Every dollar you spend on IT is one that doesn’t reach your mission.
You’re already holding a donor database, a payroll file, a Microsoft tenant nobody can find the admin for, and a donate button that has been taking gifts for years. We work three ways: a scoping engagement with a checklist your volunteer can run, security behind the person you already have, or full IT management.
The first assessment is free, and the findings are yours either way.

Vetted, tested, and in writing.
Every certified nonprofit is assessed by a third party risk assessor and keeps the required controls in place. When a funder asks how you protect donor information, you hand them a document instead of a promise.
Containment, forensics, eradication, recovery, and rebuilding if needed, at no additional cost, within defined service limits.
The Big Sky Guarantee is not an insurance policy. It’s our commitment to do the response work ourselves.
Eligible payments made directly to the organization, up to $500,000 per covered incident, depending on plan.
The Big Sky Service Warranty is not an insurance policy and does not replace cyber insurance.
For certified clients on Professional, Enterprise, or co-managed plans, with required controls in place. Eligibility requirements, service limits, and exclusions apply. Full terms are provided for your review before you sign. See which plans qualify
Nobody goes looking for an IT until something happens.
The network went down and nobody could fix it
The server or the internet dropped, staff sat idle for most of a day, and the person who usually sorts these things out didn’t know where to start.
Your payment processor
A fee appeared, or a questionnaire arrived, and the answer options don’t match anything you recognize about how your organization works.
A funder or a major donor
They asked in writing, as a condition, how you protect donor information. The grant is in limbo until that’s answered.
Your cyber insurer
Renewal came back with a multifactor authentication requirement you can’t honestly verify with your current setup.
Is your donate button under the right PCI level?
There isn’t one PCI standard. There are several, and which one applies to you depends on how card data reaches you.
If your donate page hands off to a payment provider
An embedded form or a redirect, where the card never touches your website. Roughly two dozen questions, most completed in an afternoon.
If your website hosts the payment form itself
Well over a hundred requirements, including vulnerability scanning you almost certainly aren’t doing.
PCI is one of three things we check. The other two, who still has access to your systems and what happens when someone reads a staff mailbox for a month, cost Montana nonprofits more often than a compliance form does.
“Big Sky Cybersecurity consistently goes above and beyond to support our needs as a non-profit business.”
Not sure what you can afford to fix first?
The assessment is free, and the report is yours to take to your board either way.
Three things that cost Montana nonprofits money
None of them mean anyone was careless. Nobody ever gave them another option.
Volunteers on their own laptops
Accessing your donor database from a home computer you’ve never seen, with a password they also use somewhere else.
The person who left in March
Still in the donor CRM, the shared drive, the Facebook page, and the general email account. Turnover is high in this sector, and offboarding lists are rare.
The mailbox someone read for a month
Someone gets into a staff mailbox with an old password, reads quietly for weeks, then sends messages from your own threads. By then they know your donors, your grants, and your staff.

Before you commit to anything.
Three steps, and you can stop after any of them with something useful in hand.
We find what you’re running and what it would cost to lose
Donor database, email, backups, the Microsoft tenant, every place a card enters, and who has access to each. This step decides which PCI level you’re on.
You get the report
In order by what could cost you the most, with a price next to each line. Take it to your board, or to your IT volunteer. It’s yours to roadmap from.
If you want us to run IT
Full management starts at $75 per device per month, plus a per user charge, on a one year term. Certified clients on managed plans get The Big Sky Guarantee and Service Warranty.
Keeping laptops online & defending donor data are different jobs.
Many Montana nonprofits have a volunteer, a board member’s relative, or a staff member who’s good with computers, doing a decent job with no budget, no tools, and no one to ask. We don’t replace them. We add what they can’t learn for free on evenings and weekends.
We document before we touch anything
Licenses, credentials, warranty status, backups, and patch levels, plus who has access to what, including whatever has been quietly failing. That document is yours either way.
We run alongside whoever you have now
Monitoring goes on before anything is cut over, so nothing breaks and you’re never without support. Anything urgent from week one gets fixed here.
Cutover, scheduled around your calendar
Not during your gala week, and not during year end giving. About two weeks, signature to fully managed.
We check what you actually own. The Microsoft tenant where a former volunteer is the only admin, backups running to storage nobody can access, the domain registered to someone’s personal email: we check all of it in week one and tell you what’s yours, what isn’t, and what it costs to fix.

Behind the person you already have.
What working with a Montana nonprofit looks like, written as what we do.
So we secure your systems the way attackers probe them.
Times you should call someone else
We’d rather tell you on the first call than after your board has approved a budget.
All volunteer, no paid staff, and a handful of devices
You need multifactor authentication and a password manager, not a managed contract. We’ll tell you which ones on the call and how to set them up, free. Come back when you’ve grown.
Your IT is handled by a fiscal sponsor or a parent organization
Talk to them first. If they’re covering your systems properly, you’re already paying for it. If nobody can give you a straight answer about backups or who holds admin access, that’s worth a call.
You want the cheapest number
We aren’t hourly, and we aren’t the lowest quote. Certified clients get the response under The Big Sky Guarantee, within defined service limits; anyone else calling us at 2am pays $165 an hour.
Frequently asked questions
What executive directors and boards ask before the first conversation.
We have almost no IT budget. Is this worth a call?
Sometimes the answer is that you shouldn’t hire us, and we’ll say so on the call. If you have paid staff and a donor database, co-managed costs less than full management, because we sit behind the person you already have.
How do I know which PCI level applies to us?
It depends on how card data reaches you. If your donate page hands off to a payment provider and the card never touches your website, you’re on the short questionnaire. If your site hosts the payment form itself, you’re on a much longer one. Every other place a card enters, like the gala terminal, the thrift store register, or a renewal taken over the phone, changes your scope.
We already have a volunteer handling IT. Do we have to replace them?
No, and most of the time we’d rather you didn’t. They know your organization, your people, and what has already been tried. What they usually don’t have is someone to ask at 2am, or the tooling to see a problem before it becomes one. That’s the part we add.
What changes the price?
Device count and which level of support you take, and nothing else. No setup fee, no per incident charges, and no emergency rates. If your device count drops because a program ended, the price drops with it at renewal.
Who actually does the work?
Engineers based in Montana who hold GIAC’s digital forensics certifications. The credentials that identify what an attacker saw and how long they were in are the same ones your board and your insurer ask about afterwards, and the person configuring your donor database access has read the logs of organizations that got hit.
Are we without support while we switch?
Never. We run alongside whoever you have now until cutover, so there’s no window where nobody is responsible. If something breaks during the switch, it’s ours to fix, and we schedule the cutover around your calendar.
What if the handoff from our current person goes badly?
We don’t require their cooperation. If passwords or admin access aren’t forthcoming, we rebuild access independently, and we’ll tell you on the first call which kind of handoff we think you’re going to get.
How do we know our backups would actually restore?
Because someone tests them. A backup that reports success every night and has never been restored is an assumption, not a safeguard. We check restore behavior during the first week, and we tell you what we found whether or not you hire us.
Here’s what happens when you call.
The assessment is free, and the report is yours either way.
“Fantastic and timely support. Always professional with a great sense of humor!”
