Clare Mills, Co-CEO, Charity Finance Group, shares her reflections since the launch of CFG’s Charity Banking Report, and considers how to build resilience for when the systems and services we rely on falter.

Since we published our ‘Charity Banking Report: Findings and Recommendations’ in July, more charities than ever have been in touch to tell us about their own experiences of banking, what they find hardest, and what they need. The sector wants to be heard, and this strengthens our resolve to keep pushing, alongside banks and regulators, for banking services that work for charities.
Charities tell us that when it comes to banking a lot feels outside of their control; from trying to change their mandate, to getting in front of a helpful representative.
Alongside the challenges laid out in our report, the past few weeks have also offered a timely reminder of something every charity can do now – get ready.
Disruption is part of the landscape
Disruption to the digital systems that we rely on is no longer rare – it affects organisations of every size and sophistication. This is the reality of the environment we now all operate in.
Over ten days in spring 2025, Marks & Spencer, the Co-op and Harrods were all hit by cyber attacks that took out business-critical services; Jaguar Land Rover and a Heathrow supplier were struck later in the year. The independent Cyber Monitoring Centre judged the M&S and Co-op incidents a single systemic event, with an estimated cost of between £270m and £440m.
The charity sector has just had its own reminder – in fact, two. In late July, CAF Bank, which serves more than 14,000 charities, suspended its online banking service after detecting suspicious activity on some accounts. The bank confirmed that its core banking was unaffected and that customers' money was safe, and prioritised time-sensitive payments such as payroll. They also redirected more resources to respond to enquiries.
CAF Bank have confirmed that all banking services are now bank online. However, for those charities that have been caught in the middle – some of whom have struggled to pay staff and suppliers – the strain is real and raw.
Almost at the same time, Beacon CRM – a database platform used by more than 1,500 charities to manage their relationships with donors, supporters and volunteers – discovered that compromised credentials had been used to get into its systems and copy its database backups. The platform kept running, but Beacon has told charities to work on the assumption that the data they held there may have been taken.
As a donor, I’ve had email alerts from two charities, warning that my data may have been compromised. The Charity Commission is planning to issue guidance for charities affected by data breaches. Two very different incidents, but both reaching charities through a third party, and both well outside those charities' direct control.
The lesson isn’t that these business providers are badly run organisations, in fact I’d argue it’s quite the opposite! It's that this is the world we now work in, and preparing for it is everyone's responsibility. As we’ve said often – it’s not a case of if you will experience a cyber-attack, but when.

Building greater resilience
Following any incident or crisis, it’s natural to reflect on any of the lessons that can be learned. Perhaps the main one here is that even when your money and your data are completely safe, losing access to a service can bring day-to-day operations to a shuddering halt. This is a business continuity issue and the good news is that charities can largely be prepared.
And here’s the point: we all rely, far more than we often realise, on third-party providers and some of them are all but invisible to us. Your bank, your CRM, your payroll software, your website host, the cloud service sitting behind another tool you use every day. When one of them stumbles, the effect lands on you, even though the problem started somewhere else entirely.
The advice below won’t necessarily be new to you, but it doesn’t harm to remind ourselves that some things can be within our control – and those things are worth spending time on, sooner rather than later.
Practical steps to take now
- Write a short business continuity plan. Answer one question in advance: what would we do if we lost access to our banking for a week? Note who does what, which payments are time-critical, and how you'd make them by other means. Agree it before you ever need it. Plans made calmly are usually far better than plans made under pressure. Include staff contact details. Print it off and give a copy to everyone who will be involved in delivering the plan.
- Hold a second bank account with a different provider. This is the single most useful safeguard. If one bank's systems go down, a back-up account with another institution means you can still run payroll and pay suppliers. Treat it with the same governance discipline as your main account – keep the mandate current and the controls tight. Having it there could be the difference between a minor inconvenience and a crisis.
- Know your critical suppliers – not just your bank. Make a simple list of the providers you couldn’t operate without: banking, CRM and donor data, payroll, email, your website. Then ask the same question of each one: what would we do if this went down, or was breached, tomorrow? You can’t control their security, but you can decide in advance how you’d cope – and you can check what they’d do for you, too. Make sure you have an up to date list of contacts and phone numbers, and know how to prove your identify to service providers.
- For your bank accounts, keep your user details and bank mandate up-to-date. Ensure that bank signatories know telephone passwords, that you have sufficient signatories or users to authorise payments even if one of them is unavailable, and that your data is up-to-date.
- Have an all-staff WhatsApp group (or a preferred alternative). If your usual systems or email go down, you’ll still need a fast, reliable way to reach everyone. A simple group chat, agreed in advance, means you can share updates and coordinate at a moment’s notice.
- Keep an operating buffer if you can. A small reserve, or funds spread across more than one bank, means a short outage at month-end doesn't stop you meeting payroll or essential bills. The size of that buffer will depend on your organisation’s needs.
- Get your own cyber basics in place. Turn on multi-factor authentication, back up your essential data and keep it separate, keep software updated, and help your people spot phishing. The National Cyber Security Centre (NCSC) is clear that charities are targeted just as readily as private firms.
And remember, you are not on your own. As well as resources and support from CFG, the NCSC offers free, charity-specific guidance – including its Small Charity Guide and its guide to responding to and recovering from an incident, plus a 24/7 line on 0300 123 2040 if you're ever hit by a live cyber-attack. Smaller charities can also get government-backed Cyber Essentials certification, now funded for many. And through the Home Office-funded National Cyber Resilience Group your charity can access free training and services.
CFG will keep working with our partners across the banking sector and with the regulators to make the whole system stronger because when it falters, it is charities and the people they serve who feel it first. And CFG's corporate partners from other sectors are also here if you need them for advice and guidance too.
Get in touch
We're not able to advise on individual disputes or specific situations with any bank or other service provider, including anything relating to the recent CAF Bank or Beacon CRM disruption. What we can do is listen to the broader challenges facing charities and use that insight in our work with banks and regulators. If you'd like to share your experience of banking in that spirit, talk through the resilience steps above, or share your own best practice for others to learn from, we'd be glad to hear from you. Email CFG.
CFG Resources