A volunteer who left eight months ago still has an active account, because no one removed it. An attacker buys that volunteer's reused password from a breach and walks straight into the organisation's systems, reaching donor records. With the controls we put in place — prompt offboarding, multi-factor authentication, and monitoring for unusual logins — that dormant door is closed, the stolen password is not enough on its own, and the suspicious access is flagged and stopped. The donors' trust, which is everything to a not-for-profit, is protected.