Community IT Innovators Nonprofit Technology Topics
Community IT offers free webinars monthly to promote learning within our nonprofit technology community. Our podcast is appropriate for a varied level of technology expertise. Community IT is vendor-agnostic and our webinars cover a range of topics and discussions. Something on your mind you don’t see covered here? Contact us to suggest a topic! http://www.communityit.com
Community IT Innovators Nonprofit Technology Topics
Doing an IT Assessment at Nonprofits Pt 1
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Is it time for an IT assessment at your nonprofit? Maybe you need an assessment for a grant requirement, a change in leadership, or a switch to a new IT provider.
In part 1 of this two-part episode, Carolyn talks with CEO Johan Hammerstrom and Senior IT Consultant Nuradeen Aboki about what a comprehensive, nonprofit-focused IT assessment actually involves, and how to tell a genuine, agnostic assessment from one that's really just a sales pitch.
This episode covers:
- What Community IT means by a "comprehensive" IT assessment, and how that differs from the free evaluations many MSPs offer as part of a sales process
- How to vet an assessment provider: what to ask about methodology, sample reports, and references
- Common objectives and scenarios that prompt nonprofits to get an assessment done, including leadership transitions and preparing for growth
- The four categories every assessment should cover: infrastructure and core systems, data and digital platforms, security and compliance, and governance and strategy
- An inside look at the discover, evaluate, align, and plan approach Community IT uses to turn findings into a strategic roadmap
Part 2 continues next week with assessment deliverables, what a healthy nonprofit IT environment looks like, and next steps if it's time to change your IT support.
_______________________________
Start a conversation :)
- Register to attend a webinar in real time, and find all past transcripts at https://communityit.com/webinars/
- email Carolyn at cwoodard@communityit.com
- on LinkedIn
- on reddit/r/nonprofitITmanagement
- on the Community IT website
Thanks for listening.
Thank you for joining Community IT for this podcast, part one. Subscribe wherever you listen to podcasts and leave us a rating to help others find this leadership resource for nonprofits. Listen for part two in your podcast feed.
Carolyn WoodardWelcome everyone to the Community IT Innovators webinar on doing IT assessments at nonprofits with Nuradeen Aboki and Johan Hammerstrom. There are a lot of reasons why a nonprofit or a foundation might want to do an IT assessment. It might be recommended as part of a grant you're receiving. You may have a change in personnel or leadership, and the new person wants an outside assessment to understand your systems and your priority projects. You may be changing providers, and the new MSP starts off with an assessment. So whether you've had an assessment done before or this is your first one, it helps to know what you're getting into.
Carolyn WoodardMy name is Carolyn Woodard. I'm the outreach director for community IT, and I'll be the moderator today. I'm very happy to hear from our experts, but first I want to go over our learning objectives. So today we want to focus on these themes. What is an IT assessment? What does it typically include, and why should you have one done? What does a healthy nonprofit IT environment look like? Is there a checklist? And what if your assessment tells you it is time to change your IT support? What are typical next steps? So, Noura, would you like to introduce yourself?
Nuradeen AbokiYeah, thanks, Carolyn. Uh, I'm Nuradeen Aboki, a senior consultant at Community IT. In my work with nonprofit assessments are really about helping organizations understand what their network is today and uh where risk or if you you could say even friction may show up, and what practical steps uh can help them move forward. So I'll be focusing on what uh the process looks like uh from the inside, uh, what to look for, uh how we organize uh findings and how recommendations become something a nonprofit can actually use. And now I'll ask Johan to introduce himself.
Johan HammerstromYeah, thank you, Nura. Good afternoon, everyone. Thanks for joining us today. Uh,
Johan HammerstromMy name is Johan Hammerstrom, I'm the CEO at Community IT. I've been helping nonprofit organizations with IT support for over 25 years. And in that time, I've uh had the opportunity, the privilege to assess a lot of nonprofit IT environments. And I'm very excited today because uh we're gonna talk a little bit about the current version of assessment that we do at Community IT, which has really matured a lot in the last uh three or four years. And I think it's really matched what we've found to be a growing priority on IT maturity in the nonprofit sector. So we're we're excited to be here with you today, and thank you for joining us.
