The government's Cyber Security Breaches Survey 2025/2026, published on 30 April 2026 from fieldwork run between August and December 2025, found that 28% of UK charities identified a cyber security breach or attack in the previous twelve months — around 57,000 organisations. 25% were hit by phishing, and among charities that suffered any breach, 69% named phishing as the most disruptive type. Impersonation attacks fell to 7%, and account takeovers to 1%. In other words: the exotic threats are rare and the boring one is nearly universal.
The same survey found only 30% of charities have a trustee with explicit responsibility for cyber security, and that senior-management priority has slipped — 60% called it a high priority, down from 68%, with the fall driven by lower-income charities (53%, down from 64%). That is the gap this article is about, and most of it closes with paperwork and two payment controls rather than technology.
The ICO fee: what a charity actually pays
UK data protection law applies to charities and CICs exactly as it does to companies, and most data controllers must pay an annual data protection fee to the Information Commissioner's Office. The fee has three tiers, set by the Data Protection (Charges and Information) (Amendment) Regulations 2025 and in force since 17 February 2025: tier 1 is £52 (10 or fewer staff, or turnover under £632,000), tier 2 is £78 (250 or fewer staff, or turnover under £36 million) and tier 3 is £3,763. Paying by direct debit takes £5 off any tier.
The sector-specific point: a registered charity that is liable for the fee pays the tier 1 fee of £52 regardless of its size or income. A charity with 40 staff and £3m of income that would sit in tier 2 as a business still pays £52 — £47 by direct debit.
There is also a narrow exemption for not-for-profit bodies. To use it you must be established as a not-for-profit, and process personal data only to establish or maintain membership or support, or to provide or administer activities for members and people in regular contact with you. Two things routinely destroy it without anyone noticing: CCTV installed for crime prevention takes you outside the exemption immediately, and so does processing that goes beyond members and regular contacts — a bought-in mailing list, or trading activity. If in doubt, £52 is cheaper than the argument.
A village hall trust with no staff, no CCTV, and records only of its members and regular volunteers meets the not-for-profit exemption and pays £0.
The same trust installs a camera at the entrance for crime prevention. The exemption is gone, and it now pays the tier 1 fee of £52, or £47 by direct debit.
A registered charity with 40 staff, £3.1m income and a donor database would be a tier 2 controller as an ordinary business at £78. As a charity it pays tier 1: £52, or £47 by direct debit. Failing to pay at all risks a penalty from the ICO of up to £4,350 — for a fee of fifty-two pounds.
The six things that need to be written down
None of these need a consultant. All of them will be asked for if something goes wrong, and increasingly by funders before anything goes wrong.
- A lawful basis for each type of processing. Delivering your services, administering a donor relationship, complying with a legal duty — different bases for different data. Write down which applies to what.
- A privacy notice that donors and beneficiaries can actually find, saying what you collect, why, how long you keep it, and how to complain.
- A record of what you hold and where. The spreadsheet on a trustee's home laptop counts. So does the WhatsApp group with beneficiary names in it.
- A retention schedule. Gift Aid declarations have their own retention needs; a list of donors who lapsed in 2014 has none. Old data is liability, not an asset.
- A route for individual rights requests. People can ask what you hold, ask for it to be corrected, and in many cases ask for deletion, and you generally have one month to respond.
- Extra care over special category data. Health, disability, religion, ethnicity, sexual orientation — the categories many charities hold about beneficiaries precisely because that is the need being met. These require a lawful basis and a separate Article 9 condition, and usually an appropriate policy document.
Fundraising has its own rulebook
Fundraising and marketing messages are governed by the Privacy and Electronic Communications Regulations as well as UK GDPR. Broadly: consent is needed to email or text individuals, every message must carry a working unsubscribe, and opt-outs must be honoured promptly and permanently. Use an email platform that manages consent and suppression lists properly rather than a spreadsheet and a BCC field, because the evidential burden sits with you. The Fundraising Regulator's Code of Fundraising Practice layers sector expectations on top, including on vulnerable donors.
