Knowledge Hub

Risk IT, technology and digital

Cyber risk and resilience: what recent incidents mean for charities

In this article, Tim Larden, Associate Director at Access Insurance, discusses two recent cyber-related incidents which show how charities can be affected, even indirectly. Tim notes that these instances highlight the importance of cyber resilience for charities and provides some actionable insights for how you can prepare.

Why this matters

Recent incidents involving a fundraising CRM and a charity bank show why cyber resilience matters for charities. One involved possible compromise of supplier-held information; the other disrupted access to an essential service. Together, they demonstrate that a charity does not need to be directly attacked to be affected by a cyber incident.

Two supplier risks

The fundraising CRM incident highlights the risk of supplier-held information being compromised. Outsourcing is not the problem as it often gives charities access to better technology, security and expertise than they could build alone. The key point is that trustees should understand what information is shared, how important it is and what could happen if it were exposed.

In short, outsourcing a system does not outsource the risk associated with relying on it.

The banking outage illustrates a different risk: loss of access to an essential service. Even if a charity’s own systems are secure and working, disruption to an essential service or supplier can still affect a charity's activities and functions.

For non-technical charity leaders, the focus does not need to be on terms such as ransomware, malware, encryption or vulnerabilities. The more useful question is practical: what would happen if a critical supplier or digital service was unavailable tomorrow?

A changing risk environment

If we look at the cyber risk picture as whole, we can see from reports such as The Charity Commission’s 2026 Charity Sector Risk Assessment, that charities still face cyber attacks (30%) and phishing remains the most common and disruptive form, with ransomware increasing. AI could further enhance the risks to charities by making impersonation, fraud and deception more convincing.

Cyber should therefore be considered as part of the charity's wider approach to governance, financial resilience and business continuity, rather than as a standalone technology issue.

Trustees do not need to become cyber security specialists, but they should understand what the charity depends on, what could go wrong, and how the organisation would respond. This is particularly important for smaller charities with limited staff, tight budgets and little in-house expertise.

Practical steps towards resilience

A practical starting point is to identify critical suppliers.

Trustees and senior leaders should keep a simple record of external providers and ask what each supplier is used for, what information it holds, how long the charity could operate without it, what alternatives exist and who would lead the response if something went wrong.

Charities should also understand their data: what personal and sensitive information they hold, where it is stored and which suppliers can access it. Retaining unnecessary information increases the potential harm if a breach occurs, so good information governance reduces both operational and reputational risk.

Business continuity planning should include digital suppliers. Charities should consider whether payroll could be processed, donations received, key people contacted, beneficiary services maintained and essential payments authorised if a system or supplier was unavailable for several days. The discussion helps expose weaknesses before an incident occurs.

Basic controls remain vital. Multi-factor authentication should be used where appropriate, access should reflect what each person genuinely needs, and old accounts should be removed promptly when staff or volunteers leave. Charities can also ask suppliers about security certifications, backups, incident notification, service restoration and contingency arrangements they have in place.

Incident response and reporting

Resilience means also preparing for the possibility that controls fail. One of the worst times to decide who is responsible for responding to a cyber incident is while one is taking place.

Even a simple plan can identify: who coordinates the response, contacts the affected supplier, informs trustees, considers regulatory reporting, manages communications with staff, beneficiaries or supporters, and contacts insurers or specialist advisers. The plan should be available even if normal IT systems cannot be accessed.

Reporting responsibilities should be considered in advance. A supplier incident does not automatically mean every customer charity must make the same report, but trustees should assess whether there is significant harm or risk to the charity, its beneficiaries, assets, services or reputation. If personal data has been compromised, separate data protection obligations may also arise.

Where insurance fits

Insurance can form part of the resilience conversation, although it is no substitute for good security or planning. Specialist cyber insurance can provide access to legal, forensic, regulatory, communications and crisis management support, as well as protection against certain financial losses. For smaller charities without in-house support, immediate access to expertise can be especially valuable.

Key questions to ask

Technology helps charities operate efficiently, reach supporters, process donations, manage finances and deliver services, but reliance on third-parties must be part of risk management. Cyber resilience means understanding those dependencies and preparing a practical response before something goes wrong.

Here’s five questions to use as a useful starting point:

1. Which digital services could we not operate without?

2. Where is our important or sensitive information held?

3. What would we do if one of those systems was unavailable for several days?

4. Who would lead our response if information was compromised?

5. What alternatives and specialist support would we have available?

« Back to the Knowledge Hub