When a nonprofit experiences ransomware, account takeover or another cyberattack, employees immediately need reliable instructions.
They need to know who has authority to isolate systems, contact vendors, preserve evidence, notify leadership and communicate with employees, participants or donors. Yet many organizations keep those instructions in the same email, cloud storage or network environment that may become unavailable during the incident.
A response plan that cannot be accessed during an attack is not a usable plan.
Build One Trusted Response Source
Cybersecurity procedures are often scattered across IT tickets, insurance documents, vendor contracts, employee handbooks and personal contact lists. Different departments may also hold conflicting versions.
The nonprofit should document:
- Who declares a cyber incident
- Internal and external response contacts
- Cyber insurance notification procedures
- Technology vendor escalation paths
- Steps for isolating affected accounts or devices
- Backup communication methods
- Legal and regulatory review responsibilities
- Evidence-preservation procedures
- Approved public communication roles
- Recovery priorities
- Password-reset and access-restoration procedures
- Post-incident review requirements
CISA recommends maintaining and regularly exercising an incident-response plan and a communications plan covering ransomware and data-extortion events. Its StopRansomware Guide provides practical preparation and response guidance.
NIST’s current incident-response recommendations treat preparation, response and recovery as parts of broader cybersecurity risk management rather than a document created only after an attack. (NIST CSRC)
Keep an Offline or Independent Copy
SharePoint should serve as the organized knowledge source during normal operations. It can contain approved response procedures, blank incident forms, role assignments, vendor information and training materials.
However, essential contact lists and first-response instructions should also be available through a protected offline or independently accessible method. Employees should not assume Microsoft 365, email, Teams or the organization’s network will remain available.
The backup copy must be controlled carefully. It should not expose passwords, private keys, recovery codes or detailed security information to unauthorized employees.
Use AI Before and After the Attack—Not as the Incident Commander
Copilot Studio provides the conversational AI layer. Through Maisy, authorized employees might ask during normal operations:
- Who handles a suspected phishing incident?
- Where is the cyber insurance policy?
- Which vendor manages our Microsoft tenant?
- What information must be preserved?
- Who approves external communications?
- When was the response plan last tested?
Microsoft states that a Copilot Studio agent using SharePoint can surface only content the authenticated user already has permission to access. SharePoint access can also be limited through Microsoft 365 and Entra security groups. (Microsoft Learn)
Maisy should not decide whether to pay a ransom, determine whether a breach notification is legally required or direct forensic activity. Those decisions require leadership, legal counsel, cybersecurity professionals, insurers and law enforcement when appropriate.
Security platforms remain authoritative for technical alerts. Signed insurance policies remain authoritative for coverage. Incident records should remain in the approved secured system.
How Maisy Helps
Pixeldust begins by identifying repeated security questions, critical vendors, response roles, authoritative procedures and gaps in backup access.
Pixeldust then resolves conflicting documents, assigns content owners, reviews permissions and organizes approved guidance in SharePoint. Maisy is configured through Copilot Studio and tested with realistic scenarios before an actual incident occurs.
This helps the nonprofit retain institutional knowledge about cybersecurity response while ensuring that human experts—and an accessible backup plan—remain in control when systems fail.





