Online Safety for Small Charities: A Practical Guide
Small charities do enormous good with limited time, money and people. That same lean setup is exactly what attackers look for. The good news: a handful of simple, low-cost steps will protect you, your donors and your beneficiaries - without needing an IT department.
Why charities are targeted
Charities hold something attackers want: donor and beneficiary data, payment details, and an established trust with the public that's easy to impersonate. Many also process Gift Aid claims and grant funds, which makes them appealing for fraud.
Smaller charities are often picked out because they're seen as less likely to have formal security training, dedicated IT support, or strict approval processes for payments. That's not a criticism, it's reality. The point is: you don't need to match a corporate budget to dramatically reduce the risk.
Protecting donor data
Only collect what you actually need
The less personal information you hold, the less there is to lose. Review your sign-up forms and donation pages, do you really need date of birth, full address, or phone number for every supporter?
Keep donor records in one secure place
Avoid scattered spreadsheets on personal laptops or shared via email. Use a reputable CRM (many offer free or discounted charity tiers, see below) so access can be controlled and removed when staff or volunteers leave.
Take payments through trusted providers
Use established platforms (Stripe, GoCardless, JustGiving, CAF, Enthuse, PayPal Giving Fund) so card details never touch your own systems. This massively reduces both your risk and your compliance burden.
Know your data protection basics
UK GDPR applies to charities of every size. The ICO has free guidance, most of it is straightforward.
See our deeper guide on donor data protection for step-by-step practices.
Email and phishing risks for charity staff
The most common attacks on charities arrive by email. They typically take one of these forms:
- "CEO fraud", an email pretending to be your director or a trustee, asking finance or admin to urgently move money or buy gift cards.
- Fake invoices or grant notifications, designed to look like a funder or supplier, with a link to "view the document" that steals login details.
- Donation scams, bogus messages thanking you for a donation, asking you to confirm bank details or click a link.
- Account warnings, fake alerts from Microsoft, Google, JustGiving or your bank, pressuring staff to "verify" their account.
The single best defence is a moment's pause. If a message creates urgency, involves money or login details, or just feels off, verify it through a different channel (a phone call, or by typing the website address yourself). You can read our full guide on how to spot a phishing email.
Password habits for volunteers and staff
Volunteers come and go, and shared logins are tempting, but they're also one of the biggest risks. A few simple rules go a long way:
- Give every person their own login. Never share a single username and password between volunteers.
- Use a password manager. Bitwarden and 1Password both offer free or heavily discounted plans for charities, and make managing dozens of logins easy.
- Turn on two-factor authentication (2FA) for email, banking, your CRM, and your social accounts. This is the single highest-impact change you can make.
- Have a leavers process. When a volunteer or staff member leaves, remove their access the same day. Keep a short checklist so nothing gets missed.
- Use long passphrases, three random words like "RedKettleBicycle" are far stronger than "Charity2024!".
See our full strong-password guide for more.
Free and low-cost tools available to charities
You don't need a security budget to make real progress. Small charities can access a remarkable amount for free or near-free:
- NCSC Cyber Essentials, the National Cyber Security Centre offers free guidance and tools, including the Small Charity Cyber Action Plan.
- Charity Digital Exchange, heavily discounted software including Microsoft 365, antivirus, Bitdefender, and more, for registered UK charities.
- Google for Nonprofits and Microsoft for Nonprofits, free business email, document storage and admin tools (with built-in security).
- Bitwarden Teams (free for charities), a password manager you can roll out across staff and volunteers.
- Cloudflare for Nonprofits, free protection for your website against attacks and downtime.
Free CyberSafe Coach access for charities
We believe small charities shouldn't have to choose between their mission and online safety.
Through our community access programme, registered UK charities can apply for free or heavily subsidised access to CyberSafe Coach, including awareness checks, staff training, and ongoing guidance for everyone in your organisation. International registered charities can also apply via the CyberSafe Foundation C.I.C.
Apply for charity accessNot sure where to start?
Take the free 5-minute CyberSafe Coach check and get a personalised score for your charity, with clear next steps. No jargon, no scare tactics.
Start my free safety checkYour one habit from this lesson
Collect only the supporter data you actually need, keep it in one secure place, and take payments through a trusted provider.
Track your progress and earn XP
Sign in to mark this lesson complete and add +25 XP to your safety score.
Sign in or create a free account