Back to blog
Sectors

Cybersecurity for non-profits: doing this on a real budget

Charities hold donor and beneficiary data, run on volunteers and constrained budgets, and are targeted precisely because attackers expect weak defences. What actually matters when you cannot buy your way out.
GRC Copilot Team
Cybersecurity for non-profits: doing this on a real budget

Charities are targeted because attackers correctly assume limited defences, and the data they hold is often more sensitive than a commercial equivalent. Beneficiary records can include health, immigration status, safeguarding concerns or domestic abuse details - information where disclosure causes real harm to people already vulnerable.

What is actually at stake

  • Beneficiary data, frequently special category and genuinely dangerous if exposed.
  • Donor records including payment details and giving history.
  • Payment fraud - charities are heavily targeted with invoice and payment-diversion fraud, and losses come straight out of programme funding.
  • Reputation, which for a charity is the fundraising base rather than a market position.

The constraints are real

Small or no IT function, volunteers with varying technical confidence and high turnover, restricted funding that cannot easily be spent on infrastructure, donated or ageing equipment, and trustees who may have no technology background. Advice that assumes a security team is useless here.

The controls worth having first

  1. MFA everywhere, especially email and finance systems. Free on every major platform, and it addresses the dominant attack path.
  2. Out-of-band verification for payment changes - a phone call to a known number. Free, and it defeats the fraud that actually costs charities money.
  3. Separate finance authorisation so one person cannot both set up and approve a payment.
  4. Managed devices and automatic updates, using built-in platform tooling rather than purchased products.
  5. Backups that are tested, including one copy an attacker who compromises an account cannot delete.
  6. Access removal when volunteers leave - high turnover makes this the most commonly failed control in the sector.
Every item on that list is free or near-free. The gap in most charities is not budget for tooling - it is that nobody owns the task.

Structure the programme without buying a large one

GRC Copilot gives you a control set, gap assessment and evidence tracking so a small team can run a credible programme.

Volunteers need a different approach

Volunteers are not employees: turnover is high, onboarding is informal, and devices are often personal. What works is minimising what they need access to, using role-based access so removal is a single action, setting expiry dates at account creation, and keeping training genuinely short and specific rather than a corporate module.

Removing access is the control that fails most often, because departures are frequently informal - someone simply stops coming. A quarterly reconciliation of active accounts against current volunteers catches this cheaply.

Funder and regulatory expectations

Grant funders increasingly ask about data protection and security in applications, and some require specific certifications for particular work. Charity regulators expect trustees to manage risk, including cyber risk, and serious incidents may be reportable. Privacy law applies in full regardless of size - there is no charity exemption.

Practical benefit: a modest, documented programme often unlocks funding and partnerships, which makes it easier to justify internally than framing it purely as risk reduction.

Governance without a security committee

Give one trustee explicit responsibility for cyber and data risk. Put it on the risk register with an honest rating. Report briefly to the board twice a year. That is proportionate governance and it satisfies most of what a funder or regulator wants to see.

Frequently asked questions

Where do we start with no budget?

MFA everywhere and payment verification by call-back. Both are free and address the highest-loss scenarios.

Do we need a certification?

Only if a funder or partner requires it. A basic scheme is affordable and often sufficient where one is asked for.

Does privacy law apply to small charities?

Yes, in full. There is no exemption for size or charitable status.

How do we manage volunteer access?

Role-based access, expiry at creation, and a quarterly reconciliation against current volunteers.

Key takeaways

  • Beneficiary data can be more sensitive than commercial data.
  • The highest-value controls here are free - the gap is ownership.
  • Volunteer access removal is the most commonly failed control.
  • A documented programme often unlocks funding, not just reduces risk.
#non-profit #charity #donor-data #volunteers #budget #grant-funding