6bf75a5f38d922fce6c148ee35e94fd1

USA for IOM

CASE STUDY

Empowering a Mission-Driven Nonprofit with PCI Compliance

RSI Security helped nonprofit leader USA for IOM achieve PCI compliance and
build a secure digital fundraising foundation.

2a506ad4243c5b7f336ff2c7880b7797

About the Client

USA for IOM is the U.S. nonprofit partner of the International Organization for Migration (IOM), the UN agency responsible for migration. Their mission is to raise awareness and mobilize support for humanitarian and development initiatives that improve the lives of migrants and displaced communities globally. With a small but passionate team, USA for IOM plays a pivotal role in funding life-saving programs and amplifying the voices of vulnerable populations.

40
Countries
1m+
Benefited
56
Partners

The Challenge Achieving PCI Compliance for Digital Fundraising

When USA for IOM set out to accept digital donations independently for the first time, one major hurdle stood in their way: achieving Payment Card Industry (PCI) compliance. In the past, donation platforms and data systems were handled by a much larger partner organization. But this year, USA for IOM needed to stand on its own.

With a team of just four—and no dedicated IT staff—the organization faced:

  • A steep learning curve in understanding PCI DSS requirements
  • Tight internal resources and capacity
  • A complex, evolving compliance landscape
  • High urgency to meet donor expectations
    and support growing fundraising needs

This wasn’t just a checkbox exercise. It was critical infrastructure for funding life-changing work around the world.

“Despite our limited technical knowledge, RSI made the process approachable by explaining requirements in plain language and helping us understand what was needed from our vendors and systems.”

fba2000be4159df136d1475f56594f0d

— Sonia Agnesod, Planning, Coordination, and Compliance, USA for IOM

The Outcome

Successful PCI Certification and New Capabilities

Despite limited internal resources and a fast-approaching deadline, USA for IOM achieved full PCI compliance—with several lasting benefits:

  • Secure acceptance of digital donations as an independent nonprofit
  • Quarterly vulnerability scanning and long-term compliance scheduling
  • Clarity on renewal timelines and vendor expectations
  • Robust policies and documentation aligned to industry best practices
  • Increased donor confidence and readiness for future fundraising growth

“They Didn’t Just Guide Us—They Partnered With Us.”

Achieving Success Through Collaboration

This success wasn’t just a milestone—it was a transformation. Key to that transformation were RSI Security team members Kavya Prakash, Peter Phaneuf, and Patrick Murphy, whose leadership and expertise elevated the entire engagement. Their clear communication, proactive support, and steady guidance turned what could have been a daunting audit into a valuable learning experience.
Thanks to their partnership, the USA for IOM team emerged stronger, more confident, and fully prepared for ongoing compliance.

“RSI Security went above and beyond throughout the engagement. Their team was consistently organized, responsive, and proactive... Their dedication made all the difference in our success.”

— Sonia Agnesod, Planning, Coordination, and Compliance, USA for IOM

Secure, Compliant, and Future-Ready

Achieving PCI compliance was a critical step in expanding USA for
IOM’s impact and outreach.

With a solid compliance foundation, the organization is now positioned to:

  • Pursue new funding opportunities

  • Build stronger donor relationships

  • Operate with increased
    cybersecurity confidence

acc-3
acc-4
acc-2
acc-5
acc-1
TESTIMONIALS

What our clients are saying

client
Peter Ripa
CEO of Century Club of San Diego Farmers Insurance Open

"We were looking for an IT partner who was both an ASV and QSA vendor with a long-term view of out organization's growing security needs. We were very pleased with the overall experience. I can sleep a little easier at night."

client
Dan Poloche
Director of Security and Compliance Fattmerchant

"RSI Security is a great QSA for advanced service providers that leverage technology such as tokenization. First time PCI Level 1 service providers would also benefit from their knowledge and personalized approach."

client
Neil Zerrusen
Three Z Printing Co.

"We’ve partnered with RSI Security for over a year and are impressed with their professionalism, reliability, and commitment to our security. We would highly recommend RSI Security to anyone looking for a top-tier security provider."

LATEST

Case Studies

Epic Games Case Study | RSI Security’s Penetration Testing Success

Epic Games Case Study

Macomb Community College Case Study | RSI Security's Compliance Expertise

Macomb Community College Case Study

Lumistry Case Study | Scalable vCISO Services by RSI Security

Lumistry Case Study

Tillys Case Study | RSI Security's Retail Cybersecurity & PCI DSS Expertise

Tilly’s Case Study

RSI Security

Power Digital Case Study

meltmedia Case Study | RSI Security’s HITRUST & HIPAA Compliance Support

Meltmedia Case Study

WorkWave Case Study | RSI Security’s ISO 27001 Readiness & Cybersecurity Strategy

WorkWave Case Study

Finix Case Study | RSI Security’s PCI DSS & Cybersecurity Program Advisory

Finix Case Study

CUSTOMERS

Organizations that trust RSI Security

samsung
RSI Security
Epic
PowerDigital_SecondaryLogo_Transparent_Black_67181
Tenet
cisco-impact
Workwave-1
sandag
tarleton-state-university-logo-freelogovectors.net_
Island
Rady_Childrens_Hospital_logo.svg
RSI Seal
century-club-sd