eligibility rules have been tightened. A board member who remembers a program from 2021 may be remembering something that no longer exists in that form.

So the step is to verify current eligibility and current terms rather than assume, and to do it before the budget is set rather than after. We do this as part of onboarding, and it is common for it to cover a meaningful share of a nonprofit's annual software spend.

Two cautions. First, a discount on licensing is not a discount on the work: the grant gives you the tenant, not the configuration, and an unconfigured Microsoft 365 tenant with no conditional access, no retention policy, and no multifactor enforcement is a liability with a logo on it. Proper Microsoft 365 administration is where the security actually lives. Second, grants tend to arrive as a pile of entitlements nobody has mapped to the organization's needs, which is how agencies end up paying for a second backup product they already had.

What should managed IT services for a non profit cost, and how is it budgeted?

Managed IT services for a non profit are priced the same way they are for any organization of the same size and complexity, most often per user or per device with the scope written down. What differs is how the number gets justified and where it gets funded from.

Three things make that easier. First, a flat monthly figure is far better for a nonprofit than hourly billing, because it can be entered in a budget in October and will still be true in June, and because it removes the incentive to avoid calling for help (an incentive that in practice means problems get reported late, when they are expensive). We wrote about how flat-fee pricing is actually built in our piece on what managed IT services cost in Western PA, and the mechanics are the same here.

Second, technology is frequently an allowable cost. Under federal and state pass-through funding, IT can often be charged as a direct cost when it is allocable to a specific program, or recovered through the indirect cost rate. Many agencies underclaim here simply because nobody has ever asked the question of their fiscal officer. That conversation is worth having before the next contract cycle, not after.

Third, capacity building and technology grants exist at both the regional and national level, and community foundations in Mercer, Lawrence, and Crawford counties have funded technology modernization before. Those applications go far better when the organization can attach an actual assessment and a costed plan rather than a paragraph of intent.

The number to avoid is zero. An organization running on a volunteer, a closet of donated laptops, and no line item has not saved money. It has moved the cost onto staff time and onto risk, and neither shows up in the budget until something breaks.

Does a fifteen person nonprofit really need to worry about cybersecurity?

Yes, and the reasoning is not the one people expect.

Nonprofit cybersecurity matters less because attackers are targeting charities specifically and more because most attacks are indiscriminate. Automated credential stuffing and phishing campaigns do not check tax status. What they do check, effectively, is whether multifactor authentication is on and whether anyone is watching, and a fifteen person agency with a volunteer-built network typically fails both.

The exposure is unusually asymmetric. A nonprofit holds client data that is often more sensitive than a business's customer list, and if it is HIPAA-bound it carries breach notification obligations identical to a hospital's. It moves money in ways that are easy to imitate, which is why fake-invoice and payroll-diversion fraud land so often on organizations where the executive director approves payments by email. And it survives on reputation with donors and funders, which means the reputational consequence of a breach is disproportionate to its size.

The countermeasures are not exotic: multifactor authentication everywhere, managed endpoint protection rather than whatever antivirus shipped with the donated laptop, offsite backups that are actually tested, and a payment approval process that requires a voice. None of that is expensive. All of it requires somebody to own it.

Increasingly the question also arrives from outside. Funders and county contracting offices have started asking about data handling, and cyber liability insurers ask at renewal. We covered what that review looks like in what a cyber security audit actually examines, and the questions do not get softer because the answering organization is a charity.

What happens when the volunteer who set everything up leaves?

This is the failure mode we see most, and it is a documentation problem rather than a technical one.

When one trusted person builds everything informally, the organization ends up not owning its own infrastructure. The domain is registered to a personal account. The Microsoft tenant's global administrator is a Gmail address. The firewall password exists in one person's memory. The backup is a drive somebody remembers to swap. None of that is malice, and all of it is a single point of failure that the board is unaware it has accepted.

The fix is unglamorous and takes about a week. Inventory what exists. Move every registration, tenant, and license into accounts owned by the organization with the executive director as a recorded contact. Write down what runs where and who to call. Establish real backups with restores that get tested rather than assumed. Then set up onboarding and offboarding so accounts stop outliving the people they belonged to. If your organization is living through the departure version of this right now, the sequence we walk through in our IT guy quit, now what applies almost word for word.

After that, ongoing managed IT support exists mainly so it never happens again: patching and monitoring that continue whether or not anybody is thinking about them, a help desk staff can call without feeling like they are imposing on a volunteer, and a written record that survives any individual, including us.

The agency in Sharon got its domain back in about ten days, mostly spent proving to a registrar that the organization was who it said it was. The server turned out to be fine. The backups had not run since February, which is the part the executive director still thinks about, because for four months an incident would have cost them every client record they had, and nobody in the building would have known until they went looking.

MCR Business Tech Solutions provides nonprofit IT support, cybersecurity assessments, and ongoing managed IT for nonprofit and human services organizations across Mercer, Lawrence, Butler, Crawford, Erie, Armstrong, and Allegheny counties (Sharon, Hermitage, Grove City, Greenville, New Castle, Butler, Meadville, Erie) plus bordering eastern Ohio and northern West Virginia. If your technology is currently held together by one person's goodwill, call 833-859-9021 or Request an IT assessment through our contact page, and we will start by writing down what you actually have.

nonprofit it supportmanaged it services for non profitnonprofit cybersecuritynonprofit technology supportgrant compliancemercer countywestern pa

Talk to us

Ready for IT
that just works?

No commitment. No sales pitch. Just a straightforward conversation about your tech.

Keep reading

Related articles

Managed IT

Our IT Guy Quit. Now What? A Survival Plan for Western PA Small Businesses

When your in-house IT person leaves, the password vault walks out the door with them. A 72-hour survival plan for Western PA small businesses, plus how managed IT services replace the one-IT-guy model.

Managed IT

Three IT Companies, Three Wildly Different Prices, and Not One of Them Explained Why.

If you have collected quotes from IT providers and felt like you were comparing apples to bowling balls, you are not doing it wrong. Managed IT services pricing is quoted so many different ways (per user, per device, tiered, all-inclusive) that three honest companies can look completely different on paper. Here is a plain-English breakdown of how managed IT is actually priced, what you are really paying for, what pushes the monthly number up or down, why the cheapest quote is often the most expensive, and how a business in Butler, Mercer, or Lawrence county can compare providers without the apples-to-oranges mess.

Cybersecurity

Our Biggest Customer Sent Us a Security Questionnaire and Nobody Here Can Answer It

Most small businesses do not go looking for cyber security audit services. They get asked for one: by a cyber liability insurer at renewal, by a large customer running a vendor security review, or by a regulator. Here is what a cyber security audit actually examines, how it differs from a vulnerability scan and from cyber security risk assessment services, what happens when the findings are bad, how long it takes, and how often a 5 to 50 employee business in Western Pennsylvania actually needs one.

Call 833-859-9021Get Assessment