Menu
Menu
Cybersecurity for Small Charities
Transcript
Quick Links
Slide 1: Cybersecurity
Hello and welcome to this recording from Support Cambridgeshire. This is one of several recordings we have developed to support small charities.
To accompany the recording, there are guidance links available at the end of the transcript, which will provide you with any materials or links we mention.
Slide 2: What we’ll cover
This training uses resources and training developed and supplied with consent from the National Cyber Security Centre (NCSC) and the National Association for Voluntary Community Action (NAVCA)
During this short introduction, we will cover:
- Awareness of NCSC
- Why cybersecurity is important
- What you and your group should be aware of and looking out for when it comes to cyber attacks
- Where can you access support and resources for you and your group for free
This on-demand training is aimed at individuals linked to community and voluntary groups and small charities. The goal is to encourage you to consider your cybersecurity position.
Slide 3: Awareness of the NCSC
Who are the National Cyber Security Centre?
The National Cyber Security Centre or NCSC are formally a part of GCHQ, one of the 3 main UK intelligence agencies. The NCSC’s mission is to help make the UK the safest place to live and work online.
The NCSC provides key and up-to-date guidance for charities, which is free to use.
Their website is a one-stop shop for any of your cyber questions.
You can contact the NCSC via their enquiries page. There is a helpful link from Charity Digital’s article, An A-Z glossary of cybersecurity terms and definitions.
Slide 4: What is a cyberattack?
A cyber attack is considered any malicious attempt to damage, disrupt or gain unauthorised access to computer systems, IT networks or devices (such as laptops, phones and tablets).
Specifically, without your knowledge and permission.
Recent cyber attacks have made news headlines; in June 2024, the NHS was attacked, and several GP surgeries and hospitals were affected, causing serious disruption. The British Library were also a victim of a cyber attack in October 2023.
Slide 5: What is Cybersecurity?
In the opposite way, cybersecurity is the actions you take to protect your systems and devices from such an attack.
By protecting your systems sufficiently, you stand a significantly stronger chance of keeping your systems and charity safe from an attack.
Just as the internet is a fundamental part of life in keeping your charity running and accessible to all, so is your cybersecurity.
Slide 6: Why are Charities and groups at risk?
Charities hold funds (often electronically), personal, financial and commercial data of interest to individuals and often of monetary value to a criminal. Often, this data is sensitive, valuable and vulnerable to attack.
Think about how your supporters would feel if their data were taken from your systems.
The Impact of a cyber-attack can range from missing data, stopping your operations temporarily or permanently, costs of a breach or lost revenue, including the time taken to recover, and finally, the reputation of your charity.
A Cumbria-based community charity, The Milom Network Centre, which supports local people with its food pantry, second-hand furniture sales and educational programmes, lost all of its charitable funds in May 2024 when it fell victim to fraud.
Scammers emptied its entire bank account. Before the bank agreed to refund the charity, they faced the very real fear of closure.
Slide 7: Who could attack a charity?
Cybercriminals might attack a charity. This can be either untargeted or targeted.
No matter which way it is, it’s usually always for financial gain. There is no information to say that charities are specifically targeted over other sectors.
However, we know criminals scan the internet for organisations that have weak security defences.
If you think about an opportunistic burglar walking down a street looking for properties with open windows.
The burglar or cyber criminal won’t care if those windows belong to a small or large charity. It’s not just ransomware.
Criminals can steal money through other routes, like pretending to be a supplier and asking for urgent payment on an invoice.
Nation States: There is currently no evidence of nation states targeting the charity sector, but it is possible to be caught up in an untargeted attack by a nation state.
Lastly, the Insider threat. And by that I mean a member of staff, volunteer, or trustee who’s working in the charity. The overwhelming majority of cyber incidents caused by insiders are accidental.
However, they can still have a significant impact on the operation of the charity.
It’s really important for charities not to foster a culture of blame for accidental ‘insider’ cyber incidents.
It is so easy to make a mistake, whether it’s clicking on a suspicious link or opening an attachment which could unleash a virus.
The important thing is that staff feel that they can report without fear of repercussions. That way, IT can be up and running quicker, and data recovered faster.
But there could be a chance that the insider threat could be on purpose.
Perhaps a member of staff is disgruntled, or a trustee feels they have been ignored.
All these threats, whether targeted or untargeted, accidental or on purpose, can be mitigated by using some key cybersecurity approaches.
Slide 8: How are charities being attacked?
Ransomware is a type of malware that makes data or systems unusable until the victim makes a payment. Typically, the data is encrypted, but it may also be deleted or stolen, or the computer itself may be made inaccessible.
