View Video
Subscribe to our Youtube Channel here
with Nuradeen Aboki and Johan Hammerstrom
Is it time for an IT assessment at your nonprofit? Maybe it’s part of a grant requirement. Maybe you have new leadership who wants an outside view of your systems. Maybe you’re evaluating a change in IT providers.
Whether you’ve had an assessment before or this would be your first, it helps to know what you’re getting into, and what a good assessment actually looks like.
Webinar: Doing an IT Assessment at Nonprofits
Not all IT assessments are the same. Some MSPs offer a quick, free assessment as part of their sales process, or onboarding process, and that might be all your nonprofit needs. Other assessments can cost six figures. In this session, Johan Hammerstrom and Nuradeen Aboki walk through Community IT’s approach to a comprehensive IT assessment: what it covers, how long it takes, and what you get out of it.
Join Community IT with CEO Johan Hammerstrom and Senior IT Consultant Nuradeen Aboki for a conversation about what a thorough, nonprofit-focused IT assessment involves and why you might want one. They cover the four categories a strong assessment should evaluate: infrastructure and core systems, data and digital platforms, security and compliance, and governance and strategy. They also discuss the discover, evaluate, align, and plan approach Community IT uses to move from findings to an actionable roadmap.
The conversation covers how to vet an assessment provider so you can tell the difference between an independent, agnostic evaluation and one designed to lead you toward a sale; what a healthy nonprofit IT environment looks like in practice; and the typical next steps if your assessment points toward changing IT support.
Community IT is proudly vendor-agnostic, and our webinars cover a range of topics and discussions. Webinars are never a sales pitch, always a way to share our knowledge with our community.
As with all our webinars, this presentation is appropriate for an audience of varied IT experience.
Presenters:

Nuradeen Aboki is a Senior Consultant at Community IT. In that role, he proactively oversees technology infrastructure for select clients, providing strategic IT advice, recommending IT solutions and solution design to meet business objectives, and then overseeing solution implementations. Nura provides leadership and guidance for strategic planning and solutions architecting with clients who have sophisticated technical and business requirements. He gathers core business, technical and IT service management requirements through a variety of activities including key stakeholder interviews, document review and technical assessments.
Nura started his career at Community IT as a Network Administrator. In 2012, he was promoted to Network Engineer and assumed a supervisory role in IT service operations, then became an IT Business Manager, where he has guided some of our largest clients through complex implementation of effective technology investments and utilizing efficient IT services in direct support of their missions. He has a lot of experience in helping nonprofits discover nonprofit IT essentials for challenging times, and is our resident expert on the value of governance and IT policies, and how to craft them.
Prior to joining Community IT Innovators, Nura served as a member of the technical support team at George Washington University and held a Network Specialist role at the Economic Community of West African States (ECOWAS) Parliament in Abuja, Nigeria. Nura holds a Bachelor of Science in Computer Engineering and Master of Science in Electrical Engineering, both from George Washington University.

Johan Hammerstrom’s focus and expertise are in nonprofit IT leadership, governance practices, and nonprofit IT strategy. In addition to deep experience supporting hundreds of nonprofit clients for over 20 years, Johan has a technical background as a computer engineer and a strong servant-leadership style as the head of an employee-owned small service business. After advising and strategizing with nonprofit clients over the years, he has gained a wealth of insight into the budget and decision-making culture at nonprofits – a culture that enables creative IT management but can place constraints on strategies and implementation.
As CEO, Johan provides high-level direction and leadership in client partnerships. He also guides Community IT’s relationship to its Board and ESOP employee-owners. Johan is also instrumental in building a Community IT value of giving back to the sector by sharing resources and knowledge through free website materials, monthly webinars, and external speaking engagements.

Carolyn Woodard is currently head of Marketing and Outreach at Community IT Innovators. She has served many roles at Community IT, from client to project manager to marketing. With over twenty five years of experience in the nonprofit world, including as a nonprofit technology project manager and Director of IT at both large and small organizations, Carolyn knows the frustrations and delights of working with technology professionals, accidental techies, executives, and staff to deliver your organization’s mission and keep your IT infrastructure operating. She has a master’s degree in Nonprofit Management from Johns Hopkins University and received her undergraduate degree in English Literature from Williams College. She loved talking with Johan and Nura about doing IT assessments at nonprofits and what they have learned over the years.
Transcript:
Carolyn Woodard: Welcome everyone to the Community IT Innovators webinar on doing IT assessments at nonprofits with Nuradeen Aboki and Johan Hammerstrom. There are a lot of reasons why a nonprofit or a foundation might want to do an IT assessment. It might be recommended as part of a grant you’re receiving. You may have a change in personnel or leadership, and the new person wants an outside assessment to understand your systems and your priority projects. You may be changing providers, and the new MSP starts off with an assessment. So whether you’ve had an assessment done before or this is your first one, it helps to know what you’re getting into.
