Cyber security for charities — where to start in the first year

If your charity holds supporter details, gift records or staff payroll, you already have something worth stealing. Too many charities treat cyber security as a low-priority checkbox; that’s how breaches happen. Start with the specific, time-boxed fixes that reduce risk quickly, then build from there.

First week

Begin with visibility and the quick wins. Do these three things straight away and you reduce the bulk of opportunistic attacks.

  • Know what you hold. List where personal data and financial information live: email accounts, shared drives, cloud apps. If you can’t name the top five places sensitive data is stored, make that your top task.
  • Fix the basics on accounts. Ensure every staff and volunteer account has a strong password and multi-factor authentication (MFA) enabled. MFA blocks most credential-theft attacks overnight.
  • Confirm backups. Check that critical files and databases are backed up off-site and that at least one recent restore has been tested. Backups are your recovery plan when prevention fails.

These actions take a few hours each for most small charities, and they materially reduce risk.

First month

Now move from quick wins to simple policy and supplier checks. Your aim in month one is to close easy gaps and make responsibilities clear.

  • Assign ownership. Nominate one person—staff or a trustee—as responsible for cyber security oversight. They do not need to be technical, but they must drive the work.
  • Create a short incident plan. One page is fine. It should say who to call if systems fail, where backups are, and what external help you will use. Having a named contact list halves confusion during an incident.
  • Review third-party access. Check which suppliers, volunteers or apps have access to sensitive systems and remove accounts no longer needed. A surprising number of breaches happen through forgotten vendor logins.
  • Apply security updates. Ensure all office PCs, servers and cloud apps receive their latest patches. Set automatic updates where possible, and schedule a monthly check.

By the end of the month you should have clearer roles, a tested backup spot, and fewer exposed access points.

First quarter

With basics in place, move to risk reduction and data protection measures that take a few weeks to implement but have lasting impact.

  • Improve access control. Adopt the principle of least privilege: give people only the access they need. Where feasible, segregate financial systems from general shared drives.
  • Train staff and volunteers. Run a short phishing awareness session and issue simple rules for handling donations and invoices. Real-world phishing is how most compromises start; training reduces click-through rates considerably.
  • Formalise data handling. Write or update a short data protection policy covering collection, storage and deletion. This helps with ICO expectations and reassures donors.
  • Check cyber insurance options. If you hold donor funds or run events, look at cyber insurance and read what it covers; some policies require basic controls to be in place before they pay out.

These steps cost little but make it harder for attackers to move and extract value from your systems.

First year

At the one-year mark, plan the more structured measures that protect continuity and reputation as the organisation grows.

  • Adopt a proportionate framework. Use a simple checklist—such as elements from the NCSC—to build a repeatable security programme. This creates clarity for trustees and auditors. For publicly available, practical advice, see NCSC’s guidance on cyber security.
  • Review supplier contracts. Make sure cloud providers and payroll suppliers meet reasonable security standards and that responsibilities for data breaches are clear.
  • Test your incident response. Run a tabletop exercise with trustees and staff to walk through the incident plan you created. A practiced response saves time and reputational damage when something real happens.
  • Plan for continuity. Ensure key roles and credentials are available to more than one person so a single absence does not stop fundraising or payroll.

Revisit access rights, backups and patching as ongoing tasks—security is maintenance, not a one-off project.

What to watch for next

After the first year, focus on these signals that it’s time to step up further:

  • Growth in income, staff, or data volume—bigger operations attract more sophisticated attackers.
  • New services that process payments or personal data—payments and integration points raise the stakes.
  • Regulatory changes affecting fundraising or data protection—these can change your obligations quickly.

If you spot any of the above, schedule a formal review and consider external help to run a risk assessment and board briefing. For a concise starting point that explains services and costs, see our charity cyber security overview.

Finish by picking one concrete next action: block-and-enable MFA, test a restore from backup, or run a 30-minute phishing session with staff. Those are actions that save time, defend income, and protect your reputation.

If you can spare half a day this month, complete the First week checklist and book a review with your IT contact or trustee. That investment buys calm and credibility for the months ahead.

Related reading