Skip to main content

CYBER SECURITY SOLUTIONS, PROTECT YOUR BUSINESS TODAY

Click here to find out more

Could your charity continue operating after a cyber attack?

“CYBER ATTACK” highlighted in red against a dark digital code background.

Rebecca Wilson

Cyber Security Solutions Manager

If your charity lost access to its systems tomorrow, how long could it continue supporting beneficiaries, processing donations and communicating with funders?

For charities and not-for-profit organisations, a cyber attack is not just an IT issue. It can disrupt services, expose sensitive personal data, redirect funds and undermine the trust built with donors, beneficiaries, regulators and the wider community.

Trustees and senior leaders do not need to be cyber security experts, but they do need to understand the organisation’s key risks, ensure proportionate safeguards are in place and know how the charity would respond if something went wrong.

Charity Commission guidance is clear that trustees remain responsible for protecting their charity from cyber crime, even where day-to-day IT support is outsourced. Cyber security should therefore be treated as part of good governance, risk management and operational resilience, rather than something owned solely by IT.

Cyber risk is affecting the charity sector

The UK Government’s Cyber Security Breaches Survey 2025/2026 found that 28% of charities reported a cyber security breach or attack in the previous 12 months, equating to an estimated 57,000 UK charities. Phishing remains one of the most common threats, particularly for organisations that rely on email, online giving, grant applications and regular communication with supporters.

Third-party providers can increase exposure

Many charities depend on cloud platforms, fundraising systems, payroll providers, CRM solutions and outsourced IT support. These services can be efficient and cost-effective, but they can also introduce risk if supplier access, data handling, security responsibilities and business continuity arrangements are not clearly understood.

The recent Beacon CRM cyber security incident demonstrates how an issue at a third-party provider can affect multiple organisations at once. Supplier due diligence, clear contractual expectations, regular access reviews and tested incident response plans are therefore important parts of managing cyber risk.

Why charities can be attractive targets

Charities often hold information that is valuable to criminals, including donor details, beneficiary records, employee information, safeguarding data and payment information. They may also handle regular donations, grant funding and supplier payments, making them vulnerable to phishing, impersonation, payment diversion, ransomware and account compromise.

Common challenges include limited in-house cyber security expertise, reliance on outsourced providers, competing budget pressures, legacy systems, volunteer access and varying levels of cyber awareness across staff, trustees and volunteers.

Building cyber resilience does not need to be overly complex

Improving cyber resilience does not always require significant investment. The most effective steps are often practical and proportionate: enabling multi-factor authentication, keeping systems updated, training people to spot phishing, limiting access to sensitive data, maintaining tested backups and having a clear incident response plan.

The aim is not to remove cyber risk entirely. Instead, charities should understand where they are most exposed, prioritise the controls that matter most and make sure they can continue operating if an incident occurs.

Trustees may find it helpful to ask: do we know who has access to our systems and data; are payments independently checked before changes are made; are backups tested; who would lead our response to an incident; and have we sought independent assurance over the controls our IT provider manages?

 Improve your cyber resilience

Independent cyber assurance can help trustees, senior leadership teams and finance professionals understand whether the right controls are in place and whether cyber risk is being managed in a way that is proportionate to the organisation’s size, complexity and charitable activities.

Armstrong Watson works with charities and not-for-profit organisations to identify risks, assess existing controls and provide clear, practical recommendations that support good governance, protect funds and data, and strengthen operational resilience.

Our services include cyber health checks, Cyber Essentials certification support, phishing simulation and awareness campaigns, policy development, incident response planning and independent reviews of cyber security arrangements. These are designed to help trustees and management teams make informed decisions, evidence good governance and prioritise practical improvements.

Subscribe to
Inspired

Our monthly bulletin INSPIRED is packed with useful articles to keep you up to date with news and legislation that may affect you or your business.

Subscribe

Related news stories

3rd December 2024

The importance of cyber security for the not-for-profit sector

hands in the middle

3rd July 2026

Will my charity require an audit?

8th September 2026

Key VAT considerations for charities and not-for-profit organisations

Recent news stories

White delivery van parked along a suburban street lined with cars and residential buildings in daylight.

14th September 2026

Mandatory payrolling of benefits in kind: modernisation, but employers need more than payroll support

Interview banner with Frank Maher, Solicitor and Partner at Keystone Law, beside a Lady Justice statue.

9th September 2026

An interview with … Frank Maher, Solicitor and Partner at Keystone Law

8th September 2026

Key VAT considerations for charities and not-for-profit organisations

Armstrong Watson can help

If you would like to understand your current cyber security position or discuss practical steps to improve resilience, please get in touch. Call 0808 144 5575 or email help@armstrongwatson.co.uk.

Contact the team