IT support for charities has to solve a problem no commercial business has: the organisation is simultaneously tiny and heavily regulated, run by people who are not paid to think about technology, holding data about vulnerable people that outlives everybody currently in the building. A charity with four staff and sixty volunteers carries the same UK GDPR duties as a bank, the same reporting obligations to a statutory regulator, and none of the budget. IT support for charities is the discipline of holding that contradiction together.
This guide is written for UK charity chief executives, finance and operations managers, and trustees who have found the technology file on their desk. It is about what good IT support for charity organisations actually delivers: the Microsoft 365 nonprofit grant and what it quietly leaves out, the cybersecurity gap the government’s own survey measures every year, mail and identity, backup against retention clocks running from six months to seventy-five years, and the cost of each shape written out in pounds.
Two datasets underpin the numbers below and both are re-countable. The first is the Charity Commission’s full register extract dated 22 August 2026, which we downloaded and counted ourselves — 170,332 registered main charities in England and Wales. The second is the DSIT and Home Office Cyber Security Breaches Survey 2025/2026, published 30 April 2026, which interviewed 1,085 UK registered charities between August and December 2025. Everything read off a source was read on 22 August 2026. Where a figure is modelled rather than published it is labelled modelled and the arithmetic is shown.
The worked example throughout is a three-site UK charity with £2.4m annual income and 68 people holding accounts — 41 core staff across fundraising, finance, services and administration, and 27 frontline or sessional workers — plus roughly 310 volunteers who need no account at all. Sector guides for neighbouring industries answer the same questions for different estates: IT support for accountancy firms and IT support for dental practices. What we deliver day to day sits on our managed IT services page.
Table of contents
- Why IT Support for Charities Is Its Own Discipline
- The Register Says the Buyer of IT Support for Charities Is Tiny
- The Consumer Webmail Problem IT Support for Charities Has to Fix First
- Microsoft 365 for Charities: What IT Support for Charities Should Actually Buy
- What the Free Business Basic Grant Does Not Give You
- Cybersecurity for Charities: What the Breaches Survey Tells IT Support for Charities
- Phishing, Donation Fraud and Payment Diversion
- Identity and Access When Volunteers Outnumber Staff
- Backup, Retention and Three Clocks That Span Seventy-Five Years
- How Much Storage a Charity Actually Grows, Modelled
- Data Protection, Fundraising Data and the ICO Record
- Serious Incident Reporting to the Charity Commission
- Trustees, Governance and Who Actually Owns the Risk
- Cyber Essentials for Charities, Costed
- Devices, Volunteers and Bring-Your-Own-Everything
- Automation, AI and the Small Team Problem
- Shops, Hubs and Multi-Site IT Support for Charities
- What to Ask a Provider of IT Support for Charities
- Costing IT Support for Charities
- A 90-Day Plan for IT Support for Charities
- References and Further Reading
Why IT Support for Charities Is Its Own Discipline
A commercial provider will look at a charity and see a small business: a handful of laptops, a mail tenant, a website, a finance package. That reading is wrong in three specific ways, and every one of them changes the design. IT support for charities that starts from the small-business template gets the licensing wrong, the retention wrong and the identity model wrong, in that order.
IT support for charities serves two populations, not one
Every commercial organisation has staff. A charity has staff and volunteers, and the volunteer population is usually larger, more transient and less supervised. Volunteers turn over constantly, arrive without HR onboarding, often use their own devices, and frequently need access to exactly one system for exactly one shift. Designing IT support for charity teams around a staff-shaped identity model is the single most common structural mistake.
The money has strings attached and the strings reach the IT budget
Restricted funds cannot be spent on general overheads, grant funders ask what proportion of income reaches charitable activity, and technology sits awkwardly in both conversations. That pressure produces the sector’s characteristic posture: nothing is replaced until it fails. Good IT support for charities works with the constraint rather than pretending it away, which mostly means favouring operating expenditure, grant-funded licensing and long device lifecycles.
IT support for charities answers to a regulator with real teeth
The Charity Commission registers the charity, receives its annual return and takes reports of serious incidents. The Information Commissioner’s Office regulates the data. HMRC regulates Gift Aid. For a charity working with children or adults at risk, a safeguarding regulator is watching too. IT support for charities is largely the work of making those four evidence trails producible without asking a two-person team to assemble them by hand.
The people who sign off the risk of IT support for charities are volunteers
Trustees are unpaid, usually part-time, and legally responsible. They carry the duty of care that makes cybersecurity their problem, and most have no technical background. That is why IT support for charity boards has to produce plain-language reporting rather than dashboards, and why a provider who cannot explain a risk to a retired headteacher in one paragraph is the wrong provider.
Downtime does not cost revenue here, it costs delivery
When a commercial firm goes offline it loses sales. When a charity goes offline a food bank cannot check a referral, a helpline cannot see a caller’s history, a night shelter cannot confirm a bed. The loss never appears on a spreadsheet, which makes it much easier to underinvest in preventing. IT support for charities has to translate delivery risk into a language a finance committee will actually fund.
Nobody in the building owns the IT support for charities decision
In a commercial firm of this size there is usually an owner-manager who decides. In a charity the decision is distributed across a chief executive, a finance lead, an operations manager and a board, none of whom have technology in their job title. IT support for charities that does not supply a clear recommendation and a written rationale will simply watch the decision fail to happen.
The Register Says the Buyer of IT Support for Charities Is Tiny
Before designing anything it is worth knowing who the buyer actually is. We downloaded the Charity Commission’s full register extract dated 22 August 2026 and counted it: 170,332 registered main charities in England and Wales, of which 161,695 carry a latest income figure. The distribution is more skewed than almost anyone expects, and it explains most of what IT support for charities has to be.
Nine in ten buyers of IT support for charities sit under half a million pounds
Of the 161,695 charities with an income figure on the register, 146,478 — 90.59% — report under £500,000 a year. Between them they hold £8.59bn, which is 7.99% of the money IT support for charities is being funded out of, from a sector’s £107.45bn. The typical buyer of IT support for charities is therefore not a household name with a marketing department; it is an organisation whose entire annual income would not cover a mid-sized firm’s payroll.
Three-quarters are under one hundred thousand pounds
Push the line lower and it gets starker. 118,607 charities — 73.35% — report under £100,000 a year, and together they hold £2.35bn, or 2.18% of sector income. IT support for charities at that scale has to be genuinely cheap before it can be real. 59,284 of them report under £10,000. For that segment IT support for charities is not a line item to be optimised; it is a question of whether anybody is looking after the technology at all.
The income sits almost entirely at the top
At the other end, 2,933 charities report over £5m. That is 1.81% of the register and they hold £80.71bn — 75.12% of all sector income. Add the £1m to £5m band and 9,261 charities, 5.73% of the register, account for 88.07% of the money. IT support for charities is therefore sold into two markets wearing one name. IT support for charity clients therefore splits cleanly into two products that share almost no design assumptions.
What the split means for how IT support for charities is bought
Below £500k the charity has no internal IT function and needs a fully managed service that includes the thinking. Above £1m there is usually one internal person, sometimes a small team, and what is needed is co-managed cover: out-of-hours, specialist skills, project delivery and escalation. Selling the first shape to the second organisation, or the second shape to the first, is the most common procurement error in the sector.
Legal form changes what IT support for charities has to file
The register shows 39,712 charitable incorporated organisations, 23.31% of the total, and 31,366 charities carrying a company registration number, 18.41%. A charitable company files with Companies House as well as the Commission, which adds a second set of deadlines and a second record-retention regime. IT support for charities has to know which form it is dealing with before it designs the document estate.