My name is Carolyn Woodard. I’m the outreach director for Community IT, and I’ll be the moderator today. I’m very happy to hear from our experts, but first I want to go over our learning objectives. So today we want to focus on these themes: What is an IT assessment? What does it typically include, and why should you have one done? What does a healthy nonprofit IT environment look like? Is there a checklist? And what if your assessment tells you it’s time to change your IT support? What are the typical next steps? So, Nura, would you like to introduce yourself?
Nuradeen Aboki: Thanks, Carolyn. I’m Nuradeen Aboki, a senior consultant at Community IT. In my work with nonprofit assessments, it’s really about helping organizations understand what their network is today and where risk, or you could say even friction, may show up, and what practical steps can help them move forward. So I’ll be focusing on what the process looks like from the inside, what to look for, how we organize findings, and how recommendations become something a nonprofit can actually use. And now I’ll ask Johan to introduce himself.
Johan Hammerstrom: Thank you, Nura. Good afternoon, everyone. Thanks for joining us today.
My name is Johan Hammerstrom, I’m the CEO at Community IT. I’ve been helping nonprofit organizations with IT support for over 25 years. And in that time, I’ve had the opportunity, the privilege, to assess a lot of nonprofit IT environments. I’m very excited today because we’re going to talk a little bit about the current version of the assessment that we do at Community IT, which has really matured a lot in the last three or four years. And I think it’s really matched what we’ve found to be a growing priority on IT maturity in the nonprofit sector. So we’re excited to be here with you today, and thank you for joining us.
Carolyn Woodard: And before we begin, if you’re not familiar with Community IT, a little bit about us. We are a 100% employee-owned managed services provider. We provide outsourced IT support. We work exclusively with nonprofit organizations, and our mission is to help nonprofits accomplish their missions through the effective use of technology. We are big fans of what well-managed IT can do for your nonprofit. We serve nonprofits across the United States, and we’ve been doing this for 25 years.
We are technology experts and are consistently given an MSP 501 recognition for being a top MSP, which is an honor we just received again in 2026, and we believe we’re the only MSP on the list serving nonprofits exclusively. I want to remind everyone for these presentations that Community IT is vendor agnostic. We only make recommendations to our clients, and we only base those on their specific business needs. We never try to get a client into a product because we get some kind of incentive or benefit from that. We do consider ourselves a best of breed provider, so it’s our job to know the landscape: what tools are available, reputable, and widely used. And we make recommendations on that basis for our clients based on their business needs, priorities, and budget.
So we’re recording this presentation today without an audience because of some scheduling issues. So while we don’t have an audience Q&A today, if you do have questions about this topic, you can always join us and our experts at any time in our community on Reddit at r/nonprofitITmanagement. And we try to answer questions over there within about a week. You can also contact us through our website at www.communityit.com.
A little bit more about us. Our mission is to create value for the nonprofit sector through well-managed IT. We also identify four key values as employee owners that define our company: trust, knowledge, service, and balance. We seek to always treat people with respect and fairness, to empower our staff, clients, and our sector to understand and use technology effectively, to be helpful with our talents, and we recognize that the health of our communities is vital to our well-being and that work is only a part of our lives. And with that, I want to turn it over to Johan, who I think can walk us through this slide of what is an IT assessment at a nonprofit.
What Is an IT Assessment?
Johan Hammerstrom: Thank you, Carolyn. We wanted to talk a little bit specifically about the approach that we take to IT assessments, which is very well defined, something that has a very specific methodology associated with it. It’s possible to get an IT assessment that can cover all kinds of different activities. If you bring on a new IT support provider, they might conduct an assessment of your network. If you’re working with a third-party consultant, particularly to select a new software solution, they may assess certain aspects of your data and the IT systems you’re using.
But at Community IT, when we talk about an IT assessment, we’re talking about something very specific, and we wanted to define that at the outset. So from our perspective, an IT assessment is a structured review of all aspects of IT. It’s comprehensive, and it’s intended to look not just at one particular component of an organization’s IT environment, but to look at all of those components.
So we look at IT systems: all your laptops, your cloud-hosted systems, all of your applications, the different solutions that you’re using to do your work. That’s pretty common and pretty typical.
But we also look at IT operations. So we don’t want to look just at the technology that’s being used; we want to look at how it’s being maintained, how it’s being supported, how the staff in the organization are being supported in their use of those systems. So IT operations is a critical part of the evaluation that’s being done during an assessment. We especially want to look at risks, and in this day and age that’s critically important, particularly cybersecurity-related risks.
We also look at IT governance: how are IT decisions being made in the organization? How is the IT team formed? Who’s overseeing that team? How is their performance being monitored and evaluated over time?
And then finally, looking at future needs: where is the organization headed, and how is technology evolving to meet the future needs of the organization?
