Introduction
Digital transformation has fundamentally changed the way non-profit organisations operate. Charities increasingly rely on digital systems to manage daily operations, deliver programmes, communicate with beneficiaries and donors, run campaigns, collect donations, maintain records, analyse data, and prepare reports.
This transformation has improved efficiency, accelerated processes, and enhanced service quality. At the same time, it has introduced new challenges related to protecting digital systems from increasingly sophisticated cyber threats.
Cyberattacks are no longer confined to commercial organisations or government bodies. Non-profit organisations are also exposed because they often hold valuable personal and financial data, while some operate with more limited technical infrastructure or cybersecurity resources than other sectors.
The consequences of a cyber incident can extend well beyond system disruption or data loss. They may damage organisational reputation, interrupt essential services, undermine donor and beneficiary trust, disrupt operations, and potentially expose the organisation to regulatory consequences where sensitive information is compromised or compliance requirements are breached.
Cybersecurity has therefore become a core element of institutional governance. It is no longer the responsibility of the IT Department alone. It is a shared responsibility that begins with the Board, extends through executive leadership, and includes employees and volunteers.
Professional practice increasingly shows that organisations most capable of managing cyber risk are not necessarily those with the most sophisticated technologies. They are those that understand their digital assets and risks, apply appropriate controls, train their people, prepare for incidents, and know how to continue operating and recover when disruption occurs.
This article explores the foundations of a cybersecurity framework for charities, the principal digital threats they face, the controls used to reduce those risks, and the practical steps required to build a secure digital environment that protects operations and strengthens the confidence of beneficiaries, donors, and funding organisations. It preserves the institutional and practical structure of the original article while strengthening its treatment of digital assets, risk management, continuity, and institutional readiness.
First: What Is Cybersecurity?
Cybersecurity refers to the policies, procedures, technologies, and practices used to protect digital systems, networks, devices, applications, and data from compromise, disruption, manipulation, or unauthorised access.
Cybersecurity is not limited to antivirus software or firewalls. It involves an integrated approach to digital risk management, service continuity, and the protection of critical information on which the organisation depends.
Within a charity, cybersecurity may include protecting:
- Beneficiary and donor management systems.
- Online donation platforms.
- Databases and digital records.
- Organisational email accounts.
- Websites and applications.
- Mobile devices and computers.
- Networks and cloud services.
- Administrative accounts and external platforms.
The objective is not simply to prevent attacks, but to reduce the likelihood of incidents, limit their impact, detect them, respond effectively, and restore operations afterwards.
Second: Cybersecurity and Data Protection
Although closely related, cybersecurity and data protection focus on different aspects of information management.
Data Protection concerns how personal information is collected, used, shared, and retained responsibly and in accordance with applicable requirements.
Cybersecurity focuses on protecting the systems, networks, devices, and accounts that process or store that information from attacks and digital threats.
In simple terms:
Data Protection: How do we manage information responsibly?
Cybersecurity: How do we protect the digital environment in which that information is processed?
Together, the two disciplines create a more secure, trusted, and resilient operating environment.
Third: You Cannot Protect What You Do Not Know You Have
Before purchasing cybersecurity tools, an organisation needs to understand its digital assets.
This begins with an Asset Inventory.
Depending upon the organisation, the inventory may include:
Devices | Systems | Websites and Applications | Databases | Email | Domains | Cloud Accounts | External Services | Administrative Accounts
For each asset, the organisation may record:
- The asset owner or responsible person.
- Its purpose.
- Its importance to operations.
- The type of data it handles.
- Authorised users.
- Relevant service provider.
- Criticality level.
Not every asset carries the same level of risk.
A temporary outage of an informational website may be manageable, while disruption to a donation platform or beneficiary management system may have an immediate impact on essential operations.
Cybersecurity therefore begins with two questions:
What do we have?
and then:
Which assets could we least afford to lose, disrupt, or have compromised?
Fourth: Why Are Charities Targeted?
