Personal giving

From one-off donations to long-term giving, or designing your personal philanthropic strategy, we work together to help you realise your giving ambitions.

DISCOVER OUR PERSONAL GIVING SOLUTIONS

Corporate giving

You have the vision for making a difference. So do we. We help you plan how to give based on your goals.

DISCOVER OUR CORPORATE GIVING SOLUTIONS

Services for charities

Helping your charity or social enterprise become more resilient.

DISCOVER HOW WE SUPPORT CHARITIES

Insights

Discover the latest insights for donors and charitable organisations to help create a greater impact

Explore

About us

We are a leading charity, working at the centre of the giving world. We help donors to give more impactfully and charities to build their resilience so they can do more of their life-changing work.

Find out more about CAF
Home Services for charities Resources for charities Building cybersecure futures together: practical steps for charities

Building cybersecure futures together: practical steps for charities

Emma Winfield & Hannah Fogarty Emma Winfield & Hannah Fogarty Senior Information Security Analyst, IT & Information Security Analyst, IT

Running a small charity often means balancing many priorities with limited time and resources. That can make cybersecurity easy to put off, but charities are increasingly being targeted by criminals looking to exploit common weaknesses such as phishing emails, weak passwords and outdated software.

The good news is that improving your cybersecurity does not have to involve major investment or technical expertise. A few practical steps can help reduce risk and protect your charity's people, data and services.

This Cyber Security Awareness Month, we've brought together guidance from trusted organisations including the National Cyber Security Centre (NCSC), Charity Digital and the National Cybersecurity Alliance to help you get started.

1. Turn on Multi Factor Authentication (MFA) 

MFA adds a quick extra step when you log in, usually a code from an app on your phone. It is one of the most effective ways to prevent account-takeover attacks, even if someone has your password. You can find more details in the NCSC’S guidance.  


What small charities can do: 


  • Turn on MFA for email, banking, fundraising and cloud accounts. 
  • Use an authenticator app instead of SMS. 
  • Share simple instructions with staff and volunteers on how to turn it on. 

If you only do one thing: 

Turn on MFA for your charity’s main email account. It blocks most unauthorised login attempts. 



2. Use strong passwords 

Passwords protect almost everything your charity relies on. Criminals often target small charities knowing people reuse simple passwords across different accounts. 


A strong password does not need to be complicated. The NCSC recommends using three random words. This creates long and memorable passphrases that are hard for criminals to guess. For more information check NCSC’S guidance on passwords. 


What small charities can do: 


  • Choose long passphrases made of three random words. 
  • Avoid shared passwords between volunteers. 
  • Use a password manager so you do not need to remember everything. 
  • Change passwords when volunteers or employees leave. 

If you only do one thing: 

Make sure your email and banking accounts do not reuse passwords. 



3. Recognise and report scams (especially phishing) 

Most cyber incidents start with a message that looks genuine but is not. Phishing emails, texts and calls may often impersonate banks, partners or volunteers. 


Being alert to the warning signs can help you spot scams before they cause harm. You can find more advice in the NCSC’s guidance on phishing.  


What small charities can do: 


  • Pause before clicking links or opening attachments. 
  • Check the sender’s email address carefully. 
  • Ask someone else if a message feels unusual. 
  • Share examples with personal details removed so volunteers know what to look for. 
  • Always confirm requests to change bank details using a trusted phone number or in person. Never use the contact details provided in the message. 


4. Be careful with payment detail changes 

Criminals often impersonate suppliers or partners and ask you to change bank details. If money is sent to the wrong place, it may need to be paid again. For more guidance refer to the NCSC guidance on payment fraud.  


If you only do one thing: 

Slow down before acting on unexpected requests. A second opinion can prevent most mistakes. 



5. Protect your data and make reliable backups 

Every charity stores information that matters. This may include donor records, financial documents or safeguarding notes. If a device fails, is lost or becomes encrypted by ransomware, it can be very hard to recover without a backup. You can find more advice in the NCSC backup guidance.  


What small charities can do: 


  • Back up important files to the cloud or an external drive. 
  • Keep at least one backup stored separately from the device. 
  • Turn on automatic backups where possible. 
  • Test occasionally that your backup works. 

If you only do one thing: 

Turn on automatic cloud backup for the files that matter most. 



6. Keep your devices and browsers updated 

Many attacks succeed because devices or browsers are not updated. Updates fix known weaknesses that criminals look for. 


What small charities can do: 


  • Turn on automatic updates for laptops, tablets and phones. 
  • Keep your web browser updated, including Chrome, Edge, Safari or Firefox. 
  • Restart devices regularly so updates can install. 

If you only do one thing:

Enable automatic updates on the devices you use daily. 



Why these steps matter 

Small and micro charities do vital work with limited time, resources and technical support. Many rely on personal devices, shared accounts or volunteer run administration. Criminals know this and look for easy opportunities rather than complex targets. 

The practical steps in this article protect against the most common methods criminals use. MFA, strong passwords, spotting scams, reliable backups and keeping devices updated are simple habits anyone can adopt without an IT team or specialist tools. 

Resilience is not about perfection. It is about taking small and consistent actions that make your charity harder to target and easier to recover if something goes wrong. 

Looking for more advice on protecting your organisation? Visit CAF Bank's Security Centre for practical tips on fraud prevention and keeping your funds secure.


You may also be interested in

Keep exploring