Gift Aid and property widen the record-keeping problem for IT support for charities
63,520 registered charities — 37.29% — are flagged on the register as claiming Gift Aid, and 56,095 — 32.93% — as holding land. Both flags import long-lived records: donor declarations that have to survive HMRC scrutiny, and title and lease documents that outlive every member of staff. Neither is a mail problem, and both land squarely inside the remit of IT support for charities.
The Consumer Webmail Problem IT Support for Charities Has to Fix First
The same register download carries a published contact email address for most charities, and counting those addresses produces the most useful single diagnostic in this article. It is a direct, national, first-party measurement of how far the sector sits from a managed mail platform, and it is worse than the sector’s own self-reporting suggests.
More than a third of registered charities publish a consumer webmail address
Of the 170,332 registered main charities, 148,201 — 87.01% — publish a contact email address. Of those, 63,091 use a free consumer webmail domain: Gmail, Hotmail, Outlook.com, Yahoo, AOL, BT Internet, iCloud and their relatives. That is 37.04% of the whole register and 42.57% of every charity publishing an address at all. The single largest domain is gmail.com, with 30,316 charities. It is the clearest public measure of where IT support for charities has not yet arrived.
Why this is an IT support for charities problem and not a cosmetic one
A consumer mailbox is a personal account. It has no tenant administrator, no audit log the organisation can compel, no legal hold, no data loss prevention, no conditional access and no way to recover the account when the volunteer who created it stops answering the phone. Every message in it belongs to an individual rather than to the charity, which is a governance failure long before it becomes a security one. IT support for charities has to fix ownership before it fixes filtering.
It is also a domain authentication failure IT support for charities has to close
A charity sending fundraising mail from a gmail.com address cannot publish SPF, DKIM or DMARC records that say anything meaningful about its own identity, because it does not control the sending domain. That makes the charity trivially impersonable: an attacker registers a similar consumer address and the recipient has no technical means of telling the two apart. Fixing this is the cheapest high-impact task in IT support for charities.
The pattern is almost perfectly graded by income
Split the same measurement by income band and the gradient is extraordinary. Among charities under £10k that publish an address, 54.42% use consumer webmail. In the £10k to £100k band it is 48.90%, then 25.97%, then 9.25%, then 3.67%, and among charities over £5m it is 0.57% — sixteen organisations out of 2,791. A charity under £10k is 94.93 times more likely to be running on consumer webmail than one over £5m. That gradient is the demand curve for IT support for charities drawn straight from public data.
The website numbers tell exactly the same story
60.11% of registered charities publish a website. Split by band it runs 42.29%, 62.46%, 80.61%, 85.81%, 88.76% and 94.37%. So the smallest charities are not only unlikely to hold organisational mail, they are also least likely to have any controlled online presence at all — which removes the last independent channel a donor could use to verify a payment request before sending money. Closing that gap is early work for IT support for charities.
A shared mailbox is not a shared password, and IT support for charities must separate them
The pattern underneath the consumer-webmail number is almost always one address whose password is known to several people and has been known to several more. There is no way to attribute an action, no way to revoke one person’s access, and no way to answer a regulator asking who read a record. Named accounts with a shared mailbox delegated to them solve the same operational problem correctly, and IT support for charities should make the swap in the first month.
What IT support for charities should do about it in week one
The migration is small, cheap and almost entirely unglamorous: register or reclaim a domain, stand up a Microsoft 365 tenant on the nonprofit grant, create named accounts, publish SPF, DKIM and DMARC, import the historic mail, then forward from the old consumer account for ninety days before closing it. That sequence is a fortnight of part-time work and it retires an entire class of risk permanently.
Microsoft 365 for Charities: What IT Support for Charities Should Actually Buy
Microsoft’s nonprofit programme is the largest single subsidy available to a UK charity’s technology budget, and it is routinely either unclaimed or claimed badly. Getting the licensing shape right is worth more to a small charity than any other decision IT support for charities will make in the first year.
The grant IT support for charities should claim is Business Basic, free to 300 users
Microsoft publishes a grant of Microsoft 365 Business Basic at no cost for up to 300 users for eligible nonprofits. Business Basic gives web and mobile Office apps, Exchange Online mail, Teams, SharePoint and OneDrive. At Microsoft’s published UK list price of £5.40 per user per month on an annual commitment excluding VAT, a fully used 300-seat grant is worth £19,440 a year to a charity that claims it, and claiming it is the first commercial job of IT support for charities.
The discount puts Business Premium at roughly a sixth of list
Microsoft publishes nonprofit Business Premium at $5.50 per user per month against a commercial list price of $32.00, a discount of 82.81%. Applied to Microsoft’s published UK Business Premium list price of £24.60, that implies a modelled UK nonprofit rate of £4.23 per user per month. Third-party UK resellers quote around £4.20, which is consistent with the modelled figure and suggests the ratio holds across currencies. IT support for charities should quote both numbers and show the working.
The three-way licensing comparison IT support for charities should produce
Our 68-account charity can be licensed three ways. All 68 on commercial Business Premium costs 68 × £24.60 × 12 = £20,073.60 a year. All 68 on nonprofit Business Premium costs 68 × £4.23 × 12 = £3,451.68, which is 17.19% of the commercial figure. Putting the 41 core staff on nonprofit Premium and the 27 frontline workers on the free Basic grant costs £2,081.16, or 10.37% of commercial. Those three lines are the whole licensing conversation IT support for charities needs to have.
The number that should decide it
The gap between full nonprofit Premium and the tiered mix is £1,370.52 a year. That is what it costs to give the 27 frontline and sessional workers Defender for Office 365, Intune device management and Entra ID P1 conditional access instead of leaving them on bare Basic. Divided by 27 people it is £50.76 each per year, or £4.23 a month. Almost no charity board, shown that arithmetic plainly, chooses to save it, which is why IT support for charities should always present it as a per-person figure.
Eligibility is a paperwork exercise IT support for charities should run first
Microsoft validates nonprofit status through a registration process that for a UK charity generally means supplying the registered charity number and confirming the organisation’s purpose. Political organisations, government bodies, individual schools and healthcare providers delivering non-charitable services are excluded. IT support for charities should run this validation before designing anything, because the answer changes the entire cost model underneath the design that IT support for charities is about to propose.
Do not forget the rest of the nonprofit catalogue
The same programme discounts Microsoft’s security and compliance add-ons: the Defender suite and the Purview suite are each published at $4 per user per month for nonprofits, $6 for both together, with the Entra suite at $4.80 and Intune standalone at $4. Enterprise plans are discounted too, with E3 at $9.75 and E5 at $24. For a charity above 300 users those enterprise rates, not the grant, are the relevant number, and IT support for charities should model them before the tenant is built.
Watch the renewal, because IT support for charities has to reprice this every year
Nonprofit pricing is expressed as a discount against commercial list, so when Microsoft raises list prices the nonprofit rate rises in step. A charity that budgeted on last year’s figure and never revisited it will find the assumption quietly broken at renewal. Put the licence review in the same annual cycle as the accounts, and make IT support for charities produce the comparison rather than the finance officer, because IT support for charities is the party holding the price list.
| Option | Who gets what | Annual cost, 68 accounts | Share of commercial | Accounts with no Defender, Intune or conditional access |
|---|---|---|---|---|
| Commercial Business Premium | All 68 at UK list £24.60 | £20,073.60 | 100.00% | 0 of 68 |
| Nonprofit Business Premium | All 68 at modelled £4.23 | £3,451.68 | 17.19% | 0 of 68 |
| Tiered: Premium plus Basic grant | 41 core on Premium, 27 frontline on the free grant | £2,081.16 | 10.37% | 27 of 68 |
| Grant only | All 68 on free Business Basic | £0.00 | 0.00% | 68 of 68 |
What the Free Business Basic Grant Does Not Give You
The Business Basic grant is genuinely generous and it is also the most misread product in the sector. Charities treat it as “we have Microsoft 365, so we are covered”, and the gap between that belief and the actual licence entitlement is where most incidents live.