It is sometimes assumed that charities are unattractive targets because they are non-profit organisations. In practice, they may hold highly valuable digital assets and information.
Factors that can increase risk include:
- Personal and financial data.
- Online donation processing.
- Legacy or unpatched systems.
- Limited cybersecurity budgets.
- Inconsistent staff awareness.
- Reliance on cloud services.
- Remote working.
- Dependence on external vendors and service providers.
Not all charities face the same level of cyber risk. Controls should therefore be proportionate to the organisation's size, the sensitivity of its information, the importance of its systems, and the potential consequences of disruption or compromise.
Fifth: Cybersecurity as Part of Enterprise Risk Management
Cybersecurity should be managed through Cyber Risk Management, rather than treated as an isolated technical issue.
A practical risk-management process may involve:
Identify Assets → Identify Threats and Vulnerabilities → Assess Likelihood and Impact → Apply Controls → Monitor Residual Risk
Significant cyber risks should be incorporated into the organisation's wider Enterprise Risk Register and reviewed by executive leadership and the Board according to their severity.
The risk is not simply that a technical vulnerability exists.
The more important question is the potential organisational impact.
For example:
What would happen if the organisation lost access to email for three days?
Or:
What would happen if an attacker gained control of the donation platform's administrative account?
These are the questions that connect cybersecurity with governance and executive decision-making.
Sixth: Common Cyber Threats Facing Charities
Cyber threats continue to evolve, and many attacks do not begin with technically sophisticated intrusion. They may begin with an ordinary-looking email.
Phishing
Fraudulent messages or links designed to steal credentials, induce users to download malicious files, or persuade them to take an unsafe action.
Ransomware
Malicious software that encrypts files or disables systems and then attempts to extort payment in exchange for restoring access.
Malware
Software designed to steal information, spy on users, damage files, or provide attackers with access to systems.
Account Compromise
Accounts may be compromised because of weak or leaked passwords, password reuse, or the absence of Multi-Factor Authentication.
Social Engineering
Manipulating trust, fear, urgency, or authority to persuade an employee to perform an unsafe action.
Business Email Compromise (BEC)
BEC deserves particular attention in charities.
An attacker may impersonate a senior manager, supplier, or partner—or compromise their mailbox—and then request:
- An urgent transfer.
- A change to supplier banking details.
- Payment of an invoice.
- Disclosure of a sensitive document.
A strong practical rule is:
Any unusual financial request or change to banking details should be independently verified through a channel other than the one in which the request was received.
Seventh: Core Cybersecurity Controls
Charities do not all require highly complex security architectures, but they do need a baseline set of controls proportionate to their risks.
These may include:
- A documented Cybersecurity Policy.
- Regular operating system and application updates.
- Device protection.
- Encryption of sensitive information where appropriate.
- Backups and tested recovery.
- Monitoring of unusual activity.
- Restricted access permissions.
- MFA for important systems.
- Periodic security reviews.
- An Incident Response Plan.
These controls are most effective when they operate as a connected framework rather than as isolated measures.
Eighth: Patch and Vulnerability Management
The existence of a security update does not mean the organisation has managed the underlying risk.
A simple Patch and Vulnerability Management process should help the organisation answer:
What systems do we use?
↓
Are they still supported?
↓
Are important vulnerabilities or updates known?
↓
Which are most critical?
↓
Who is responsible for remediation?
↓
Has the issue been resolved?
Internet-facing systems and systems processing sensitive information or controlling critical functions should generally receive higher priority.
The objective is not to install every update immediately regardless of context, but to maintain a clear, risk-based process for managing vulnerabilities and patches.
Ninth: Passwords and Multi-Factor Authentication
Credentials remain one of the most important lines of defence.
Useful practices include:
- Using strong and sufficiently long passwords.
- Avoiding password reuse.
- Avoiding shared accounts.
- Changing credentials when compromise is suspected.
- Using suitable password-management tools where appropriate.
More importantly, organisations should enable Multi-Factor Authentication (MFA) on critical accounts.
