ONG (Setor Social)
IT/Cybersecurity RFP
Detalhes
Descrição
The purpose of this RFP is to solicit proposals from experienced IT and cybersecurity firms to:
- Establish foundational IT and cybersecurity practices (we can share results from an initial
exposure scan)
- Reduce operational and financial risk
- Improve nonprofit audit readiness and governance
- Provide ongoing, right-sized IT and security support as we continue to grow
- Ensure compliance with data protection regulations
Given our size and priorities, Nest is seeking a pragmatic, phased approach that prioritizes material risk
reduction over enterprise-scale solutions.
Scope of Work
Comprehensive IT Audit & Risk Assessment
The selected vendor will conduct an initial assessment to establish Nest’s IT and cybersecurity baseline.
Expected activities include:
Scope:
- Creating an organized framework demonstrating how our organization currently operates
(processes, technology, data)
- Identification of key IT and cybersecurity pain points and risks
Deliverables:
- Written risk assessment summary
- Prioritized remediation roadmap (0–3 months, 3–6 months, 6–12 months, 12+ months)
Core IT & Security Needs
The selected vendor will propose implementation and/or management solutions across the following:
Identity & Access Management
Scope:
- Review current identity and access management practices
- Provide role-based access control recommendations
- Implement or optimize multi-factor authentication (MFA) and related access controls
Deliverables:
- Recommend a restructure of account hierarchy, shared drives, groups, and security settings
designed to reduce risk exposure to scams
- Centralize identity and access management framework documentation
Backup & Recovery
Scope:
- Assess backup coverage and storage architecture across systems and data repositories (Note:
Nest currently has no formal backup practices beyond Google Drive's native retention features,
and no separate backup or retention method for data held in other platforms such as Sage
Intacct or Salesforce.)
- Recommend testing cadence and recovery procedures
Deliverables:
- Documented backup recovery strategy
- Backup testing plan and testing schedule
- Documentation of recovery procedures and timelines
Secure Remote Access
Scope:
- Evaluate current remote access methods and tools
- Recommend secure remote access solutions appropriate for Nest’s environment
- Review third-party applications and access pathways
- Recommend a standardized antivirus / endpoint protection solution
Deliverables:
- Security control documentation for remote access
- Develop timeline and plan for deploying antivirus / endpoint protection solution
- Staff training on security awareness
- Documentation of required staff behavior changes to ensure compliance with recommendations
Data Protection and Privacy Requirements
The selected vendor will support the organization in maintaining strong compliance with applicable
global data protection regulation including:
Scope:
- Support compliance with relevant international standards and laws, including:
- Compliance with EU General Data Protection Regulation (GDPR)
- Compliance with applicable U.S. federal and state privacy laws (e.g., CCPA), in addition
to GDPR and other international requirements, given Nest's U.S.-based donor base
- Guidance for organizations like Nest handling EU resident data
- Alignment of privacy policies with appropriate, recognized security frameworks
- Develop an incident response plan for security breaches, aligned to regulation requirements
Deliverables:
- Data compliance assessment or gap analysis
- Compliance roadmap with prioritized remediation actions
Policies, Governance & Audit Readiness
The selected vendor will support the development of right-sized, nonprofit-appropriate governance
documentation and processes to strengthen Nest’s IT security posture and support audit readiness.
Scope:
- Conduct a review of Nest’s current IT security practices an documentations in relation to
existing audit requirements and industry best practices
- Draft practical and enforceable IT governance policies appropriate for a globally operating
nonprofit environment
- Ensure policies address key areas such as cybersecurity risk management, data processing and
protection, backup and recovery, and data retention and deletion
Deliverables:
- A set of practical, enforceable IT governance policies aligned with Nest’s audit requirements and
operational needs
- Recommendations for a lightweight change management system to reduce risks associated with
emergency or undocumented systems changes
- Staff training on incident reporting and data protection requirements
Ongoing Support & Advisory Services
The selected vendor may support ongoing support services. Proposals should describe a support model,
including:
- Help desk or user support approach for Nest staff
- Ongoing security monitoring including periodic (quarterly or semi-annual) security reviews
- Named point of contact and escalation procedures (Note: board member accounts were
previously targeted in phishing attempts. Vendor support will cover @buildanest.org accounts,
including board members using Nest email addresses; assistance with accounts outside the
buildanest.org domain will likely be limited.)
