Other Impact Areas Contract

IT/Cybersecurity RFP

Nest Inc.

Posted

Aug 26, 2026

Location

Remote

Type

Contract

Compensation

$20000 - $25000

Mission

What you will drive

The purpose of this RFP is to solicit proposals from experienced IT and cybersecurity firms to: Establish foundational IT and cybersecurity practices (we can share results from an initial exposure scan) Reduce operational and financial risk Improve nonprofit audit readiness and governance Provide ongoing, right-sized IT and security support as we continue to grow Ensure compliance with data protection regulations Given our size and priorities, Nest is seeking a pragmatic, phased approach that prioritizes material risk reduction over enterprise-scale solutions. Scope of Work Comprehensive IT Audit & Risk Assessment The selected vendor will conduct an initial assessment to establish Nest’s IT and cybersecurity baseline. Expected activities include: Scope: Creating an organized framework demonstrating how our organization currently operates (processes, technology, data) Identification of key IT and cybersecurity pain points and risks Deliverables: Written risk assessment summary Prioritized remediation roadmap (0–3 months, 3–6 months, 6–12 months, 12+ months) Core IT & Security Needs The selected vendor will propose implementation and/or management solutions across the following: Identity & Access Management Scope: Review current identity and access management practices Provide role-based access control recommendations Implement or optimize multi-factor authentication (MFA) and related access controls Deliverables: Recommend a restructure of account hierarchy, shared drives, groups, and security settings designed to reduce risk exposure to scams Centralize identity and access management framework documentation Backup & Recovery Scope: Assess backup coverage and storage architecture across systems and data repositories (Note: Nest currently has no formal backup practices beyond Google Drive's native retention features, and no separate backup or retention method for data held in other platforms such as Sage Intacct or Salesforce.) Recommend testing cadence and recovery procedures Deliverables: Documented backup recovery strategy Backup testing plan and testing schedule Documentation of recovery procedures and timelines Secure Remote Access Scope: Evaluate current remote access methods and tools Recommend secure remote access solutions appropriate for Nest’s environment Review third-party applications and access pathways Recommend a standardized antivirus / endpoint protection solution Deliverables: Security control documentation for remote access Develop timeline and plan for deploying antivirus / endpoint protection solution Staff training on security awareness Documentation of required staff behavior changes to ensure compliance with recommendations Data Protection and Privacy Requirements The selected vendor will support the organization in maintaining strong compliance with applicable global data protection regulation including: Scope: Support compliance with relevant international standards and laws, including: Compliance with EU General Data Protection Regulation (GDPR) Compliance with applicable U.S. federal and state privacy laws (e.g., CCPA), in addition to GDPR and other international requirements, given Nest's U.S.-based donor base Guidance for organizations like Nest handling EU resident data Alignment of privacy policies with appropriate, recognized security frameworks Develop an incident response plan for security breaches, aligned to regulation requirements Deliverables: Data compliance assessment or gap analysis Compliance roadmap with prioritized remediation actions Policies, Governance & Audit Readiness The selected vendor will support the development of right-sized, nonprofit-appropriate governance documentation and processes to strengthen Nest’s IT security posture and support audit readiness. Scope: Conduct a review of Nest’s current IT security practices an documentations in relation to existing audit requirements and industry best practices Draft practical and enforceable IT governance policies appropriate for a globally operating nonprofit environment Ensure policies address key areas such as cybersecurity risk management, data processing and protection, backup and recovery, and data retention and deletion Deliverables: A set of practical, enforceable IT governance policies aligned with Nest’s audit requirements and operational needs Recommendations for a lightweight change management system to reduce risks associated with emergency or undocumented systems changes Staff training on incident reporting and data protection requirements Ongoing Support & Advisory Services The selected vendor may support ongoing support services. Proposals should describe a support model, including: Help desk or user support approach for Nest staff Ongoing security monitoring including periodic (quarterly or semi-annual) security reviews Named point of contact and escalation procedures (Note: board member accounts were previously targeted in phishing attempts. Vendor support will cover @buildanest.org accounts, including board members using Nest email addresses; assistance with accounts outside the buildanest.org domain will likely be limited.) Optional Proposals may include optional services with separate pricing, such as: Device management (inventory tracking and lifecycle management) Support for our annual audit