The two controls that stop the attack you will actually get
Phishing accounted for 95% of the cyber crime experienced by charities in the 2025/2026 survey. The version aimed at charities almost always arrives through the finance function, and it does not need to break anything technical.
Monday. A part-time administrator receives an email that appears to come from a regular supplier the charity has paid for three years. It thanks her by name, references the last project, and says the company has changed bank. New sort code and account number attached, on headed paper.
Tuesday. A follow-up arrives, apparently from the chief executive, asking her to get it paid before the month end. The address is one character different from the real one.
Wednesday. A payment of £14,800 is made to the new account. Nothing is compromised, no malware is involved, no password is stolen. The controls simply were not there.
Friday. The genuine supplier chases the same invoice. The money is gone; recovery after 48 hours is unlikely.
Two controls stop this cold, and both are free. Verify any change of bank details by telephone, on the number you already hold — never the number in the email. And require dual authorisation on payments above a threshold your board sets, so no single person can move money alone. Our business banking guidance covers setting both up, and if a volunteer treasurer is handling the account, what is a treasurer's account covers the signatory arrangements that make dual authorisation possible in the first place.
Alongside those: two-factor authentication on banking, email, the donation platform and the CRM; unique passwords in a password manager rather than reused across services; backups that have been restored at least once to prove they work; and a five-minute standing item at induction telling every new staff member and volunteer that no genuine request will ever ask them to bypass the payment process.
If it happens, two clocks start
A personal data breach that poses a risk to people's rights and freedoms must be reported to the ICO within 72 hours of you becoming aware of it, and where the risk is high, the affected individuals must be told without undue delay. Knowing that in advance converts a panic into a process, because 72 hours includes the weekend.
The second clock is the Charity Commission's. A significant data breach or loss is expressly listed as a reportable serious incident, as are fraud, theft and cyber-crime. Responsibility for reporting rests with the trustees, though it can be delegated in practice to a member of staff or your professional advisers. Reporting promptly and showing what you did about it is consistently treated better than the Commission learning about it from somewhere else.
The theoretical maximum fine under UK GDPR is £17.5 million or 4% of global annual turnover, whichever is higher. For a small charity the realistic damage is different and worse: donors who stop giving, a funder who asks why the incident was not disclosed, and a public register entry that stays visible.
Cyber Essentials: worth it, and increasingly asked for
Cyber Essentials is the government-backed scheme covering five technical controls — firewalls, secure configuration, user access control, malware protection and patching. Certification is priced by organisation size and starts at £320 + VAT. UK organisations with turnover under £20 million that certify the whole organisation get cyber liability insurance included, with 24/7 incident response support. Cyber Essentials Plus adds independent technical testing of the same controls.
Only 16% of charities were even aware of the scheme in the 2025/2026 survey, rising to 40% among higher-income charities. That matters because some government and larger grant programmes now require it, so awareness is quietly becoming a funding qualifier rather than just a security question.
What to do this week
- Check the ICO register for your charity's name. If you are not on it and you do not clearly meet the not-for-profit exemption, register and pay the £52 — £47 by direct debit.
- Ask whether you have CCTV. If you do and you thought you were exempt, you are not.
- Write the bank-detail verification rule down in one sentence and tell whoever pays your invoices: any change of bank details is confirmed by phone on a number we already hold, no exceptions, no urgency overrides it.
- Turn on two-factor authentication for online banking, the finance email account and the donation platform. Budget twenty minutes.
- Put one named trustee on the board's cyber security responsibility. Only 30% of charities have done this, and it costs nothing.
- Find your oldest supporter list and delete what you have no reason to hold. Data you do not have cannot be breached.
How we help
We build the financial controls that stop the attack charities actually get — dual authorisation, verified supplier details, clean records and a payment process nobody can be socially engineered around — and we keep the compliance calendar, including the filing deadlines that follow a serious incident. It is part of our social-sector packages, from £39 + VAT a month. Get started.