So the IT assessment is supposed to be comprehensive and very thorough. For that reason, it usually takes seven to nine weeks to conduct a complete IT assessment. There are a variety of activities that are conducted during that period of time. Those activities include interviews with key stakeholders, and the number of interviews that need to be conducted really varies based on the circumstances and the situation of the organization. But it usually varies between three or four interviews on the low end and 10 to 12 interviews on the high end. Oftentimes we’ll do group interviews, so we’ll meet with multiple stakeholders at the same time.
In addition to the interviews, we’re conducting technical discovery. Oftentimes that means running tools that scan the network for vulnerabilities, for example, or looking at other aspects of the various IT systems. It always involves hands-on evaluation of the different IT systems, how they’ve been configured and how they’re being managed, looking at analysis of reports such as ticket histories, the number of tickets that are being generated on an ongoing basis and supported by the organization. Validating things like documentation: we always want to look at any documents that currently exist, whether it’s IT policies, network or IT system documentation, data management, and then validating those documents to some extent as part of the assessment process.
Once all that information is gathered, then the real work begins: synthesizing it. That’s something that takes a significant amount of time and effort. And once that synthesis is completed, it results in recommendations for the organization. How can the IT environment be improved to better meet the long-term needs and strategic objectives of the organization? So that leads into planning and roadmap work, which we’ll talk about, and we’re going to get into more details in this presentation as to the deliverables that come out of the IT assessment.
Because it’s such a thorough and involved process, IT assessments typically cost between $20,000 and $30,000, varying based on the size of the organization and the number of systems being evaluated. Sometimes it can be a little bit less than that, sometimes it can be a little bit more, but in general that range works well for doing the bulk of the work that needs to be done for an assessment. We’re going to talk a little bit more about why you would want to get an assessment done, so I’ll leave that for the moment.
How to Vet an Assessment Provider
Carolyn Woodard: Before we go on to the next slide, I feel like I have to ask: do you have advice on how to vet an assessment provider? Because I would expect that sometimes some companies might use, quote unquote, an “assessment” really just as part of their sales process. So they’re going to give you an assessment that tells you that they’re the only one who can solve any of your problems and you should hire them right away.
What can you look for in a vendor when you’re talking to them to try and get a thorough, agnostic assessment? And is there any way to tell how competent they would be at giving an assessment?
Johan Hammerstrom: Well, I think that’s a great question. And I think the first thing to remember is that what one firm calls an assessment may be very different from what another firm calls an assessment.
And that’s part of the reason we wanted to do this webinar, to just kind of clarify what we mean by an IT assessment. From our perspective, it’s comprehensive. It covers the organization’s entire approach to IT.
A lot of managed service providers, for example, will say they’ll do a free assessment, either as part of the sales process or at the beginning of an engagement. That’s very different from what we’re talking about. It may be exactly what the organization needs. If an organization doesn’t need a comprehensive evaluation that looks at IT operations, management, and governance, then that sort of free assessment that happens at the beginning of an engagement may be sufficient.
And in some ways, that’s what we do when we onboard a new client for our managed services: we conduct a similar sort of evaluation of the systems that we’re going to be supporting. We would distinguish that from a full-blown assessment of the kind we’re discussing in this webinar today.
I think in terms of how to evaluate vendors or providers that are offering an assessment, I would just ask them to share their methodology. What’s the framework they’re using for conducting the assessment? Have them share sample reports, so they should be able to share a generic report from previous assessments they’ve done, and then ask for references so you can talk to other nonprofit organizations they’ve conducted assessments for. I think that’ll give you a good sense of whether or not their approach to doing assessments is the right fit for what your organization is looking for.
Because it’s possible… there are $100,000 assessments. We don’t do those, but there are firms that do. And there may be some organizations that really benefit from a $100,000 assessment that maybe takes not nine weeks but nine months to complete. So we’re not saying that this is necessarily the only way to do an assessment, but I think it’ll be clear as we go through the presentation today what it is that we do. And hopefully that sheds some light on whether or not it’s the right fit for what a particular organization is looking for.
Carolyn Woodard: So it sounds like the organization, as they’re starting on this process of thinking, “I probably need an IT assessment,” needs to get clear on their assessment objectives to begin with.
Assessment Objectives and When to Get One
Johan Hammerstrom: Yeah, you should be very clear on why you’re doing the assessment and what you hope to get out of it. I think that’s a good segue to our next slide. Thank you, Carolyn, for that smooth transition. So I’ll hand it over to Nura. I’ve been talking a lot.
Nura, can you talk a little bit about when we conduct an assessment? What are the objectives? What are we hoping to get out of that assessment process?
Nuradeen Aboki: Well, thank you, Johan. Objectives of an assessment are intentionally broader than just “the computer works.” We are looking at the IT environment as a whole, as you mentioned, Johan: the IT systems, the infrastructure, the management, and the governance.