Carolyn WoodardAnd before we begin, if you're not familiar with community IT, a little bit about us. We are a 100% employee-owned managed services provider. We provide outsourced IT support. We work exclusively with nonprofit organizations, and our mission is to help nonprofits accomplish their missions through the effective use of technology. We are big fans of what well-managed IT can do for your nonprofit. We serve nonprofits across the United States, and we've been doing this for 25 years.
Carolyn WoodardWe are technology experts and are consistently given an MSP 501 recognition for being a top MSP, which is an honor we just received again in 2026. And we believe we're the only MSP on the list serving nonprofits exclusively. I want to remind everyone for these presentations that community IT is vendor agnostic. We only make recommendations to our clients and we only base those on their specific business needs. We never try to get a client into a product because we get some kind of incentive or benefit from that. We do consider ourselves a best of breed provider. So it's our job to know the landscape, what tools are available, reputable, and widely used. And we make recommendations on that base basis for our clients based on their business needs, priorities, and budget.
Carolyn WoodardSo we're recording this presentation today without an audience because of some scheduling issues. So while we don't have an audience QA today, if you do have questions about this topic, you can always join us and our experts at any time in our community on Reddit at r slash nonprofit IT management. And we try to answer questions over there within about a week. You can also contact us through our website at www.community it.com.
Carolyn WoodardA little bit more about us. Our mission is to create value for the nonprofit sector through well-managed IT. We also identify four key values as employee owners that define our company: trust, knowledge, service, and balance. We seek to always treat people with respect and fairness, to empower our staff, clients, and our sector to understand and use technology effectively, to be helpful with our talents, and we recognize that the health of our communities is vital to our well-being and that work is only a part of our lives. And with that, I want to turn it over to Johan, who I think can walk us through this slide of what is an IT assessment at a nonprofit.
Johan HammerstromYeah, thank you, Carolyn. Uh, we wanted to talk a little bit uh specifically about the approach that we take to IT assessments, which is very well defined, something that has a very specific methodology associated with it. It's possible to get an IT assessment that can cover all kinds of different activities. And if you bring on a new IT support provider, they might conduct an assessment of your network. If you're uh working with a third-party consultant, particularly to select a new software solution, they may assess certain aspects of your data and your IT systems that you're using.
Johan HammerstromBut at Community IT, when we talk about an IT assessment, we're talking about something very specific. And we wanted to define that at the outset. So, from our perspective, an IT assessment is a structured review of all aspects of IT. So it's comprehensive and it's intended to look not just at one particular component of an IT, of an organization's IT environment, but to look at all of those components.
Johan HammerstromSo we look at IT systems. So all your laptops, your cloud-hosted systems, all of your applications, the different solutions that you're using to do your work. And that's pretty common and pretty typical.
Johan HammerstromBut we also look at IT operations. So we don't want to look just at the technology that is being used, but we want to look at how it's being maintained, how it's being supported, how the staff in the organization are being supported in their use of those systems. So IT operations is a critical part of uh the uh evaluation that's being done during an assessment. We especially want to look at risks in this day and age, that's critically important, particularly uh cyber security-related risks.
Johan HammerstromWe also look at IT governance, how are IT decisions being made in the organization? How is the IT team uh formed? Who's overseeing that team? Um, how is their performance being monitored and evaluated over time?
Johan HammerstromAnd then finally, looking at future needs, where is uh the organization headed and how is technology evolving to meet the future needs of the organization?
