A strong need exists to enhance the security on the NationBuilder Control Panel.
Whether this is through IP Address restriction that allows access only from certain IP addresses, or two factor authentication (or something else) there is huge potential for major loss with nothing standing between a mal-intended person and your entire supporter base but a password.
This post touched on the other important issue that there needs to be much more visibility of administrative actions. Emails/alerts etc for new admins, for exports andeven for logins outside a range of set IP addresses.
Update 04/30/2018 - We have made a few security enhancements. All NationBuilder sites now come with SSL & the password minimum is now 8 characters.
Thank you - there are multiple security enhancements that our team is working on!