Skip to main content
    CyberSafe Coach
    Something happening right now?Digital 999
    Digital safety guide for charities

    Online Safety for Small Charities: A Practical Guide

    Small charities do enormous good with limited time, money and people. That same lean setup is exactly what attackers look for. The good news: a handful of simple, low-cost steps will protect you, your donors and your beneficiaries - without needing an IT department.

    Why charities are targeted

    Charities hold something attackers want: donor and beneficiary data, payment details, and an established trust with the public that's easy to impersonate. Many also process Gift Aid claims and grant funds, which makes them appealing for fraud.

    Smaller charities are often picked out because they're seen as less likely to have formal security training, dedicated IT support, or strict approval processes for payments. That's not a criticism, it's reality. The point is: you don't need to match a corporate budget to dramatically reduce the risk.

    Protecting donor data

    Only collect what you actually need

    The less personal information you hold, the less there is to lose. Review your sign-up forms and donation pages, do you really need date of birth, full address, or phone number for every supporter?

    Keep donor records in one secure place

    Avoid scattered spreadsheets on personal laptops or shared via email. Use a reputable CRM (many offer free or discounted charity tiers, see below) so access can be controlled and removed when staff or volunteers leave.

    Take payments through trusted providers

    Use established platforms (Stripe, GoCardless, JustGiving, CAF, Enthuse, PayPal Giving Fund) so card details never touch your own systems. This massively reduces both your risk and your compliance burden.

    Know your data protection basics

    UK GDPR applies to charities of every size. The ICO has free guidance, most of it is straightforward.

    See our deeper guide on donor data protection for step-by-step practices.

    Email and phishing risks for charity staff

    The most common attacks on charities arrive by email. They typically take one of these forms:

    • "CEO fraud", an email pretending to be your director or a trustee, asking finance or admin to urgently move money or buy gift cards.
    • Fake invoices or grant notifications, designed to look like a funder or supplier, with a link to "view the document" that steals login details.
    • Donation scams, bogus messages thanking you for a donation, asking you to confirm bank details or click a link.
    • Account warnings, fake alerts from Microsoft, Google, JustGiving or your bank, pressuring staff to "verify" their account.

    The single best defence is a moment's pause. If a message creates urgency, involves money or login details, or just feels off, verify it through a different channel (a phone call, or by typing the website address yourself). You can read our full guide on how to spot a phishing email.

    Password habits for volunteers and staff

    Volunteers come and go, and shared logins are tempting, but they're also one of the biggest risks. A few simple rules go a long way:

    • Give every person their own login. Never share a single username and password between volunteers.
    • Use a password manager. Bitwarden and 1Password both offer free or heavily discounted plans for charities, and make managing dozens of logins easy.
    • Turn on two-factor authentication (2FA) for email, banking, your CRM, and your social accounts. This is the single highest-impact change you can make.
    • Have a leavers process. When a volunteer or staff member leaves, remove their access the same day. Keep a short checklist so nothing gets missed.
    • Use long passphrases, three random words like "RedKettleBicycle" are far stronger than "Charity2024!".

    See our full strong-password guide for more.

    Free and low-cost tools available to charities

    You don't need a security budget to make real progress. Small charities can access a remarkable amount for free or near-free:

    • NCSC Cyber Essentials, the National Cyber Security Centre offers free guidance and tools, including the Small Charity Cyber Action Plan.
    • Charity Digital Exchange, heavily discounted software including Microsoft 365, antivirus, Bitdefender, and more, for registered UK charities.
    • Google for Nonprofits and Microsoft for Nonprofits, free business email, document storage and admin tools (with built-in security).
    • Bitwarden Teams (free for charities), a password manager you can roll out across staff and volunteers.
    • Cloudflare for Nonprofits, free protection for your website against attacks and downtime.

    Free CyberSafe Coach access for charities

    We believe small charities shouldn't have to choose between their mission and online safety.

    Through our community access programme, registered UK charities can apply for free or heavily subsidised access to CyberSafe Coach, including awareness checks, staff training, and ongoing guidance for everyone in your organisation. International registered charities can also apply via the CyberSafe Foundation C.I.C.

    Apply for charity access

    Not sure where to start?

    Take the free 5-minute CyberSafe Coach check and get a personalised score for your charity, with clear next steps. No jargon, no scare tactics.

    Start my free safety check

    Your one habit from this lesson

    Collect only the supporter data you actually need, keep it in one secure place, and take payments through a trusted provider.

    Track your progress and earn XP

    Sign in to mark this lesson complete and add +25 XP to your safety score.

    Sign in or create a free account