Co. no. 00598511
Edwards Bros / Insights

Cyber Essentials for charities

What the certification covers, how trustees' and volunteers' own devices affect the scope, why funders are starting to ask for it — and the two answers that now fail an application outright.

Charities are asked about Cyber Essentials from three directions. A grant funder or commissioner includes it in due diligence. An insurer asks whether the charity holds it before quoting for cyber cover. Or a trustee, having read one more headline about a charity losing funds to invoice fraud, asks what the charity is actually doing about security — and the treasurer goes looking for a sensible answer.

Cyber Essentials is a government-backed certification covering five basic technical controls, assessed by questionnaire and reviewed by a qualified assessor. It does not require an IT department, and for a small charity most of the work is administrative: establishing what the charity has, who has access to it, and tightening a handful of settings. It is genuinely achievable — but the charity sector has its own recurring failure points, and they are worth knowing before anyone opens the questionnaire.

The five controls, briefly

  • Firewalls — every internet-connected device protected, including laptops used at home.
  • Secure configuration — default passwords changed, unused software and accounts removed, screens locked.
  • Security update management — operating systems and applications still supported by the vendor, and patched within the required window.
  • User access control — individual accounts for individual people, admin rights separated from daily use, leavers removed.
  • Malware protection — anti-malware in place, or app-store-only installation on phones and tablets.

The two automatic failures

Before anything else, know these. Under the current question set two answers fail the entire assessment on their own, regardless of how well everything else is answered.

MFA on the cloud services

For a typical charity the in-scope cloud services are email, the accounts package, online banking, the fundraising platform, the website CMS and wherever the governing documents and minutes live. Multi-factor authentication is now mandatory on every one of them, for all users rather than just administrators. Where a service offers it and it is not switched on, the assessment fails — and it makes no difference whether MFA is free, bundled or only available as a paid option. For a charity this is also the control most directly aimed at the payment fraud that actually hits the sector, so it is worth doing regardless of certification.

Patching within fourteen days

Security updates rated critical or high risk must be installed within fourteen days of release — across operating systems, applications and network equipment including the router. This is the second outright failure, and it is the one most likely to catch a charity where a laptop belonging to a volunteer sits unopened for weeks at a time.

Where charities get caught out

Everyone works on their own device

The typical small charity owns almost no equipment. The treasurer runs the accounts on a personal laptop, the secretary holds the mailing list on theirs, and trustees read charity email on personal phones. Every one of those devices that touches charity data is potentially in scope, and must meet the same standard as an office machine: supported operating system, separate user account, updates applied.

The way through is a deliberate scoping decision, made before the questionnaire is answered. If access on personal devices can be confined — charity-provided equipment for the roles that handle data, or access restricted to web services with nothing stored locally — the scope shrinks from "every trustee's phone" to a manageable handful of devices. Getting this decision right at the start is the single biggest determinant of how hard certification is. Note too that cloud services are now formally defined and cannot be excluded from scope at all. The same question arises for councils, and is covered in our guide for parish councils.

The shared mailbox with the shared password

One generic info@ login used by the chair, the secretary and two volunteers — with a password unchanged since the account was created — is close to universal, and it fails the access control requirement. Shared mailboxes are fine; shared credentials are not. Each person needs their own login with access to the shared mailbox, with multi-factor authentication switched on.

Nobody knows who still has access

Charities are long-lived and their people turn over: trustees retire, treasurers hand on, volunteers drift away. The most time-consuming part of certification is usually the inventory — which devices, which services, which former treasurer still technically has the banking login. That document is worth building even if the charity never certifies.

Is it worth it without a funder demanding it?

Two honest arguments in favour. Charities hold exactly the data that makes breaches painful — donor details, beneficiary records that are often sensitive, gift aid declarations — and the five controls are aimed at the most common ways that data is actually lost. And certification requirements travel: it is far less pressured to certify on the charity's own timetable than in the weeks before a funding application deadline. The argument against is cost, which for a small charity is a real trustee decision — the assessment fee is set by the certification body and scales with organisation size, and the remediation for most small charities is configuration time rather than new equipment. Trustees weighing it up can reasonably treat it as part of their duty to protect the charity's assets, of which its data and its bank balance are both examples.

Where to start

Before any questionnaire: list every device used for charity work including personal ones, every online service the charity uses, and every person with access to each. Then make the scoping decision about personal devices deliberately. Nine times out of ten, the inventory and the scoping call are the real work, and everything after them is straightforward.

Scheme requirements are reviewed periodically and question sets change between years — confirm the requirements applying to your own assessment before you begin.

PassCyber · Edwards Bros

Certification without the guesswork

We scope the assessment properly — including the personal-device question — tell you plainly what would fail and fix it, then take the charity through certification. No jargon, and nothing left for the treasurer to work out alone.

passcyber.co.uk · peter@edwardsbros.co.uk · 07540 288077

PassCyber is a trading name of Edwards Bros (Spaldwick) Ltd