Optional
Proposals may include optional services with separate pricing, such as:
- Device management (inventory tracking and lifecycle management)
- Support for our annual audit
Benefícios
NA - IT/Cybersecurity RFP
Nível de Proficiência do Idioma
English proficiency
Localização
Local Associado
Como se inscrever
Please contact cleopatra@buildanest.org with questions. The Full RFP is below:
Proposal Submission Requirements
Interested vendors should submit proposals according to the following requirements:
- Submission deadline: proposals will be reviewed on a rolling basis, with priority given to
proposals received by September 11, 2026 at 5 pm, EST.
- Submission format: proposals should be submitted as a PDF via email to Cleopatra Frazier at
- Point of contact: all questions regarding this RFP should be directed to Cleopatra Frazier at
cleopatra@buildanest.org. Vendors should not contact other Nest staff directly regarding this
RFP.
- Proposal contents should include: a scope of work response addressing each section above, an
itemized pricing breakdown, a proposed timeline, vendor qualifications (see below), and at least
two references from comparable engagements.
Vendor Qualifications
To be considered, vendors should demonstrate:
- Prior experience working with nonprofit organizations, ideally of comparable size and
remote-first structure to Nest.
- Experience supporting organizations with a distributed, fully remote workforce.
- At least two references from past clients, ideally including at least one nonprofit client.
- Direct experience remediating or preventing incidents similar to those Nest has previously
encountered, including financial fraud and phishing-based social engineering.
- Proof of the vendor's own cyber liability insurance, including coverage amount, submitted with
the proposal.
Nest Request for Proposal
IT & Cybersecurity Services
Organizational Overview
Nest is a fully remote nonprofit organization dedicated to preserving craft traditions and expanding
economic opportunity for artisans and makers worldwide. Nest works with a distributed staff and relies
on cloud-based systems to support its programs and operations.
Nest currently has no internal IT staff and is seeking a qualified external partner to provide IT and
cybersecurity services appropriate to its size, risk profile, and nonprofit context.
Nest currently operates with:
- Fully remote workforce using personally assigned computers (both MacOS and Windows)
- Phones/computers are intermingled between work and personal use
- Staff primarily located in the U.S. and Europe
- No servers, firewalls, or on-premises infrastructure
- Core systems include Google Suite, Justworks (PEO), Zoom, Canva, Salesforce/Virtuous, Sage
Intacct, and SAP Concur as well as secondary systems such as Dropbox, Docusign, Microsoft
365, Asana, MediaGraph, Meta, Flodesk and Squarespace
- No standardized account ownership, single sign on (SSO), or password policies for above
systems
- Legacy shared-login accounts (e.g., info@) accessed by multiple staff simultaneously, which
currently block org-wide multi-factor authentication (MFA) enforcement ahead of Google's
October 20, 2026, 2-Step Verification requirement for Cloud Console access
- No formal IT, cybersecurity, or incident response policies or staff (basic day-to-day support
provided by Operations staff)
- History of attempted cybersecurity attacks (bank fraud which has since been contained and
addressed, phishing schemes, targeting of board member emails, etc.);
- Works with a wide range of donors, grantee partners, vendors, and third parties based across the
globe (e.g., individuals, small businesses, cooperatives, multi-national corporations)
Purpose of This RFP
The purpose of this RFP is to solicit proposals from experienced IT and cybersecurity firms to:
- Establish foundational IT and cybersecurity practices (we can share results from an initial
exposure scan)
- Reduce operational and financial risk
- Improve nonprofit audit readiness and governance
- Provide ongoing, right-sized IT and security support as we continue to grow
- Ensure compliance with data protection regulations
Given our size and priorities, Nest is seeking a pragmatic, phased approach that prioritizes material risk
reduction over enterprise-scale solutions.
Scope of Work
Comprehensive IT Audit & Risk Assessment
The selected vendor will conduct an initial assessment to establish Nest’s IT and cybersecurity baseline.
