<!-- Bizible Script --> <script type="text/javascript" class="optanon-category-C0004" src="//cdn.bizible.com/scripts/bizible.js" ></script> <!-- End Bizible Script -->
Not For Profit Suite

Cyber security for charities: because your work is too important to risk

Every day, you manage donations, coordinate volunteers and deliver essential services, using technology to store and manage the sensitive information that comes along with it.

With that in mind, cyber security for charities is essential for protecting the people, communities and causes you support.

In fact, 28% of charities reported experiencing a cyber security breach or attack in the previous 12 months, according to the UK Government's Cyber Security Breaches Survey 2025/2026.

That's around three in ten charities, so understanding the importance of cyber security for charities – and knowing how to reduce your risk – deserves a place on every charity's agenda.

This guide walks you through what cyber security involves, the threats most likely to affect your charity, and six practical steps you can take to protect your organisation, whatever your size or budget. You'll also find a quick self-assessment checklist to help you work out where to start.

6 minutes

Written by Chris Field – Engineering and CRM expert.

Posted 16/07/2026

First, what is cyber security?

Let's start with the basics. Cyber security is simply the practice of protecting your systems, networks, devices and data from unauthorised access, damage or disruption.

Or, put another way, it's everything you do to keep the wrong people out of your stuff.

In practice, it comes down to four things:

  • Preventing attacks before they reach your systems
  • Managing access to sensitive data, so only the right people see it
  • Keeping systems updated to close known weaknesses
  • Knowing how to respond when something looks wrong

Cyber security for charities has its own challenges, though. You're often looking after sensitive personal information while working with tight budgets and a lean team, which is a tricky balance to strike.

The good news is that staying secure isn't about any single clever fix. It's a mix of the right technology, a few clear processes, and people who know what to watch for, and together those three things go a long way towards reducing risk, protecting trust and keeping your services safely running.

Why is cyber security important for charities?

The importance of cyber security for charities goes well beyond protecting data and systems, and it's not just us saying so.

Writing in the National Cyber Security Centre's Cyber threat report: UK charity sector, Helen Stephenson, then Chief Executive of the Charity Commission for England and Wales, described staying secure online as,

"not an optional extra for trustees, but a core part of good governance."

So why do charities end up in the firing line, and what's really at stake when things go wrong? Let's take each in turn.

Charities are attractive targets for cyber criminals

Cyber criminals go looking for weak spots that let them reach personal data, financial information or key systems. Charities can be appealing because they often hold valuable information but run on limited resources, and attackers know it.

Think about how much of your work runs through digital fundraising platforms, email, cloud services and online tools. All essential for connecting with supporters, but each one is a door that needs locking if it isn't properly protected.

And here's a myth worth busting: it's easy to assume criminals only target big organisations, but the opposite is often true. Attackers tend to see smaller organisations as the softer option, precisely because they're banking on fewer defences being in place. 

The impact goes beyond financial loss

The damage from a cyber attack rarely stops at money. For a charity, a single incident can mean:

  • Lost trust: charities depend heavily on public confidence, and a security incident can affect how donors and supporters view the organisation
  • Exposed data: a breach could reveal confidential information and create concerns about how personal details are handled
  • Disrupted services: if systems become unavailable or funds are stolen, charities may struggle to process donations or deliver essential support
  • Recovery pressure: getting back to normal takes time and effort, particularly for teams already managing busy workloads
  • Legal consequences: organisations that fail to protect personal data, or don't meet their responsibilities for reporting serious incidents, may face regulatory action

What cyber risks do charities face today?

It's harder to defend against threats you aren't aware of, so knowing the common tactics is the first real step towards better cyber security for charities.

For each risk below, we've added a quick "what helps most" note, then covered the how-to properly in the step-by-step section that follows.

Phishing attacks

Phishing attacks use fake emails, messages or websites to trick people into sharing information, clicking harmful links or handing over access to accounts. They remain the most common cyber threat facing the sector.

The Cyber Security Breaches Survey found that 25% of charities experienced a phishing attack in the past year, making it by far the most frequently reported type of incident.

Phishing works because it targets people rather than just technology. For charities, phishing messages may appear to come from trusted contacts, suppliers or fundraising platforms. A successful attack could lead to stolen passwords, financial fraud, or unauthorised access to sensitive information.

  • What helps most: regular team training so people can spot suspicious messages, and multi-factor authentication so a stolen password alone isn't enough to get in.

Data breaches

A data breach is simply information being accessed, shared or stolen without permission. For a charity, that might be donor details, volunteer information, beneficiary records or internal documents. It's worth knowing that breaches don't always come from a dramatic cyber attack, either. Plenty happen through honest mistakes, like sharing information with the wrong person or using an insecure tool.

As more charities adopt artificial intelligence tools, there's also a risk that sensitive information could be entered into platforms without a clear understanding of how that data is stored or used. The Cyber Security Breaches Survey also found that, while AI use is growing among charities, only around a quarter of organisations using or considering AI have security practices in place to manage the risks.

