Top 10 Cyber Fundamentals for Charities and Social Enterprises to Consider in 2026

For charities and social enterprises, cyber security is no longer just an IT issue. It is a governance issue, a reputational issue, and increasingly, a funding and insurance issue too. Trustees and directors are responsible for protecting the organisation’s people, data and services, especially where sensitive beneficiary, donor, employee or volunteer information is involved.

In 2026, the fundamentals matter more than ever. The government-backed Cyber Essentials scheme remains a widely recognised baseline for protecting organisations against common cyber threats, and recent updates place stronger emphasis on consistent controls, cloud services and multi-factor authentication where available. Official guidance for charities also makes clear that trustees remain responsible for taking reasonable steps to protect their organisation from cyber crime. For organisations built on community, excellence and integrity, good cyber hygiene is part of responsible leadership.

Here are ten practical steps every trustee and director should have in place:

10 Cyber Fundamentals for 2026

  1. No personal email addresses for trustees or directors.
    Every trustee, director and senior volunteer should have an organisation-managed email address. When governance conversations, sensitive files and third-party logins are tied to personal Gmail, Hotmail or other private accounts, oversight is weakened and risk increases. A company-controlled address supports continuity, accountability and secure access management. Point 2 explains why this matters beyond just security.

  2. Personal inboxes create GDPR and data governance exposure.
    Where personal data is stored in private inboxes, the organisation may struggle to meet its duties around access, deletion, retention and breach response. If a subject access request arrives, or if a personal account is compromised, the organisation could face significant data protection and reputational consequences.

  3. Know what happens to data when a trustee leaves.
    Too many organisations discover too late that key documents, board correspondence, donor records or supplier contacts were sitting in someone’s personal mailbox or device. Build a formal offboarding process that revokes access promptly, recovers organisation data, transfers ownership of accounts and confirms what information has been retained or deleted.

  4. Treat Cyber Essentials as the minimum baseline, not the finish line.
    Cyber Essentials remains an important benchmark for UK organisations of every size and is especially valuable for charities and social enterprises that need a practical starting point. It helps establish core controls around secure configuration, patching, malware protection, access control and boundary security. Completing Cyber Essentials also signals seriousness to funders, partners and insurers.

  5. Take third-party app risk seriously.
    Many breaches do not start with your core systems. They begin with a connected app, a marketing tool, a calendar plug-in or a file-sharing platform linked to a personal account. If a trustee’s personal Hotmail account is breached and that account has access to charity systems or third-party applications, the impact can spread quickly. Review connected apps regularly and remove anything unnecessary or unmanaged.

  6. Turn on multi-factor authentication everywhere it is available.
    Email, cloud file storage, CRM platforms, payroll systems, finance tools and administrator accounts should all be protected with multi-factor authentication. Passwords alone are no longer enough. In practice, MFA is now one of the simplest and most effective ways to reduce account compromise.

  7. Reduce bring-your-own-device risk.
    Charities and social enterprises often rely on personal phones, laptops and tablets, especially among trustees and volunteers. If this cannot be avoided, set minimum standards for device security, software updates, screen locks and antivirus protection. Be clear about what organisational data can and cannot be accessed on personal devices.

  8. Make patching and updates routine.
    Out-of-date software remains one of the easiest ways for attackers to get in. Trustees do not need to manage patching themselves, but they do need assurance that devices, systems, firewalls and cloud services are being updated promptly and consistently. Delayed patching can turn a manageable weakness into a serious incident.

  9. Control access using least privilege.
    Not everyone needs access to everything. Review user permissions for staff, volunteers, trustees and suppliers so people only have access to the systems and data they genuinely need. This limits the damage if an account is compromised and helps the organisation demonstrate good governance.

  10. Prepare for the day something goes wrong.
    Even well-run organisations can suffer cyber incidents. Have a simple incident response plan covering who to contact, how to isolate affected systems, how to communicate with stakeholders, and when to notify insurers, IT providers, regulators or law enforcement. Resilience is not just about prevention; it is also about response.

A Practical Trustee and Director Checklist

  • Check that every trustee and director uses an organisation-managed email address.

  • Confirm where personal data is stored and whether any of it sits in personal inboxes or devices.

  • Review trustee and volunteer offboarding procedures.

  • Ensure Cyber Essentials is current and supported by day-to-day good practice.

  • Audit third-party apps connected to email, CRM, finance and file-sharing systems.

  • Verify that multi-factor authentication is enabled wherever available.

  • Review who has administrator access and remove unnecessary privileges.

  • Ask when key systems were last patched and updated.

  • Check that backups exist and can be restored.

  • Make sure there is a documented incident response process.

Why This Matters

For organisations that exist to serve communities, cyber risk is never only a technical matter. It affects trust, continuity and the ability to deliver impact. Strong cyber fundamentals reflect the same values that underpin good governance: community, excellence and integrity.

As Accredited Cyber Insurance Brokers, we see first-hand how cyber incidents affect charities and social enterprises, not just financially, but operationally and reputationally too. Cyber liability insurance has an important role to play, but it works best alongside practical risk management. Having completed Cyber Essentials ourselves, we believe the best outcomes come when organisations combine proportionate controls, clear governance and the right specialist support

Next
Next

A Guide to Cyber Insurance in the UK