










NCSC identifies phishing as the most common attack against charities. Attackers pose as donors, grant issuers, or partners. Spear-phishing targets trustees and finance staff. Trust-based culture means urgent requests are actioned without verification.
NCSC highlights BEC as a major charity threat. CEO fraud tricks finance into paying fake invoices or transferring funds to fabricated overseas projects. International NGOs are exposed during cross-border transfers. Domain spoofing intercepts legitimate donations.
NCSC warns ransomware is devastating for charities with limited recovery resources. Double-extortion threatens to leak vulnerable beneficiary names or anonymous donor identities. No tested backups means mission-threatening downtime.
NCSC identifies charity websites as targets for data theft and payment skimming. Magecart-style attacks on donation pages. CRM and JustGiving API vulnerabilities. Payment theft from online and event channels.
Safeguarding records and abuse files exposed through compromise. Health data from hospice and mental health charities. Children's and vulnerable adult data. ICO enforcement carries financial penalties and reputational devastation.
NCSC identifies insider risk from volunteer turnover. Orphaned accounts never revoked. Weak passwords with no MFA. Donated equipment with insecure configurations. Free cloud tier misconfiguration.
Trustees legally accountable for cyber attacks
Scottish Charity Regulator governance obligations
Required for government grants, lottery funding, and contracts
Comprehensive resilience for third sector
ICO enforcement, fines for donor/beneficiary exposure
Mandatory for health charities accessing NHS data
Donation processing via telethons, online, and street fundraising
Donor data collection and storage
Charity services aimed at children
Children Act and Care Act data security
NCSC recommends securing websites and online services. We test donation pages, JustGiving integrations, and Blackbaud/Salesforce platforms. CMS security. API reviews. PCI DSS for donation channels.
NCSC recommends DMARC, SPF, and DKIM controls. We deliver M365 and Google Workspace assessments, BEC prevention, domain spoofing protection, and MFA validation for staff and volunteer accounts.
NCSC recommends managing privileges and keeping software updated. We deliver penetration testing, cloud configuration reviews, and BYOD advisory proportionate to charity environments.
NCSC recommends Cyber Essentials as the foundational step. As an authorised body we deliver CE+ and ICA with gap analysis, unlocking grant, lottery, and contract eligibility.
NCSC recommends incident response planning. We deliver UK GDPR gap analysis, NHS DSPT, Charity Commission preparedness, PCI DSS for donations, and trustee governance guidance.
NCSC recommends training staff on threats. We deliver differentiated phishing simulations for trustees (governance), staff (operations), and volunteers (phishing). Incident response for organisations without IT.
Identify vulnerabilities across your charity network before attackers reach donor and beneficiary data.
View serviceTest donation pages and CRM integrations against the website attacks NCSC identifies as targeting charities.
View serviceAssess Google Workspace or M365 for the cloud misconfigurations NCSC highlights as a key charity vulnerability.
View serviceAudit Blackbaud, Salesforce Non-Profit, JustGiving, and donor management platforms your charity depends on.
View serviceAlign controls with Charity Commission, UK GDPR, NHS DSPT, and Fundraising Regulator obligations.
View serviceAchieve the CE+ NCSC recommends as foundational, unlocking grant and contract eligibility.
View serviceDeliver the training NCSC recommends with differentiated simulations for trustees, staff, and volunteers.
View serviceTest charity mobile apps, volunteer tools, and beneficiary service applications for vulnerabilities.
View serviceImplement the email controls NCSC recommends, hardening M365 against BEC and CEO fraud.
View service
Most SMBs and mid-market firms have “silent” gaps in their people, process and tech controls implementation. Take the 90-second maturity audit to see your percentile rank.