Now onboarding businesses across Leeds & Yorkshire — book a free IT & security review
← All resources

IT and Cyber Security for Charities and Non-Profits in the UK

In short

Charities hold sensitive donor and beneficiary data but often run on tight budgets and rely on volunteers. This guide covers the practical basics: protecting personal data, controlling who can access what, spotting phishing, backing up your systems, and using Cyber Essentials as a low-cost roadmap. Small, steady steps matter far more than expensive tools.

Some links on this page are affiliate links: if you sign up or buy through them, Dacros may earn a commission, at no extra cost to you. We only recommend tools we use and rate. Full disclosure.

Why charities are a target, not an afterthought

It is easy to assume cyber criminals only go after banks and big corporations. In reality, most attacks are not personal at all. Criminals use automated tools to scan the whole internet for weak passwords, out-of-date software and people who might click a bad link. Your charity is on that list whether you like it or not.

What makes charities appealing is a difficult combination: you handle money and personal data, you often run on donated time and stretched budgets, and IT is rarely anyone’s main job. That gap between what you look after and what you can spend on protecting it is exactly what attackers hope to find.

The good news is that you do not need a big budget or a technical background to close most of that gap. This guide walks through the practical basics in plain English.

The data you hold is more sensitive than you think

Charities sit on two kinds of personal data, and both deserve care.

Donor data. Names, addresses, email addresses, bank details and Gift Aid declarations. If this leaks, donors lose trust, and rebuilding a supporter base is slow and expensive.

Beneficiary data. This is often the most sensitive information of all. Many charities support vulnerable adults, children, or people in crisis. Details about someone’s health, housing, immigration status or safety are exactly the kind of information that can cause real harm if it falls into the wrong hands.

Under UK GDPR you are legally responsible for keeping this information secure, and the ICO expects charities to take it seriously regardless of size. A breach involving vulnerable people is not just a technical problem; it is a safeguarding one. If you are unsure of your wider obligations, our GDPR basics for UK small business is a friendly starting point.

That gap between what you look after and what you can spend on protecting it is exactly what attackers hope to find.

Controlling who can see what

Charities live and breathe on volunteers and part-time staff, and people naturally come and go. That churn is a security risk if access is not managed, so a few simple habits make a big difference.

Give everyone their own login. Shared accounts, where three volunteers all use the same email and password, are a common shortcut that causes real problems. You cannot tell who did what, and when someone leaves you cannot cut off their access without disrupting everyone else.

Grant only what is needed. A fundraising volunteer probably does not need access to beneficiary case notes. Give people access to the systems and folders their role requires, and nothing more. This limits the damage if any single account is compromised.

Keep a simple leavers list. When a volunteer or trustee moves on, remove their access promptly. A short shared checklist of who can access what, reviewed every few months, is often enough.

Turn on multi-factor authentication (MFA). This is the single most valuable thing most charities can do. Even if a password is guessed, reused or phished, MFA adds a second check, usually a code or a prompt on a phone, that stops an attacker getting in. It is free on most systems and takes minutes to enable. Our guide to multi-factor authentication explained walks through it step by step, and note that Cyber Essentials already requires MFA on all cloud services.

Passwords without the headache

Asking volunteers to invent and remember strong, unique passwords for every system is unrealistic, and it leads to the same weak password being reused everywhere. A password manager solves this. It creates and stores long, random passwords so people only have to remember one master password.

For charities that also want private email, encrypted storage and a shared password vault in one place, Proton offers a well-regarded, privacy-focused set of tools and has charity-friendly options worth asking about. If you want to weigh up the choices first, see our rundown of the best password manager for small business.

Phishing: the attack you will actually see

Most breaches do not start with clever hacking. They start with a convincing email. Someone receives a message that looks like it is from a bank, a grant funder, a supplier or even the CEO, and they click a link or hand over a login.

Charities are especially exposed because staff and volunteers are used to helping and to receiving genuine emails from strangers, such as donation notifications and enquiries. A few habits protect everyone:

  • Slow down with any email that creates urgency or asks for money, bank detail changes or login credentials.
  • Check the sender’s actual email address, not just the display name.
  • Hover over links before clicking to see where they really go.
  • When in doubt, confirm by phone using a number you already have, not one from the email.

