Small organizations often assume they are too small to attack. That misreads how attacks work now. Nobody is targeting you specifically. Automated tools are scanning everyone constantly, and they do not care whether the door they find belongs to a bank or a twelve-person nonprofit.
Three scripts account for nearly everything we see. A phishing email harvests a real password, and the account has no second factor. A password reused from some breached shopping site gets tried against your email and works. Or a website runs a plugin with a known vulnerability, patched by the vendor months ago and never applied, and a bot finds it before you do.
The defenses are as unglamorous as the attacks. Multi-factor authentication on email and anything touching money, which alone would have stopped the majority of incidents we have been called in to clean up. A password manager so nothing is reused. And a patching habit, because a known vulnerability with an available fix is not bad luck when it is exploited. It is a missed appointment.
None of this requires a security budget worthy of the name. It requires deciding once, setting it up in a week, and keeping the habit. The organizations that get hurt are rarely the unlucky ones. They are the ones that left the well-known doors open.