Currently dealing with a breach or active incident?Call 406-924-3731×
≡
Nonprofits — Great Falls, Helena, Billings, and across Montana

Every dollar you spend on IT is one that doesn’t reach your mission.

You’re already holding a donor database, a payroll file, a Microsoft tenant nobody can find the admin for, and a donate button that has been taking gifts for years. We work three ways: a scoping engagement with a checklist your volunteer can run, security behind the person you already have, or full IT management.

The first assessment is free, and the findings are yours either way.

A community group meeting
10 min
Median first response
for security issues, measured in our own system over the last 90 days
100+
Incidents supported
by our team
7,500+
Devices monitored
under current contracts
5.0
On Google and Birdeye
Our standard

Vetted, tested, and in writing.

Every certified nonprofit is assessed by a third party risk assessor and keeps the required controls in place. When a funder asks how you protect donor information, you hand them a document instead of a promise.

Ransomware
● Response within 1 hour
Business email compromise
● Response within 1 hour
Backup recovery failure
● Response within 4 hours
The Big Sky Guarantee
We do the work.

Containment, forensics, eradication, recovery, and rebuilding if needed, at no additional cost, within defined service limits.

The Big Sky Guarantee is not an insurance policy. It’s our commitment to do the response work ourselves.

PLUS
The Big Sky Service Warranty
Up to $500,000

Eligible payments made directly to the organization, up to $500,000 per covered incident, depending on plan.

The Big Sky Service Warranty is not an insurance policy and does not replace cyber insurance.

For certified clients on Professional, Enterprise, or co-managed plans, with required controls in place. Eligibility requirements, service limits, and exclusions apply. Full terms are provided for your review before you sign. See which plans qualify

Why you’re reading this

Nobody goes looking for an IT until something happens.

The network went down and nobody could fix it

The server or the internet dropped, staff sat idle for most of a day, and the person who usually sorts these things out didn’t know where to start.

Your payment processor

A fee appeared, or a questionnaire arrived, and the answer options don’t match anything you recognize about how your organization works.

A funder or a major donor

They asked in writing, as a condition, how you protect donor information. The grant is in limbo until that’s answered.

Your cyber insurer

Renewal came back with a multifactor authentication requirement you can’t honestly verify with your current setup.

Your donate button

Is your donate button under the right PCI level?

There isn’t one PCI standard. There are several, and which one applies to you depends on how card data reaches you.

The short version

If your donate page hands off to a payment provider

An embedded form or a redirect, where the card never touches your website. Roughly two dozen questions, most completed in an afternoon.

The long version

If your website hosts the payment form itself

Well over a hundred requirements, including vulnerability scanning you almost certainly aren’t doing.

PCI is one of three things we check. The other two, who still has access to your systems and what happens when someone reads a staff mailbox for a month, cost Montana nonprofits more often than a compliance form does.

From a Montana nonprofit
“Big Sky Cybersecurity consistently goes above and beyond to support our needs as a non-profit business.”
Melissa T., Montana nonprofit

Not sure what you can afford to fix first?

The assessment is free, and the report is yours to take to your board either way.

What we usually find

Three things that cost Montana nonprofits money

None of them mean anyone was careless. Nobody ever gave them another option.

Found in nonprofits

Volunteers on their own laptops

Accessing your donor database from a home computer you’ve never seen, with a password they also use somewhere else.

Found in nonprofits

The person who left in March

Still in the donor CRM, the shared drive, the Facebook page, and the general email account. Turnover is high in this sector, and offboarding lists are rare.

Found in nonprofits

The mailbox someone read for a month

Someone gets into a staff mailbox with an old password, reads quietly for weeks, then sends messages from your own threads. By then they know your donors, your grants, and your staff.

Swiftcurrent Lake in Glacier National Park, Montana
How it works

Before you commit to anything.

Three steps, and you can stop after any of them with something useful in hand.

Step 01

We find what you’re running and what it would cost to lose

Donor database, email, backups, the Microsoft tenant, every place a card enters, and who has access to each. This step decides which PCI level you’re on.

Step 02

You get the report

In order by what could cost you the most, with a price next to each line. Take it to your board, or to your IT volunteer. It’s yours to roadmap from.

Step 03

If you want us to run IT

Full management starts at $75 per device per month, plus a per user charge, on a one year term. Certified clients on managed plans get The Big Sky Guarantee and Service Warranty.

What onboarding looks like

Keeping laptops online & defending donor data are different jobs.

Many Montana nonprofits have a volunteer, a board member’s relative, or a staff member who’s good with computers, doing a decent job with no budget, no tools, and no one to ask. We don’t replace them. We add what they can’t learn for free on evenings and weekends.

Days 1–5

We document before we touch anything

Licenses, credentials, warranty status, backups, and patch levels, plus who has access to what, including whatever has been quietly failing. That document is yours either way.