So a strong assessment should help the organization develop a strategic technology plan for implementing recommendations. That means we’re not just naming gaps; we’re helping leadership understand priorities, sequencing, dependencies, and what will be realistic. Because oftentimes we could find an assessment that’s too technical. Really taking an approach where you’re looking at a strategy around the assessment, and the objectives of the assessment, is very important.
Another key objective is alignment. IT touches leadership, staff, finance, development, operations, the board. So if those groups aren’t aligned on what matters most, it becomes very difficult to invest wisely. And sometimes an assessment supports organizational change: that might mean clarifying ownership, adjusting a support model, preparing for leadership transition, or sequencing a larger technology initiative.
Johan Hammerstrom: And I think that speaks to some of the scenarios we find when we’re doing an assessment. Leadership transition: that’s often when assessments get done. Previous leadership has departed, new leadership is coming in, maybe IT isn’t fully meeting the needs of the organization.
Oftentimes organizations change, or organizations don’t change: the environment around the organization has changed, but the organization has kind of remained static. New leadership comes in, and they want to get a complete picture, a third-party sense of what’s happening with IT.
So those are some of the scenarios in which assessments get completed. I think, just to reiterate the point, a lot of times now auditors, cyber insurance providers, even the board will ask the organization to conduct a “security assessment.” Well, oftentimes they’re just asking for a vulnerability scan. They’re asking for something very basic. It’s probably best not to do a comprehensive assessment in that case, because you’re going to overdo the effort for what’s needed.
But other times, maybe a new CEO is coming into the organization and they’re seeing the need for IT to be a strategic enabler of the organization’s mission, and they’re wondering: is it capable of doing that? That’d be a perfect scenario to conduct one of these comprehensive assessments. And I think the things we look at during the assessment process will also shed some light on that.
So maybe Nura, you could talk a little bit about the different categories we’re evaluating during the assessment process.
The Four Categories of an IT Assessment
Nuradeen Aboki: Yeah, these are the four categories you see on the slide deck; they give the structure of the assessment. They help organize the findings, so leadership can see patterns inside of what might otherwise look like a random list of issues we discover during the evaluation process.
The first is infrastructure and core systems, and there you can see a list of core infrastructure systems such as network connectivity, endpoints, identity, and some productivity application platforms the organization may be using, whether the organization is still in the cloud or has on-premises servers. Any support lifecycle management of the endpoints and hardware is also considered part of infrastructure and core IT systems.
Then another category we look at is data and web, or you would say digital platforms. This is where you see your CRM systems, your reporting system, your website, engagement platforms, business applications, integrations, as well as how information flows through the organization, because this is where the intersection of data, web, and digital platforms lies.
Another critical, I would say crucial, category in an assessment is security and compliance. This has to do with cybersecurity controls, identity and access, backup and recovery, data protection specifically, and then permissions, monitoring, incident readiness, and any risk or compliance obligations your organization may have. Security is becoming more and more important.
We utilize best practices, both industry best practices from a cybersecurity standpoint and best practices that nonprofit organizations actually leverage, and that’s what we use to assess security and compliance for our clients.
And then lastly, the fourth category has to do with governance and strategy. Governance is so important: who’s making the decisions, how are they making decisions, are there policies already established in the organization, or does the organization need to improve its IT policies? How is budgeting done from an IT standpoint when it comes to technology investments? Vendor management is something we look at too, because these days we find organizations use several vendors, and we look at how those vendors are managed and whether the SLAs, or service level agreements, are being met.
Then the ownership of IT in general at the organization; we take a look at that as well, and also leadership alignment. Change capacity is important too, because as technology evolves rapidly, it’s quite important to understand what the organization’s change capacity is for technological change. And then roadmap execution: if the organization has a roadmap, how are they planning to execute and implement it? If they don’t have one, then the outcome of an assessment will also produce a roadmap, with guidance on how to execute it.
Johan Hammerstrom: And I think it’s important to note that this is an overview of what’s being assessed. These are the categories, but within each category, there are literally dozens of different specific points of evaluation.
So in the infrastructure and core systems category, we’re looking at antivirus protection and how it’s being managed and how it’s running. We’re looking at how the environment is being managed and configured. Do mobile devices have access, and if so, are they being proactively managed?
In the data and web category, we’re looking at things like data integrity: is there a retention policy governing the data? How is SEO being used to drive traffic to the website?
Security and compliance: looking at vulnerability scans, as we mentioned earlier, but also looking at incidents that may have happened over the past year. And then governance and strategy: looking at, as Nura said, policies, operational management, IT leadership.
So it’s an extremely thorough evaluation conducted in these four different categories, and there’s also an extremely well-defined approach for evaluating all of these different categories. So Nura, maybe you could walk us through that approach a little bit.
