Cybersecurity Essentials for Charities

A suspicious email lands in someone’s inbox. A former volunteer still has access to a shared folder. A staff member downloads donor information to finish a report from home. None of these situations feels dramatic in the moment, but they are exactly where everyday cybersecurity starts.

For charities, protecting technology is really about protecting the work that depends on it. Email, donor records, shared files, payment systems, and staff accounts all need sensible safeguards around them, and those safeguards should be part of the same thinking you use when reviewing your managed IT support for your charity.

Cybersecurity does not need to become another overwhelming project on an already full list. When the basics are handled well, your team can work with more confidence and spend less time wondering whether something has been missed.

Protect Accounts and Access

A strong password helps, but passwords alone are no longer enough for the systems your team relies on every day. Multi-factor authentication adds another layer of protection, so a stolen password is less likely to turn into access to your email, donor database, or shared files.

It is also worth looking at who has access to what. Shared logins may feel convenient, especially for volunteers or part-time staff, but they make it harder to know who can see sensitive information and harder to remove access cleanly when someone leaves. Giving each person their own account, with access only to what they need, makes day-to-day work easier to manage and reduces unnecessary risk.

That becomes especially important when someone leaves, changes roles, or finishes a volunteer term. A clear password and access management process helps make sure old accounts, shared credentials, and forgotten permissions do not quietly stay behind.

Protect Donor and Sensitive Information

Sensitive information often becomes harder to protect when it moves outside the system where it belongs. A report gets emailed to someone, a spreadsheet is downloaded for a board meeting, or a file ends up on a personal laptop because that was the quickest way to get the work done.

The practical fix is not to lock everything down so tightly that staff cannot do their jobs. It is to be clear about where sensitive information should live, who genuinely needs access, and how it can be shared safely when people are working across different teams or locations.

Those everyday decisions are a big part of protecting donor and payment data, because good security should make careful handling easier for staff, not add another layer of confusion.

Keep Devices and Email Secure

Most security problems do not start with anything dramatic. They start with an old laptop that has missed updates, a fake Microsoft 365 sign-in page, or an email that looks just convincing enough to click when someone is rushing between meetings.

Keeping devices updated and protected closes off many of those everyday gaps. Email deserves the same attention because it is often where staff receive password resets, invoices, shared files, and requests that appear to come from someone they trust.

Staff do not need to become experts at spotting every scam. They need a clear habit of checking unexpected requests, slowing down when something feels unusual, and knowing exactly who to contact when they are unsure.

Back Up Important Information

Even with good security in place, things can still go wrong. A file can be deleted by mistake, a laptop can fail, or ransomware can make important information unavailable when your team needs it most.

Reliable backups give you a way to recover without scrambling. They should run automatically, be checked regularly, and cover the systems your team actually depends on, not just the files someone remembered to copy months ago.

Being in the cloud does not automatically mean everything is backed up the way you expect. It is worth knowing what can be restored, how quickly, and who is responsible for getting your team working again.

What your IT Provider Should Be Helping With

Good cybersecurity support is not a collection of tools that were installed once and forgotten. Your IT provider should know what needs protecting, who has access to it, whether those protections are working, and what happens when something changes.

That means looking across your environment rather than treating email, laptops, accounts, and backups as separate problems. For example, adding multi-factor authentication is useful, but it does not solve much if former staff still have active accounts or administrators are using more access than they need. Backups matter too, but the real question is whether the information your charity depends on can actually be restored when needed.

Here are some of the areas your provider should be actively managing:

Area

  What Good Support Should Look Like

New accounts are set up with the right permissions, multi-factor authentication is enforced where appropriate, and access is changed or removed when someone changes roles or leaves.

Staff computers are monitored for missing updates, unsupported software, security problems, and devices that have quietly fallen outside normal management.

Suspicious messages, malicious attachments, and fake sign-in attempts are filtered where possible, while unusual activity can be investigated when staff report it.

Backups are monitored rather than simply assumed to be working, and there is a clear understanding of what can be restored, from where, and how long recovery is likely to take.

Your provider has a defined process for investigating suspicious activity, securing affected accounts or devices, preserving useful information, and helping your team understand what happened.

Security settings, accounts, devices, and risks are reviewed as your charity changes rather than remaining frozen in whatever configuration was set up years ago.

Your provider should also be able to spot the less obvious gaps that appear as organizations grow. A new fundraising platform may be introduced without anyone reviewing who has administrative access. A staff member may start working from a personal computer because their laptop is being repaired. A shared mailbox created for a short-term campaign may still be active two years later. None of these situations is unusual, but they are easy to miss when nobody is looking at the whole picture.

There should also be some way for leadership to understand the state of security without reading a technical report. If you ask whether all staff are using multi-factor authentication, whether any unsupported devices are still connected, or whether your backups have been successfully tested, your provider should be able to give you a clear answer. “We have security software installed” is not the same thing as knowing that your protections are working.

This becomes especially important when comparing managed IT support for your charity. Ask what the provider actually monitors, what gets reviewed regularly, what happens when they find a problem, and how they will keep you informed. Those answers tell you much more than a long list of security products ever will.

Cybersecurity Should Feel Manageable

Cybersecurity works best when it becomes part of the way your charity already operates. Clear access rules, protected devices, reliable backups, and a team that knows when to ask for help can prevent a lot of unnecessary disruption without turning security into everyone’s full-time job.

You also should not have to carry all of this yourself. If you are constantly wondering whether something has been missed, that is usually a sign that your IT support needs to be doing more of the watching, checking, and explaining for you.

You Shouldn’t Have to Become the IT Person too

The right IT partner should make technology feel easier to manage, not give you another set of things to worry about. That means clear answers, practical support, and people who understand that your systems are there to support your mission.

If that sounds different from the IT support you are used to, you can see more about how we work with mission-driven organizations.