It's Monday morning, and someone is working from home. They open the VPN client, wait for it to connect, re-enter a password it has already asked for twice this month, and watch the little spinner turn while it authenticates. If it drops out, and it will, they start again. Once they are in, they wait for the mapped drive to reappear so they can find the membership file that only lives on the server back at the office. If it does not reappear, they email the office and hope someone is at their desk. Across all industries, this can be disastrous, and for a Not-for-Profit (NFP) organisation, this can have a real knock-on effect for real people.
Nobody in this scene is doing anything wrong. This is what remote access looks like when an association is still built around a physical server, a VPN, and one person who understands how it all fits together. It does not feel like a crisis. It feels like Tuesday. That is exactly the problem: the friction has become so familiar that nobody thinks to call it a cost anymore.
Every Association Is Running the Same Legacy Stack
This pattern is not unique to any one organisation. It is close to universal across the sector.
Infoxchange's 2025 Digital Technology in the Not-for-Profit Sector Report found that cloud collaboration tools have reached 87% adoption among Australian and New Zealand NFPs, up from 24% a decade ago. Yet the same report found only 23% of NFPs have a documented cybersecurity plan in place, and organisations with 150 staff or fewer are the least likely to have effective processes to manage information security risk. The sector has adopted cloud-based tools without necessarily retiring the underlying infrastructure.
A server sits in a cupboard or a comms room, ageing quietly past its warranty. Staff connect to it through a VPN that was fast when it was installed and has been getting progressively slower every year since. Files live on mapped network drives rather than anywhere staff can find them on a laptop, on a phone, or on a new starter's first day. Support is reactive: something breaks, someone rings the one person who knows the system, and the fix happens whenever that person is free. None of these trips is an alarm on its own. Together, they define legacy IT and are what an on-premises-to-cloud migration is actually replacing.
Why 'It Still Works' Feels Like the Safe Call
Operational leaders who put off this decision are not being reckless. The instinct makes sense almost everywhere else in the organisation. A server that has run for six years without failing looks like a system that has earned its keep. Migration sounds like risk: downtime, retraining, a project that could go sideways in front of the board. Staff already know the workarounds. Why introduce new ones on purpose?
The instinct is right. The system being applied to has changed underneath it.
The Australian Signals Directorate named the replacement of legacy IT as one of its four priority 'big moves' for organisations in its 2024–25 Annual Cyber Threat Report, alongside a 28% rise in publicly reported vulnerabilities that year. Separately, Coalition's 2025 Cyber Threat Index found that 58% of ransomware incidents originated from vulnerabilities in VPNs and firewalls, the exact technology most associations rely on for remote access. The server that has never gone down is not the same thing as the server that is not a target. It is simply a target nobody has checked on lately. Staying still is no longer the cautious option. It is the exposed one.
What Actually Changes the Day You Go Cloud-First
Picture a peak body with a dozen staff, a membership database running into the thousands, and a server that has quietly been doing its job since an office move whose date nobody quite remembers. Here is what changes for an organisation like that on the day it becomes genuinely cloud-first, not just cloud-adjacent.
Access
Before: a VPN connection, a password prompt, a wait, and a mapped drive that may or may not appear. Staff effectively work from one location, the office network, wherever they happen to be sitting.
After: staff sign in once through Microsoft 365 and Entra ID, and their files, email and systems are simply there, from a laptop at home, a phone at a conference, or a new starter's first login before they have even met the IT team. Location stops being what determines whether someone can do their job.
Member data security
Before: a single server holding member records, payment details and login credentials, protected by whatever backup routine someone remembers to run and a VPN that is one unpatched vulnerability away from being the way in.
After: identity and access are behind multi-factor authentication and conditional access policies, patching happens automatically in the background, and data is encrypted and backed up without anyone needing to remember. Member data security does not depend on a single piece of hardware or a single habit.
Support
Before: reactive and person-dependent. Something breaks, someone calls the one colleague who understands the server, and the fix happens whenever that person is available, on top of their actual job.
After: a managed service model with logged tickets, defined response times, and monitoring that often catches a problem before a staff member notices it. Support stops being a favour someone does and becomes a service the organisation can actually rely on.
Cost
Before: unpredictable and lumpy. Nothing for years, then a server replacement, a licence renewal, and an emergency callout all landed in the same budget cycle.
After: a predictable, largely per-user operating cost that a finance committee can forecast a year out instead of discovering in an invoice. Predictable IT costs are not a minor convenience for an association working to an annual budget approved by a volunteer board. They are the difference between planning and reacting.
None of these four changes on its own justifies a board agenda item. Together, they are the difference between an organisation that manages its technology and one that is quietly managed by it.
Why Next Step Starts With What Changes, Not What It Costs
This is why Next Step Infrastructure Services does not open an association IT modernisation conversation with a licensing quote. It opens with a walk-through of exactly what would change in that organisation's day-to-day: who logs in from where, what member data is stored on which system, who gets called when something breaks, and what the current setup is already costing in time and risk. For a leadership team that is financially literate but not technical, that is a far more useful starting point than a product list. It turns 'cloud-first' from an abstract IT project into a concrete, specific picture of Tuesday morning, three months from now.
The Question That Changes the Conversation
Most boards and leadership teams ask the same question: Will a cloud migration for our not-for-profit be disruptive? That is a fair question, but it is not the one that determines the outcome.
The sharper question is what the current environment is already disrupting, quietly, every week: the hours lost to VPN drop-outs and rekeying data between systems that will not talk to each other, the exposure sitting on a server that has not been properly assessed in years, and the entire organisation's dependence on one person's knowledge that is not written down anywhere. Migration risk is visible and easy to imagine.
The cost of staying on legacy infrastructure is spread thin across a hundred small frictions, and that is exactly why it is easy to underestimate.
Five Signs You're Still Running on Borrowed Time
An operations leader can answer these honestly in a few minutes, without an IT background:
- Can staff access everything they need to do their job from home, on day one, without calling anyone?
- Is there a single person whose absence would stop something important from working?
- Is multi-factor authentication enabled for every system that holds member data?
- Does a support request get logged and tracked, or does it depend on someone being at their desk?
- What does your IT actually cost for the next twelve months, or only for the next invoice?
If two or more of these give an uncomfortable answer, the organisation is not weighing whether to modernise. It is deciding how much longer to carry the cost of not doing it.
The Bottom Line
Cloud-first is not simply a bigger version of Microsoft 365 or a cloud-based CRM. It is a fundamental shift in how your technology operates. Instead of relying on ageing on-premises infrastructure, associations gain secure access from anywhere, stronger built-in security, proactive support and predictable IT costs.
For most associations, cloud-first is not a one-off project. It is the point where technology stops being a constraint and starts supporting the NFP’s long-term goals.
You do not need a migration plan to begin. You need a clear understanding of where you stand today.
Next Step's Scorecard provides that starting point. 25 questions in under 10 minutes, across five key areas to benchmark your technology maturity and identify where the biggest opportunities lie. From there, the conversation shifts from planning a migration to building an IT environment that supports your NFP and those in need.
If cloud-first is on your radar, start with Next Step's Association Technology Maturity Scorecard.
