Charity Cyber Security: The NCSC Guide, Applied

Charities are attractive cyber targets because they hold donor payment data and Gift Aid records but often run on volunteer IT; DCMS's Cyber Security Breaches Survey 2024 found 32% of UK charities identified a breach or attack in the previous 12 months. The NCSC's Small Charity Guide distils protection into five free or low-cost steps, and a single afternoon covering multi-factor authentication, a password manager, shared-inbox access review and a proper backup closes most of the gaps phishing and ransomware exploit.

Why charities are targeted

Bigger charities have an IT manager who owns charity cyber security; at my charity it’s me — a technologist by trade, admittedly, but still fitting the security basics around evenings and weekends like every other small-charity trustee. This guide is written for that reality: the NCSC’s advice applied in one afternoon, with no budget drama. And the afternoon is worth finding, because charities are targeted for a reason — they hold valuable data (donor bank details, Gift Aid records, beneficiary information) while typically running leaner IT and security budgets than a business of comparable size. According to DCMS’s Cyber Security Breaches Survey 2024, 32% of UK charities identified at least one cyber security breach or attack in the previous 12 months, rising to 66% among charities with £500,000 or more annual income.

The same survey found phishing is by far the most common attack type affecting charities, cited in 83% of the breaches charities reported. Criminals know that charities process bank transfers, hold Gift Aid declarations linked to individuals’ tax status, and often rely on a small, trusted circle of trustees, staff and volunteers who are used to acting quickly on urgent-sounding requests, which is exactly the psychology phishing exploits.

Smaller charities are not exempt just because they feel like a low-value target. Attackers increasingly run automated, low-cost campaigns (mass phishing, credential-stuffing, opportunistic ransomware) that don’t discriminate by charity size; they simply exploit whichever inbox clicks first. The NCSC’s Cyber threat report: UK charity sector makes the same point: funds, assets and reputation are all at risk, and the sector’s public trust makes a breach reputationally costly even when the financial loss is modest.

None of this means charities need enterprise security budgets. It means the basics (the ones covered below) need to actually be in place, because most successful attacks exploit gaps a single afternoon of work can close. (Cyber is one duty among many — our charity compliance handbook shows where it sits in the full picture.)

The NCSC Small Charity Guide in 5 moves

The NCSC Small Charity Guide condenses charity cyber security into a short set of free or low-cost actions covering backups, malware protection, device and account security, password practice and phishing awareness, designed to be implementable by someone without a technical background. It is published by the National Cyber Security Centre specifically for small charities and voluntary organisations that don’t have a dedicated IT function.

The guide’s core moves map cleanly onto what most small charities are missing:

  • Back up your data regularly and keep at least one copy disconnected from your main systems, so ransomware can’t reach it.
  • Protect your organisation from malware by keeping devices and software updated and using reputable antivirus tools.
  • Keep smartphones and tablets secure with screen locks, encryption and the ability to remotely wipe a lost device.
  • Use strong passwords and enable multi-factor authentication (MFA) wherever it’s offered, especially on email and banking.
  • Prevent and detect phishing attacks by training staff and trustees to recognise suspicious messages and by reporting them rather than just deleting them.

Read the guide in full via the NCSC’s charity sector collection; the downloadable PDF is short enough to read over a cup of tea — it’s the first thing I point new trustees at when security comes up — and the checklist below turns it into concrete tasks you can tick off in one sitting.

The one-afternoon hardening checklist

Most of the NCSC guide’s recommendations can be actioned in a single afternoon by one trustee or member of staff with admin access to your email, cloud storage and finance systems, working through a fixed checklist rather than trying to “do cyber security” as an open-ended project. Block out three to four hours, get admin logins ready, and work down this list in order. It’s essentially the same afternoon I ran for my own charity — MFA first, then the password manager — and the order matters, because everything after those two gets easier.