Following the initial ransomware attack, those responsible will usually send a ransom note demanding payment to recover the data.
Law enforcement does not encourage, endorse, or condone the payment of ransom demands. If you pay.
There is no guarantee that you will get access to your data or computer. Ransomware attacks can have a devastating impact on organisations, with victims spending significant amounts of time and money to reinstate critical services.
Often, skills need to be bought in from elsewhere. Replacing or upgrading expensive IT equipment is also often required.
The British Library and NHS cyber attacks I referred to earlier were Ransomware attacks.
Malware is malicious software that is designed to interfere with a computer’s normal functioning and can be used to obtain information and commit cybercrimes.
Phishing is where untargeted, mass emails are sent to many people asking for sensitive information (such as bank details) or encouraging them to visit a fake website.
Most of us have heard about not opening suspicious-looking attachments or weblinks, but these attacks do still regularly happen. Criminal groups will use charity branding or logos to make the emails look more legitimate; these can be obtained from websites or a simple Google search.
A couple of examples on the slide. In May 2024, Companies House sent out an email warning of scam letters being sent out claiming to be from Companies House.
The letters claimed that the recipient needed to make a payment for Enhanced Web Filing Access.
In June 2024, CCVS posted on LinkedIn that they had been made aware by the Cambridge City Council of a fraudulent message aimed at Homes for Ukraine visa holders that was circulating online.
The message falsely claimed to be from the Home Office and requested personal data.
Slide 9: What can you do to protect your charity?
What can you do to protect your data?
We will look at each area in a little more detail.
- Backing up your data
- Protecting against malware
- Keeping devices secure
- Create strong passwords
- Defend against phishing
Slide 10: What can you do to protect your charity?
1. Back up your data
Backing up your data is your vital first step in your cybersecurity strategy. You must ensure not only that your charity is taking regular back-ups of important data, but test that they can be restored. This will reduce the inconvenience of any data loss from theft, fire, other physical damage or ransomware.
Identify what needs to be backed up. Usually, this includes documents, emails, contacts, legal information, calendars, financial records and supporter or beneficiary databases.
Ensure the device containing your backup is not permanently connected to your network, either physically or over a local network.
Consider backing up to the cloud. This means your data is stored in a separate location (away from your offices/devices), and you’ll also be able to access it quickly, from anywhere. Link to Cloud security guidance from the NCSC is on the slide.
Slide 11: What can you do to protect your charity?
2. Protect against malware
Protecting your charity against malware (which is malicious software, including viruses) doesn’t have to be pricey or complicated. I have listed a few low-cost and simple options on the slide.
- Use antivirus software on all computers and laptops. Only install approved software on tablets and smartphones, and prevent users from downloading third-party apps from unknown sources.
- Patch all software and firmware by promptly applying the latest software updates provided by manufacturers and vendors. Use ‘automatically update’ options where available.
- Control access to removable media such as SD cards and USB sticks. Consider disabling ports or limiting access to sanctioned media. Encourage staff to transfer files via email or cloud storage instead.
- Switch on your firewall (included with most operating systems) to create a buffer zone between your network and the Internet.
There is a link on the slide to smartphone and device security guidance from NCSC.
Slide 12: What can you do to protect your charity?
3. Keep Devices secure
Smartphones and tablets (which are used outside the safety of the office and home) need even more protection than ‘desktop’ equipment.
- Switch on PIN/password protection/fingerprint, and face recognition for mobile devices.
- Configure devices so that when lost or stolen, they can be tracked, remotely wiped or remotely locked.
- Keep your devices (and all installed apps) up to date, using the ‘automatically update’ option if available.
- When sending sensitive data, don’t connect to public Wi-Fi hotspots – use 3G or 4G connections (including tethering and wireless dongles) or use VPN’s.
- Replace devices that are no longer supported by manufacturers with up-to-date alternatives.
There is a link to an NCSC blog post about mobile device management software on the slide.
Slide 13: What can you do to protect your charity?
4. Creating strong passwords
Passwords – when implemented correctly – are a free, easy and effective way to prevent unauthorised people from accessing your devices and data.
- Make sure all laptops, Macs and PC’s use encryption products that require a password to boot. Switch on password/PIN protection or fingerprint and face recognition for mobile devices.
- Use two-factor authentication (2FA) for important websites like banking and email if you are given the option. Two-factor authentication requires using a password and one other form of protection, like a fingerprint, face recognition, pin or text message.
- Avoid using predictable passwords (such as family and pet names). Avoid the most common passwords that criminals can guess (like passw0rd).
- Do not enforce regular password changes: they only need to be changed when you suspect a compromise.