Johan HammerstromSo the IT assessment is supposed to be comprehensive and very thorough. For that reason, it usually takes seven to nine weeks to conduct a complete IT assessment. There are a variety of activities that are being conducted during that period of time. Those activities include interviews with key stakeholders, and and that and the number of interviews that need to be conducted really varies based on the circumstances and the situation of the organization. But usually it varies, excuse me, between you know four, three or four interviews on the on the low end and 10 to 12 interviews uh on the high end. Oftentimes we'll do group interviews, so we'll meet with uh multiple stakeholders at the same time.
Johan HammerstromIn addition to the interviews, we're conducting technical discovery. Oftentimes that means running tools that are scanning the network for vulnerabilities, for example, or looking at other aspects of the various IT systems. Uh, it always involves hands-on uh evaluation of the different IT systems, how they've been configured and how they're being managed, uh, looking at analysis of uh reports such as um ticket histories, number of tickets that are being uh generated on an ongoing basis and supported by the organization. Uh validating things like documentation. So we we always want to look at any documents that currently exist, whether it's IT policies, uh network or uh IT system documentation, data management, and then validating those documents to some extent as part of the assessment process.
Johan HammerstromOnce all that information is uh gathered, then the real work begins, synthesizing it. And that's something that um takes a significant amount of time and effort. And once that synthesis is completed, it results in recommendations for the organization. How can the IT environment be improved to better meet the long-term needs and strategic objectives of the organization? So that leads into planning and roadmap work, which we'll talk about. And we're gonna get into more details in this presentation as to the deliverables that come out of the IT assessment. Uh,
Johan HammerstromBecause it's such a thorough uh and involved process, the IT assessments typically cost between $20,000 and $30,000, uh, varying based on the size of the organization, the number of systems that are being evaluated. Um, sometimes it can be a little bit less than that, sometimes it can be a little bit more, but in general, that range uh works well for um doing the bulk of the work that needs to be done for an assessment. Um we're gonna talk a little bit more about why you would want to get an assessment done. So I'll kind of leave that uh for the moment.
Carolyn WoodardBefore we go on to the next slide, um, I feel like I have to ask, do you have advice on how to vet an assessment provider? Because I would expect that sometimes some companies might use a quote unquote assessment really as just a sales part of their sales. So they're going to give you an assessment that tells you that they're the only one who can solve any of your problems and you should hire them right away. So, um,
Carolyn WoodardWhat can you look for in a vendor when you're talking to them to try and get you know a thorough agnostic assessment? And is there any way to tell like how competent they would be at giving an assessment?
Johan HammerstromWell, I think that that's a great question. And I think the first thing to remember is that um what one firm calls an assessment may be very different from what another firm calls an assessment.
Johan HammerstromAnd that's part of the reason that we wanted to uh do this webinar is to just kind of clarify what we mean by an IT assessment. And from our perspective, it's comprehensive. It's uh it covers the entire the organization's entire approach to IT. Um
Johan HammerstromAa lot of managed service providers, for example, will say they'll they'll do a free assessment, you know, either as part of the sales process or at the beginning of um of the engagement. And that's very different from what we're talking about. It may be exactly what the organization needs. You know, if an organization doesn't need a comprehensive evaluation that looks at IT operations management and governance, then that sort of free assessment that that begin you know happens at the beginning of an engagement uh may be sufficient.
Johan HammerstromAnd in some ways, that's what we do when we onboard a new client for our managed services, we do sort of conduct a similar sort of evaluation of the systems that we're going to be supporting. Uh, we would we would uh distinguish that from a full-blown assessment of the kind that we're discussing in this in this webinar today for organizations.
Johan HammerstromI mean, I think in terms of how to evaluate uh uh vendors or providers that are offering an assessment, I would just ask them to share their methodology. You know, how do they what's the framework that they're using for conducting the assessment? Um, have them share sample reports. So they should be able to share kind of a generic report from previous assessments that they've done, and then ask for references so you can talk to other nonprofit organizations that they've uh conducted assessments for. And I think that'll give you a good sense of whether or not their approach to doing assessments is the right fit for what your organization is looking for.