Days 6–10

We run alongside whoever you have now

Monitoring goes on before anything is cut over, so nothing breaks and you’re never without support. Anything urgent from week one gets fixed here.

Days 11–14

Cutover, scheduled around your calendar

Not during your gala week, and not during year end giving. About two weeks, signature to fully managed.

We check what you actually own. The Microsoft tenant where a former volunteer is the only admin, backups running to storage nobody can access, the domain registered to someone’s personal email: we check all of it in week one and tell you what’s yours, what isn’t, and what it costs to fix.

Paperwork on a nonprofit office desk
How we work with a nonprofit

Behind the person you already have.

What working with a Montana nonprofit looks like, written as what we do.

Before anything else
MFA on every account, including the shared ones and the ones volunteers use.
When someone leaves
Every account comes off: the donor CRM, the shared drive, the Facebook page, and the general email.
For your IT volunteer
Someone to ask at 2am, and the tooling to see a problem before it becomes one.
Every night
Backups run, and we test that they restore rather than taking the dashboard’s word for it.
When you call
Our support team is based in Montana, so someone here picks up, and contract clients get same day onsite.
Before anyone touches a system
Every engineer passes a background check first.
Forensics and ethical hacking

So we secure your systems the way attackers probe them.

CISSP Certified Ethical Hacker (CEH) CompTIA PenTest+ GIAC GCFA GIAC GCFE GIAC GNFA GIAC GCIH
Where we’re not the right fit

Times you should call someone else

We’d rather tell you on the first call than after your board has approved a budget.

01

All volunteer, no paid staff, and a handful of devices

You need multifactor authentication and a password manager, not a managed contract. We’ll tell you which ones on the call and how to set them up, free. Come back when you’ve grown.

02

Your IT is handled by a fiscal sponsor or a parent organization

Talk to them first. If they’re covering your systems properly, you’re already paying for it. If nobody can give you a straight answer about backups or who holds admin access, that’s worth a call.

03

You want the cheapest number

We aren’t hourly, and we aren’t the lowest quote. Certified clients get the response under The Big Sky Guarantee, within defined service limits; anyone else calling us at 2am pays $165 an hour.

FAQ

Frequently asked questions

What executive directors and boards ask before the first conversation.

We have almost no IT budget. Is this worth a call?

Sometimes the answer is that you shouldn’t hire us, and we’ll say so on the call. If you have paid staff and a donor database, co-managed costs less than full management, because we sit behind the person you already have.

How do I know which PCI level applies to us?

It depends on how card data reaches you. If your donate page hands off to a payment provider and the card never touches your website, you’re on the short questionnaire. If your site hosts the payment form itself, you’re on a much longer one. Every other place a card enters, like the gala terminal, the thrift store register, or a renewal taken over the phone, changes your scope.

We already have a volunteer handling IT. Do we have to replace them?

No, and most of the time we’d rather you didn’t. They know your organization, your people, and what has already been tried. What they usually don’t have is someone to ask at 2am, or the tooling to see a problem before it becomes one. That’s the part we add.

What changes the price?

Device count and which level of support you take, and nothing else. No setup fee, no per incident charges, and no emergency rates. If your device count drops because a program ended, the price drops with it at renewal.

Who actually does the work?

Engineers based in Montana who hold GIAC’s digital forensics certifications. The credentials that identify what an attacker saw and how long they were in are the same ones your board and your insurer ask about afterwards, and the person configuring your donor database access has read the logs of organizations that got hit.

Are we without support while we switch?

Never. We run alongside whoever you have now until cutover, so there’s no window where nobody is responsible. If something breaks during the switch, it’s ours to fix, and we schedule the cutover around your calendar.

What if the handoff from our current person goes badly?

We don’t require their cooperation. If passwords or admin access aren’t forthcoming, we rebuild access independently, and we’ll tell you on the first call which kind of handoff we think you’re going to get.

How do we know our backups would actually restore?

Because someone tests them. A backup that reports success every night and has never been restored is an assumption, not a safeguard. We check restore behavior during the first week, and we tell you what we found whether or not you hire us.

How it starts

Here’s what happens when you call.

The assessment is free, and the report is yours either way.

01
You call, and our team answers
After hours, you get a callback the next business day. We schedule an onsite visit, 30 to 45 minutes, at a time you pick.
02
We find what you’re running
Donor database, email, backups, the Microsoft tenant, and every place a card enters.
03
You get the report that same week
Ordered by risk and cost, with a fix and a price next to each line. Or see pricing now.
“Fantastic and timely support. Always professional with a great sense of humor!”
Mary Anne S., Montana nonprofit
5.0 on Google and Birdeye. Serving nonprofits from Great Falls, Helena, and Billings.Read the reviews
Sent. We’ll reply within one business day with a time for your assessment.
That didn’t send. Call 406-924-3731 and we’ll pick up.
We reply within one business day.