The Assessment Approach: Discover, Evaluate, Align, Plan
Nuradeen Aboki: Yeah, thank you, Johan. The approach is straightforward, as we put it here: we try to simplify it into discover, evaluate, align, and plan.
But within each of these processes described as part of the approach lies a tremendous amount of work that goes into ensuring the discovery phase gathers context thoroughly. This includes interviews, review of documentation, system inventory reviews, and discussion around pain points an organization, a department, or a leader may be feeling. So as we go through, we’re taking notes of these pain points.
Then their prioritization: what are the organization’s priorities when it comes to IT? Do they have something already in view? Are there changes to their mission or priorities that will impact their mission? We want to get that early in the discovery phase, and also talk about security risk to the organization, just to understand their sense of it: are there any imminent risks, are there any known risks, before we actually begin the evaluation phase.
And then in that evaluation phase, we look at the current state. As Johan said, it’s quite thorough. Each of those four categories, we do a deep dive into each one, depending on the systems the organization has, whether it’s infrastructure or the core systems; we begin with those, running our tools as we do the evaluation of the network or the technology infrastructure they have. That keeps the analysis organized, honestly. Once we go through those four high-level categories, it helps us avoid focusing too narrowly on just one specific tool or technology issue.
But we’re taking notes along the way during the discovery phase and even in our evaluation. As we find, for instance, a risk an organization has not implemented multi-factor authentication for its systems administrator accounts, that’s a risk. We note that down, and during our project check-ins, we report that and see if there are any early actions we could take to remediate it, because there are some risks that just can’t wait as we go through the evaluation process.
Then we shift, after the evaluation, into the alignment phase. Here we connect the findings to the leadership priorities of staff experience, mission, budget, and change, or capacity for change.
And this is where the nonprofit context really matters. The findings could be a long list; we really want to make sure they’re relevant to the nonprofit organization going through the assessment, and we take their priorities to heart as we try to find that alignment for them.
And then finally, we move into the planning phase. This is where we convert those findings, what we’ve discovered, into recommendations, as well as a strategic technology plan, which eventually arrives at the IT roadmap. We’ll talk some more about the deliverables very soon. But the framework, as you can see, is category-based, but the output has to be practical: what to do, why it matters, and how to sequence it.
Carolyn Woodard: I have a quick question for you, Nura, because having been on the other side of the desk in this too, I wonder how often it happens when you’re doing those initial interviews that people really know what the risks are and they tell you what the pain points are. Or does it happen fairly often that you discover a risk they weren’t even aware of?
Nuradeen Aboki: So in the initial phase, those interviews reveal what matters to the users, the staff, or the organization: what they know. Whether it’s their day-to-day work, they’re struggling with a report they’re unable to generate, or they can’t find data coherently, they need a dashboard. So they talk about their needs. To them, that may not necessarily constitute a risk, but sometimes the leaders of the organization may find that everyone is using some open, unpaid AI tool, just to give you an example: an AI that’s open source and not a paid account, so there’s a risk of proliferation or exfiltration of data, which a leader is just concerned and nervous about. And then they bring that up.
But during the technical evaluation, or the evaluation phase, this is where we’re looking at the infrastructure itself and going in deep, as Johan mentioned; we’re reviewing configuration. And sometimes an organization that’s been around for 10 years has been through a number of IT support teams, and there could be some misconfiguration that hasn’t been resolved. This is where we take a deep look at those systems to make sure they have some basic or baseline standard configuration that is, if you will, error-free, or that doesn’t have any misconfiguration. But if we find one, and we find that it’s risky to the organization based on our criteria, we report that immediately.
Assessment Deliverables: Report, Recommendations, Strategic Plan, and IT Roadmap
Carolyn Woodard: And you said that you deliver a plan after going through this process. So what does that usually include?
Nuradeen Aboki: Yeah, I think that plan begins with a report, a comprehensive evaluation report. What are the findings? What did we find? Because that describes the current state: the strengths, the gaps, the risks across the IT or technology environment that was evaluated.
And then coming out of that is the list of recommendations. So you found a number of risks and gaps: what do you recommend we do about this? This is where we put together a list, and typically you find it in a table form, simple and easy to digest. Here’s the list of risks; it’s categorized and linked to the four assessment areas. So when you’re looking at infrastructure, you see which ones are related to infrastructure, which ones are related to data, security, and governance.
And with that recommendation list, we also do an initial prioritization of the recommendations, so that when you see that spreadsheet, you’re not wondering where to begin; you’re looking at it from the standpoint of what are the most important ones, from a Community IT lens.
But it doesn’t stop there, because we want to make sure we collaborate with you to put together a strategic technology plan. That’s where we take those recommendations and the initial prioritization and convert them into a practical plan for implementing the recommendations. So you may say, okay, out of these 30 recommendations, realistically 12 of them are the ones that are relevant at this point in our maturity as a nonprofit organization. And we align on that strategic technology plan. It should account for sequencing, ownership, dependencies, and organizational fit.