Profile

What makes you a great fit

The purpose of this RFP is to solicit proposals from experienced IT and cybersecurity firms to: Establish foundational IT and cybersecurity practices (we can share results from an initial exposure scan) Reduce operational and financial risk Improve nonprofit audit readiness and governance Provide ongoing, right-sized IT and security support as we continue to grow Ensure compliance with data protection regulations Given our size and priorities, Nest is seeking a pragmatic, phased approach that prioritizes material risk reduction over enterprise-scale solutions. Scope of Work Comprehensive IT Audit & Risk Assessment The selected vendor will conduct an initial assessment to establish Nest’s IT and cybersecurity baseline. Expected activities include: Scope: Creating an organized framework demonstrating how our organization currently operates (processes, technology, data) Identification of key IT and cybersecurity pain points and risks Deliverables: Written risk assessment summary Prioritized remediation roadmap (0–3 months, 3–6 months, 6–12 months, 12+ months) Core IT & Security Needs The selected vendor will propose implementation and/or management solutions across the following: Identity & Access Management Scope: Review current identity and access management practices Provide role-based access control recommendations Implement or optimize multi-factor authentication (MFA) and related access controls Deliverables: Recommend a restructure of account hierarchy, shared drives, groups, and security settings designed to reduce risk exposure to scams Centralize identity and access management framework documentation Backup & Recovery Scope: Assess backup coverage and storage architecture across systems and data repositories (Note: Nest currently has no formal backup practices beyond Google Drive's native retention features, and no separate backup or retention method for data held in other platforms such as Sage Intacct or Salesforce.) Recommend testing cadence and recovery procedures Deliverables: Documented backup recovery strategy Backup testing plan and testing schedule Documentation of recovery procedures and timelines Secure Remote Access Scope: Evaluate current remote access methods and tools Recommend secure remote access solutions appropriate for Nest’s environment Review third-party applications and access pathways Recommend a standardized antivirus / endpoint protection solution Deliverables: Security control documentation for remote access Develop timeline and plan for deploying antivirus / endpoint protection solution Staff training on security awareness Documentation of required staff behavior changes to ensure compliance with recommendations Data Protection and Privacy Requirements The selected vendor will support the organization in maintaining strong compliance with applicable global data protection regulation including: Scope: Support compliance with relevant international standards and laws, including: Compliance with EU General Data Protection Regulation (GDPR) Compliance with applicable U.S. federal and state privacy laws (e.g., CCPA), in addition to GDPR and other international requirements, given Nest's U.S.-based donor base Guidance for organizations like Nest handling EU resident data Alignment of privacy policies with appropriate, recognized security frameworks Develop an incident response plan for security breaches, aligned to regulation requirements Deliverables: Data compliance assessment or gap analysis Compliance roadmap with prioritized remediation actions Policies, Governance & Audit Readiness The selected vendor will support the development of right-sized, nonprofit-appropriate governance documentation and processes to strengthen Nest’s IT security posture and support audit readiness. Scope: Conduct a review of Nest’s current IT security practices an documentations in relation to existing audit requirements and industry best practices Draft practical and enforceable IT governance policies appropriate for a globally operating nonprofit environment Ensure policies address key areas such as cybersecurity risk management, data processing and protection, backup and recovery, and data retention and deletion Deliverables: A set of practical, enforceable IT governance policies aligned with Nest’s audit requirements and operational needs Recommendations for a lightweight change management system to reduce risks associated with emergency or undocumented systems changes Staff training on incident reporting and data protection requirements Ongoing Support & Advisory Services The selected vendor may support ongoing support services. Proposals should describe a support model, including: Help desk or user support approach for Nest staff Ongoing security monitoring including periodic (quarterly or semi-annual) security reviews Named point of contact and escalation procedures (Note: board member accounts were previously targeted in phishing attempts. Vendor support will cover @buildanest.org accounts, including board members using Nest email addresses; assistance with accounts outside the buildanest.org domain will likely be limited.) Optional Proposals may include optional services with separate pricing, such as: Device management (inventory tracking and lifecycle management) Support for our annual audit