Blaze Blog /

A Hack to Give Back 2026: Free security assessments for NGOs & charities

Insights
Jan 15, 2026
5min read
Hand shaking a robot's hand
Loading the Elevenlabs Text to Speech AudioNative Player...

Nonprofits shouldn't have to choose between delivering impact and defending against cyber threats. But for many nonprofits, limited budgets and small IT teams make it hard to invest in mature security measures – even when their digital infrastructure is essential to delivering services.

That's why Blaze Information Security is launching A Hack to Give Back 2026, donating $30,000 worth of penetration testing work. We'll select three nonprofit organizations to receive a free penetration testing engagement designed to help identify vulnerabilities and better protect the systems they rely on to serve communities. With cyber attacks, it's essential to prevent rather than cure, since the potential consequences for organizations can be heavy.

Why is cybersecurity for nonprofits important?

Nonprofit cybersecurity is mission protection. Many nonprofit organizations depend on public-facing systems, email, cloud services, and donor platforms as part of their daily work. At the same time, a lot of nonprofits face unique challenges like small teams and limited budgets, which can leave gaps that attackers can exploit.

For many charity organizations, protecting sensitive data (including donor information, donor databases, volunteer and beneficiary data, and sometimes financial records or financial information) can be hard. A security breach or data breaches can lead to unauthorized access, financial losses, reputational damage, and loss of donor trust, which can disrupt operations when services are most needed.

Depending on your work and where your stakeholders are located, you may also have obligations under data protection regulations and various regulations. For example, certain nonprofits that process healthcare or financial information may need to consider frameworks such as HIPAA or GDPR.

This is where penetration testing (also called pen testing) helps. It involves simulated attacks that mirror real-world attacks and a real-world attack scenario, aiming to uncover vulnerabilities in an organization's systems before malicious actors do. In a controlled and secure environment, testers attempt realistic ways to gain unauthorized access to critical assets – often by chaining issues like misconfigured settings, outdated software, human errors, and even social engineering (including phishing attacks and phishing emails).

What to Expect From Pen Testing

A well-run security assessment also produces a detailed report where vulnerabilities identified are clearly explained with impact and fixes. In practice, penetration testing demonstrates to stakeholders that the organization is taking proactive security measures and can support compliance efforts by identifying and addressing security gaps related to data protection and data security.

Penetration tests can be executed in different styles depending on access and goals, including black box testing, grey box testing or white box testing, where more context and sometimes source code or "full access" to specific components is provided to the testers.

Professional pen testers may hold credentials such as Certified Ethical Hacker or Offensive Security Certified Professional, but what matters most is partnering with a qualified pen tester who can tailor scope to your size, constraints, and risk.

Who can apply

A Hack to Give Back 2026 is open to registered nonprofits, charities, and NGOs worldwide.

To keep selection fair (and to make sure the work is useful), we only consider organizations that meet a few baseline criteria. In plain terms, we're looking for nonprofits that do clear community-good work, handle meaningful risk, and would struggle to fund a commercial assessment, while still being able to engage in scoping and follow-up.

Applications must meet all of the following:

  • Registered nonprofit / charity / NGO (documentation required)
  • Clear community benefit (direct services, communities, education, health, humanitarian support, etc.)
  • Security needs + sensitivity: you handle personal data, sensitive information, beneficiary information, or run a high-trust service where a security breach could cause serious harm
  • Resource constraint: your organization can't reasonably fund a commercial pentest in 2026
  • Readiness: you can provide a technical point of contact and commit time for scoping, coordination, and remediation planning

If you're unsure whether you "count" as ready, a simple rule of thumb is this: you don't need a perfect security program, but you do need someone on your side who can answer technical questions, provide access safely, and act on a remediation plan.

What's included

Each selected organization receives one professional penetration testing assessment, and you can choose one of the following:

  • Web / API pentest
  • Mobile pentest (iOS and/or Android)
  • External pentest (internet-exposed systems)

It's important to note that nonprofits can only pick one option, since splitting time across multiple targets usually reduces value. During scoping, we'll help you pick the surface that best protects your critical assets and reduces the most risk.

Your engagement includes a structured scoping call and rules of engagement, followed by a pentest (automated + manual) using the same methodology we use for paying clients. You'll then receive a detailed report with findings, severity, impact, reproduction steps, and recommended fixes, plus a short Q&A window so your team can clarify results and next steps. If you need it for governance or donors, you can also request a letter of attestation confirming the assessment took place.

Because people often ask this directly: yes, this can support compliance work. Penetration testing helps ensure compliance with data protection standards by identifying and addressing security gaps, and conducting it regularly can help nonprofits avoid potential violations by meeting regulatory obligations.

Rules and boundaries

According to our scope boundaries, the chosen NGO can choose one surface only: web/API, mobile or external, and one environment, which is typically production or staging, depending on risk and access.

The offer is a time-boxed engagement of about 30 hours' worth of assessment. The organization cannot choose "all of the above", meaning we won't spread the time across multiple apps, multiple APIs, and infrastructure.

What's not included

We want to clarify that our assessment does not include 24/7 monitoring, incident response retainers or ongoing security management. Retesting and extended fix validation are also not included.

This offer also excludes large multi-system environments, complex multi-tenant platforms, broad red-team style engagements or anything that would require us to disrupt services or introduce material operational risk.

Operational requirements

The selected organization must meet some operational requirements, including permission to test the selected systems and written authorization. The organization also needs to support basic logistics, such as a technical contact, a test window, and access provisioning, where applicable.

Additionally, they must agree to adhere to our confidentiality and master service agreements without any modifications.

On our side, if we identify a critical issue, we will notify you promptly and work with you on safe disclosure and next steps.

How selection works

A Hack to Give Back 2026 selection process infographic

Timeline

You can apply here until the end of March 2026. The selection will take place by the end of April 2026 or on a rolling basis until three organizations are chosen.

Regarding delivery, commitments are scheduled for the second quarter of 2026 based on mutual availability.

Do you have questions? Let's talk.

Get in touch with our cybersecurity experts

Read More