This is a particular concern for organisations without a clear AI policy to guide teams on how to use these tools safely.

  • What helps most: clear access controls so people only see the data they need, and simple policies covering how information (and AI tools) should be used.

Ransomware

Ransomware is where criminals lock up an organisation's systems or data and demand payment to hand it back. For a charity, that can be hugely disruptive, especially if your team relies on digital systems to run services and stay in touch with supporters.

And here's the sting: even if you don't pay the ransom, getting everything back up and running can be slow and resource-heavy. That's more pressure on your team, and important work put on hold while the lights come back on.

  • What helps most: regular, tested backups stored separately from your main systems, and keeping software up to date so known weaknesses can't be exploited.

Risks from disconnected systems

Most charities juggle several different systems for fundraising, finance, volunteer information and communication. It's completely normal, but when those systems don't talk to each other, keeping information secure gets harder.

Disconnected systems tend to breed inconsistent access permissions and manual workarounds, which is where mistakes creep in. They also make it tougher to keep an eye on security risks and to move quickly if something does go wrong.

  • What helps most: reducing the number of places your data lives, and making sure the systems you do use meet recognised security standards.

You can read more on "the case for a cohesion" here.

"The charities I speak to often assume good cyber security means big budgets and dedicated IT teams. In reality, the organisations that cope best with threats are usually the ones that get the basics consistently right: training people, controlling access, and keeping systems up to date. None of that requires deep pockets, just a decision to make it part of how you work."

Tim Leahy Engineering Lead, Access Not for Profit

6 practical steps: how to strengthen your charity's cyber security

Good news: improving cyber security for charities rarely calls for anything complicated or expensive. Here's our charity cyber security best practices, roughly in order of effort:

  • Get the password basics right
  • Train your team to understand the risks
  • Control who can access sensitive information
  • Plan how you'd respond to an incident
  • Consider Cyber Essentials certification
  • Invest in secure, integrated systems

Work through them in order if you're starting from scratch, or dip into the ones you haven't covered yet. The NCSC's resources are also well worth a look for advice tailored to small and medium-sized organisations. 

Get the password basics right

Strong, unique passwords are one of the simplest protections available, and the NCSC's advice is refreshingly practical:

  • Use three random words to create passwords that are easy to remember but hard to guess
  • Don't force regular password changes; only change passwords if you suspect they've been compromised
  • Never require people to share accounts or logins to do their jobs

Where it's available, switch on multi-factor authentication (sometimes called two-factor authentication or 2FA), starting with email, banking and any system holding donor or beneficiary data. It's usually free, takes minutes to set up, and stops most attacks that rely on stolen passwords.

Train your team to understand the risks

Your people are one of the most important lines of defence for preventing cyber attacks. When staff and volunteers know what a threat looks like, they're far more likely to spot something – and therefore less likely to make a costly slip.

Regular training helps everyone recognise phishing attempts, handle information properly, and understand what they're responsible for. This matters even more for charities that rely on volunteers with different levels of digital confidence. A great starting point is the NCSC's free online cyber security training, which takes around 30 minutes and is designed for people without a technical background.

Control who can access sensitive information

It's worth checking, regularly, that people can only reach the information they actually need for their role. Tight access controls cut the risk of accidental sharing or unauthorised access, which really matters when employees, volunteers and external contributors all need different permissions.

This is a particularly important consideration when managing digital volunteering.

Make sure to put clear processes in place for granting and changing permissions, as well as removing access when someone leaves the organisation. A simple habit that helps: review who has access to what once a quarter, and every time someone joins or leaves.

Plan how you'd respond to an incident

The Charity Commission's guidance on protecting your charity from cyber crime recommends that every charity has a plan for responding to a cyber attack, and that trustees take responsibility for making sure it exists.

Your plan doesn't need to be long. At a minimum, it should cover:

  • Who to contact when something goes wrong, both inside and outside your charity
  • How to keep operating if key systems are unavailable
  • Your reporting responsibilities: cyber crime should be reported to Action Fraud, and serious incidents to the Charity Commission

The NCSC's free Exercise in a Box tool lets you rehearse your response to common attacks, such as phishing, in a safe environment.

Consider Cyber Essentials certification

Cyber Essentials is a government-backed certification scheme that helps organisations of all sizes protect against the most common cyber attacks. For charities, it offers a clear framework to work towards, reassurance for funders and partners, and it's increasingly requested in funding applications and required for government contracts.

Certification is annually renewable and built around five technical controls, so it doubles as a practical to-do list even before you certify. The NCSC's free Cyber Essentials Readiness Tool can help you assess where you currently stand.

Invest in secure, integrated systems

Secure, integrated systems take a lot of the complexity out of managing information. When your data sits together consistently, your team can see where everything is held and how it's being looked after, rather than guessing.

Using a single system can also reduce the need to transfer information between separate platforms, helping to minimise the points where data could be exposed or compromised. 

This connected approach can improve security while also making every day processes easier for staff and volunteers, and this sits at the heart of the Access Charity Suite

"Having worked with hundreds of charities on their data flows, a pattern I see often is that risk hides in the gaps between systems. Every time information moves manually between platforms, you create a point where it can be altered by accident, duplicated or exposed."

