Cyber Essentials for charities
What the certification covers, how trustees' and volunteers' own devices affect the scope, why funders are starting to ask for it — and where small charities get caught out.
Charities are asked about Cyber Essentials from three directions. A grant funder or commissioner includes it in due diligence. An insurer asks whether the charity holds it before quoting for cyber cover. Or a trustee, having read one more headline about a charity losing funds to invoice fraud, asks what the charity is actually doing about security — and the treasurer goes looking for a sensible answer.
Cyber Essentials is a government-backed certification covering five basic technical controls, assessed by questionnaire and reviewed by a qualified assessor. It does not require an IT department, and for a small charity most of the work is administrative: establishing what the charity has, who has access to it, and tightening a handful of settings. It is genuinely achievable — but the charity sector has its own recurring failure points, and they are worth knowing before anyone opens the questionnaire.
The five controls, briefly
- Firewalls — every internet-connected device protected, including laptops used at home.
- Secure configuration — default passwords changed, unused software and accounts removed, screens locked.
- Security update management — operating systems and applications still supported by the vendor, and patched promptly.
- User access control — individual accounts for individual people, admin rights separated from daily use, leavers removed.
- Malware protection — anti-malware in place, or app-store-only installation on phones and tablets.
Where charities get caught out
Everyone works on their own device
The typical small charity owns almost no equipment. The treasurer runs the accounts on a personal laptop, the secretary holds the mailing list on theirs, and trustees read charity email on personal phones. Every one of those devices that touches charity data is potentially in scope, and must meet the same standard as an office machine: supported operating system, separate user account, updates applied.
The way through is a deliberate scoping decision, made before the questionnaire is answered. If access on personal devices can be confined — charity-provided equipment for the roles that handle data, or access restricted to web services with nothing stored locally — the scope shrinks from "every trustee's phone" to a manageable handful of devices. Getting this decision right at the start is the single biggest determinant of how hard certification is.
The shared mailbox with the shared password
One generic info@ login used by the chair, the secretary and two volunteers — with a password unchanged since the account was created — is close to universal, and it fails the access control requirement. Shared mailboxes are fine; shared credentials are not. Each person needs their own login with access to the shared mailbox, with multi-factor authentication switched on.
MFA on the cloud services
For a typical charity the in-scope cloud services are email, the accounts package, online banking, the fundraising platform, the website CMS and wherever the governing documents and minutes live. Multi-factor authentication is expected on all of them. Where it is available and not enabled, that alone can fail the assessment — and for a charity, MFA on email and banking is also the control most directly aimed at the payment fraud that actually hits the sector.
Nobody knows who still has access
Charities are long-lived and their people turn over: trustees retire, treasurers hand on, volunteers drift away. The most time-consuming part of certification is usually the inventory — which devices, which services, which former treasurer still technically has the banking login. That document is worth building even if the charity never certifies.
Is it worth it without a funder demanding it?
Two honest arguments in favour. Charities hold exactly the data that makes breaches painful — donor details, beneficiary records that are often sensitive, gift aid declarations — and the five controls are aimed at the most common ways that data is actually lost. And certification requirements travel: it is far less pressured to certify on the charity's own timetable than in the weeks before a funding application deadline. The argument against is cost, which for a small charity is a real trustee decision — the assessment fee is modest and set by the certification body, and the remediation for most small charities is configuration time rather than new equipment. Trustees weighing it up can reasonably treat it as part of their duty to protect the charity's assets, of which its data and its bank balance are both examples.
Where to start
Before any questionnaire: list every device used for charity work including personal ones, every online service the charity uses, and every person with access to each. Then make the scoping decision about personal devices deliberately. Nine times out of ten, the inventory and the scoping call are the real work, and everything after them is straightforward.
Certification without the guesswork
We scope the assessment properly — including the personal-device question — tell you plainly what would fail and fix it, then take the charity through certification. No jargon, and nothing left for the treasurer to work out alone.
peter@edwardsbros.co.uk · 07540 288077
Peter Edwards ACMA CGMA · chartered management accountant