A charity’s most valuable asset is often trust. It sits behind every donation, referral, volunteer application and confidential conversation. That is why cybersecurity policies charities use should do more than satisfy a funder’s checklist. They should help real people make safer decisions when they are busy, working remotely or simply trying to keep vital services running.

For many charities, a cyber incident does not begin with a dramatic technical failure. It starts with a convincing-looking invoice, a reused password, a lost mobile phone or a staff member sharing a spreadsheet with the wrong person. Clear, practical policies reduce the chance of those moments becoming a major disruption.

Why charities need policies that people will actually follow

Charities often hold sensitive information: donor details, bank information, safeguarding records, health information, case notes and staff records. They may also depend on a small team of employees, trustees and volunteers, all using a mixture of devices and working patterns. That makes good security a shared responsibility, not something that can sit solely with one technically minded colleague.

A policy gives the organisation a consistent answer to ordinary questions. Can volunteers use their personal laptops? What should someone do if they receive a suspicious email? Who is allowed to access the charity’s bank account? How quickly must a lost phone be reported?

Without those answers, people tend to improvise. That is understandable, particularly in a stretched organisation, but it can create gaps that fraudsters are very good at exploiting.

The right level of detail depends on your charity’s size, the type of information you handle and the systems you rely on. A small community group does not need a 60-page manual. A larger charity handling sensitive client information may need more formal controls. In both cases, policies should be plain English, proportionate and reviewed when the way you work changes.

The essential cybersecurity policies for charities

Rather than starting with a large policy pack, begin with the areas that prevent the most common and costly problems. These policies should be approved by trustees or senior leaders, but written for everyone who uses your systems.

Acceptable use and device policy

This sets expectations for charity-owned computers, phones, email accounts, internet access and personal devices used for work. It should explain that devices must be kept updated, protected by a screen lock and not shared with family members or friends.

If people use their own phones or laptops, be realistic. Banning personal devices outright may not be practical. Instead, state what is required: a passcode, supported software, antivirus where appropriate, and agreement that charity data is not saved in personal folders or unapproved apps. You may also decide that certain work, such as accessing safeguarding records or processing payments, can only be done on managed devices.

Password and account access policy

Passwords remain one of the easiest routes into a charity’s systems. The policy should require a unique, long password for every important account and make clear that passwords must never be shared by email, text message or sticky note.

Multi-factor authentication should be switched on wherever it is available, especially for email, cloud storage, finance systems and social media accounts. It adds a small extra step at sign-in, but it can stop a stolen password from becoming a full account takeover.

Access should match the person’s role. A volunteer organising an event may need access to a contact list, but not to payroll or financial records. When someone leaves, changes role or finishes a short-term placement, their access must be removed promptly. This is one of the simplest controls to put in place, yet it is often missed during a busy handover.

Email, phishing and payment verification policy

Phishing emails are no longer limited to obvious spelling mistakes and strange attachments. Criminals can copy a supplier’s branding, impersonate a chief executive or send a message that appears to come from a trusted supporter. Some will even use information from social media to make a request feel personal.

Your policy should tell staff and volunteers to pause before clicking links, opening unexpected attachments or giving out information. More importantly, it should set a clear process for checking unusual requests.

For payments or changes to bank details, require an independent check using a known telephone number or a separate trusted contact method. Do not rely on the number in the email itself. Two people should approve higher-value payments where possible. This can feel cautious, but it is far less disruptive than trying to recover money sent to a fraudster.

Data protection and secure sharing policy

Cybersecurity and data protection overlap, but they are not exactly the same thing. Your data protection policy explains how personal information is collected and used. Your security policy explains how that information is kept safe in practice.

Set out where charity data can be stored, who can access it and how it can be shared. Approved cloud storage with controlled permissions is usually safer than sending sensitive files back and forth by email. Staff should avoid downloading personal data onto desktops, USB sticks or personal cloud accounts unless there is a clear business reason and suitable protection.

Retention matters too. Holding information forever creates unnecessary risk. Agree how long different records are needed, then securely delete what is no longer required. For charities working with vulnerable people, seek appropriate data protection advice where legal duties or safeguarding requirements are involved.

Incident response and reporting policy

People are more likely to report a mistake quickly when they know they will be supported rather than blamed. That matters because the first few hours after a suspicious email, lost device or compromised account can make a huge difference.

Your incident policy should say who to contact, how to contact them and what information to provide. It should cover incidents such as lost equipment, suspected phishing, unusual account activity, accidental sharing of personal information and ransomware warnings.

Keep the instructions simple: report it immediately, do not try to hide it, do not continue using a device that may be infected, and do not delete evidence such as the suspicious email. A named internal contact and an IT support contact should be easy to find, including outside normal office hours if your services operate then.

Turning a policy into everyday practice

A policy stored in a shared folder and never discussed will not protect anyone. The useful work happens when it becomes part of onboarding, regular conversations and everyday habits.

Start by giving every new starter, trustee and regular volunteer a short introduction to the rules that apply to them. Cover how to spot suspicious emails, how to use multi-factor authentication, where files belong and how to report a concern. Repeat this training regularly, because phishing techniques change and people forget details when they are not using them every day.

It also helps to run short, relevant reminders rather than one long annual session. A five-minute discussion at a team meeting about invoice fraud can be more memorable than a dense presentation. Use examples that match your charity’s work: a fake donation email, a request for beneficiary information, or a message pretending to be from a trustee.

Technical controls should support the policy, not replace it. Managed updates, secure backups, antivirus protection, email filtering and properly configured cloud accounts all reduce risk. Regular backup testing is particularly important. A backup is only useful if you can restore the files you need when you need them.

Give trustees a clear role

Trustees do not need to become IT experts, but they do need enough oversight to ask sensible questions. Cybersecurity should appear on the risk register and be discussed at appropriate intervals, particularly after a significant system change or incident.

Useful questions include whether multi-factor authentication is in place, whether backups have been tested, whether access is removed when people leave, and whether staff have had recent awareness training. Trustees should also know who would lead the response if email, files or finance systems became unavailable.

If you are applying for contracts, grants or partnerships, you may be asked to show evidence of your controls. A clear policy set, staff training records and a recognised standard such as Cyber Essentials can help demonstrate that your charity takes security seriously. Certification is not a magic shield, but it can provide a useful framework for getting the basics right.

Keep security manageable

The best cybersecurity policy is not the strictest one on paper. It is the one your people understand, can follow and know how to use when something feels wrong. Start with the biggest risks, assign ownership and make improvements in sensible stages.

For charities across Bradford, Leeds and Halifax, local, patient IT support can make that process far less daunting. Bees Knees IT can help turn confusing security requirements into practical routines that protect your team and the people who rely on you. Give us a buzz, and take the sting out of IT before a small mistake becomes a difficult day.