Charity Sector  ◆  Charity Commission · ICO · CC26

Your cause deserves more
than good intentions.

Charities hold sensitive donor, beneficiary, and financial data — and are subject to the same data protection law, insurance obligations, and governance requirements as commercial organisations. The difference is that trustees carry personal responsibility, and most charities cannot absorb the cost of getting it wrong.

Talk to Us Understand the Detail
What We Address

Trustee Governance

Under Charity Commission guidance CC26, trustees have a personal duty to ensure adequate internal controls — and technology infrastructure is explicitly within scope. Inadequate IT is a governance failure, not just an operational inconvenience.

Donor & Beneficiary Data

Charities handle some of the most sensitive personal data imaginable — health conditions, vulnerability status, financial circumstances. The ICO applies the same standards to a charity of ten people as it does to a FTSE company. A breach is a breach, regardless of good intent.

Funding & Insurance Continuity

Grant bodies, statutory funders, and cyber insurers are increasingly requiring Cyber Essentials certification as a condition of engagement or coverage. Without it, your funding pipeline and your insurance validity are both at risk — simultaneously.

Talk to Us Understand the Detail
For the Detail-Focused

Understand the Compliance Landscape

Charity Sector Obligations

The regulations that carry direct technology obligations. Select any panel to understand what it means for your infrastructure — in plain English.

High Risk
Charity Commission — CC26 Internal Controls & Trustee Duty of Care A cyber incident with no documented controls is a governance failure.
High Risk
Data Protection Act 2018 / UK GDPR ICO Obligations & 72-Hour Breach Notification The ICO applies no lower standard to the charitable sector.
Medium Risk
NCSC / Government Scheme Cyber Essentials — Funding & Grant Eligibility Grant bodies increasingly require certification as a condition of funding.
High Risk
Cyber Insurance Policy Validity & Claim Conditions A voided claim is not a setback for most charities — it is existential.
Opportunity
Microsoft Non-Profit Licensing Donated & Discounted Technology Entitlements Most registered UK charities are not claiming Microsoft 365 at reduced or zero cost.
High Risk
Operational Security Volunteer & Remote Access Risk High turnover, personal devices, and inconsistent access controls create unique gaps.
Go Deeper

Detailed analysis for your sector

Threat Intelligence

2025 UK Cyber Attack Review

How the latest UK cyber threats are specifically targeting charities and third sector organisations.

Explore →
Insurance Risk

Cyber Insurance Integrity Audit

Are your four technical warranties in place? A voided claim is existential for most charities.

Explore →
Data Resilience

Data Resilience & SaaS Liability

Understanding what your cloud providers actually protect — and what remains your responsibility.

Explore →

Can your trustees evidence
adequate internal controls?

We come to you. A structured review of your infrastructure against your Charity Commission, ICO, and insurance obligations — producing a plain-English written report your board can act on. No jargon, no assumption that anyone in the room has a technical background.

Request a Charity Infrastructure Audit

No commitment required  ◆  We respond within one business day