Cybersecurity for West Sussex Charities and Non-Profits: What You Need to Know
You don't need to be a bank to be targeted by cybercriminals. Charities and non-profit organisations across West Sussex are increasingly in the crosshairs of attackers, and the assumption that "we're too small" or "there's nothing worth stealing" is costing organisations their data, their reputation, and sometimes their continued operation.
This is a practical guide for charity leaders, trustees, and operations managers who want to understand the real threats and what to do about them.
Why Charities Are Attractive Targets
The premise that criminals only go after organisations with money is wrong. What criminals actually want is data, access, and opportunity. Charities typically hold all three in abundance.
Donor databases contain names, addresses, email addresses, and often financial information. Beneficiary records may include sensitive personal and health data. Staff and volunteer information is routinely stored without adequate protection. And email systems — often Microsoft 365 or Google Workspace — are frequently configured out of the box without the additional security controls that make them genuinely safe.
There's also the question of resource. A small charity with a full-time IT resource is the exception. Most rely on volunteers, part-time staff, or whoever happens to be most technically capable. This creates predictable gaps that attackers know how to find.
The Charity Commission has been clear: trustees have a legal responsibility to protect beneficiary data under GDPR, and a failure to do so is a breach of duty. That's not scare-mongering; it's the regulatory reality.
The Most Common Threats Facing Charities
Phishing remains the single most effective attack vector against charities. A convincing email — appearing to be from a trustee, a major donor, or a partner organisation — asking staff to click a link, update payment details, or provide login credentials. These emails have become sophisticated enough to fool experienced professionals. The telltale signs of poor grammar and suspicious sender addresses are increasingly absent.
Business email compromise is particularly damaging. An attacker gains access to a legitimate email account — usually through a phishing attack — and uses it to redirect donation payments, change bank details on invoices, or instruct finance staff to transfer funds. The Charity Commission reports substantial financial losses each year from this attack type. The reason it works is that the instruction appears to come from a trusted person within the organisation.
Ransomware is less targeted but increasingly automated. Attackers scan for organisations with weak security configurations, encrypt their data, and demand payment for its return. For a charity that relies on its database of beneficiaries, donors, or service records, losing access to that data is potentially catastrophic. Many small organisations cannot recover because they have no adequate backup strategy.
Credential stuffing exploits the habit of reusing passwords. If an employee uses the same password across their charity login and a personal account, and that personal account is compromised in a data breach, attackers can use those credentials to access the charity's systems. This happens at scale using automated tools that try thousands of credential combinations per second.
What the ICO Expects from Charities
The Information Commissioner's Office applies GDPR equally to charities and commercial organisations. The size of your operation does not reduce your obligations.
Under GDPR, charities must process personal data lawfully and securely, ensure data is only held for as long as necessary, have a lawful basis for processing, report data breaches to the ICO within 72 hours if they meet the reporting threshold, and implement appropriate technical and organisational security measures.
"Appropriate" is the key word. It doesn't mean you need enterprise-grade security infrastructure. It means you need to have assessed your risks honestly and put in place controls that are proportionate to those risks. For a charity holding medical or financial data, that bar is higher.
The ICO has issued enforcement notices and fines to charities. The reputational damage of a public breach notification is often worse than any financial penalty.
Practical Security Steps for Charities
Multi-factor authentication should be your first priority. It is the single most effective control against account takeover. If every staff member and volunteer requires a second form of verification to log in to charity systems, the majority of credential-based attacks fail immediately. Microsoft 365 and Google Workspace both support MFA at no additional cost. The barrier is implementation and user training, not budget.
Email security configuration matters more than most charities realise. Both Microsoft 365 and Google Workspace have significant security capabilities that are not enabled by default. DMARC, DKIM, and SPF records prevent attackers from sending emails that appear to come from your domain. Safe Links and Safe Attachments in Microsoft 365 provide protection against phishing URLs and malicious attachments. These controls require configuration; they don't come switched on out of the box.
Endpoint protection across all devices that access charity data. This includes personal devices if staff use them for work. An unprotected personal laptop connecting to your charity's cloud environment is a potential entry point. Managed endpoint detection and response provides real-time monitoring and automatic threat containment.
A backup strategy that has been tested. Having backups is not the same as having a working recovery process. Many charities discover during a ransomware incident that their backups either don't exist, haven't run recently, or can't be restored successfully. Test your backups. Run a recovery exercise. Know how long it would take to restore your systems if you needed to.
Staff and volunteer security awareness training. Your technical controls can only do so much. People remain the most common entry point for attackers. A phishing simulation programme — sending fake phishing emails to your team and tracking who clicks — combined with regular security awareness training significantly reduces the risk of a successful attack.
Cyber Essentials for Charities
Cyber Essentials is the UK government's baseline cybersecurity certification. For charities, it provides a structured framework for implementing essential security controls and demonstrates to funders, regulators, and beneficiaries that you take data protection seriously.
Some funders, particularly government bodies, now require Cyber Essentials certification as a condition of grant funding. Even where it isn't required, it provides a useful framework for smaller organisations that don't have dedicated IT or security staff.
The five control areas — firewalls, secure configuration, user access control, malware protection, and patch management — map closely onto the most common attack vectors. Getting these right reduces your exposure significantly.
Working with Limited Budgets
Budget constraints are real. Most charities cannot afford an in-house IT team, let alone dedicated security staff. Managed IT and cybersecurity providers can provide access to expertise and tooling at a fraction of the cost of equivalent in-house resource.
When evaluating providers, look specifically for experience with the charity and non-profit sector. Your data protection obligations, your operational model, and your risk profile differ from a commercial SME. A provider that understands those differences will give you better advice.
Ask about Cyber Essentials support, email security configuration, endpoint protection, and incident response. These are the practical areas where a managed provider adds the most value for a charity.
Taking the First Step
The most common reason charities delay improving their security is the belief that they don't know where to start. A security assessment changes that. It maps your systems, identifies your most significant risks, and tells you exactly what to prioritise.
We offer free security assessments for charities and non-profits in West Sussex. No commitment, no sales pressure — just a clear picture of where you stand and what to focus on. If you're holding donor data, beneficiary records, or personal information of any kind, you have an obligation to protect it. Let us help you understand what that means in practice.