Expected activities include:
Scope:
- Creating an organized framework demonstrating how our organization currently operates
(processes, technology, data)
- Identification of key IT and cybersecurity pain points and risks
Deliverables:
- Written risk assessment summary
- Prioritized remediation roadmap (0–3 months, 3–6 months, 6–12 months, 12+ months)
Core IT & Security Needs
The selected vendor will propose implementation and/or management solutions across the following:
Identity & Access Management
Scope:
- Review current identity and access management practices
- Provide role-based access control recommendations
- Implement or optimize multi-factor authentication (MFA) and related access controls
Deliverables:
- Recommend a restructure of account hierarchy, shared drives, groups, and security settings
designed to reduce risk exposure to scams
- Centralize identity and access management framework documentation
Backup & Recovery
Scope:
- Assess backup coverage and storage architecture across systems and data repositories (Note:
Nest currently has no formal backup practices beyond Google Drive's native retention features,
and no separate backup or retention method for data held in other platforms such as Sage
Intacct or Salesforce.)
- Recommend testing cadence and recovery procedures
Deliverables:
- Documented backup recovery strategy
- Backup testing plan and testing schedule
- Documentation of recovery procedures and timelines
Secure Remote Access
Scope:
- Evaluate current remote access methods and tools
- Recommend secure remote access solutions appropriate for Nest’s environment
- Review third-party applications and access pathways
- Recommend a standardized antivirus / endpoint protection solution
Deliverables:
- Security control documentation for remote access
- Develop timeline and plan for deploying antivirus / endpoint protection solution
- Staff training on security awareness
- Documentation of required staff behavior changes to ensure compliance with recommendations
Data Protection and Privacy Requirements
The selected vendor will support the organization in maintaining strong compliance with applicable
global data protection regulation including:
Scope:
- Support compliance with relevant international standards and laws, including:
- Compliance with EU General Data Protection Regulation (GDPR)
- Compliance with applicable U.S. federal and state privacy laws (e.g., CCPA), in addition
to GDPR and other international requirements, given Nest's U.S.-based donor base
- Guidance for organizations like Nest handling EU resident data
- Alignment of privacy policies with appropriate, recognized security frameworks
- Develop an incident response plan for security breaches, aligned to regulation requirements
Deliverables:
- Data compliance assessment or gap analysis
- Compliance roadmap with prioritized remediation actions
Policies, Governance & Audit Readiness
The selected vendor will support the development of right-sized, nonprofit-appropriate governance
documentation and processes to strengthen Nest’s IT security posture and support audit readiness.
Scope:
- Conduct a review of Nest’s current IT security practices an documentations in relation to
existing audit requirements and industry best practices
- Draft practical and enforceable IT governance policies appropriate for a globally operating
nonprofit environment
- Ensure policies address key areas such as cybersecurity risk management, data processing and
protection, backup and recovery, and data retention and deletion
Deliverables:
- A set of practical, enforceable IT governance policies aligned with Nest’s audit requirements and
operational needs
- Recommendations for a lightweight change management system to reduce risks associated with
emergency or undocumented systems changes
- Staff training on incident reporting and data protection requirements
Ongoing Support & Advisory Services
The selected vendor may support ongoing support services. Proposals should describe a support model,
including:
- Help desk or user support approach for Nest staff
- Ongoing security monitoring including periodic (quarterly or semi-annual) security reviews
- Named point of contact and escalation procedures (Note: board member accounts were
previously targeted in phishing attempts. Vendor support will cover @buildanest.org accounts,
including board members using Nest email addresses; assistance with accounts outside the
buildanest.org domain will likely be limited.)
Optional
Proposals may include optional services with separate pricing, such as:
- Device management (inventory tracking and lifecycle management)
- Support for our annual audit
Pricing & Budget
Nest anticipates a budget of $20,000 – $25,000 for an initial four-month implementation engagement.
Nest anticipates completing the core scope of work outlined above by December 2026, with ongoing
support and advisory services considered as a separate, subsequent engagement, which should be
clearly noted as such in the proposal. Proposals should include:
- Total cost and cost breakdown by service area
- Implementation timeline
- Assumptions and clear exclusions
- Contract term and termination provisions (Nest's preference: an initial term with a renewal
option.)
- Payment terms, including any applicable deposits or retainer fees