Even where a password has been obtained by an attacker, MFA can provide an additional barrier to unauthorised access.
Tenth: Least Privilege — Not Every Employee Needs Access to Everything
The principle of Least Privilege means granting each user only the permissions required to perform their responsibilities.
Employment within the organisation should not automatically result in access to all systems and data.
Permissions should be reviewed throughout the employee lifecycle:
Recruitment → Role Change → Promotion or Transfer → Departure
When an employee leaves, access should be revoked without unnecessary delay.
Shared accounts should also be avoided wherever practical because the organisation should be able to determine:
Who performed the action, when, and under what authority?
Eleventh: Administrative Accounts Require Stronger Protection
Some accounts provide extensive control over the organisation's digital environment and should therefore be treated as critical assets.
Examples include:
- Domain Registrar.
- Hosting.
- Cloud Administration.
- Google Workspace or Microsoft 365 Administration.
- CRM Administration.
- Donation platforms.
- Payment systems.
- Social media administration.
These accounts should receive stronger controls, including:
MFA + No Shared Credentials + Secure Recovery Methods + Periodic Access Review + Clear Ownership
Compromise of a single privileged account may be significantly more damaging than compromise of numerous ordinary user accounts.
Twelfth: Protecting Email and the Organisation's Digital Identity
Email is one of the most commonly exploited attack channels.
Good practice includes:
- Verifying senders.
- Treating unexpected attachments and links with caution.
- Independently verifying payment requests.
- Reporting suspicious emails.
- Using appropriate email-security tools.
Protection should not depend solely upon employee awareness.
Organisations can also strengthen the security of their email domain through mechanisms such as:
SPF — DKIM — DMARC
These controls can help reduce the risk of attackers impersonating the organisation's domain in fraudulent messages.
Thirteenth: Device, Network, and Remote-Working Security
Remote and field-based working means that the organisation's security boundary no longer ends at the office door.
Useful practices include:
- Protecting devices with suitable lock mechanisms.
- Keeping operating systems updated.
- Encrypting devices containing sensitive information where appropriate.
- Avoiding untrusted public networks for sensitive activities.
- Establishing rules for Bring Your Own Device (BYOD) where personal devices are permitted.
- Providing secure methods for accessing organisational systems remotely.
- Maintaining the ability to protect or disable lost devices where supported.
Fourteenth: Vendors Can Become Part of the Cyber Risk
An organisation's own systems may be well protected while compromise occurs through a third-party provider that has access to its systems or information.
Third-Party Cyber Risk should therefore be considered when using:
- Cloud services.
- Hosting providers.
- CRM platforms.
- Donation platforms.
- Technology vendors.
- Tools integrated with organisational systems.
Important questions include:
What can the vendor access?
How is it protected?
What happens if the vendor experiences a security incident?
How quickly will the organisation be informed?
How will data be recovered?
What happens to permissions and data when the relationship ends?
Relevant cybersecurity obligations should be reflected in suitable contracts and agreements.
Fifteenth: Backups — Will They Survive the Attack?
Backups are one of the most important protections against system failure, human error, and ransomware.
A commonly used practical model is the 3-2-1 approach:
3 copies of data
Across 2 different media or environments
With 1 copy separate or off-site
More important than the number of copies, however, is ensuring that an attacker who compromises the operational environment cannot easily delete both the original data and every backup copy.
Recovery should also be tested regularly.
A backup that has never been tested does not provide sufficient assurance that the organisation can actually restore its systems.
Sixteenth: Disaster Recovery — How Much Time and Data Can We Afford to Lose?
A Disaster Recovery Plan defines how critical systems will be restored following a major incident.
Two concepts are particularly useful:
RTO — Recovery Time Objective
What is the maximum acceptable period for which a system may remain unavailable?
RPO — Recovery Point Objective
How much recent data can the organisation afford to lose?
For example:
Can the donation platform remain unavailable for 24 hours?