So after taking that strategic technology plan, developed in collaboration with the nonprofit organization, it arrives at the final product, which is the IT roadmap. This is where the execution view over time is represented, with attention to budget, capacity, risk, and any change readiness the organization needs to be aware of.
So while the comprehensive evaluation report, documented findings, and evidence are all there, I find that nonprofit leaders typically rely most heavily on the recommendations, the strategic plan, and the IT roadmap when making decisions and allocating resources.
Two Key Principles for a Successful Assessment
Johan Hammerstrom: And I think these sets of deliverables really highlight two key principles that we try to adhere to in our assessment process, and that, if you’re considering getting an assessment, I’d strongly encourage you to keep in mind, because I think they’re key to having a successful assessment.
The first principle is that the assessment and its deliverables have to operate at multiple levels. They need to operate at the level of technical detail, the level of organizational management, and the level of strategic governance. An assessment that simply gives you a list of technical recommendations isn’t going to be effective, because the fact that those recommendations need to get accomplished, the fact that you have technology issues that need to be changed, means the structures for managing technology and making good IT decisions aren’t in place either. So those need to be addressed as well.
It also means the audience for these deliverables is spread throughout the organization. If you’re only providing technical recommendations, that’s going to be meaningless to the board and potentially to senior leadership. So it’s really incumbent on the assessor to translate the meaning of those technical recommendations into a form that’s intelligible to senior leadership, and hopefully even the board.
Conversely, if you’re just providing a strategic plan that isn’t grounded in the reality of the technology itself, then it’s just platitudes: generic and unactionable. It’s strategy theater, as people like to say.
So the most effective assessments operate at all of those levels simultaneously, and that’s really the best way to get value out of the assessment process.
The second principle, going back to the previous slide on the assessment approach, is that the assessment has to be approached with an open mind. It has to be open-ended.
If whoever’s doing your assessment… let’s say you’re using Google Workspace, and whoever’s doing your assessment comes in saying you have to be on Microsoft 365, then don’t bother getting that assessment done. You already know they don’t need to do the discovery, they don’t need to talk to your staff. You already know what they’re going to recommend, so you don’t need to go through an assessment process to get that recommendation.
But how do you know that’s actually the right recommendation for your organization? That sort of approach short-circuits the analysis that makes for a successful assessment process.
So whoever’s doing the assessment needs to go into it with an open mind. The first step is discovery, and you discover things you weren’t aware of prior to learning about them. So it’s really important that whoever’s doing the assessment is bringing in a wealth of expertise, hopefully, and an understanding of how technology can be effective at nonprofit organizations, but they shouldn’t be bringing in their biases.
And if they do have biases, they should state those clearly at the outset so everybody understands what they are.
What a Healthy Nonprofit IT Environment Looks Like
Carolyn Woodard: Can you talk a little bit about what a healthy nonprofit IT environment looks like? Because we do see it: it’s not that it doesn’t exist. We know a lot of nonprofits have challenges around their IT for lots of different reasons. But can you talk a little bit about what it looks like when you’re in that healthy state?
Johan Hammerstrom: Yeah, I’ll let Nura answer this one, but I’ll also say, I don’t know if I’d call this a bias, but this is our philosophy. This is how we think about healthy IT at nonprofit organizations, and we want to be upfront with organizations before we do the assessment. So broadly speaking, from an agnostic perspective, this is what healthy IT looks like to us.
Nuradeen Aboki: Thank you. You could start to think of a healthy IT environment this way.
It’s not just about having the most expensive tools or the newest systems. It’s about whether the technology environment supports the work of the organization in a reliable, secure, and manageable way.
So as we look at those four assessment categories we mentioned, we want to take a look at IT infrastructure and core IT systems. Are they healthy? That means reliable devices, supported networks, managed accounts, stable collaboration tools, and clear expectations for support. It’s vendor agnostic; we’re just looking for whether those things are there or not.
Then when it comes to data, web, and digital platforms, it means the core systems fit the work: data is findable and protected, reporting is useful, and integrations reduce friction rather than creating it. So we’re looking for that seamless approach when it comes to finding data and that integration with web and digital platforms: where are the bottlenecks? Is it working, or are we finding data integrity issues, data reliability issues?
Another aspect of a healthy nonprofit IT environment is security and compliance. There are some foundational security approaches or standards we expect to see in a healthy environment: do you practice managed devices? Meaning, are they being patched, are they managed centrally, do they have consistent configuration, or are they unmanaged? Do you have multi-factor authentication implemented?