Task Time Cost
Turn on MFA for email, banking and your CRM/database 30 min Free
Set up a password manager for the organisation and migrate shared logins into it 60 min Free–£30/yr per user
Review who has access to shared inboxes and remove leavers 20 min Free
Confirm automatic updates are switched on for all work devices 15 min Free
Set up or verify a 3-2-1 backup for finance, donor and case-management data 45 min Free–£5/month
Send a short phishing-awareness reminder to staff, trustees and volunteers 20 min Free
Write (or update) a one-page cyber incident response note 30 min Free

None of this requires specialist IT knowledge or a paid consultant. Where you do want independent verification that the basics are properly in place, that’s what Cyber Essentials certification is for, and CharityIQ’s own guide to preparing walks through the certification in detail: see our Cyber Essentials for charities post.

Passwords, MFA and shared inboxes

Weak, reused or shared passwords are one of the easiest wins for an attacker, so the single highest-value change a charity can make is enabling multi-factor authentication (MFA) on email, banking and any donor database, combined with a password manager so staff stop reusing passwords across systems. MFA alone blocks the overwhelming majority of automated account takeover attempts, because a stolen password is useless without the second factor.

Shared inboxes (info@, fundraising@, admin@) deserve particular attention because they’re often the account with the widest access and the weakest ownership. Practical rules:

  • Give each person their own login where the platform allows it, rather than sharing one password among five volunteers.
  • Where a shared inbox is unavoidable, store its password in a shared password manager vault, not a spreadsheet or sticky note.
  • Review access every time a volunteer, trustee or staff member leaves, and remove them the same week, not “next time someone updates the list.”
  • Turn on MFA for the shared inbox itself, using an authenticator app rather than SMS where the provider supports it.

A password manager is not a luxury tool for tech-savvy organisations. Free tiers of reputable password managers cover most small charities’ needs, and migrating your existing shared logins into one is typically the single fastest security improvement you can make in an afternoon.

From experience: When cyber security reaches a small charity’s board agenda, the discussion usually drifts to insurance and antivirus — the things you can buy. The two controls that do the real work cost nothing: MFA on email and banking, and a live list of who can still get into the shared inbox. At my own charity the access review is a standing calendar entry, because a leaver’s forgotten login is the gap nobody spots until it matters. If you only take two actions from this page, take those two.

Backing up: the 3-2-1 rule on a charity budget

The 3-2-1 backup rule means keeping three copies of your important data, on two different types of storage, with one copy stored offsite or offline, and it is achievable for most small charities using cloud storage tools they may already have through Microsoft 365 or Google Workspace charity licensing. The point of the rule is that no single failure (a stolen laptop, a ransomware infection, a deleted folder) can take out every copy of your data at once.

In practice, for a small charity that looks like:

  • Copy 1: the live version on your working device or cloud drive.
  • Copy 2: an automatic sync to cloud storage (SharePoint, Google Drive, Dropbox) on a different platform or account to your main system.
  • Copy 3 (offsite/offline): a periodic export to an external drive kept off-site, or a second cloud provider entirely disconnected from your everyday logins, so ransomware that encrypts your live files and their live sync can’t also reach this copy.

Test the restore, not just the backup. A backup nobody has ever restored from is a hope, not a plan; once a quarter, actually recover a test file from your offsite copy and confirm it opens. I keep that quarterly test as a standing entry in my own calendar — it takes five minutes and settles the question. The NCSC’s guidance on mitigating malware and ransomware attacks covers this in more detail and is worth the ten-minute read.

What the annual return now asks about cyber

The Charity Commission’s annual return now includes explicit questions on cyber security, asking whether your charity has experienced a cyber incident in the reporting year and whether it has a cyber security policy in place, and honest “not yet, but planned” answers are treated as acceptable rather than penalised. This is a factual disclosure exercise, not a test you can fail by being small; the Commission has said it is trying to understand sector-wide readiness, not catch charities out. I file my own charity’s annual return each year, so I’ve answered these questions on the live form — they read as exactly what they are: disclosures, not a trap.

What this means practically: the afternoon of work above (MFA, backups, a written incident note) is exactly what turns “we don’t really have a policy” into a genuine, defensible “yes” on next year’s return. If your charity’s financial year end is approaching, pair this post with our detailed walkthrough of the Charity Commission Annual Return 2026, keep our annual return prep checklist beside you when you file, and read the cyber-specific section of our cyber and the annual return post for exact question wording.