No installed desktop applications
Business Basic entitles web and mobile Office apps only. Users who need the full installed Word, Excel, Outlook or PowerPoint on a laptop are not licensed under the grant. For a finance officer running complex workbooks, or a fundraiser working offline on a train, that is a real working constraint which has to be solved with a paid licence rather than quietly ignored by IT support for charities.
No Microsoft Defender for Office 365
Advanced phishing protection, safe links, safe attachments and automated investigation come with Business Premium, not with Basic. Given that the Cyber Security Breaches Survey found phishing to be the most prevalent breach type and it hit 25% of charities, running an entire charity on Basic means running it without the one control aimed squarely at the one threat, and no amount of IT support for charities elsewhere compensates for that.
No Intune and therefore no device management
Business Basic does not license Intune, so there is no way to enforce encryption, screen locks, compliance policies or selective wipe on a laptop or phone. For an organisation whose devices go home with volunteers, that is the difference between a lost laptop being an inconvenience and a lost laptop being a reportable personal data breach with a seventy-two-hour clock attached, which is why IT support for charities treats device licensing as a compliance decision.
No Entra ID P1, so no conditional access
Conditional access — the rules deciding who can sign in, from where, on what device, with what second factor — sits in Entra ID P1, which arrives with Business Premium. Without it a charity can enable multi-factor authentication but cannot enforce it consistently, cannot block legacy authentication cleanly and cannot restrict access by device state. That is most of the value of modern identity, missing, and IT support for charities should price the upgrade rather than explain the absence.
No Purview retention or data loss prevention
Basic carries no retention labels, no litigation hold and no data loss prevention policies. For a charity facing a seventy-five-year safeguarding retention expectation alongside a six-year statutory accounting minimum, the absence of a retention engine means every retention decision is a manual one — which is precisely how records get destroyed by accident while IT support for charities is looking somewhere else.
The honest recommendation IT support for charities should make
Use the grant for accounts that genuinely need only mail and Teams: shop volunteers, sessional workers, trustees who sign in once a month. Put everyone who touches donor data, finance, case records or administrative privilege on Business Premium at the nonprofit rate. The split is a per-person judgement rather than an organisation-wide one, and it should be reviewed at every renewal by whoever provides IT support for charities.
| Capability | Business Basic (free grant) | Business Premium (nonprofit rate) | Why a charity cares |
|---|---|---|---|
| Installed desktop Office apps | No, web and mobile only | Yes | Finance workbooks and offline working |
| Defender for Office 365 | No | Yes | Phishing is the top breach type for charities |
| Intune device management | No | Yes | Encryption and remote wipe on volunteer devices |
| Entra ID P1 conditional access | No | Yes | Enforcing multi-factor authentication properly |
| Purview retention labels and DLP | No | Yes | Six-year accounts and long safeguarding holds |
| Exchange, Teams, SharePoint, OneDrive | Yes | Yes | The baseline both plans share |
| Cost per user per month | £0.00 up to 300 users | £4.23 modelled | The whole decision in one line |
Cybersecurity for Charities: What the Breaches Survey Tells IT Support for Charities
The Cyber Security Breaches Survey is the only annual, statistically weighted measurement of UK charity cyber posture, and its 2025/2026 edition interviewed 1,085 registered charities. Read carelessly it looks like good news for the sector. Read properly it says something much less comfortable, and every provider of IT support for charities should be able to explain the difference.
Charities report fewer breaches than businesses, and IT support for charities should not relax
28% of charities identified a breach or attack in the previous twelve months against 43% of businesses. That gap is usually presented as charities being safer. The far more likely explanation is detection: with 45% of charities running network firewalls against 74% of businesses, and 17% running a VPN against 36%, there is simply less instrumentation in place to notice an incident happening.
When a charity is hit, it is more likely to be a crime
The survey’s own cross-tabulation settles the argument. Among organisations identifying any breach or attack, 44% of businesses and 49% of charities ended up victims of cyber crime as defined by the Computer Misuse Act. So a charity identifies fewer incidents but a larger share of what it does identify is criminal. That is the signature of under-detection, not of safety.
Phishing is the threat IT support for charities has to design against
Phishing was experienced by 25% of charities and named the most disruptive breach type by 69% of the organisations that suffered one. Yet only 36% of charities have an agreed process for staff to follow with a fraudulent email, against 58% of businesses. The control most obviously matched to the dominant threat is the one with the largest behavioural gap, and it costs almost nothing to close.
The basic technical controls all sit well behind business adoption
Across thirteen controls the survey measures, the average charity-to-business gap is 16.69 percentage points. The widest are organisation-owned device restrictions at 31 points, firewalls at 29 and the fraudulent-email process at 22. The narrowest are rules for storing personal data at 4 points and restricted admin rights at 8. Closing the widest three is the highest-value work available to IT support for charities in any first year.
Cyber Essentials coverage is half the business rate, and IT support for charities starts there
13% of charities reported having the technical controls associated with Cyber Essentials in all five areas, against 24% of businesses. Prompted awareness of the scheme itself was 16% among charities and 17% among businesses, so the gap is not one of awareness. It is a gap of implementation, and implementation is precisely what IT support for charities is for.
Charities are more likely to hold unprotected personal data
22% of charities said they held personal data not protected by techniques such as anonymisation or encryption, against 14% of businesses. Read alongside the sector’s case files, safeguarding notes and donor records, that is the most alarming single line in the survey — a population holding more sensitive data than average, protecting it less than average.
Attention is going the wrong way, which makes IT support for charities harder to fund
60% of charities said cybersecurity was a high priority for their senior management, down from 68% the year before, a decline the survey attributes to lower-income charities. Board-level responsibility sat at 30% of charities against 31% of businesses. Staff training and awareness reached only 17% of charities. Priority is falling in the population least able to absorb an incident, which changes how IT support for charities has to make its case.
Insurance and incident planning are both thin
35% of charities reported being insured against cyber risk in some way, against 47% of businesses, and only 19% had a formal incident response plan against 25%. The median perceived cost of the most disruptive breach was £0 for both populations, with charities’ interquartile range running £0 to £80. That reported cost is what keeps the priority number falling, and it is the hardest objection IT support for charities has to answer.
| Rule or control | Businesses | Charities | Gap, percentage points |
|---|---|---|---|
| Only allowing access via organisation-owned devices | 66% | 35% | 31 |
| Firewalls covering the network and individual devices | 74% | 45% | 29 |
| An agreed process for fraudulent emails or websites | 58% | 36% | 22 |
| Security controls on organisation-owned devices | 61% | 42% | 19 |
| A VPN for staff connecting remotely | 36% | 17% | 19 |
| Up-to-date malware protection | 81% | 63% | 18 |
| A password policy requiring strong passwords | 74% | 56% | 18 |
| Backing up data securely via a cloud service | 74% | 57% | 17 |
| Separate Wi-Fi networks for staff and visitors | 38% | 25% | 13 |
| Backing up data securely via other means | 48% | 38% | 10 |
| Any two-factor authentication for networks or applications | 47% | 38% | 9 |
| Restricting IT admin and access rights to specific users | 73% | 65% | 8 |
| Rules for storing and moving personal data securely | 51% | 47% | 4 |
Phishing, Donation Fraud and Payment Diversion
Charities are unusually exposed to fraud that arrives by email, for reasons that have nothing to do with how careful the staff are. The organisation publishes its cause, its beneficiaries, its trustees and often its finance contact. It receives unsolicited money from strangers as a matter of routine. And it is culturally disposed to say yes.
