TAG Cybersecurity Pre-Event Questionnaire

The Technology Association of Grantmakers (TAG) is excited to launch this brief pre-event assessment to better understand your organization’s current cybersecurity practices and preparedness.

TAG, along with members Junell Felsburg (The Columbus Foundation) and Steve Sharer (RipRap Security), will be hosting a session on April 29, 2026, about foundational cybersecurity best practices. Through this questionnaire, we hope to:
  • Develop specific and actionable recommendations
  • Ensure the session series is highly relevant to the TAG community
  • Share anonymized, aggregate survey results to help you benchmark against peer organizations
Instructions: For each question, select the response that best reflects your understanding of your organization. The survey contains 16 multiple-choice questions and should take approximately 3-4 minutes to complete.
Demographics
These questions help us understand the size and structure of participating organizations.
1.What is the size of your full-time staff?(Required.)
2.What workplace model do you use?(Required.)
3.Who is responsible for IT and Security at your organization?(Required.)
4.Do you issue laptops to staff?(Required.)
Security
These questions assess foundational cyber security practices at your organization. If you're unsure about any answer, select "Unsure"—that's useful information too.
5.Do you maintain an inventory of hardware and software used at your organization?(Required.)
6.Do you have device management in place for organizationally issued computers?(Required.)
7.Does your organization require multi-factor authentication (MFA) for your productivity suite (Google Workspace, Microsoft 365, etc.)(Required.)
8.Do you provide a password manager for staff?(Required.)
9.Do you provide at least quarterly cyber security training for staff?(Required.)
10.Do you have any tools installed on computers to detect malicious activity (anti-virus, endpoint detection & response tools, etc)?(Required.)
11.Do you have an incident response plan?(Required.)
12.Do you have cyber insurance?(Required.)
13.Do you vet potential vendors on their security procedures and policies? (Required.)
14.Do you have a data governance policy?(Required.)
15.Do you back up data in your productivity suite to an external, third-party service?(Required.)
16.What types of sensitive data does your organization handle/manage? (Select all that apply)(Required.)