- Primary risk
- Beneficiary data exposure
- Drivers
- Funders, Charity Commission
- Constraint
- Genuinely limited budget
- Our approach
- Proportionate, honest
The data is the risk
Depending on your cause, you may hold information about domestic abuse survivors, people with health conditions, immigration status, addiction, criminal history or safeguarding concerns about children. Exposure here is not an inconvenience — it can put people in physical danger.
That is a genuinely different risk profile from a commercial organisation losing customer email addresses, and it deserves to be treated differently.
What we consistently find
- Volunteers with staff-level access, often retained long after they stop volunteering.
- Beneficiary data in spreadsheets on shared drives, emailed between staff, copied to personal devices.
- No offboarding process — the most consistent finding in the sector.
- Donated or ageing hardware running unsupported software.
- Free-tier cloud services adopted informally, holding real personal data with no contract or DPA.
- Shared logins for case management, making it impossible to know who accessed what.
Who is asking
Funders increasingly attach data protection and security conditions to grants. Local authority and NHS commissioning brings its own requirements, frequently including Cyber Essentials. Corporate partners send security questionnaires. And the Charity Commission expects trustees to manage risk, which now plainly includes cyber risk.
What we will tell you for free
A good deal of what a small charity needs costs nothing. The NCSC publishes genuinely good free guidance for charities and small organisations. Multi-factor authentication is free on Microsoft 365 and Google Workspace. Microsoft and Google both offer substantial non-profit discounts, and many charities are paying for licences they could have free.
We would rather point you at those than charge you to restate them. Where you need something we provide — Cyber Essentials certification, an external test because a funder requires evidence — we will scope it to what is actually needed.
Where to start
MFA on everything, universally. An access review — who can see beneficiary data, and do they still need to. A written offboarding checklist. A tested backup. Then Cyber Essentials if a funder or commissioner requires it. A penetration test is rarely the right first spend for a small charity, and we will say so.
Common questions
We have almost no budget. What should we do?
MFA on email and any remote access, review who can see beneficiary data, write down an offboarding process, and test that your backup restores. All four cost time rather than money and address most of what we see go wrong.
Do you offer reduced rates for charities?
We size engagements to what is genuinely needed rather than selling a standard package, and we'll discuss staging work across a financial year. We'd also rather tell you something is unnecessary than sell it. Ask, and we'll be straight with you.
A funder is asking about our data security. What do they usually want?
Typically: how you store beneficiary data, who can access it, what happens if there's a breach, and whether you hold any certification. Cyber Essentials answers a good portion of it. Send us the actual question and we'll help you work out what's being asked.
Our volunteers use their own devices. Is that a problem?
It's manageable but needs thought. The key questions are whether beneficiary data ends up stored locally, what happens when someone stops volunteering, and whether the account can be disabled centrally. Often the answer is to change how data is accessed rather than to ban personal devices.
Related
Solusec
Typically replies within one business day
Hi 👋 Need a hand with pen testing, Cyber Essentials, or something urgent? Pick whichever suits you:
💬 WhatsApp usQuick questions, quick answers 📞 Call us
+44 (0)1902 288763 ✉️ Email us
info@solusec.co.uk 📝 Leave a message
We'll reply within one business day