Free Cybersecurity for Canadian Nonprofits & Municipalities

πŸ›‘οΈ Enterprise-grade cybersecurity for Canadian nonprofits and municipalities. Free or on a pay-what-you-can basis β€” so every organization can protect its mission, no matter the budget.

How It Works

Step 1: Request a Free Assessment

Fill out our short form or give us a call. Tell us about your organization and we'll schedule a discovery call at your convenience β€” no commitment required.

Step 2: We Assess and Plan

Our team conducts a thorough security assessment of your network, devices, and practices. We identify vulnerabilities and prioritize risks, then present you with a clear, jargon-free report.

Step 3: We Implement and Support

We deploy security tools, harden your systems, train your staff, and set up monitoring β€” all at no cost. We remain available for ongoing questions and support after implementation.

Who We Are

Our Mission & Values

We believe every nonprofit and municipality β€” regardless of size or budget β€” deserves the same robust cybersecurity protection that large enterprises rely on. Our team brings hands-on expertise in IT security, network infrastructure, and open-source tools, all delivered as a community service.

Our Founder

Ross Moravec founded Nonprofit Tech Support after 15+ years in IT, including frontline experience at Canada Revenue Agency and ATB Financial. A certified cybersecurity professional (Cambrian College Graduate Certificate, CompTIA A+, MCSE), Ross specializes in Zero Trust architecture, SIEM, and open-source security platforms.

How Can We Help?

Security Scans

We scan your entire network to identify every connected device and give you a clear picture of your security posture β€” all at no cost. This is typically the first step for organizations that have never had a formal security review.

Learn more about security scans β†’

Vulnerability Assessment

Using tools like OpenVAS, we systematically probe your systems for known weaknesses before attackers can find them. You receive a clear, prioritized report so you know exactly what to fix first β€” no technical jargon, just actionable next steps.

Learn more about vulnerability assessments β†’

Open-Source Security Solutions

We deploy enterprise-grade, open-source security platforms β€” Wazuh for intrusion detection, Grafana for real-time dashboards, and OPNsense for firewall protection. These are the same tools used by large organizations, deployed for free in your environment.

Security Hardening

We lock down your systems by configuring Group Policies, setting up firewalls, enforcing least-privilege access, and applying security best practices across your network. Think of it as putting strong locks on all your digital doors.

Backup and Disaster Recovery

We set up robust backup solutions using Veeam Backup and Replication Community Edition so your critical data is always protected. If a disaster or ransomware attack strikes, you will have a tested recovery plan ready to get your organization back online fast.

Security Awareness Training

Your staff are your first line of defence. We deliver practical, engaging training that teaches your team to spot phishing emails, handle suspicious links, and follow secure practices every day. Awareness training is often the most cost-effective security investment you can make.

Compliance and Planning

We help you understand the compliance requirements that apply to your organization and develop a practical incident response plan. Being prepared means less downtime and fewer surprises when security events occur.

Cybersecurity Insurance

Considering cyber insurance? We walk you through the prerequisites, help you meet the requirements, and guide you toward coverage that fits your organization's risk profile and budget.

Resources from Reputable Organizations

We connect you with trusted resources from CISA, the Global Cyber Alliance, and the Cyber Readiness Institute. These curated guides and toolkits give your team the knowledge to stay ahead of evolving threats.

Browse curated resources β†’

Network Traffic Analysis

Using Zeek, we analyze your network traffic in real time to spot anomalous behavior and potential threats. This deep visibility helps catch intrusions early, before they can cause serious damage to your organization.

Endpoint Detection and Response

We query your endpoints like a database, monitoring and investigating activity across every system in real time. This lets us detect suspicious behavior the moment it appears, giving your team the power to respond immediately.

Incident Response Automation

Using platforms like TheHive and Cortex, we automate your incident response workflows, integrate threat intelligence feeds, and coordinate actions across your organization. When a security event occurs, the response is fast, consistent, and well-documented.

Our Impact by the Numbers

500+ Vulnerabilities Remediated

Critical security gaps found and fixed β€” before attackers could exploit them.

10+ IT Environments Secured

Enterprise-grade security deployed across nonprofit and municipal networks, from endpoint detection to SIEM monitoring.

5,000+ Community Members Protected

The people served by the organizations we protect β€” staff, clients, donors, and residents who depend on secure systems.

$0 Free & Pay-What-You-Can

We provide all services on a free (pro-bono) or pay-what-you-can basis, ensuring every nonprofit can access enterprise-grade protection regardless of budget.

Frequently Asked Questions

Is your service really free?

Yes, completely. Our initial security assessment costs your organization nothing. We are a volunteer-driven initiative dedicated to making enterprise-level cybersecurity accessible to nonprofits who cannot afford it. There are no hidden fees, contracts, or upsells.

What cybersecurity services do you offer?

We offer a full range of cybersecurity services including: network security scans, vulnerability assessments, security hardening, backup and disaster recovery setup, staff security awareness training, compliance planning, cybersecurity insurance guidance, and deployment of open-source security tools.

How long does an assessment take?

The initial assessment typically takes 1-2 weeks depending on the size of your organization and network. After that, we discuss findings with your team and prioritize the most critical issues. Implementation timelines vary by service, but most foundational security improvements can be completed within 30-60 days.

Do we need our own IT staff to work with you?

Not at all. We handle the technical implementation ourselves and explain everything in plain language. Many of the nonprofits we work with have no dedicated IT staff β€” that is exactly why we exist. We will work with whoever you designate as your point of contact.

Where are you based and who can you serve?

We are based in Alberta but work with nonprofits across Canada. Much of our work β€” including security scans, vulnerability assessments, and training β€” can be done remotely. For on-site deployments, we primarily serve the Edmonton and greater Alberta region.

Contact Us

Fill out the form and we will reach out within 1–2 business days to schedule your free security assessment. No obligation, no contracts, no cost β€” ever. We serve nonprofits and municipalities across Canada.

Submitting sends the fields above to Web3Forms for spam screening and delivery. Do not include sensitive personal information. Read our privacy policy, or use the direct contact options below to avoid the form service.

Or email hello@nonprofittechsupport.ca or call (780) 860-1852.