Why a charity is a better phishing target than a comparable business
An attacker researching a commercial firm has to guess at the org chart. A charity publishes its trustees on the register, its senior team on its website and its campaigns on social media. The tone of a plausible approach — urgent, emotive, on-mission — is handed to the attacker in the charity’s own words. IT support for charities has to assume the reconnaissance against its client is already complete.
Donation fraud runs in both directions
Fraudulent donations are used to test stolen card numbers, because a charity donation form is a low-friction, low-scrutiny transaction. The charity absorbs the chargebacks and the processor’s fees, and can find its merchant account flagged. Rate limiting, a minimum donation value, address verification and a fraud-scoring layer on the donation form are all cheap and all routinely missing from the scope IT support for charities is given.
Payment diversion is the expensive one IT support for charities must prevent
The classic attack is an email, apparently from a supplier or a senior colleague, changing bank details for a legitimate payment. The Charity Commission’s internal financial controls guidance is explicit that a charity needs one person to create a payment request and a different person to authorise it, and that changes to the bank mandate need dual authorisation with a trustee as the second approver, and IT support for charities should check that procedure exists before quoting anything.
The control that actually works is a phone call
Every documented payment-diversion loss shares one feature: nobody rang the supplier back on a number they already held. Written into the finance procedure, verified callback on any change of bank details is free, takes two minutes and defeats the entire attack class. IT support for charities should insist on seeing that written procedure before selling anything more technical.
Technical controls IT support for charities can turn on this week
Publish SPF, DKIM and a DMARC policy at enforcement so nobody can send as your domain. Turn on external-sender warning banners. Block auto-forwarding to external addresses. Enable impersonation protection for the chief executive, the finance lead and the trustees. On Business Premium these are configuration, not purchases, which makes them the cheapest security wins IT support for charities can deliver in a week.
Train against the specific scenario, not the generic one
Generic phishing awareness training tells people to look for spelling mistakes. Charity-specific training should rehearse the three scenarios that actually happen: the supplier changing bank details, the chief executive urgently needing a gift card purchase, and the “grant funder” requesting bank confirmation. Ten minutes on three concrete scenarios beats an hour of general advice.
Record what happened, because the regulator will ask
If money is lost, the Charity Commission expects a serious incident report and will want to know what controls existed. A written incident log with timestamps, the emails preserved rather than deleted, and a note of who approved what is the difference between a regulator seeing a well-run charity that was attacked and a regulator seeing a poorly run charity. IT support for charities should make that log easy to keep.
Identity and Access When Volunteers Outnumber Staff
Identity is where charity IT differs most sharply from business IT, and it is where generic providers most reliably get it wrong. The design has to hold a population that is larger than the payroll, changes constantly, and cannot be managed through an HR system that does not cover them.
IT support for charities needs a joiners and leavers process that includes volunteers
Most charities have an offboarding process for staff and nothing at all for volunteers. The result is accounts that stay live for years after the person stopped attending. A single shared register of everyone with access — staff, volunteers, trustees, contractors — reviewed quarterly against reality is the foundation, and it is a spreadsheet before it is ever a system that IT support for charities automates.
Named accounts, always, even for one shift
The temptation to hand a volunteer the shared login is enormous and it should be resisted every time. Named accounts cost nothing under the Business Basic grant, and they are the only way to answer the questions that follow an incident: who opened this record, who sent this message, whose access do we revoke. Shared credentials make every subsequent investigation impossible.
Multi-factor authentication has to be enforced by IT support for charities, not offered
38% of charities report any two-factor authentication, against 47% of businesses. Offering it produces adoption in the tens of percent; enforcing it through conditional access produces adoption at one hundred. For volunteers without work phones, authenticator apps on personal devices, hardware keys for the finance team and temporary access passes for onboarding all solve the practical objections IT support for charities will hear from a volunteer coordinator.
Least privilege matters more when the population is transient
A volunteer sorting donations in a shop needs the rota and nothing else. A helpline volunteer needs today’s cases and nothing historic. Role-based groups, assigned at onboarding and inherited by the systems behind them, turn access control into a one-decision problem instead of a per-system one. This is ordinary access management, applied by IT support for charities to a population most tools were never designed for.
Trustees are the most over-privileged group IT support for charities will meet
Trustees frequently hold administrative rights in the finance system, the donor database and sometimes the Microsoft 365 tenant, because somebody once needed them to and nobody removed it. They are also the group least likely to have a managed device or enforced multi-factor authentication. Trustee accounts should be read-only by default, with elevation on request and a written record of each elevation held by IT support for charities.
Break-glass accounts and the succession problem
A charity where one person holds every administrative credential is one resignation away from a crisis, and this happens constantly in a sector with long-serving volunteers. Two emergency administrator accounts with credentials held in sealed form by the chair and the treasurer, tested annually, is the standard answer, and IT support for charities can set it up in an afternoon.
Offboarding is a data question for IT support for charities as well as an access question
When a volunteer leaves, the account is disabled but the data they created stays. Mail should be converted to a shared mailbox, OneDrive contents transferred to a named owner, and any personal-device access wiped selectively. Doing this at the moment of departure rather than at the annual review is the difference between a clean estate and an archaeological one, and it is a core duty of IT support for charities.
Backup, Retention and Three Clocks That Span Seventy-Five Years
Retention is the technical problem charities get most wrong, because the sector holds records with wildly different lifespans in the same filing system. A charity can be legally required to destroy one document promptly and to keep another for three generations, and the two often live in the same folder.
The statutory floor for IT support for charities is six years, and it is not negotiable
Section 131 of the Charities Act 2011 requires trustees to preserve the charity’s accounting records “for at least 6 years from the end of the financial year of the charity in which they are made”. If the charity ceases to exist within that period, the obligation passes to the last trustees unless the Commission consents in writing to disposal. That six-year floor is the baseline every backup design by IT support for charities should start from.
Gift Aid attaches its own six years, and some records forever
HMRC requires Gift Aid records to be kept until six years after the end of the accounting period for a charitable company, and for a charitable trust until the later of six years after the tax year or twelve months after the claim. Enduring declarations must be kept permanently, with the clock only starting from the last donation. Inadequate records mean repaying the tax with interest and possible penalties, so IT support for charities should treat the Gift Aid store as a finance system.
Safeguarding records run to seventy-five years
The Independent Inquiry into Child Sexual Abuse recommended that records known to relate to allegations or cases of child sexual abuse be retained for seventy-five years with appropriate review periods, and the government has committed to an ICO code of practice on the point. For any charity working with children, that is the real design horizon — twelve and a half times the statutory accounting floor, and it is the number that should shape how IT support for charities designs the archive.
And DBS certificate information has to go almost immediately
The DBS code of practice runs the other way entirely: certificate information should not be kept for longer than is necessary once the recruitment decision has been made, with narrow exceptions for disputes, safeguarding audits and inspection requirements, after which it must be destroyed by secure means. A charity therefore holds a near-zero maximum and a seventy-five-year minimum in the same recruitment file, which is a problem only IT support for charities can automate away.
What that means for how IT support for charities designs backup
Backups are not archives. A thirty-day rolling backup satisfies none of these clocks, and an infinite backup satisfies the long ones while breaking the short one. The answer is a retention engine — Purview labels on Business Premium, or an equivalent in the case management system — that applies a policy per record class, with backup sitting underneath purely for recovery, and IT support for charities owning the difference.
Test the restore, because nobody in a charity ever has
57% of charities back up to a cloud service. Far fewer have restored anything. A restore test twice a year, timed, with a written record of what came back and how long it took, converts a comforting assumption into a measured recovery objective. It is the single most valuable hour IT support for charities can spend in a year.