- Change the manufacturers’ default passwords that devices are issued with, before they are distributed to staff.
- Provide secure storage so staff can write down passwords and keep them safe (but not with the device). Ensure staff can reset their own passwords easily.
- Consider using a password manager. And if you do use one, make sure that the ‘master’ password (that provides access to all your other passwords) is a strong one.
Links to further information and resources from the NCSC are on the slide
Slide 14: What can you do to protect your charity?
5. Defend against phishing
Phishing attacks are when scammers send fake emails asking for sensitive information (such as bank details), or the emails include links to bad websites, and the emails encourage you to click on the links.
To defend your charity against phishing attacks, you can:
- Ensure staff don’t browse the web or check emails from an account with Administrator privileges. This will reduce the impact of successful phishing attacks.
- Scan for malware and change passwords as soon as possible if you suspect a successful attack has occurred. Don’t punish staff if they get caught out (it discourages people from reporting in the future).
- Check for obvious signs of phishing, like poor spelling and grammar, or low-quality versions of recognisable logos. Does the sender’s email address look legitimate, or is it trying to mimic someone you know? This is challenging as emails are increasingly sophisticated.
Link on the slide is to the 5 top tips to avoiding phishing attacks from NCSC.
Slide 15: What to do if you are a victim of a cyber attack?
Despite your best efforts, cyber attacks can happen, and if you think your charity has been the victim of a cyber attack, online fraud, scams or extortion, you should report this through the Action Fraud website. There is a link on the slide.
You must report certain incidents that you’re legally obliged to report to the Information Commissioner’s Office (ICO), regardless of whether your IT is outsourced.
This includes a personal data breach under the GDPR or the Data Protection Act.
You will also have to report it as a serious incident to the Charity Commission through the Charity Commission (England and Wales) website.
Reporting incidents will demonstrate that you have taken responsible action to identify problems within your charity. It also helps the Commission to gauge threats that may affect the wider sector and to take steps to address these with targeted advice and guidance.
If you are not sure if you have been attacked or need further advice, you can contact the NCSC enquiries.
Slide 16: NCSC Resources
The NCSC has produced several tools called the Active Cyber Defence tools, or ACD. These are offered to organisations across certain sectors, including charities, for free.
There are 3 tools which are worth looking into for your charity. They are Mail and web check, and Early Warning.
Slide 17: NCSC Resources and guidance
The NCSC also has a lot of free resources, including guides, support and advice. On the slide are a few resources that are useful to smaller charities in particular.
- Small charity guide
- Infographics: These are useful if your team has any specific questions or wants to learn more. They are available on the NCSC website and can be downloaded and printed.
- E-learning courses: this includes “top tips for staff”. The training can be completed online or downloaded and built into your own training platform. It takes less than 30 minutes to complete and is deliberately non-technical. This training is aimed at small organisations, so some of the terminology is not aimed at charities, but it is a useful resource for colleagues who may like some basic cyber skills.
Slide18: The Future
The future. Technology is constantly developing at an ever-increasing pace, with policy, legislation, and security furiously trying to play catch-up. Plans for future legislation have again been amended with a new Labour Government elected in July 2024.
AI briefly appears on the agenda, but the focus appears to be on data protection matters and privacy rights.
We plan to update this training transcript with any relevant updates.
February 2026 update: The government introduced the Cyber Security and Resilience Bill to Parliament in November 2025 and it just had its second reading on 6 January 2026. The Bill aims to improve the UK’s security in respect of critical infrastructure, preventing it from being stopped or slowed by cyber-attacks or other digital disruption.
Slide 19: Here to help
We hope that this training has been of assistance in increasing your awareness of what cybersecurity is, who the National Security Council is and how you can protect yourself and your charity from possible cyber-attacks. Please do reach out to us directly with any further support needs, and do check out our website for further training resources.
Guidance and links
NCSC resource links
- NCSC general enquiries
- NCSC Small Charity Guide
- NCSC A-Z of NCSC infographics
- NCSC E-courses for small organisations
NCSC Active Cyber Defence tools or ACD
NCSC guidance links
- Charity Digital: An A-Z glossary of cybersecurity terms and definitions
- British Library Blog Post March 2024 Lessons from the cyber attack
- Guardian Article June 2024 Cyber-attack on London Hospitals
- BBC News article, May 2024 Scammers emptied charity’s account
- Gov.UK Reporting scams to Companies House
- CCVS LinkedIn post-June 2024. Cambridge City Council warns about fraudulent messages aimed at Homes for Ukraine visa holders
- Cyber Security and Resilience Bill