Johan HammerstromBecause it's possible, you I mean, there's a hundred thousand dollar assessments. We don't do those, but there are firms that do. And there may be, you know, some organizations really benefit from uh a $100,000 assessment that maybe takes not nine weeks, but nine months to complete. So um we're not saying that this is necessarily the only way to do an assessment, but I think it'll be clear as we go through the presentation today what what it is that we do. And hopefully that sheds some light on you know whether or not it's the right fit, you know, for what a particular organization is looking for.
Carolyn WoodardSo it sounds like the organization, as they're starting on this process of thinking, I probably need an IT assessment, they need to get their assessment objectives kind of under understand what their objectives are to begin with.
Johan HammerstromYeah, you should be very clear on what you hope why you're doing the assessment, what you hope to get out of it. I think that's a good uh segue to our next slide. Thank you, Carolyn, for that uh smooth transition. Um so I'll I'll hand it over to Nura. I've been talking a lot. And uh
Johan HammerstromNura, can you talk a little bit about when we conduct an assessment? What are the objectives? What are what are we hoping to get out of that assessment process?
Nuradeen AbokiWell, thank you, Johan. Uh, you know, objectives of an assessment are intentionally broader than uh the computer just working. You know, so uh we are looking at the IT environment as a whole, as you mentioned, Johan, the IT systems, the infrastructure, the management, and governance.
Nuradeen AbokiSo a strong assessment uh should help the organization develop a strategic technology plan for implementing recommendations. Uh that means uh we are not just naming gaps, uh, we are helping leadership understand priorities, sequencing, uh dependencies and what will be realistic. Because oftentimes we get we could find an assessment that's too technical. And uh really sort of taking an approach where you're looking at a strategy around the assessment and the objectives of the assessment is very important.
Nuradeen AbokiAnother key objective is uh alignment. Uh so IT touches leadership, staff, you know, finance, development, operations, uh, the board. Uh so if those groups uh are not aligned on what matters most, uh it becomes very difficult to invest uh wisely. And sometimes an assessment uh supports uh organizational change. Uh uh that might mean uh clarifying ownership, uh adjusting a support model, uh preparing uh for leadership transition or sequencing uh a larger technology initiative.
Johan HammerstromAnd I think that that speaks now to the um some of the scenarios that we find uh when we're doing an assessment. Leadership transition, that that is often when assessments get done. Um previous leadership has departed, new leadership is coming in, um, maybe IT isn't fully meeting the needs of the organization. Um
Johan HammerstromOftentimes organizations change, or organizations don't change. You know, the environment around the organization has changed, but the organization has kind of remained static. New leadership comes in, they want to under, they want to get a complete picture, a third-party sense of what's happening with IT.
Johan HammerstromSo those are some of the scenarios in which um assessments are are getting completed. I think, you know, just to kind of reiterate the point that it's typically not done, you know, a lot of times now um auditors, cyber insurance providers, even the board will ask the organization to conduct a security assessment. Well, oftentimes they're just asking for like a vulnerability scan. Uh, they're asking for something very basic. Um, it's probably best not to do a comprehensive assessment in that case because you're gonna overdo the effort for what's needed. Uh,
Johan HammerstromBut other times, you know, maybe a new CEO is coming into the organization and they're they're seeing the need for IT uh to be a strategic enabler of the organization's mission, and they're perhaps wondering is it capable of doing that? That'd be a perfect scenario to conduct one of these comprehensive assessments. And um, I think uh the the things that we look at during the assessment process will also uh shed some light on that. \
Johan HammerstromSo maybe Nara, you could talk a little bit about the different categories that we're evaluating during the assessment process.
Nuradeen AbokiYeah, these are four categories that you see on on the slide deck uh you know, give the structure of the assessment. Uh they help uh organization finds findings, uh they do help with the organization of the findings so leadership can see patterns inside of this random list of issues that we may discover during the evaluation process.