Question sets are revised between reporting years, so before you file, check the exact current wording of the cyber questions against the live GOV.UK annual return guidance.

Incident response: first 24 hours

The first 24 hours after discovering a cyber incident should focus on containment, assessment and reporting, in that order: disconnect affected devices from the network, work out what was accessed, and report to the right bodies before you worry about anything else. Acting fast but calmly in this window is what limits the damage and protects your charity’s legal position.

  1. Contain it. Disconnect the affected device(s) from Wi-Fi and any shared drives immediately. Do not switch the device off if ransomware is suspected; isolating it from the network is usually the priority, and NCSC’s device recovery guidance covers the detail.
  2. Assess what happened. Identify which systems and data were involved, including whether personal data (donor, beneficiary or staff records) was accessed or exfiltrated.
  3. Report it. If personal data was compromised, you may need to notify the ICO within 72 hours of becoming aware — our data breach playbook walks that decision through step by step. Report the incident itself to the NCSC and, if fraud or financial loss is involved, to Action Fraud.
  4. Communicate internally, then externally. Brief trustees promptly; charity law and good governance both expect trustees to be told about material incidents. Only communicate externally (donors, beneficiaries, press) once you know enough to be accurate, but don’t delay so long that people hear about it elsewhere first.

Serious incidents involving fraud, significant data loss or safeguarding implications may also need reporting to the Charity Commission as a serious incident report — fraud in particular has no fixed minimum value for reporting; it’s judged on significance, not a pound threshold — and our fraud playbook covers those first-week decisions. See the Commission’s own guidance on protecting your charity from cyber crime for what it expects to be told about.

What to do next

Cyber security for a small charity is a checklist, not a project plan, and the fastest way to close your biggest gaps is to work through the concrete steps above in order rather than trying to solve everything at once.

  1. Block out one afternoon this week and work through the hardening checklist above, starting with MFA on email and banking.
  2. Set up or verify your 3-2-1 backup and actually test a restore before you assume it works.
  3. Write a one-page incident response note now, while there’s no pressure, so the first 24 hours of a real incident are calmer.
  4. Read the cyber annual return post so this afternoon’s work becomes next year’s honest “yes” on the Charity Commission return.

Want compliance tasks like this tracked automatically alongside your annual return? Join the CharityIQ compliance module waitlist →

Frequently asked questions

Phishing is the leading risk, cited in 83% of breaches charities reported to DCMS's 2024 survey, followed by weak or reused passwords, unmanaged shared inboxes, and unpatched devices. Ransomware is less common but far more damaging when it hits, especially without tested backups.

The NCSC Small Charity Guide recommends five core actions: regular backups with an offline copy, malware protection and updates, secured mobile devices, strong passwords with MFA, and phishing awareness training for everyone with an inbox, all achievable free or at low cost.

Many small charities can operate without dedicated cyber insurance if their exposure is limited, but any charity handling online donations, large donor databases or beneficiary case data should assess it. Premium ranges and eligibility criteria shift with market conditions, so check current terms with a UK charity insurance broker or against the Charity Commission's own guidance before deciding.

The current annual return asks whether the charity experienced a cyber incident in the reporting year and whether it has a cyber security policy, with honest 'not yet, planned' answers accepted. Exact wording should be checked against the live GOV.UK annual return guidance each year, as questions are periodically revised.

Most of the highest-impact steps (MFA, a free-tier password manager, a written incident response note, staff phishing awareness) cost nothing beyond staff time. Paid extras like premium password manager seats or a second cloud backup provider typically run to a few pounds per user per month, well within most small charity budgets.

Cyber Essentials is worth pursuing if your charity handles online donations, grant funding that requires certification, or wants independent proof its basics are in order; it verifies the same fundamentals as the NCSC Small Charity Guide. See CharityIQ's dedicated Cyber Essentials for charities post for the certification process and cost.