Why are charities increasingly being attacked by cyber criminals? 

cybersecure charity using secured devices

More than a quarter of charities reported falling victim to cybercrime in the past year.

In 2025, 26% of charities experienced cybersecurity breaches, which is significant when compared to the 43% of total businesses that were affected. It is, therefore, vital to assess the growing risk of cyberattacks for the charity and nonprofit sector.

With limited awareness of both the risks and the best practices to help fight cybercrime, the number of charities attacked by cybercriminals every year will only continue to grow. So, why exactly are charities increasingly being attacked by cybercriminals and what steps can they take to protect themselves?

Main reasons for charity cybersecurity attacks

There are many reasons charities and nonprofit organisations are falling victim to cyberattacks, from unregulated device policies to supplier risks.

Use of personal devices

Where modern IT equipment can be lacking and office space is often minimal, personal devices including BYOD (bring your own device) policies are often prevalent throughout the charity sector.

Personal devices use can create an opportunity for a cyber-attack because these are often unregulated devices that might lack security, such as regular patching. The National Cyber Security Centre has stated that various older versions of software, no longer receive security updates or patches. This will leave devices using this software far more vulnerable to future attack. If charity workers are running older versions of Windows on their personal devices, for example, then the organisation’s data is more likely to be in jeopardy.

BYOD also means that cybersecurity updates and monitoring are far less effective and are even less likely to be carried out. Without regular organisation-wide updates and vital monitoring of devices, charities are far more likely to fall victim to cybersecurity breaches.

The use of personal devices in the workplace has been propelled by the pandemic. With even more charity workers having to work remotely and spending more time working outside of an office, often due to lack of office space and remote working policies, workers are using less secure networks. Less security makes these organisations an even easier target for cybercriminals.

worker using secure ipad for charity work

Assessing supplier risk

According to the latest Cyber Security Breaches Survey, just 9% of charities review the cybersecurity risks posed by their immediate suppliers and only 4% assess the wider supply chain.

If a charity allows third-party access to IT systems, for example, these suppliers are given an opportune moment to attack. By having the presumption that the immediate and wider supply chain are reliable and trustworthy, organisations are left exposed to cyberattacks.

Attitudes towards cybersecurity

Another reason charities are increasingly vulnerable to cyberattacks may be their attitudes towards cybersecurity itself. Whilst charities acknowledge the importance of cybersecurity, a majority report that cybersecurity remains a lower priority than operational activities.

In the latest findings, cybersecurity remained a high priority for 68% of charities, but this still leaves a significant number without strong governance focused on cyber risk.

With the increased use of personal devices, stay-at-home policy andand ongoing funding challenges, administering and monitoring cybersecurity measures has become increasingly difficult, or ignored altogether. With these additional challenges, the already strained resources for cybersecurity have presented charities with increasingly difficult circumstances to ensure they remain as protected as possible.

Cybersecurity responsibility

Ensuring that both organisations and employees are empowered by, and responsible for, their cybersecurity is vital. Only around 30% of charities have a board member or trustee with explicit responsibility for cybersecurity. Many organisations only update top level management, too, leaving many workers without the knowledge needed to protect them.

The more organisations can provide up-to-date knowledge and skills to their workforce on cybersecurity best practice, the greater their resilience to cybercrime. Cybersecurity training is a simple yet highly effective way to prepare charity workers to prevent, and to react to, cybercrime. Your ‘human firewall’, for example, is the biggest line of defence against cybercriminals and should be a high priority for any charity.

Cybersecurity in charity office (1)

Need better cybersecurity to protect your charity?

ramsac offer reliable, adaptable, and high-quality IT support services for charities and nonprofit organisations. Not only is a support service available to give you peace of mind, but ramsac also offer cybersecurity training to better equip workers with the essential knowledge to protect themselves and their organisations.

Don’t delay – contact us today to see how we can help protect your charity.

Related Posts

  • Most data issues are accidental. Here’s how to reduce the risk.

    Most data issues are accidental. Here’s how to reduce the risk.

    Cybersecurity

    Most data breaches aren’t caused by hackers, they’re caused by everyday behaviour. Discover how accidental risk builds in Microsoft 365 and what you can do to reduce it without [...]

    Read article

  • When Cyber Insurance Matters: Lessons from Co‑op, M&S, Harrods and JLR

    When Cyber Insurance Matters: Lessons from Co‑op, M&S, Harrods and JLR

    Cybersecurity

    Cyberattacks hit Coop, M&S, Harrods and JLR in 2025. This blog explores real-world lessons from these breaches and why cyber insurance is now essential for every organisation. [...]

    Read article

  • Celebrating Cybersecurity Awareness Month 2025

    Celebrating Cybersecurity Awareness Month 2025

    Cybersecurity

    October is Cybersecurity awareness month, follow us on LinkedIn for tips on how you can protect your organisation against Cybercrime. [...]

    Read article

  • 13 Phishing attacks blocked in minutes, here’s how we did it.

    13 Phishing attacks blocked in minutes, here’s how we did it.

    Cybersecurity

    Phishing attacks are increasing, but last week our team stopped 13 in their tracks. Read how secure+ protected our clients, what caused the spike, and the key lessons your [...]

    Read article

  • How to set up a secure password policy in Microsoft 365

    How to set up a secure password policy in Microsoft 365

    CybersecurityMicrosoft 365

    Discover the benefits of a robust Microsoft 365 password policy and how to set it up. Strengthen your organisation's cybersecurity and protect your data today. [...]

    Read article

  • 11 ways to stop cyber attacks in 2026

    11 ways to stop cyber attacks in 2026

    Cybersecurity

    Protect your data with our 11-step cybersecurity strategy. [...]

    Read article

Quiz yourself

Are you more cyber savvy than an 11 year old?

11-14 year olds get asked these questions in school. Could you get these right?