Can the organisation tolerate losing the previous 24 hours of donation transactions?
Answering these questions helps determine appropriate backup, infrastructure, and recovery arrangements for each critical system.
Seventeenth: Business Continuity — What If the System Cannot Be Restored Immediately?
Disaster Recovery focuses on restoring systems.
Business Continuity focuses on keeping the organisation operating.
If digital systems become unavailable, the charity should know:
- How critical services will continue.
- How employees will communicate.
- How emergency information will be accessed.
- How field operations will continue.
- How donations and payments will be handled.
- Who has authority to make decisions during disruption.
The question is therefore not only:
How do we restore the system?
It is also:
How do we continue delivering our mission until the system returns?
Eighteenth: Cyber Incident Response
No organisation can guarantee that every incident will be prevented.
A charity therefore needs an Incident Response Plan defining:
Who receives the report?
↓
Who leads the response?
↓
How is the incident contained?
↓
How is the impact assessed?
↓
How are services restored?
↓
Who is authorised to communicate?
↓
How will lessons be incorporated afterwards?
The core stages generally include:
Detection and Reporting → Containment → Analysis → Remediation → Recovery → Review and Improvement
Practical Example
A Finance Officer receives an email appearing to come from the Chief Executive requesting an urgent transfer to a new bank account.
The transfer is made, and it is later discovered that the Chief Executive's mailbox had been compromised.
The response should not end with changing a password.
It may require attempting to stop or recover the payment, securing the compromised account, revoking active sessions, determining the scope of access, preserving relevant evidence, assessing the incident's impact, completing any required notifications, and identifying the root cause.
A simple but powerful corrective control may then be introduced:
Changes to bank details must never be approved solely on the basis of an email request.
Nineteenth: Cyber Awareness — People Are a Critical Line of Defence
A single click can bypass many technical controls.
Cybersecurity therefore requires investment in:
- Regular training.
- Phishing awareness.
- Understanding Social Engineering.
- Safe use of email.
- Password protection.
- Secure handling of files.
- Rapid incident reporting.
- Appropriate attack simulations where useful.
The objective is not to turn every employee into a cybersecurity specialist.
It is to enable them to:
Recognise Risk → Avoid Unsafe Action → Report Quickly
Twentieth: Artificial Intelligence Creates a New Category of Risk
AI tools are increasingly used in everyday work and can substantially improve productivity. They may also become an unintended channel for information disclosure.
An employee may copy into an AI tool:
- Beneficiary information.
- Donor data.
- Contracts.
- Internal reports.
- Financial information.
- Passwords.
- API Keys.
- Confidential documents.
Organisations should therefore establish clear rules for the use of AI tools, including which tools are approved and which categories of information must not be entered.
A useful baseline principle is:
Do not enter personal data, confidential information, credentials, or restricted documents into AI tools that have not been approved by the organisation.
Twenty-First: Cybersecurity Maturity Indicators
Policies alone are insufficient. Organisations need to understand whether their controls are actually being implemented.
Useful indicators may include:
- Percentage of staff completing cybersecurity training.
- Percentage of critical systems using MFA.
- Compliance with system update requirements.
- Number and nature of cyber incidents.
- Average detection and response time.
- Backup restoration success rate.
- Results of risk assessments and security reviews.
- Percentage of access permissions reviewed.
- Percentage of corrective actions closed.
Cybersecurity does not require dozens of metrics. A small number linked to the organisation's most significant risks is generally more useful for management.
Twenty-Second: Cybersecurity and Governance
Cybersecurity is a governance issue because it concerns asset protection, risk management, business continuity, and trust.
This is reflected through:
Leadership and Oversight: Board and executive review of significant cyber risks.
Accountability: Clear responsibility for systems and controls.
Risk Management: Integration of cyber risks into Enterprise Risk Management.
Business Continuity: Preparedness for system and service disruption.
Compliance: Consideration of relevant legal, contractual, and donor requirements.
Cybersecurity therefore moves beyond an IT function and becomes a component of institutional resilience.
