Cyber resilience for the third sector
Improve your ability to respond to evolving cyber threats
Get in touchA sector often with highly sensitive data and restricted training budgets, increasingly targeted by cybercriminals and primarily at risk from phishing, ransomware and supply-chain compromise.
Challenges
Charities play a vital role in society, offering crucial support to those in need. However, despite their noble missions, they are not immune to cyber-attacks. The consequences of such attacks can be devastating, not only for the organisation itself but also for the individuals and communities they serve.
According to a 2022 survey, 30% of UK charities reported experiencing a cyber-attack within the previous twelve months. Non-profit organisations encompass a wide range of entities with diverse needs, often operating with a high volume of part-time staff and limited budgets. Unlike businesses, charities are less likely to employ robust technical cybersecurity controls, as revealed by the DCMS Cyber Security Breaches Survey 2022.
The third sector has also suffered more than its fair share of third-party attacks – having their data lost by trusted partners, as demonstrated by incidents like the Blackbaud breach of 2020, which affected over 166 UK organisations and the Kokoro data breach in 2023 which lost data belonging to About Loyalty, a survey company working with numerous charities.
Many charities handle sensitive information related to individuals in desperate situations, making them prime targets for cybercriminals. A data breach compromising such sensitive data would be catastrophic, not only for the organisation’s reputation but also for the well-being of those it serves. As a regulated industry, it is vital that all charities know when and how they should report an incident to the Charities Commission.
Awareness of the cyber risk to the sector is improving. In the UK the NCSC has released advice and guidance on how charities can improve their cyber resilience and be better prepared in the event of a cyber-attack.
Despite their altruistic missions and limited budgets, charities must prioritise cybersecurity measures to safeguard both their operations and the people they support.
How Red Goat Can Help
Red Goat can help organisations retain public trust by improving your organisation’s understanding of cyber risk through staff and board training, cyber exercising and plan development.
Red Goat can improve your cyber resilience with:
Cyber exercising. We can assist you in delivering cyber exercises at board, gold and silver team level with scenarios utilising the latest threat intelligence and historical attacks on organisations in the third sector.
Awareness training. We have experience in creating awareness and resilience training for a number of different charitable sectors, including organisations providing support services for domestic abuse, housing and gender identity. Working with the Dot Project, we have developed a number of online and blended learning programmes on data security and handling a cyber incident. Having a charity- specific cyber awareness course will increase uniformity of training across a diverse workforce.
Board training. It is vital that board members understand their responsibilities with regards to cyber resilience and reporting. Red Goat can design and deliver concise face-to-face or virtual training to ensure your team understand the threats to the organisation and what they should do in the event of an incident.
Red Goat can also assist with implementation of NCSC guidance. You can learn more about the cyber risk to charities in the NCSC report here.
Get in touch to see how Red Goat can support your organisation on its cyber resilience journey.
Get in touch to discuss how we can help you achieve your security awareness or resilience goals.
By submitting your message and your phone number and/or email address, you are permitting us to contact you by these means in response to your enquiry or feedback. You also acknowledge that you have read our privacy terms and that you consent to our processing data in accordance with them.
Read our privacy policy here.








