Mads introducing the blog Cyber security for charities. "Even if your organisation doesn't sell products online, your website likely holds valuable information." 6 minute read.

October is Cyber Security Awareness Month, and while headlines often focus on big business data breaches, it’s not just large retailers or global corporations that need to stay alert. Charities, non-profits and membership organisations are just as vulnerable to cyber attacks — sometimes even more so, because attackers know that smaller organisations may have fewer resources to dedicate to online safety.

At Pooka & Co, we know how important it is for you to safeguard the trust of your members, donors and supporters. You may be asking yourself: “Are we safe from data breaches?” Unfortunately none of us can be 100% safe, but what matters is that we take action that demonstrates our commitment to protecting the personal data that we’re entrusted with.

This isn’t just a good idea for maintaining relationships with your stakeholders – should your organisation ever find itself the unfortunate victim of a serious data breach, make sure you’re able to show the Information Commissioner’s Office that you’ve taken your responsibilities seriously.

The reassuring news is that there are straightforward steps you can take to reduce the risk of this happening — and we’re here to help guide you through them.

Why Cyber Security Matters for Charities and Non-Profits

Even if your organisation doesn’t sell products online, your website likely holds valuable information: supporter records, donor data, event registrations, mailing lists or member details. Criminals see this as a treasure trove. A breach doesn’t just put personal data at risk — it can damage your reputation, harm relationships with donors, and in some cases, lead to legal consequences.

But don’t worry — protecting your website and your community’s data doesn’t have to be overwhelming.

The Online Safety Act: What You Need to Know

You may have heard about the UK’s Online Safety Act – some of which came into force in 2025. While much of the attention has focused on social media platforms, there are also important implications for charities, non-profits, and membership organisations. If you haven’t already done so, you should use the tool provided by Ofcom to check whether the regulations apply to you.

In short, the Act aims to make online spaces safer and more accountable. For organisations like yours, this means paying closer attention to:

  • Protecting personal data: Donor and member information must be stored securely and processed responsibly.
  • Preventing harm: You should assess the risk of harm to users of your service, especially if those users are children. You’ll need to implement robust processes for mitigating these risks, and the action you’ll take to combat harmful content.
  • Transparency: Set out exactly what measures you’re putting in place so that your users know how to report harmful content. As ever, you should also ensure clear communication with your supporters about how their data is used, stored and protected.

This doesn’t mean you need to become a legal expert overnight. It does mean, however, that every organisation should review their digital policies and website practices.

Simple Steps You Can Take Today

Even if you don’t have an IT department, there are easy checks you can do to boost your online safety:

  • Make sure all website administrators use strong passwords and two-factor authentication (2FA).
  • Take the time to check your organisation’s processes and policies are in line with the requirements set out in the UK GDPR.
  • Review key documents such as your privacy policy and ensure it clearly explains how and why supporter data is used.
  • Test your own internal file backups — it’s not enough to have them, you need to know you can restore them if the worst happens.
  • Run a simple data audit: who has access to supporter information, and do they still need it?
  • Train your staff and volunteers in basic digital hygiene: spotting phishing emails, not sharing passwords and reporting suspicious activity.

There are also free and low-cost tools available, such as password managers (to help staff store strong, unique passwords) and two-factor apps like Google Authenticator or Authy.

You Don’t Have to Do It Alone

Cyber security can feel daunting, but it doesn’t have to be. Pooka & Co’s Data Privacy services help charities, non-profits and membership organisations navigate the complexities of digital privacy and compliance. We want to work with you, to help ensure your practices not only meet legal requirements, but also build greater trust with your supporters.

Secure, Fully Managed Web Hosting

Pooka & Co work proactively alongside our trusted hosting partners to keep all of our client’s websites secure. Here are just some of the things we do behind the scenes for our clients:

  1. Regular Software Updates
    WordPress, plugins, themes, CiviCRM and its extensions are kept up-to-date and tested to close off any vulnerabilities before hackers can exploit them.
  2. Strong Password Enforcement
    We make sure that administrators use strong, unique passwords — one of the simplest but most effective safeguards.
  3. Two-Factor Authentication (2FA)
    Adding a second layer of login protection ensures that even if a password is stolen, your admin accounts stay secure.
  4. Brute Force Protection
    Hackers often try to “guess” passwords by bombarding a login page. We block these attempts before they can do any damage.
  5. Daily Security Scans
    Our systems check your website files every day for unexpected changes — an early warning system against tampering.
  6. Nightly Offsite Backups
    Every night, your website is backed up securely. If there’s ever a hack or an outage, we can restore it quickly and minimise disruption.
  7. 24/7 Uptime Monitoring
    We keep an eye on your site around the clock, so if it goes offline for any reason, we know right away.
  8. Domain Reputation Monitoring
    We monitor your domain’s standing online, making sure it’s not blacklisted or linked to suspicious activity.
  9. Firewalls at Multiple Levels
    Both at the server level and within WordPress itself, firewalls act as a protective barrier against malicious traffic and bad actors.

Taken together, these measures give you a strong defence — and peace of mind.

Final Thoughts

Cyber threats may be on the rise, but so are the tools and practices to stop them. With the right precautions — and the right partners — your charity, non-profit or membership organisation can stay safe online, keep supporter data secure and continue making a difference without unnecessary worry.This Cyber Security Month, why not take the opportunity to review your organisation’s data privacy and policies?

And if you’d like a friendly guide through the process, Pooka & Co are here to help.

The Pooka typing
The Pooka typing

Get In Touch

We’d love to hear what you’re up to. Please get in touch using hello@pooka.co or through the form linked below. Don’t be shy!