Microsoft 365 is not a backup, whatever IT support for charities has been told
Retention labels stop deletion inside the tenant; they do not protect against a compromised administrator, a malicious insider or a tenant-level failure. A third-party backup of Exchange, SharePoint, OneDrive and Teams is a separate product with a separate cost, and it is the item most often missing from a charity’s estate because everyone, including some providers of IT support for charities, assumes Microsoft is already doing it.
| Clock | Period | In days | Against the six-year floor | Source |
|---|---|---|---|---|
| DBS certificate information | Destroy once the decision is made | Effectively 0 | 0.00% | DBS code of practice |
| Personal data breach notification | 72 hours | 3 | 0.14% | UK GDPR |
| Subject access request | One month | 30 | 1.37% | UK GDPR |
| Companies House accounts, charitable company | Nine months | 273 | 12.46% | Companies Act |
| Charity annual return | Ten months | 304 | 13.88% | Charity Commission |
| Gift Aid claim window | Four years | 1,461 | 66.68% | HMRC |
| Accounting records | Six years | 2,191 | 100.00% | Charities Act 2011 s.131 |
| Child safeguarding records | Seventy-five years | 27,393 | 1,250.25% | IICSA recommendation |
How Much Storage a Charity Actually Grows, Modelled
Charities rarely run out of storage in year one and frequently run out in year five, because the growth is invisible and the retention clocks stop anybody deleting anything. Sizing it in advance costs nothing and prevents the emergency migration that always arrives at the worst moment.
The tenant allowance is smaller than it sounds
SharePoint in Microsoft 365 gives a tenant 1 TB of base storage plus 10 GB per licensed user. For our 68-account worked example that is 1,000 + 680 = 1,680 GB of shared document storage. Each user also holds their own OneDrive and a 50 GB mailbox, but neither is the right place for records the charity has to keep after that person leaves, and IT support for charities should say so during onboarding.
Fundraising media is the fastest-growing category
Model fourteen fundraising events a year, 420 photographs each at 6 MB, and that is 35.28 GB a year in images alone. Add one 1.8 GB video per event and it is another 25.2 GB. Charities keep this material because it is the raw stock of every future campaign, and almost nobody applies a retention policy to it unless IT support for charities builds one.
Case and service records grow quietly and stay forever
Model 1,150 case records a year at 14 MB each — assessments, correspondence, notes, scanned consent forms — and that is 16.1 GB a year. Add 4.2 GB of finance and governance documents and the charity’s total growth is 80.78 GB a year, which is 484.68 GB across the six-year statutory floor, or 28.85% of the 1,680 GB allowance, which is the growth curve IT support for charities should be sizing against.
The seventy-five-year horizon changes the arithmetic completely
Apply the safeguarding retention expectation to the case-record slice alone and 16.1 GB a year becomes 1,207.5 GB over seventy-five years — 71.88% of the entire tenant allowance the charity has today, for one record class, before a single photograph is stored. That is the number that should drive the archive decision rather than the year-one figure.
Archive is a different product from live storage, and IT support for charities should say so
The answer is not to buy more SharePoint. It is to move closed records into an archive tier with a retention label, immutable where the record class demands it, and to leave live storage for live work. Doing that early is cheap; doing it after the tenant is full is a project with a business case attached, so IT support for charities should raise it in year one.
Data Protection, Fundraising Data and the ICO Record
Charities hold an unusually rich mix of personal data: donors with financial histories, beneficiaries with sensitive circumstances, volunteers with background checks, and often special category data about health, religion or ethnicity. The regulator has been clear that charitable purpose is not a defence, and the enforcement record proves it.
The lawful basis question is harder for IT support for charities than for business IT
A commercial firm processes most personal data under contract or legitimate interests. A charity is running fundraising, service delivery, safeguarding and volunteering on different bases simultaneously, sometimes for the same individual. Getting the record of processing activities right is genuinely difficult, and it is the document the ICO asks for first when something goes wrong, which makes it a deliverable of IT support for charities rather than an afterthought.
Special category data raises the bar on every technical control
Health information in a case file, religious affiliation in a membership record, ethnicity in a monitoring return — all of these are special category data requiring a condition under Article 9 as well as a lawful basis. They also raise the expected standard of the security measures around them, which is why 22% of charities holding personal data unprotected by anonymisation or encryption is such an uncomfortable figure for anyone selling IT support for charities.
The Birthlink fine is the case every charity board should read
In July 2025 the ICO fined the Scottish charity Birthlink £18,000 after it destroyed approximately 4,800 personal records, up to ten percent of which may have been irreplaceable — handwritten letters from birth parents, photographs, copies of birth certificates. The fine was reduced from £45,000 after representations. The failure was not a hacker; it was the absence of a retention policy, staff training and a record of what had been destroyed, all of which sit inside the remit of IT support for charities.
What the ICO actually found missing
The investigation found limited understanding of data protection law, no relevant policies and procedures, no appropriate staff training, and record keeping so poor the charity could not identify who had been affected. Every one of those four gaps is closable with routine work, and none of them requires a large budget. That is what makes the case so useful as a board paper, and IT support for charities should put it in front of trustees.
Fundraising data carries its own history of enforcement
The sector already has a precedent set: following an ICO investigation into donor data practices, eleven charities including well-known national names were found to have misused donors’ personal data, with fines ranging from £6,000 to £18,000. Wealth screening, data appending and unconsented sharing between charities were the practices at issue, and they are all still technically available to buy, which is why IT support for charities should review the fundraising stack as well as the mail.
Subject access is an operational problem IT support for charities has to solve
A one-month deadline is generous until a beneficiary asks for everything held about them across a case management system, a mailbox, a shared drive, a paper file and a WhatsApp group nobody admitted existed. eDiscovery in Microsoft Purview turns that from a fortnight of manual searching into a query, and it is one of the strongest practical arguments IT support for charities has for licensing Business Premium rather than the free grant.
Data protection by design applies to the donation form too
Collecting a date of birth “because it might be useful”, storing full card numbers, keeping unconsented marketing lists for years — these are the ordinary failures, and they are cheap to fix at build time and expensive to fix later. IT support for charities should review every form that collects data at least annually, and delete every field nobody has used, because unused data is pure liability for IT support for charities to defend.
Serious Incident Reporting to the Charity Commission
The Charity Commission expects to hear about serious incidents, and the definition explicitly reaches into technology. Getting this wrong compounds a bad week into a governance failure, because failing to report is treated more seriously than the incident itself.
The definition covers cyber attacks and data loss directly
A serious incident is an adverse event, actual or alleged, resulting in or risking significant harm to beneficiaries, staff, volunteers, assets, property or reputation. The Commission’s guidance names cyber crime and states that charities should report “a significant data breach or loss within your charity”. A ransomware event that stops service delivery is a serious incident on any reading, and IT support for charities should build the report into the runbook.
Trustees own the reporting duty and cannot delegate it to IT support for charities
The guidance is explicit that all trustees bear ultimate responsibility for ensuring the charity makes a report and does so in a timely manner. A charity that discovered the breach through its IT provider and assumed the provider would handle notification has misread the obligation, and so has the provider of IT support for charities that allowed the assumption to stand. IT support for charities should build the trustee notification into the incident runbook as a named step.
The financial thresholds are lower than people assume
The guidance suggests reporting unverified or suspicious donations totalling £25,000 or more, and losses totalling £25,000 or more — or less than £25,000 where the loss exceeds 20% of the charity’s income. For a charity in the £100k to £500k band, a £30,000 payment diversion clears both tests comfortably, which is why IT support for charities should rehearse the reporting path in advance.
Promptly means promptly
The Commission asks for reports as soon as is reasonably possible after the incident. That runs in parallel with the seventy-two-hour UK GDPR notification clock to the ICO, and with any funder or insurer notification obligation. Three separate clocks start at the same moment, and the only way to meet all three is to have written down in advance who does which, and IT support for charities should own that document.