Twenty-Third: How Can a Donor Know That a Charity Is Cybersecurity-Mature?
It is not enough for a charity to say:
“We have antivirus and a firewall.”
A donor or partner may seek evidence that cyber risks are being managed systematically, including:
- Cybersecurity Policy.
- Asset Inventory.
- Cyber Risk Register.
- Access Control Matrix.
- Access-review records.
- MFA coverage.
- Patch and Vulnerability Management records.
- Backup procedures.
- Restore-test results.
- Incident Response Plan.
- Incident Register.
- Business Continuity Plan.
- Disaster Recovery Plan.
- Training and awareness records.
- Third-party security controls.
- Corrective actions arising from incidents and reviews.
This demonstrates the difference between an organisation that owns cybersecurity tools and one that operates an evidenced cybersecurity management system.
Before Moving to the Next Article...
A charity seeking to improve its cybersecurity can begin by:
✓ Creating an inventory of digital assets.
✓ Identifying its most critical systems.
✓ Enabling MFA on important and privileged accounts.
✓ Reviewing user permissions.
✓ Securing administrative accounts.
✓ Updating systems and addressing priority vulnerabilities.
✓ Protecting email and the organisational domain.
✓ Reviewing backups and testing restoration.
✓ Defining RTO and RPO for critical systems.
✓ Establishing an Incident Response Plan.
✓ Developing Business Continuity and Disaster Recovery arrangements appropriate to the organisation.
✓ Training staff and volunteers.
✓ Reviewing vendors that access systems or information.
✓ Establishing clear rules for the use of AI tools.
Quick Self-Assessment
Ask yourself:
□ Do we know all systems, accounts, devices, and digital services used by the organisation?
□ Do we know which of them are critical to operations?
□ Is MFA enabled on email and administrative accounts?
□ Do we have shared accounts whose users cannot be clearly identified?
□ Are permissions removed when employees leave?
□ Is there a clear process for managing patches and vulnerabilities?
□ Are privileged accounts more strongly protected than ordinary user accounts?
□ Can we reduce the risk of attackers impersonating our email domain?
□ Could an attacker who compromises our systems also delete the backups?
□ Have we actually tested system restoration?
□ Have we defined RTO and RPO for critical systems?
□ Do we know what we would do if our main systems became unavailable tomorrow?
□ Do employees know how to report a cyber incident?
□ Do we have rules governing the use of AI tools?
□ Do we review the cybersecurity risks of external vendors?
□ Could we provide evidence of these controls if requested by a donor?
If the answer is “No” to several of these questions, the first priority should not necessarily be purchasing more cybersecurity tools.
Start by understanding:
What do we have? → What matters most? → What are the risks? → Who has access? → What controls exist? → How will we respond? → How will we continue operating if those controls fail?
Conclusion
Cybersecurity is no longer a technical matter limited to protecting computers and networks. It has become a foundation of institutional sustainability in an operating environment increasingly dependent upon digital systems.
Every digital service, donation, database, administrative account, and system upon which the organisation relies is an asset whose importance and associated risks should be understood and protected appropriately.
Cybersecurity readiness is therefore not measured by the number of security products purchased. It is measured by the organisation's ability to answer practical questions:
Do we know our digital assets?
Do we know which systems are critical?
Are permissions restricted and regularly reviewed?
Can we detect and respond to incidents?
Can we recover our information?
Can the organisation continue operating if systems fail?
Can we demonstrate all of this during an assessment?
Building cybersecurity requires the integration of governance, risk management, technical controls, staff awareness, supplier management, incident response, and business continuity—the same institutional elements that formed the core of the original article.
When these practices become embedded in everyday operations, cybersecurity moves from being a technical cost to becoming an institutional capability that protects funds, data, services, reputation, and trust.
For humanitarian organisations, the ultimate purpose remains clear:
A digital failure or cyberattack should never prevent the organisation from continuing to fulfil its responsibilities toward the people who depend upon its services.