Nuradeen AbokiThe first uh is the infrastructure and core systems, and there you can see a list of uh core infrastructure systems such as uh network connectivity, endpoints, uh identity, some productivity application platforms that the organization may be using if organization is still in the cloud or has on-premises uh servers, uh, and uh any support lifecycle uh management of the endpoints and hardware is all considered as part of the infrastructure on core IT systems.
Nuradeen AbokiThen another category we look at is the data and webslash uh you would say digital platforms. This is where you see your CRM uh uh systems that we take a look at uh reporting system, website, uh, engagement platform, business applications, integrations, uh, as well as uh how information flows through the organization, because this is where the intersection of data, web, and digital platforms uh lie.
Nuradeen AbokiAnother critical, I would say crucial category that is very important in assessment is to look at your security and compliance uh areas. And this has to do with cybersecurity controls, uh identity and access, maybe backup and recovery, data protection specifically, uh and then uh permissions, you know, monitoring incident readiness and any risk or compliance obligations that your organization may have. Uh security is becoming more and more important.
Nuradeen AbokiWe uh approach uh we utilize best practices, best practices in terms of the industry uh from a cybersecurity standpoint and best practices that nonprofit organizations actually leverage on, and that's that's what we use to assess those uh security and compliance for our clients.
Nuradeen AbokiAnd then lastly, there the fourth category has to do with governance and strategy. Uh governance is so important that uh who are those making the decisions, how are they making decisions? Are there policies that are uh that are already established in the organization, or does the organization need to improve on its IT policies? Uh what as how is the budgeting done uh for from an IT standpoint when it comes to technology investments? Uh, vendor management is something we look at because these days we find in organizations utilize several vendors, but how are those vendors managed and uh are the SLAs? Or service level agreements that are being met for those vendors.
Nuradeen AbokiThen the ownership of IT in general at the organization, we take a look at that as well. And also leadership alignment. Then change capacity is important because as technology is evolving rapidly, it's quite important to understand what is the organization's change capacity for technological changes. And then a roadmap execution. If the organization has a roadmap, how are they planning to execute and implement that roadmap? If they don't have one, then the outcome of an assessment will also produce a roadmap and with guidance on how to execute on that roadmap.
Johan HammerstromAnd this is a, I think it's important to note that this is an overview of what's being assessed. You know, these are the categories, but within each category, there are literally dozens of different specific points of evaluation.
Johan HammerstromSo in the infrastructure and core systems uh category, we're we're looking at antivirus protection and how it's being managed and how it's running. Uh we're looking at how the um environment is being managed and configured. Are the are do mobile devices have access? And if so, are you know are they being proactively managed?
Johan HammerstromIn the data and web, you know, looking um at things like uh data integrity, is there a retention policy governing the data? Um, how is SEO being used uh to drive traffic to the website? Um
Johan HammerstromSecurity and compliance, looking at um, you know, the vulnerability scans, as we had mentioned earlier, uh, but also um, you know, looking at incidents that may have happened over the past year. Uh and then governance and strategy looking at uh, as Nura said, policies, um operational management, IT leadership.
Johan HammerstromSo it's an extremely thorough evaluation that's being conducted in these uh four different categories. And there's also an extremely um well-defined approach for evaluating uh all of these different categories. So Nura, maybe you could walk us through that approach a little bit.
Nuradeen AbokiYeah, thank you, Johan. And you know, it's uh uh the approach uh is straightforward as we put it here. You know, we try to simplify it into discover, evaluate, uh, align and plan.
Nuradeen AbokiBut in each uh of this uh processes uh that it is described as part of the approach lies uh a tremendous amount of work that goes into ensuring the discovery phase gathers contacts thoroughly. You know, this would include interviews, uh review of documentation, uh system inventory reviews, discussion around pain points, an organization may be feeling our department or a leader. So as we go through, we are taking notes of these pain points.
