Your fund's Responsible Investment policy: What happens if a company appears to be in breach?
Responsible investment relies on ongoing monitoring, with potential breaches assessed through data, insight and active stewardship.
We help donors to give more impactfully and charities to build their resilience so they can do more of their life-changing work.
From one-off donations to long-term giving, or designing your personal philanthropic strategy, we work together to help you realise your giving ambitions.
DISCOVER OUR PERSONAL GIVING SOLUTIONSYou have the vision for making a difference. So do we. We help you plan how to give based on your goals.
DISCOVER OUR CORPORATE GIVING SOLUTIONSHelping your charity or social enterprise become more resilient.
DISCOVER HOW WE SUPPORT CHARITIESDiscover the latest insights for donors and charitable organisations to help create a greater impact
ExploreWe are a leading charity, working at the centre of the giving world. We help donors to give more impactfully and charities to build their resilience so they can do more of their life-changing work.
Find out more about CAF
Emma Winfield & Hannah Fogarty
Senior Information Security Analyst, IT & Information Security Analyst, IT
Running a small charity often means balancing many priorities with limited time and resources. That can make cybersecurity easy to put off, but charities are increasingly being targeted by criminals looking to exploit common weaknesses such as phishing emails, weak passwords and outdated software.
The good news is that improving your cybersecurity does not have to involve major investment or technical expertise. A few practical steps can help reduce risk and protect your charity's people, data and services.
This Cyber Security Awareness Month, we've brought together guidance from trusted organisations including the National Cyber Security Centre (NCSC), Charity Digital and the National Cybersecurity Alliance to help you get started.
MFA adds a quick extra step when you log in, usually a code from an app on your phone. It is one of the most effective ways to prevent account-takeover attacks, even if someone has your password. You can find more details in the NCSC’S guidance.
What small charities can do:
If you only do one thing:
Turn on MFA for your charity’s main email account. It blocks most unauthorised login attempts.
Passwords protect almost everything your charity relies on. Criminals often target small charities knowing people reuse simple passwords across different accounts.
A strong password does not need to be complicated. The NCSC recommends using three random words. This creates long and memorable passphrases that are hard for criminals to guess. For more information check NCSC’S guidance on passwords.
What small charities can do:
If you only do one thing:
Make sure your email and banking accounts do not reuse passwords.
Most cyber incidents start with a message that looks genuine but is not. Phishing emails, texts and calls may often impersonate banks, partners or volunteers.
Being alert to the warning signs can help you spot scams before they cause harm. You can find more advice in the NCSC’s guidance on phishing.
What small charities can do:
Criminals often impersonate suppliers or partners and ask you to change bank details. If money is sent to the wrong place, it may need to be paid again. For more guidance refer to the NCSC guidance on payment fraud.
If you only do one thing:
Slow down before acting on unexpected requests. A second opinion can prevent most mistakes.
Every charity stores information that matters. This may include donor records, financial documents or safeguarding notes. If a device fails, is lost or becomes encrypted by ransomware, it can be very hard to recover without a backup. You can find more advice in the NCSC backup guidance.
What small charities can do:
If you only do one thing:
Turn on automatic cloud backup for the files that matter most.
Many attacks succeed because devices or browsers are not updated. Updates fix known weaknesses that criminals look for.
What small charities can do:
If you only do one thing:
Enable automatic updates on the devices you use daily.
Small and micro charities do vital work with limited time, resources and technical support. Many rely on personal devices, shared accounts or volunteer run administration. Criminals know this and look for easy opportunities rather than complex targets.
The practical steps in this article protect against the most common methods criminals use. MFA, strong passwords, spotting scams, reliable backups and keeping devices updated are simple habits anyone can adopt without an IT team or specialist tools.
Resilience is not about perfection. It is about taking small and consistent actions that make your charity harder to target and easier to recover if something goes wrong.
Looking for more advice on protecting your organisation? Visit CAF Bank's Security Centre for practical tips on fraud prevention and keeping your funds secure.
Responsible investment relies on ongoing monitoring, with potential breaches assessed through data, insight and active stewardship.
The UK Local Giving Report 2026 explores how charitable giving differs across the UK and the local factors that influence generosity.
This blog explores how foundations can best support charities to adapt by prioritising stability, flexibility and long‑term resilience in an increasingly challenging funding environment.