TL;DR:
- UK charities are actively targeted for donor payment fraud, fundraising platform hijacking, and ransomware — the Charity Commission reports cyber incidents as a growing concern across the sector
- NCSC’s Cyber Essentials certification is free for charities with income under £20,000 and subsidised for larger organisations; it addresses the most common attack paths
- Donor data (names, addresses, payment details, giving history) is a GDPR liability — a breach requires reporting to the ICO within 72 hours and can damage donor trust severely
Charities face a specific combination of risks: valuable data, limited security budgets, high staff turnover and volunteer dependence, and a public-facing profile that makes them visible targets. The Charity Commission’s research consistently finds that charities report higher rates of cyber attacks than small businesses of equivalent size — partly because they’re less likely to have dedicated IT support.
The good news is that most of the attacks targeting charities exploit basic weaknesses that free and low-cost measures can address.
The Threats Charities Actually Face
Fundraising platform fraud. Attackers impersonate charities on JustGiving, GoFundMe, and similar platforms, or create fake charity websites that capture donor payments. This targets your donors directly and your reputation indirectly. It also includes account takeover of your legitimate fundraising platform accounts.
CEO/trustee impersonation fraud. Attackers email your finance team or bank account administrators pretending to be a senior trustee or the CEO, requesting urgent bank transfers for a “confidential project.” Charities are high-risk for this because trustee names are public record at the Charity Commission.
Ransomware. Charities running outdated software, lacking backups, or using shared passwords across systems are straightforward ransomware targets. Being a charity doesn’t protect you — criminal ransomware groups target organisations by vulnerability profile, not by sector ethics.
Grant application fraud. Someone external submits fraudulent grant applications claiming to represent your charity, or intercepts your grant payment by diverting the payment reference.
Volunteer account compromise. Volunteers use personal devices, personal email accounts, and personal passwords for charity work. If a volunteer’s personal account is compromised, attackers may gain access to charity systems they had access to.
Beneficiary data breaches. Charities working with vulnerable adults, children, domestic abuse survivors, refugees, or people with health conditions hold sensitive personal data that carries additional regulatory weight. A breach of this data has more serious consequences than a donor address list.
The NCSC’s Free Resources for Charities
The National Cyber Security Centre has specific guidance and support for the charity sector.
Cyber Essentials certification is a government-backed scheme that tests five basic security controls: firewalls, secure configuration, user access control, malware protection, and patch management. Passing gives you a certificate that demonstrates a baseline security standard — useful for grant applications and donor reassurance.
For charities with annual income under £20,000, Cyber Essentials self-assessment is free. For larger charities, subsidised pricing is available through the NCSC’s scheme. Apply via the NCSC website or through an accredited certification body.
NCSC’s Small Charity Guide (available at ncsc.gov.uk) covers six priority areas with practical steps rather than technical jargon: backing up data, protecting against malware, keeping devices and software updated, using strong passwords and two-factor authentication, avoiding phishing attacks, and using the cloud safely.
Exercise in a Box is a free NCSC tool that runs cyber incident simulations for your team — tabletop exercises that don’t require technical knowledge to facilitate. Running one with trustees and senior staff is one of the most effective low-cost ways to improve incident response readiness.
Specific Controls for Charity Risks
Fundraising platform security. Enable two-factor authentication on all fundraising platform accounts (JustGiving, CAF Donate, etc.). Use a shared organisational email address (not a personal volunteer email) as the account email, stored in a password manager. Verify the identity of anyone requesting access to fundraising accounts.
DMARC for your charity domain. Publishing a DMARC record for your domain prevents attackers from sending emails that appear to come from your charity’s email address. This directly reduces impersonation fraud against your donors. The NCSC has a free DMARC checking tool. If your domain isn’t protected by DMARC, set it up — it’s a DNS record change, not a software installation.
Payment instruction verification. Implement a policy requiring that any bank account change for grants, supplier payments, or payroll be verified by phone to a number already on record — never to a phone number provided in the same email making the request. This single policy prevents most mandate fraud and CEO fraud.
Trustee and staff information hygiene. Trustee names must be public at the Charity Commission, but job titles, personal mobile numbers, and working patterns shared publicly on social media give attackers the social engineering material they need. Brief volunteers and staff on what information to keep private.
Separate work and personal accounts. Volunteers should use the charity’s Google Workspace or Microsoft 365 account for charity work, not their personal Gmail. When a volunteer leaves, their charity account can be deactivated. Their personal account, which may have had access to charity documents, cannot be.
Donor Data: GDPR Obligations
Donor data is personal data under GDPR. Your charity must:
- Have a legal basis for holding it (legitimate interest or consent for most charity fundraising)
- Keep it only as long as necessary (retention policies — many charities retain data indefinitely without justification)
- Protect it adequately (encryption at rest for databases, access limited to those who need it)
- Report breaches to the ICO within 72 hours of becoming aware
The ICO has specific guidance for charities (ico.org.uk/for-organisations/charities). The key risk areas for charities are donor databases in outdated CRM systems, spreadsheets shared via personal email, and paper records held without clear disposal processes.
If you hold data on vulnerable beneficiaries — domestic abuse survivors, people with health conditions, children — this is “special category” data under GDPR with stricter requirements. Check whether you’ve completed a Data Protection Impact Assessment for systems that hold this data.
Free Tools Worth Using
Bitwarden: Free password manager with team sharing features. Eliminates shared sticky-note passwords and makes offboarding volunteers safer. The free Teams tier is sufficient for most small charities.
Cloudflare Radar domain check: Free tool that checks whether your domain has DMARC, SPF, and DKIM records configured.
NCSC’s Check Your Cyber Security: Free online assessment at ncsc.gov.uk that gives a personalised action list based on your answers.
Have I Been Pwned: Free service that checks whether your charity’s email addresses appear in known data breaches. Run it for your main email domain to find compromised volunteer or staff accounts.
The cyber risks facing charities are real but largely addressable with measures that don’t require significant IT investment. The NCSC’s charity programme specifically recognises the resource constraints in the sector — the free tools and guidance are genuinely useful, not just box-ticking exercises.