Nuradeen AbokiThen their prioritization. Uh, what is the organization's priorities when it comes to IT? Uh, do they have something already in view? Uh are there changes to their mission or priorities that will impact their mission? So we want to get that early in that discovery phase and also talk about security risk to the organization just to understand what is their feel, what are there any eminent risks, are there any known risks uh before we actually begin to evaluate the moving into the evaluation phase.
Nuradeen AbokiAnd then that evaluation phase, we look at the current state. Uh, as Johan said, is quite thorough. Uh, each of those categories, uh, the four categories, we go do a deep dive into each one of them, depending on the systems that the organization have, whether it's infrastructure or the core systems, we begin with those. Uh, running our tools as we do the evaluation of uh the network or the technology infrastructure that they have. Um, that keeps the analysis organized, honestly, once we go through those four uh high-level categories, uh, and it helps us avoid focusing too much narrowly on just one specific tool or one technology issues.
Nuradeen AbokiBut we are taking notes uh along the way during the discovery phase and even in our evaluation, as we find, for instance, a risk an organization has not implemented multi-factor authentication for its systems, administrators, uh, accounts. You know, that's a risk. We note that down, and and during our project check-ins, we report that and see if there's any early actions we could take to remediate that because there's some risks that just can't wait as we go through the evaluation process.
Nuradeen AbokiThen we shift into the uh uh after the evaluation, we move into the alignment phase. Here uh we connect the findings uh to the leadership priorities of staff experience, uh, mission, budget, and change or capacity for change.
Nuradeen AbokiAnd this is where the nonprofit context really matters. As uh the findings could be a long list. Uh, we really want to make sure that they are relevant uh to the nonprofit organization that is going through that uh assessment, and we take their prioritization or their priorities into heart as we uh trying to find that alignment for them.
Nuradeen AbokiAnd then finally, we move into the planning phase, and this is where we convert those findings, uh, what we've discovered for the findings into recommendations, as well as a strategic technology plan, and which eventually arrives at the IT roadmap. And we'll talk some more about the deliverables uh very soon. But the framework, you know, as you can see, is category category-based, but the output has to be practical. For instance, what to do, why it matters, and how to sequence it.
Carolyn WoodardI have a quick question for you, Nura, because having been on the other side of the desk in this also, I wonder how often it happens when you're doing those initial interviews that the people really know what the risks are and they tell you what the pain points are. Um, or does it happen fairly often that you discover a risk that they weren't even aware of?
Nuradeen AbokiSo in the initial phase, uh those interviews reveal what matters to the users or to the staff or to the organization, what they know. Whether it's their day-to-day work, uh, they are struggling with a report that they're unable to generate or they can't find data coherently, they need a dashboard. So they talk about their needs, you know, to them, uh that may not necessarily constitute risk, but sometimes the leaders of the organization uh may find that really everyone is using open AI, for instance. Just to give you an example, an AI that is open source, that is not uh uh a paid account, or there's just risk of proliferation of exfiltration of data, uh, which a leader is just concerned and nervous about. And then they bring that up.
Nuradeen AbokiBut during the technical uh evaluation or the evaluation phase, uh this is where we are looking at uh the uh infrastructure itself and going in deep, as Johan mentioned, we're reviewing configuration. And sometimes an organization that might been around for 10 years, they've been through a number of IT support teams. Uh, there could be some misconfiguration that has not been resolved. And this is where we take a look deeply at those systems and to make sure they have some basic or baseline uh standard configuration that is uh kind of uh error-free, if you will, or that doesn't have any misconfiguration in them. But if we find one and we find that it's uh risky to the organization based on our criteria, we report that immediately.
Community IT IntroThank you for joining Community IT for this podcast, part one. Subscribe wherever you listen to podcasts and leave us a rating to help others find this leadership resource for nonprofits. Listen for part two in your podcast feed.