These are things we find that are baseline. Is there a security awareness program in place for the education and awareness of your employees? Do you have a backup policy? What type of backup solution are you using for your cloud applications, as well as any on-premises applications or assets you may have? Do you have a process for reviewing access and properly monitoring your endpoints? Do you have security controls in place just to ensure your nonprofit organization is secure? Do you have any compliance requirements you’re following, and how are you following those and ensuring compliance is enforced in your organization?
And then lastly, governance and strategy: this is what helps ensure you have good governance in place. For instance, it means you have policies: an acceptable use policy, an incident response policy. Ownership of IT at the organization: is it at the management level, the leadership level, or is it just ad hoc? Do you have budget discipline? Do you consistently ensure IT is budgeted for on a year-to-year basis, especially now that IT spend is moving more toward recurring expenditure rather than one-time fixed costs? You want to be disciplined about that; we look for that.
And then vendor oversight: you likely have multiple vendors at your organization that you have to deal with when it comes to technology, so how is that oversight done? Leadership alignment, and lastly, a roadmap, if you have one that you can actually execute on. Oftentimes some organizations don’t have any roadmap at all.
So that’s where we come in: to assess and then develop that roadmap for them.
Key Takeaways and Next Steps
Carolyn Woodard: You’ve given us so much to think about today. Are there some key takeaways we should leave this webinar with?
Nuradeen Aboki: Yes. The first one is that an assessment connects technology to mission, and we want you to understand that it should be practical. It’s something you might find funding for, but typically a good, extensive one should take about seven to nine weeks and fall in the $20,000 to $30,000 range for a thorough assessment.
Secondly, we wanted to make sure you understand that these four categories aren’t the only categories we look at; they’re high-level categories. Inside each one, we have a standardized, rigorous process for evaluating it. So remember, there’s infrastructure, which is also related to your core IT systems. Then you have data and web, as well as digital platforms. Third, you have security and compliance. And the final category is governance and strategy.
Then the last takeaway is that the organization should walk away with a clear path forward: a comprehensive evaluation report, a prioritized recommendation list, a strategic technology plan, and lastly a roadmap you can actually execute on.
Carolyn Woodard: And so once you have those four aspects of the report, after you’ve had this comprehensive, holistic evaluation done, what are the next steps? Then what?
Nuradeen Aboki: Yeah, this is where you want to take what you’ve received as output and talk to leadership. Leadership needs to take some action.
We recommend leadership convene within their circles to discuss and evaluate the assessment and roadmap recommendations. Our process should also be collaborative and transparent, because we want to ensure that at the end of the day you have some action that’s practical for your organization.
So you also want to revisit your goals and think about your IT strategy. Sometimes an organization may be focused on their mission but not necessarily have an IT strategy. The outcome of the report, as well as the roadmap, should help you develop that strategy if you don’t already have one, using the new information you’ve learned from the assessment.
And then the idea of what’s reasonable, what’s realistic for your existing IT support, is important, because if you have IT support, you want to know: do they have the capacity to implement the recommendations in this IT roadmap? Or do you need to reconsider or bring on another partner who can help you realize or implement the IT roadmap effectively? Sometimes your existing IT support partner has the capacity, and they may even be aligned, because an outside organization has done the assessment and they say, “Oh, this is something we’ve been thinking about; I’m glad to see it in writing.” It supports what they can do, and then you can negotiate on how to get those things implemented.
But there are times when third-party support is actually needed. So this is something that has to be discussed and evaluated depending on your organization’s needs. There’s one key last thing about next steps: your capacity and culture for change. For some organizations, change is difficult, especially if the roadmap points to key milestones that need to happen for your organization to move forward.
Carolyn Woodard: I just heard it referred to as “change saturation”: that especially in this age of AI, people are people, and there’s only so much change you can accomplish all at the same time. So I think that goes back to what you said about one of the deliverables being this roadmap of what the priority is, what the timeline is, and how you’re going to make the change manageable.
Nuradeen Aboki: That’s exactly right.
Resources, Audience Q&A, and Closing
Carolyn Woodard: And we have some more resources on our site for anyone looking for more information after this webinar.
We have a Cybersecurity Readiness for Nonprofits Playbook. If you’re not a cybersecurity expert, this playbook is written in very accessible language, and it walks through our philosophy of how to layer cybersecurity, the must-haves, maybe some nice-to-haves, and explains a lot of what cybersecurity requires.
We have a few other downloads, all free on our website at communityit.com, and they’ll be linked in the transcript: How Do I Know If an IT Managed Services Provider Is Right for My Nonprofit Organization?; Building a Foundation for IT Innovation, which is about getting the foundation right first so the basics are there and you can build on it if you want to do bigger, more complicated IT projects; and The Nonprofit Guide to Vetting a Managed IT Services Provider, which gives you 12 questions to ask if you haven’t used an MSP before, or if you’re thinking about changing your MSP. It’s for anyone you might put on your short list, and it helps you get more information about what kind of partner they’re going to be.
