← Toolkit

Audit · security

Cybersecurity Review & Credentialing

Muslim institutions are high-value targets — for politically-motivated attackers, for state-aligned harassment campaigns, for ordinary criminal extortion. Donor data, beneficiary records (including refugees and immigration-vulnerable populations), and even prayer-time scheduling can be weaponized when stolen or leaked. Most Muslim orgs we’ve reviewed run with minimal security posture not because they don’t care but because nobody’s handed them a checklist they can actually work through.

The Ihsan Standard Cybersecurity Review is that checklist, plus a hands-on remediation pass, plus a publicly-visible credential that gives donors and partners a reason to trust you with sensitive data.

The threat model

What we’ve actually seen happen to orgs in the cohort and to peer Muslim orgs we’ve consulted with:

The review tiers

Three credential tiers reflecting the depth of review completed. Most orgs start at Foundational and progress to Standard within 12 months.

Foundational

2-week review

  • Web stack scan (TLS, headers, common CMS vulnerabilities, exposed admin panels).
  • DNS / email auth check (SPF, DKIM, DMARC).
  • Account hygiene baseline (admin accounts, password manager rollout, MFA enforcement on critical systems).
  • Backup posture (does it exist, can it be restored).
  • Incident-response one-pager so the org knows who to call when something goes wrong.

Standard

6-week review

  • Everything from Foundational, plus:
  • Vendor risk review across the SaaS stack (which vendors hold which data, what's their security posture).
  • Donor PII audit — payment flow, CRM, email marketing.
  • Phishing simulation for staff + remediation training.
  • Beneficiary data classification and access control (especially for refugee / DV / asylum orgs).
  • Tabletop incident-response exercise with the board.

Heightened (Gold tier)

12-week engagement

  • Everything from Standard, plus:
  • Penetration test by an Ihsan Standard-vetted security firm.
  • Advanced phishing simulation with named attacker personas relevant to Muslim-org threat model.
  • Code review for in-house tools (donor portal, custom apps).
  • Threat intel monitoring (ongoing) — Ihsan Standard watches for cohort orgs being named in attacker forums.
  • Quarterly check-in calls for the first year post-credential.

The Ihsan Standard Security Credential

On successful completion, the org receives a publicly-visible credential displayed on its Ihsan Standard org page and embeddable on the org’s own donate page. The credential carries:

The credential is not a guarantee. No security review can promise that. What it is: a documented attestation that the org has done the work, fixed what was findable at the time of review, and maintains a posture that meets the Ihsan Standard threshold for the tier.

Cost

Foundational and Standard tiers: free during the pilot for orgs in the Ihsan Standard cohort. The Heightened tier involves third-party penetration testing (typically $8–$15k market rate); Ihsan Standard covers the first $5k via the security fund for orgs handling refugee, asylum, or domestic-violence data — where the threat model demands the higher standard.

Engage

If you’ve had a recent security incident, the engagement-track contact form is also the right place to start — we prioritize security incidents. They jump the queue, and we’ll pull together a triage call as fast as humanly possible.