The annual return asks whether anything went unreported
Charities above £25,000 income must declare in the annual return that there are no unreported serious incidents. That converts a decision not to report into a positive statement to the regulator, which is precisely why the decision should be documented at the time with the reasoning, whatever the outcome, and IT support for charities should keep the technical evidence that supports it.
Build the evidence pack before you need it, with IT support for charities holding the template
An incident pack should contain the timeline, the systems affected, the data categories involved, the number of individuals, the containment actions, the notifications made and the remediation plan. Assembled during an incident it takes days; assembled as a template in advance it takes an hour to populate, which is exactly the kind of preparation IT support for charities exists to do. This is ordinary preparation and it is what a competent partner brings.
Trustees, Governance and Who Actually Owns the Risk
Cyber risk in a charity has an owner whether or not anyone has named them, and the law says it is the trustees. The practical problem is that trustees are unpaid volunteers with limited time who often lack the vocabulary to challenge a technical report, and the survey data shows the consequence.
Board attention is falling in the organisations least able to absorb a loss
Board-level responsibility for cybersecurity sat at 30% of charities, essentially matching the 31% of businesses. But the share of charities calling cybersecurity a high priority for senior management fell from 68% to 60% year on year, a decline driven by lower-income charities. The population with the thinnest controls is also the population paying less attention, and IT support for charities has to compensate for both.
Give the board three numbers from IT support for charities, not a dashboard
A trustee board does not need a security operations feed. It needs three numbers reported at every meeting: the percentage of accounts with enforced multi-factor authentication, the date and result of the last tested restore, and the number of open high-severity issues with their age. Anything more granular will not be read; anything less is not oversight, and IT support for charities should produce all three without being asked.
Put cyber on the risk register properly
Most charity risk registers carry a line saying “IT failure” with a medium rating and no owner. Replace it with named risks that describe the scenario: donor database unavailable for five days, payment diverted to a fraudulent account, safeguarding records lost. Each with an owner, a control, and a residual rating the board has actually discussed with whoever provides IT support for charities.
The technology decision needs a named trustee, not a committee
One trustee with enough interest to ask the second question is worth more than a technology subcommittee that meets twice a year. Their job is not to be an expert; it is to hold the executive and the provider to the reporting rhythm. IT support for charities should identify that person in the first month and build the relationship deliberately, because that trustee is the route by which IT support for charities gets funded.
Policies exist to be used, not to be filed
An acceptable use policy nobody has read, a data protection policy written by a template generator, and an incident response plan on a shared drive that fails when the shared drive is encrypted, are all worse than nothing because they create false comfort. Print the incident plan. Keep a copy off the network. Test the phone tree once a year with IT support for charities in the room.
Skills on the board are a legitimate recruitment target
Charity boards recruit for finance, law and sector knowledge and rarely for technology. Given that the board carries the risk, recruiting one trustee with relevant experience is the cheapest governance improvement available. It also gives the executive an internal translator, which changes the quality of every conversation the charity has about IT support for charities.
Cyber Essentials for Charities, Costed
Cyber Essentials is the UK government-backed baseline, and for a charity it does three jobs at once: it forces the five controls into place, it satisfies an increasing number of funders and contract requirements, and it gives the board something concrete to point at.
The five controls are the ones IT support for charities most often has to build
Cyber Essentials covers firewalls, secure configuration, user access control, malware protection and security update management. Set against the survey’s finding that only 13% of charities have the associated controls in all five areas — against 24% of businesses — the certification is less a badge than a checklist of exactly the gaps IT support for charities has to close.
The certification cost is genuinely small
IASME publishes Cyber Essentials assessment pricing by organisation size: £320 plus VAT for nought to nine employees, £440 for ten to forty-nine, £500 for fifty to 249 and £600 for 250 or more. Our 68-account worked example sits in the £500 band. For a charity with £2.4m income that is 0.02% of annual income, and a rounding error against the cost of IT support for charities.
The real cost is remediation, which is where IT support for charities earns its fee
Certification is cheap; getting to a passing state is where the money goes. Unsupported operating systems, unmanaged personal devices, missing multi-factor authentication and absent update management are the four failures that stop a first submission, and all four take work. Budget for the remediation, quote it separately from IT support for charities, and treat the assessment fee as noise.
Cyber Essentials Plus adds a technical audit
The Plus variant adds an independent hands-on assessment of a sample of devices and is priced separately by the certification body. Funders and public-sector contracts increasingly ask for it, and it is worth checking your funding pipeline before deciding. A charity bidding for public contracts should assume it will need Plus eventually, and IT support for charities should plan for it.
Certification is annual, so IT support for charities has to sustain the controls
The certificate lasts twelve months. A charity that scrambles to pass in March and then lets patching drift will fail the next cycle, and the failure is more damaging than never having certified. Building the controls into a managed service, rather than treating certification as an annual project, is the only version of this that holds, and it is what a mature IT support for charities contract looks like.
The funder argument is increasingly the deciding one
Grant applications and public-sector contracts now routinely ask about cybersecurity, and an unambiguous yes is worth real money. Framed that way, certification stops being a cost line and becomes part of the fundraising case, which is usually the argument that gets IT support for charities approved by a board.
Devices, Volunteers and Bring-Your-Own-Everything
Only 35% of charities restrict access to organisation-owned devices, against 66% of businesses — the widest gap in the whole survey. In practice most charity work happens on a mixture of ageing organisation laptops, personal phones and home computers, and the design has to accept that rather than forbid it.
Decide the device policy per data class, not per person
The workable rule is that anything holding case records, donor data or finance sits on a managed device, and everything else can be personal. That splits our worked example neatly, and it makes the licensing decision follow the data rather than the job title. Ambiguity here is what leaves IT support for charities defending case notes on a volunteer’s home laptop.
App protection policies are the best tool IT support for charities has for personal phones
Intune app protection lets the charity control the corporate data inside Outlook and Teams on a personal phone without managing the phone itself — no enrolment, no wipe of family photographs, no consent problem. It requires a Business Premium licence and it is the single most useful device control IT support for charities can offer a charity with a volunteer workforce.
Old hardware is a security control failure, not a thrift
The sector runs devices far past their supported life because replacing them competes with delivery. An operating system past end of support cannot be patched, fails Cyber Essentials outright, and is the most common single reason a charity cannot certify. A rolling replacement of a fixed number of devices a year is cheaper and far less disruptive than a cliff-edge refresh, and IT support for charities should hold the replacement schedule.
Donated and refurbished hardware needs a standard from IT support for charities
Donated laptops arrive with unknown histories, consumer licences and sometimes previous owners’ data. A written intake standard — wipe, reimage, enrol, verify supported operating system — turns a generous gift into a usable asset. Without it, donated hardware quietly becomes the least secure part of the estate IT support for charities is asked to defend.
Shops, hubs and shared machines need their own model
A charity shop till, a community hub sign-in machine or a shared volunteer terminal cannot use a personal login model. Kiosk configuration, a locked-down shared account with no access to organisational data, and separate guest Wi-Fi are the pattern. Only 25% of charities run separate staff and visitor Wi-Fi, against 38% of businesses, and shops are where that gap bites hardest on IT support for charities.
Asset registers are where IT support for charities proves the estate is known
A charity that cannot list its devices cannot secure them, cannot certify, and cannot answer a regulator asking where a lost record was held. The register needs the device, the owner, the operating system, the encryption state and the date of last check-in. Automated from Intune it maintains itself; maintained by hand it is out of date within a month. Good device management makes this a report rather than a project.