I think we have some time for Q&A. We don’t have a live audience today, but we’ve gotten some questions over the years that we’ve been doing assessments, and one is on timing.
So if you’re in a situation where maybe your IT director just let you know that they’re leaving, is that a good time to do an assessment? Or should you wait until you have a new person, and they’ve had time to settle in and want to be part of the assessment? Do you have some advice on that timing?
Johan Hammerstrom: I think it depends on the circumstances of the departure. If you think the structure of the organization is going to more or less stay the same, and you’re pretty confident in IT management and governance but just don’t have an understanding of what’s going on with the specific systems, in that situation I’d wait for the new IT director to start so they can be part of the process. You really would want their buy-in in that situation. The last thing you’d want to do is conduct an assessment, get all the reports, and then hire someone who’s not really on board with that process or its results.
On the flip side, if you’re uncertain, if the IT director leaving has thrown all of IT into question: is this the right position, do we have the right structure, do we want to keep IT in-house or outsourced, if you’re asking a lot of questions about what could change, then it might make sense to get an assessment, which can help shed some light on those decisions. You don’t want to hire an IT director if it turns out you need a CIO, for example, and an assessment could at least give you some insight into that.
So it really depends on the circumstances, and I think it comes back to the results of the assessment and how well positioned your organization is to benefit and get value from those results, given the circumstances you’re in.
Carolyn Woodard: I think we have another question that might come up. Some people listening to this might be thinking: is there a size of organization at which an assessment really makes sense and has more value? Or is an assessment really for everyone? If you’re a two- or three-person organization, do you need an assessment at that size? What would your advice be?
Nuradeen Aboki: Yeah, I think the scope should fit the organization’s size. I’d say everyone needs an assessment, but if you have a smaller nonprofit organization, the scope should fit your size.
And sometimes you find a small nonprofit organization with tremendous infrastructure. That infrastructure might exist because they’re doing research and have to build it as a business need tied to their mission. Or it might be that they were larger at one point and then shrunk, and now they want to do an assessment to see how they can right-size their IT needs and environment.
So that’s really where the experience of the assessor comes into play. As the assessor is bidding for the assessment, they should be asking key questions about the right fit, making sure it’s tailored to present assessment results that are actionable by the organization.
So sometimes a small nonprofit may not need the same depth as a large organization, but it still needs reliable systems that work, some basic security standards, clear ownership, and a plan that fits its budget.
Carolyn Woodard: I feel like we run into so many clients where, when they started small, they just kind of went willy-nilly in every direction with their IT. With a small team, you can do that: one person chooses one thing, another person chooses something else, and you’re all kind of working on it together. So the problems don’t become apparent until you grow bigger or something more complicated comes along, and then you’re like, whoa, we have spaghetti here, we have to sort it out. So that might be something where an assessment could help you as you’re preparing to grow, to get those things in alignment.
So I want to go over our learning objectives for today. I feel like we really hit all of them. We wanted to learn what an IT assessment is, what it typically includes, and why you should have one done. Thank you both so much for sharing all of your expertise, knowledge, and experience doing these over the years, and for helping us understand what a holistic IT assessment includes. We also talked a little bit about what a healthy nonprofit IT environment looks like, and gave you a checklist of those different categories and what healthy IT looks like. And then, if your assessment tells you it’s time to change your IT support, we just talked about some of those typical next steps.
So I don’t want to let people leave without inviting them back to our next webinar next month, when I’ll be leading a presentation with my colleague Erik Solce. We’re going to talk about an ongoing project we have using AI to build a data lake for marketing, and the structure we came up with that’s really helped me manage this giant project, with a little tech coaching from Erik and a lot of AI helping me manage and connect these different channels and ask some really interesting questions across this data. We’re going to share how the project evolved, some of the things that went really well, and some things that didn’t go as well as we’d hoped.
I think this structure has a lot of potential for other nonprofit AI projects you might have on the back burner. If you’ve been putting something off because you don’t have the technical know-how, whether it’s building a data lake, analyzing program reports, or something else you want to get started on, we’re going to talk about how and where AI can be helpful and how to use it carefully and effectively. That’s at 3 p.m. Eastern, noon Pacific, on Wednesday, August 19th. You can register now on our website at communityit.com.
And Johan and Nura, I just want to thank you both so much for your time, experience, and for sharing with us today. This was so helpful; I learned a lot, and I hope everyone listening was able to benefit from this too.
Nuradeen Aboki: Thank you, Carolyn, for having me.
Johan Hammerstrom: Yeah, thank you. It was a pleasure, and thanks to everyone for watching.
As advocates for using technology to work smarter, we’re practicing what we recommend. This transcript was drafted with the assistance of AI, and is not a verbatim transcript. The content was edited for clarity, and was reviewed, edited, and finalized by a human editor to ensure accuracy and relevance.
Photo by Markus Winkler on Unsplash