Our guide on how to spot a phishing email is worth sharing with your whole team, volunteers included. Ten minutes of awareness prevents most incidents.

Back up so a bad day stays a bad day

Ransomware, a lost laptop, an accidental deletion or a failed hard drive can all wipe out records in an instant. Backups are what turn a disaster into an inconvenience.

Aim for the simple 3-2-1 approach: three copies of your important data, on two different types of storage, with one kept off-site or in the cloud. Just as importantly, test occasionally that you can actually restore a file, because a backup you have never tested is only a hope. Our guide to business backups and the 3-2-1 rule explains it without jargon.

Cyber Essentials: a free roadmap, even if you never certify

Cyber Essentials is a government-backed scheme that sets out five basic controls: firewalls, secure settings, access control, protection from malware, and keeping software up to date. It is deliberately affordable and designed for smaller organisations.

There are two reasons charities should care. First, some grant funders, local authorities and corporate partners now ask whether you hold the certificate, so it can open doors to funding. Second, and just as useful, the five controls double as a ready-made priority list. Even if you never pay to certify, working through them tells you exactly what to fix first.

While you are reviewing software, remember that Windows 10 support ended on 14 October 2025, so any charity still running it should plan to move to a supported system.

Keeping supporters close without oversharing

Many charities run newsletters and donation appeals by email. Doing this properly protects both your data and your reputation. Use a reputable email platform rather than blind-copying hundreds of addresses from your own inbox, which risks exposing your entire supporter list in one click. A dedicated tool such as MailerLite handles unsubscribes, consent and list management for you, which also helps you stay on the right side of UK marketing rules.

Small steps, steadily

You do not have to fix everything this month. If you do only a handful of things, make them these: turn on MFA everywhere, use a password manager, keep software and devices updated, back up reliably, and teach your team to pause over suspicious emails. Together these block the overwhelming majority of everyday attacks, and none of them require deep pockets.

If you would like a hand working out what matters most for your charity, or you want someone to quietly look after IT so your team can focus on your cause, get in touch. We work with mission-driven organisations across Leeds and Yorkshire and are happy to talk through your managed IT and support options at charity-friendly pricing.

Frequently asked questions

Do charities really get targeted by cyber criminals?

Yes. Attackers rarely single out charities by name, but they scan the internet for weak accounts, unpatched software and staff who might click a link. Charities are attractive because they handle donations, hold personal data and often have limited IT support. A moment of trust or a reused password is all a criminal needs, regardless of your size or cause.

What data do charities need to protect most carefully?

Anything that identifies a person. Donor names, addresses, bank and Gift Aid details, and especially information about beneficiaries, who may be vulnerable adults or children. Under UK GDPR you are responsible for keeping this safe, and a breach involving vulnerable people can cause real harm as well as reputational damage and possible ICO involvement.

Is Cyber Essentials worth it for a small charity?

For most charities, yes. Cyber Essentials is an affordable government-backed scheme that covers the five controls that stop the majority of common attacks. Some grant funders and corporate partners now ask for it, and holding the certificate reassures donors. Even if you never certify, using its checklist as a to-do list is valuable.

We rely on volunteers who come and go. How do we manage access safely?

Give every volunteer their own login rather than sharing accounts, and only grant access to the systems they actually need. Keep a simple list of who has access to what, and remove accounts promptly when someone leaves. Turning on multi-factor authentication protects those accounts even if a password is guessed or reused elsewhere.

We have almost no budget. Where should we start?

Start with the free and low-cost wins: turn on multi-factor authentication everywhere, use a password manager, keep devices and software updated, and set up reliable backups. Many providers offer charity pricing on software. These steps cost little and block most everyday attacks. Talk to us if you want a hand prioritising.

Who writes this

Dacros — led by Jordan Gilbert

Our guides are written and checked by the Dacros team, led by founder Jordan Gilbert. We run the IT and cyber security for UK small businesses — and hold our own systems to the same standard. About Jordan · About Dacros.

Want this handled for you?

Dacros runs the IT and security for UK small businesses. Book a free review and we'll tell you what's worth doing — no jargon, no pressure.