Automation, AI and the Small Team Problem
The reason technology matters so much to a charity is not efficiency for its own sake; it is that a four-person team is trying to do the work of twelve. Automation is how a small organisation buys back hours, and it is where a competent partner adds the most visible value.
Start with the tasks IT support for charities should never do by hand
Gift Aid declaration matching, donation reconciliation between the payment processor and the finance system, volunteer rota reminders, DBS renewal tracking and grant reporting deadlines are all rules-based, repetitive and error-prone. Each one automated returns hours a month to people whose time is the charity’s scarcest resource. This is where workflow automation pays for itself fastest, and where IT support for charities is most visible to the people doing the work.
Language tools handle the correspondence load
Charities answer a very large volume of similar enquiries — how do I donate, how do I volunteer, how do I get help. Triage and drafting for that correspondence increasingly uses natural language processing to route messages and propose replies, with a human approving anything that leaves the building. The gain is not fewer people; it is faster answers from the same people, which is the outcome IT support for charities should be measured on.
The data protection question comes first, not last
Before any tool touches beneficiary or donor data, the charity needs to know where the data goes, whether it trains a model, which jurisdiction it lands in, and how it gets deleted. For special category data the answer is often that the tool cannot be used at all on that dataset. Decide that before the pilot, not after somebody has uploaded a case file, and make IT support for charities produce the answer in writing.
Automate the compliance evidence IT support for charities has to produce
The reporting a charity owes its regulators, funders and board is largely mechanical assembly of things the systems already know. Automated collection of restore-test results, licence counts, multi-factor coverage and patch status turns the quarterly board paper into a generated document. Charities under-invest here because it feels like overhead; it is actually what makes the oversight sustainable and what keeps IT support for charities accountable.
Keep a human in the loop on anything about a person
A decision about a beneficiary, a safeguarding flag, a grant eligibility assessment — none of these should be made by a tool without a named person reviewing it. That is both a legal position under UK GDPR and simple good practice for an organisation whose entire authority rests on trust. Write it into the acceptable use policy before the first pilot begins, and have IT support for charities enforce it technically.
Shops, Hubs and Multi-Site IT Support for Charities
The moment a charity runs more than one building the technology problem changes shape. Shops, community hubs, day centres and offices all have different connectivity, different physical security and different staffing, and the design has to hold them without pretending they are the same.
Every site needs its own connectivity answer
A head office with fibre, a shop on a consumer broadband line and a community hub on a mobile router are three different resilience problems. The rule that scales is simple: any site that cannot operate offline for a day needs a second path, and any site that can should not be paying for one. Applying that test site by site usually saves money rather than costing it, which is a useful thing for IT support for charities to prove early.
Guest Wi-Fi is a safeguarding control as much as a security one
A community hub offering internet access to service users needs that traffic separated from the charity’s own network, filtered appropriately, and logged proportionately. Only a quarter of charities run separate networks for staff and visitors. Doing it properly is one VLAN and one firewall rule, and it protects both the charity and the people using the service, so IT support for charities should never leave it undone.
Shops need a till model, not an office model
Retail is its own discipline: an electronic point of sale system, card acquiring, Gift Aid capture on donated goods, stock and a volunteer rota. The till should be on its own network segment with no route to organisational data, and card handling should be scoped so the charity never stores card numbers. Getting this wrong imports a payment-card compliance problem the charity does not need and IT support for charities cannot easily undo.
Standardise ruthlessly across sites, because IT support for charities scales by sameness
Different hardware, different software versions and different local fixes at every site multiply support cost by the number of buildings. One device build, one network design, one printing approach and one support route makes the estate supportable by a small team. Standardisation is where multi-site IT support for charities either earns its fee or does not.
Cloud adoption removes most of the multi-site problem
A charity whose files, mail and line-of-business systems are all cloud-hosted has no site-specific data and therefore no site-specific disaster. Cloud adoption is the single biggest structural simplification available to a multi-site charity, and it converts a set of building-level risks into one identity-level risk that IT support for charities can manage centrally.
Merged charities inherit two of everything, including IT support for charities contracts
Mergers are common in the sector and they arrive with two tenants, two donor databases, two finance systems and two sets of retention obligations. The integration cannot be rushed, because the retention clocks attach to records rather than to organisations. Plan a twelve-month consolidation with a written data map, and treat the second tenant as live until the last record is accounted for, and give IT support for charities the map.
What to Ask a Provider of IT Support for Charities
Most charities choose a provider on price and personal recommendation, which is understandable and produces poor results roughly half the time. A weighted scorecard makes the comparison explicit and gives the board a defensible decision. The version below totals one hundred points, and the pass mark is seventy.
Sector understanding of IT support for charities, twenty points
Ask how many registered charities they currently support and for two references you can call. Ask what the Charity Commission’s serious incident reporting duty means for their runbook. Ask what the Microsoft nonprofit grant covers and where it stops. A provider who cannot answer the third question has not done this before, whatever the website says.
Microsoft 365 and licensing competence, fifteen points
Ask them to price your exact headcount three ways: commercial, full nonprofit and a tiered mix. Ask who submits and maintains the nonprofit validation. Ask what happens to your licensing at renewal when Microsoft moves list prices. The answer should arrive as a spreadsheet, not as a reassurance.
Security baseline, fifteen points
Ask which of the Cyber Essentials five controls they will operate and which remain yours. Ask whether multi-factor authentication is enforced by conditional access or merely enabled. Ask for their standard tenant hardening baseline in writing. Vague answers here predict vague answers during an incident.
Backup, restore and retention, fifteen points
Ask whether they back up Microsoft 365 with a third-party product, how often they test restores, and whether they will show you a timed restore report. Ask how they implement a retention policy that has to hold six years for accounts and far longer for safeguarding. A provider of IT support for charities treating Microsoft’s own retention as a backup has answered incorrectly.
Response commitments that mean something, ten points
Ask for response and resolution targets separately, with a definition of priority one that matches your delivery, not their convenience. Ask what happens at 6pm on a Friday when the helpline system fails. Ask for last quarter’s actual performance against target, not the target. Good support plans put both numbers in writing.
Volunteer-aware identity and onboarding, ten points
Ask how they onboard and offboard a volunteer who will be with you for six weeks. Ask whether they can enforce multi-factor authentication for someone without a work phone. Ask how they handle app protection on personal devices. This is the question that separates providers who have worked in the sector from those who have not.
Reporting a trustee can read, five points
Ask for a sample board report. If it contains ticket volumes and server uptime it was written for an IT manager who does not exist in your organisation. It should contain the three numbers a board needs and a plain-language commentary on what changed.
Exit and data portability, five points
Ask what happens to your tenant, your documentation and your data if you leave. Ask whether administrative credentials are held in your name or theirs. Ask for the exit terms in the contract rather than in an email. Charities stay with providers far too long partly because nobody ever asked this at the start.
Pricing transparency, five points
Ask what is included, what is billed hourly, and what triggers a project quote. Ask specifically about onboarding fees, out-of-hours rates and the cost of adding a user mid-term. Comparing two proposals is only possible when both have answered these three, and a good provider volunteers them.
| Criterion | Weight | What a strong answer looks like | What a weak answer looks like |
|---|---|---|---|
| Sector understanding | 20 | Named charity references and a serious-incident runbook | “We work with lots of small organisations” |
| Microsoft 365 and licensing | 15 | Your headcount priced three ways in a spreadsheet | “You get Microsoft 365 free as a charity” |
| Security baseline | 15 | Written hardening standard, conditional access enforced | “We turn on MFA for everyone” |
| Backup, restore and retention | 15 | Third-party backup plus timed restore reports | “Microsoft keeps everything for you” |
| Response commitments | 10 | Separate response and resolution targets, last quarter’s actuals | “We aim to respond quickly” |
| Volunteer-aware identity | 10 | A documented six-week volunteer joiner and leaver flow | “We can set up accounts for anyone” |
| Reporting a trustee can read | 5 | A one-page board report with three numbers | A ticket-volume dashboard |
| Exit and data portability | 5 | Credentials in your name, exit terms in the contract | “That has never come up” |
| Pricing transparency | 5 | Inclusions, hourly triggers and out-of-hours rates listed | A single monthly figure with no breakdown |
Costing IT Support for Charities
Charities are quoted a wider range of prices than any other sector we work with, partly because “charity” describes organisations three orders of magnitude apart in size. The ranges below are indicative UK market figures, modelled from typical managed service pricing rather than read off a published list, and they exclude VAT and licensing.
