What Charity Trustees Need to Know About Cyber Security

Cyber threats aren’t just technical issues – they’re governance concerns. For charities, the stakes are particularly high: personal data, public trust, and essential services all depend on strong cyber resilience.

As a trustee, you are accountable for ensuring your charity operates responsibly. That includes understanding cyber risks and making sure appropriate policies, training, and oversight are in place. You don’t need to be a technical expert, but you do need to ask the right questions and ensure cyber security is on the board’s radar.

This article outlines what trustees need to know about cyber risks, what’s expected of them legally, and where to start – even if your resources are limited.

Why Cyber Security Falls Under Trustee Responsibility

Charity trustees have a legal and ethical duty to protect the people, assets, and reputation of their organisation. This includes safeguarding sensitive personal data, ensuring that services can continue without disruption, and complying with regulations like GDPR.

Cyber threats can lead to data breaches, financial loss, and reputational damage – all of which trustees are ultimately accountable for. The Charity Commission expects boards to take reasonable steps to manage cyber risk, supported by policy, training, and oversight.

Common Risks for Charities

While cyber attacks affect all sectors, charities face some unique challenges. Limited budgets, volunteer-driven operations, and older IT systems often make it harder to implement robust protections.

Phishing is one of the most common risks, where attackers trick staff or volunteers into clicking malicious links or sharing passwords. Ransomware can lock your files or systems until a payment is made. Other risks include third-party breaches (through suppliers), unauthorised access due to shared logins, and accidental data leaks through poor data handling practices.

For charities working with vulnerable people or holding sensitive data, the impact of a breach can be particularly serious.

A Real-World Example: Albyn Housing Society

In August 2024, Albyn Housing Society – one of Scotland’s largest housing charities – suffered a ransomware attack by a group known as RansomHub. Hackers stole 10?GB of sensitive data, including staff payroll and tenant records, and posted it on the dark web. The incident is under investigation by Police Scotland and the National Cyber Security Centre.

This breach disrupted services, exposed personal data, and significantly damaged the charity’s reputation. It demonstrates that cybercrime can hit any organisation, regardless of size or sector. Strong board-level oversight, an up-to-date incident response plan, and proactive governance could have reduced both the likelihood and severity of the attack.

What Are Trustees Expected to Do?

Trustees aren’t expected to manage day-to-day IT operations, but they are expected to govern cyber risk appropriately. That means cyber security should be a standing item at board meetings, supported by clear policies and staff training.

The board should have visibility of key risks, understand what data the organisation holds, and know how a cyber incident would be handled. Trustees should ensure someone in the organisation – internal or external – is responsible for overseeing security, and that staff understand their roles and responsibilities.

Guidance from the Charity Commission and the National Cyber Security Centre (NCSC) reinforces these expectations. Trustees are encouraged to take a proportionate approach based on the size, complexity, and activities of the charity.

Key Questions Trustees Should Be Asking

  • What are our biggest cyber risks?
  • Do we have a current risk register?
  • Who is responsible for cyber security?
  • Are staff and volunteers trained?
  • What’s our plan if something goes wrong?

These questions help trustees identify blind spots and ensure risks are not being left unmanaged.

Where to Start if You’re Not Sure

It’s common for trustees to feel uncertain about cyber security – particularly in smaller charities without dedicated IT teams. What matters most is taking that first step toward understanding your risk.

If your charity hasn’t yet assessed its cyber governance, a structured audit or health check can provide valuable clarity. At Securious, we offer governance-focused cyber audits designed specifically for charities. These reviews provide clear, non-technical summaries for trustees and prioritised technical actions to support your team.

Final Thoughts

Cyber security is no longer a ‘nice-to-have’ – it’s a fundamental part of good governance. Trustees have a duty to protect their charity, its people, and the public’s trust.

With the right oversight and support, you can ensure your organisation is resilient, responsible, and ready to respond to threats. Taking action now could prevent far more serious consequences down the line.