← ToolkitAudit · security
Cybersecurity Review & Credentialing
Muslim institutions are high-value targets — for politically-motivated attackers, for state-aligned harassment campaigns, for ordinary criminal extortion. Donor data, beneficiary records (including refugees and immigration-vulnerable populations), and even prayer-time scheduling can be weaponized when stolen or leaked. Most Muslim orgs we’ve reviewed run with minimal security posture not because they don’t care but because nobody’s handed them a checklist they can actually work through.
The Ihsan Standard Cybersecurity Review is that checklist, plus a hands-on remediation pass, plus a publicly-visible credential that gives donors and partners a reason to trust you with sensitive data.
The threat model
What we’ve actually seen happen to orgs in the cohort and to peer Muslim orgs we’ve consulted with:
Donor-database exfiltration
Attacker exfiltrates the CRM, dumps the list publicly to chill donors. Has happened at multiple US Muslim orgs in the last 5 years.
Wire-transfer fraud
Attacker spoofs the ED's email, instructs the CFO to wire vendor payment to attacker-controlled account. Industry-wide pattern; Muslim orgs are not exempt.
Politically-motivated harassment
Doxxing of staff, board, and named scholars. Coordinated review-bombing, hosting takedowns via DMCA / abuse complaints filed in bad faith.
Beneficiary data exposure
Refugee resettlement records, asylum-seeker case files, abuse-survivor records. Catastrophic when leaked; orgs handling these have a heightened duty of care.
Ransomware
Files encrypted. For an org without backups + tested restore process, this means starting over on the books mid-fundraising-season.
Donor-page skimming
Attacker compromises the website and inserts skimming JavaScript that exfiltrates credit-card numbers from donation forms. The org and the donor both pay for it.
The review tiers
Three credential tiers reflecting the depth of review completed. Most orgs start at Foundational and progress to Standard within 12 months.
Foundational
2-week review
- •Web stack scan (TLS, headers, common CMS vulnerabilities, exposed admin panels).
- •DNS / email auth check (SPF, DKIM, DMARC).
- •Account hygiene baseline (admin accounts, password manager rollout, MFA enforcement on critical systems).
- •Backup posture (does it exist, can it be restored).
- •Incident-response one-pager so the org knows who to call when something goes wrong.
Standard
6-week review
- •Everything from Foundational, plus:
- •Vendor risk review across the SaaS stack (which vendors hold which data, what's their security posture).
- •Donor PII audit — payment flow, CRM, email marketing.
- •Phishing simulation for staff + remediation training.
- •Beneficiary data classification and access control (especially for refugee / DV / asylum orgs).
- •Tabletop incident-response exercise with the board.
Heightened (Gold tier)
12-week engagement
- •Everything from Standard, plus:
- •Penetration test by an Ihsan Standard-vetted security firm.
- •Advanced phishing simulation with named attacker personas relevant to Muslim-org threat model.
- •Code review for in-house tools (donor portal, custom apps).
- •Threat intel monitoring (ongoing) — Ihsan Standard watches for cohort orgs being named in attacker forums.
- •Quarterly check-in calls for the first year post-credential.
The Ihsan Standard Security Credential
On successful completion, the org receives a publicly-visible credential displayed on its Ihsan Standard org page and embeddable on the org’s own donate page. The credential carries:
- •The tier achieved (Foundational / Standard / Heightened).
- •The date of last review.
- •The renewal date (12 months from issue).
- •A summary of which categories of data the org handles (donor PII / financial / beneficiary-sensitive).
The credential is not a guarantee. No security review can promise that. What it is: a documented attestation that the org has done the work, fixed what was findable at the time of review, and maintains a posture that meets the Ihsan Standard threshold for the tier.
Cost
Foundational and Standard tiers: free during the pilot for orgs in the Ihsan Standard cohort. The Heightened tier involves third-party penetration testing (typically $8–$15k market rate); Ihsan Standard covers the first $5k via the security fund for orgs handling refugee, asylum, or domestic-violence data — where the threat model demands the higher standard.
Engage
If you’ve had a recent security incident, the engagement-track contact form is also the right place to start — we prioritize security incidents. They jump the queue, and we’ll pull together a triage call as fast as humanly possible.