What sits inside a managed price for IT support for charities and what does not
A managed monthly fee normally covers the service desk, monitoring, patching, antivirus and endpoint management, identity administration, standard security operations and account management. It normally excludes licensing, hardware, projects, third-party application support and anything out of hours. Comparing two quotes without checking those two lists is comparing nothing at all.
Indicative per-user pricing for IT support for charities by size
For a micro charity with fewer than ten accounts, expect £22 to £38 per user per month. Ten to forty-nine accounts typically lands at £28 to £45. Fifty to 249 accounts, which covers our worked example, runs £32 to £52. Above 250 accounts a co-managed arrangement at £18 to £30 per user plus retained specialist days is usually the better structure.
Why the smallest buyers of IT support for charities pay the most per head
Fixed costs — onboarding, documentation, tenant baseline, monitoring setup — do not scale down. A six-person charity carries the same tenant configuration work as a sixty-person one, spread across a tenth of the users. That is arithmetic rather than exploitation, and the honest way to handle it is a small onboarding fee and a transparent per-user rate rather than an inflated monthly figure.
The one-off costs to budget separately
Onboarding and documentation, tenant hardening, mail migration off consumer webmail, device enrolment and any hardware refresh are all project work. For a charity of our worked example’s size, budgeting a first-year project allowance roughly equal to three months of the managed fee is a reasonable planning assumption, and it should be quoted line by line.
The total picture for the worked example
Take 68 accounts at the middle of the fifty-to-249 range and the managed service runs about £2,856 a month. Add the tiered licensing at £2,081.16 a year, Cyber Essentials at £500 plus VAT, and third-party Microsoft 365 backup. The licensing, which is the number most boards fixate on, is the smallest line in the IT support for charities model by a wide margin.
Grant funding will pay for some of your IT support for charities
Digital and infrastructure funding exists and is under-applied for, partly because charities do not think of technology as fundable. A costed, time-bounded proposal with a clear outcome — migrate off consumer webmail, achieve Cyber Essentials, replace end-of-life devices — is a far stronger application than a general request for money towards IT support for charities.
Do not buy on price alone, but do buy on total cost
The cheapest proposal is frequently the one that excludes the most. Build a five-year total including managed fees, licensing, hardware refresh, certification and a realistic project allowance, and compare on that basis. Sensible IT outsourcing decisions are made on the five-year number, not the monthly one.
| Charity size | Typical structure | Indicative per user per month | What usually dominates the first year |
|---|---|---|---|
| Under 10 accounts | Fully managed, no internal IT | £22 to £38 | Mail migration and first device refresh |
| 10 to 49 accounts | Fully managed with a nominated internal contact | £28 to £45 | Tenant hardening and Cyber Essentials |
| 50 to 249 accounts | Fully managed or co-managed | £32 to £52 | Multi-site standardisation and identity |
| 250 accounts and above | Co-managed with retained specialist days | £18 to £30 plus day rates | Enterprise licensing and archive design |
A 90-Day Plan for IT Support for Charities
Everything above is useless without a sequence. This is the order we run it in, and it is deliberately front-loaded with work that costs almost nothing and removes the largest risks first. A charity that completes only the first thirty days is materially safer than it was.
Days 1 to 10: find out what you actually have
List every account, every device, every system holding personal data, every domain and every administrative credential. Establish who holds the Microsoft 365 global administrator account and whether the charity controls it. Check whether the nonprofit validation is in place. Nothing gets fixed before this exists, and it is usually the first time anybody has written it down.
Days 11 to 20: close the identity gaps
Enforce multi-factor authentication for every account with conditional access, starting with anyone touching finance or donor data. Create two break-glass administrator accounts with credentials held by the chair and the treasurer. Remove standing administrative rights from trustees. Disable every account belonging to somebody who has left, which is always more accounts than expected.
Days 21 to 30: get off consumer webmail
If the charity is one of the 63,091 publishing a free consumer address, this is the highest-value thirty days available. Register or reclaim the domain, stand up the tenant on the grant, create named accounts, publish SPF, DKIM and DMARC at enforcement, migrate the history, and forward the old address for ninety days before closing it permanently, which is the highest-return fortnight in IT support for charities.
Days 31 to 45: make backup real and test it
Add third-party backup for Exchange, SharePoint, OneDrive and Teams. Run a full restore test of the finance system and one case record, time it, and write down what came back. Set the recovery point and recovery time objectives the board is prepared to accept, then confirm the design actually meets them rather than assuming.
Days 46 to 60: set retention deliberately
Write a retention schedule with a row per record class: accounting records six years, Gift Aid to the HMRC rule, enduring declarations permanently, safeguarding to the long horizon, DBS information destroyed on decision. Implement it with Purview labels where licensing allows and with documented manual process where it does not. Get the board to approve the schedule.
Days 61 to 75: harden devices and the network
Enrol organisation-owned devices in Intune with encryption, screen lock and compliance policies. Apply app protection to personal phones. Separate guest Wi-Fi at every site. Replace or isolate anything running an unsupported operating system, and write the replacement plan for what cannot be done immediately.
Days 76 to 90: certify, document and report
Submit for Cyber Essentials. Write the incident response plan, print it, and keep a copy off the network. Run one tabletop exercise with the senior team. Produce the first board report with the three numbers, and agree the rhythm at which it will arrive from now on. Then start the next quarter with the risk register in front of the board.
What good IT support for charities looks like at day ninety
Every account named and protected by enforced multi-factor authentication. Mail on a controlled domain with authentication records published. A tested restore with a recorded time. A retention schedule the board has approved. Devices enrolled or explicitly excluded with a reason. A submitted certification. And a provider of IT support for charities reporting on a rhythm the trustees actually read.
The one thing to do if you can only do one thing
Move off consumer webmail and enforce multi-factor authentication. Those two actions, which cost nothing beyond a domain registration and a fortnight of attention, remove the two failure modes behind most of the incidents that reach the Charity Commission. Everything else in this guide is improvement; those two are the floor.
If you want that sequence run for you, our team delivers exactly this work as part of ongoing support plans, and we are happy to review an existing provider’s arrangement rather than replace it. The neighbouring sector guides for IT support for construction companies and IT support for recruitment agencies cover the same ground for different estates.
References and Further Reading
Charity Commission for England and Wales: Full Register Download
Charity Commission for England and Wales: Charity Register Statistics
Cyber Security Breaches Survey 2025/2026
How to Report a Serious Incident in Your Charity
Internal Financial Controls for Charities (CC8)
Charities Act 2011, Section 131: Preservation of Accounting Records
Prepare a Charity Annual Return
HMRC Charities Detailed Guidance Notes, Chapter 3: Gift Aid
ICO: Charity Fined Following Destruction of Irreplaceable Personal Records
IICSA Final Report, Part H.5: Access to Records
Handling of DBS Certificate Information
Microsoft Offers for Nonprofits
Microsoft 365 Business Plans and UK Pricing
Microsoft 365 Business Premium Documentation
NCSC: Cyber Essentials Overview
NCSC: Cyber Security Guidance for Charities