Shaf Mansour Head of Charity Product

How can connected systems improve cyber security for charities?

Connected systems can genuinely help you build a more secure, consistent way of managing information. We won't pretend it's a magic fix, mind you: moving systems takes planning and a bit of resource. But for a lot of charities, the security payoff is well worth understanding.

Keeps important information in one place

Spreading information across lots of platforms makes security harder work. Bring it together and you get better control over your data and fewer weak points, plus less temptation to fall back on insecure workarounds or manual processes.

"Data should live where it needs to live, not sit along the way in a spreadsheet on someone's desktop or a shared folder everyone can access. Bringing data together isn't just an efficiency decision, it's one of the most practical GDPR and security decisions a charity can make." 

- Shaf Mansour, Head of Charity Product

Helps everyone follow the same processes

When every team does things their own way, gaps appear. Connected systems and shared processes make it far easier for staff and volunteers to follow good security habits and keep data protection on track.

Reduces the risk of mistakes

Manual data entry and repetitive tasks are where errors sneak in, especially when people are handling a lot of information at once. Integrated systems do more of the heavy lifting, improving accuracy and cutting the slip-ups that can put data at risk.

Simplifies compliance and strengthens governance

You need to be able to show you're handling information responsibly, and connected systems make that much less painful. Backed by security essentials, they help keep your data management in line with security requirements and your data protection responsibilities, without the last-minute scramble.

Protects your charity without creating extra work

Security works best when it just quietly happens in the background. Build good safeguards into the systems your staff and volunteers already use every day, and you protect sensitive data without adding a single thing to anyone's to-do list.

A quick cyber security health check

Not sure where to begin? Grab your team and run through these questions together. Every "no" or "not sure" is pointing you straight at a step in this guide worth tackling first.

  • Do all accounts holding sensitive data have multi-factor authentication switched on?
  • Have staff and volunteers had cyber security training in the last 12 months?
  • Do people only have access to the information they need for their role?
  • Is access removed promptly when someone leaves?
  • Are your systems and software set to update automatically?
  • Are your backups stored separately from your main systems, and have you tested restoring them?
  • Do you have a written plan for responding to a cyber attack, and do trustees know about it?
  • Do you know which systems hold your donor, volunteer and beneficiary data, and how it moves between them?

How Access keeps your charity software secure 

It's only fair to ask whether a software provider actually practises what it preaches, so here's a headline look at how Access handles security. 

Independently certified standards

The Access Group's security credentials are independently verified:

  • ISO 27001:2022 certification, assessed by UKAS-accredited Alcumus ISOQAR
  • Cyber Essentials accreditation
  • ICO registration with the Information Commissioner's Office
  • G-Cloud Framework listing, the Government's register of trusted technology providers for the public sector

These certifications apply company wide, so your charity's data sits within an independently verified security framework.

Secure infrastructure and controlled access 

Access charity software is hosted on leading cloud providers i.e. Microsoft Azure, Amazon & others, with segmented cloud environments, network access controls, and encryption both in transit and at rest. Within the platform, role-based permissions, two-factor authentication options, Single Sign-On integration and audit logging mean your charity can control exactly who sees what, and prove it. 

Continuous monitoring and independent testing 

Security here isn't a tick-box exercise done once and forgotten. Systems are continuously monitored with threat detection controls in place, and penetration testing is carried out by independent third parties holding CREST and CHECK credentials, with every finding formally assessed and tracked through to resolution. Business continuity and disaster recovery plans are tested regularly, and system status and uptime is available for anyone to check.

People are part of the security model too 

Just as we'd nudge charities to train their teams, security at Access is treated as everyone's responsibility, not just the job of dedicated security and compliance specialists.  

All colleagues are required to complete training before being given access to systems, and confirm they’ve read all relevant policies. We also do annual training on cyber security and data protection, too.

It's the same principle we'd recommend to you: strong safeguards start with strong habits.

Round up

If you've made it this far, you already understand the importance of cyber security for charities. And hopefully the encouraging bit has landed too: most of what actually protects your organisation isn't expensive or complicated.

Good password habits, a bit of training, tested backups and a plan for bad days will take you a surprisingly long way.

The rest comes down to the systems you choose. If your data lives across platforms that don't talk to each other, security will always feel like a juggling act.

That's where the Access Charity Suite can help. It brings your key information and processes together in one secure, connected environment, underpinned by Access Evo

Curious how that could look for your charity?

Download the brochure for a handy overview of the entire Suite.

By Chris Field

Engineering and CRM expert

Chris is Engineering Lead for the AI-enabled Access Charity Suite, with over a decade of experience building software for charities.

A Physics graduate, he began his career as an engineer on Access Charity CRM before stepping into the Lead role, a remit he has since expanded to include Donorfy.

Outside the office, Chris is an active member of his local community and a committed bellringer; a pursuit that demands the same precision and teamwork he brings to every engineering project!