Cyber risk for charities: why they should review their cyber risk
Most charities do not think of themselves as a target for cybercrime. They are focused on supporting communities, delivering services, and managing limited resources rather than protecting commercial assets or shareholder value.
Unfortunately, cybercriminals see charities differently.
The cyber threat facing charities is far from theoretical. The UK Government's Cyber Security Breaches Survey found that 30% of charities identified a cyber security breach or attack in the previous 12 months, equivalent to around 61,000 organisations. The survey also identified phishing as the most common and disruptive form of attack affecting charities.
In many cases, attackers deliberately focus on smaller organisations because they believe security controls and fraud prevention processes may be less mature than those found in larger businesses. As charities become increasingly dependent on digital systems, cyber risk is no longer just an IT concern; it is a governance issue that should be understood and managed at leadership level.
Why are charities targeted by cyber criminals?
Cybercriminals are typically looking for financial gain, valuable personal information, or access to business systems. Charities often have all three.
Donor databases, online payment platforms, and cloud-based systems can all create opportunities for criminals. At the same time, many charitable organisations rely on volunteers, remote working, and third-party technology providers, increasing the number of potential entry points for attackers. A convincing email appearing to come from a trustee, supplier, or senior member of staff may be enough to trick someone into making a payment or disclosing sensitive information.
The National Cyber Security Centre (NCSC) has highlighted that charities are often attractive targets because they hold valuable personal data, handle financial transactions, and frequently operate with limited cyber security resources compared with larger organisations. The NCSC also notes that cyber incidents can have serious financial and reputational consequences for charities and the people they support.
AI is also making cybercrime more accessible, allowing criminals to create more convincing phishing emails and automate parts of their attacks. The issue is not necessarily that charities are less secure than other organisations. Rather, cybercriminals recognise that limited resources and busy teams can make social engineering attacks more effective.
What cyber risks do charities face?
One of the most significant threats is a data breach. This may include contact details, donation histories, payment information, and, in some cases, highly sensitive personal data. Beyond the immediate operational impact, a personal data breach can create legal obligations under UK data protection law. The Information Commissioner's Office (ICO) states that organisations must report certain personal data breaches within 72 hours of becoming aware of them and, where there is a high risk to individuals, notify the affected people without undue delay.
One common type of fraud takes place when criminals impersonate a trusted person by email, such as a trustee, supplier or senior member of staff. This is often referred to as Business Email Compromise. If staff act without verifying the request, funds may be transferred directly to criminals. For charities operating on tight budgets, even a modest financial loss can affect service delivery and future projects.
Phishing remains the most common cyber threat facing charities. According to the UK Government's Cyber Security Breaches Survey, 86% of charities that identified a cyber breach or attack experienced phishing attempts, underlining why email fraud continues to be one of the primary routes used by attackers.
Cyber risk also has a governance dimension. Trustees and directors are increasingly expected to demonstrate effective oversight of organisational risks. A cyber incident may prompt questions from regulators, donors, or stakeholders about the steps taken to protect data and manage threats. For this reason, cyber security should be viewed as a board-level responsibility rather than an operational issue.
Do charities need cyber insurance?
Many organisations assume that cyber incidents are already covered under their existing insurance arrangements. In reality, this is often not the case.
Traditional liability and commercial insurance policies frequently contain exclusions for cyber-related losses. As a result, charities may discover after an incident that they have little protection for the costs associated with a data breach, cyber attack, or certain forms of fraud.
Any charity that stores personal information, accepts online donations, processes electronic payments, or depends on digital systems should consider reviewing its cyber insurance arrangements. Understanding the scope of existing cover is an important part of effective risk management.
Zurich provides cyber insurance across a range of customer segments, including charities. Its cyber portfolio is mainly focused on large corporate and mid-market businesses and charities may be subject to a more detailed underwriting assessment, reflecting the cyber exposures and risk considerations often associated with the sector.
What does cyber insurance cover?
Cyber insurance is designed to help organisations deal with a wide range of cyber incidents, such as data breaches, hacking attacks, or ransomware events. It can provide support throughout the lifecycle of an incident, covering costs such as forensic investigations, legal advice, regulatory notifications, public relations support, system recovery, ransomware payments (where legally permitted), business interruption losses, and the restoration of damaged digital assets. Many policies also provide protection if customers, suppliers, or other third parties bring claims following a cyber incident, helping with legal costs, investigations, settlements, and other liabilities.
However, the level of protection varies significantly between insurers and policies. Some focus solely on losses suffered directly by the organisation, while others extend protection to claims brought by third parties affected by a breach. Policies may also include exclusions, conditions, or lower limits for certain types of losses. Reviewing coverage carefully before an incident occurs can help avoid unexpected gaps in protection.
In summary
The growing importance of cyber resilience is reflected in government research, which consistently shows that charities continue to experience cyber attacks and data breaches every year. As digital services, online fundraising and cloud-based systems become increasingly central to the sector, understanding cyber risks, improving cyber resilience and reviewing insurance arrangements should form part of every charity's broader risk management programme.
Sources
- National Cyber Security Centre (NCSC), Cyber Threat Report: UK Charity Sector (2023) (ncsc.gov.uk)
- Department for Science, Innovation and Technology, "Cyber security breaches survey 2025" (gov.uk)
- Department for Science, Innovation and Technology, "Cyber security breaches survey 2025 - pdf" (doc.ukdata...vice.ac.uk)
- Information Commissioner's Office (ICO), "Personal data breaches: a guide" (ico.org.uk)
- Information Commissioner's Office (ICO), "Personal data breaches" (ico.org.uk)
- National Cyber Security Centre, multi-factor authentication (MFA) guidance, "Not all types of MFA are created equal" (ncsc.gov.uk)
- National Cyber Security Centre, multi-factor authentication (MFA) guidance, "Multi-factor authentication for your corporate online services" (ncsc.gov.uk)
Sign up to our newsletter
Contact Zurich Municipal
Featured articles