Cyber Security for Charities

Charities hold some of the most sensitive personal data of any sector, usually with the least resource to protect it. We price this work accordingly and tell you when free guidance is enough.

Primary risk
Beneficiary data exposure
Drivers
Funders, Charity Commission
Constraint
Genuinely limited budget
Our approach
Proportionate, honest

The data is the risk

Depending on your cause, you may hold information about domestic abuse survivors, people with health conditions, immigration status, addiction, criminal history or safeguarding concerns about children. Exposure here is not an inconvenience — it can put people in physical danger.

That is a genuinely different risk profile from a commercial organisation losing customer email addresses, and it deserves to be treated differently.

What we consistently find

  • Volunteers with staff-level access, often retained long after they stop volunteering.
  • Beneficiary data in spreadsheets on shared drives, emailed between staff, copied to personal devices.
  • No offboarding process — the most consistent finding in the sector.
  • Donated or ageing hardware running unsupported software.
  • Free-tier cloud services adopted informally, holding real personal data with no contract or DPA.
  • Shared logins for case management, making it impossible to know who accessed what.

Who is asking

Funders increasingly attach data protection and security conditions to grants. Local authority and NHS commissioning brings its own requirements, frequently including Cyber Essentials. Corporate partners send security questionnaires. And the Charity Commission expects trustees to manage risk, which now plainly includes cyber risk.

What we will tell you for free

A good deal of what a small charity needs costs nothing. The NCSC publishes genuinely good free guidance for charities and small organisations. Multi-factor authentication is free on Microsoft 365 and Google Workspace. Microsoft and Google both offer substantial non-profit discounts, and many charities are paying for licences they could have free.

We would rather point you at those than charge you to restate them. Where you need something we provide — Cyber Essentials certification, an external test because a funder requires evidence — we will scope it to what is actually needed.

Where to start

MFA on everything, universally. An access review — who can see beneficiary data, and do they still need to. A written offboarding checklist. A tested backup. Then Cyber Essentials if a funder or commissioner requires it. A penetration test is rarely the right first spend for a small charity, and we will say so.

Common questions

We have almost no budget. What should we do?

MFA on email and any remote access, review who can see beneficiary data, write down an offboarding process, and test that your backup restores. All four cost time rather than money and address most of what we see go wrong.

Do you offer reduced rates for charities?

We size engagements to what is genuinely needed rather than selling a standard package, and we'll discuss staging work across a financial year. We'd also rather tell you something is unnecessary than sell it. Ask, and we'll be straight with you.

A funder is asking about our data security. What do they usually want?

Typically: how you store beneficiary data, who can access it, what happens if there's a breach, and whether you hold any certification. Cyber Essentials answers a good portion of it. Send us the actual question and we'll help you work out what's being asked.

Our volunteers use their own devices. Is that a problem?

It's manageable but needs thought. The key questions are whether beneficiary data ends up stored locally, what happens when someone stops volunteering, and whether the account can be disabled centrally. Often the answer is to change how data is accessed rather than to ban personal devices.

Related

Ready to talk?

Scoping conversations are free and there is no sales team to get past. Tell us what you're dealing with and we'll tell you honestly what you need.