Gaps in cybersecurity controls at UK’s largest charities, report warns

21 Aug 2026 News

AKACHA via Adobe

There are gaps in cybersecurity controls at many of the UK’s largest charities, according to new research.

After externally scanning 380 of the UK’s biggest and best-known charities, consultancy Huro Data recommended that most organisations should improve their cybersecurity, noting that “they carry a collection of smaller gaps that together make an attacker’s job easier than it needs to be”.

Staff and supplier passwords are already circulating for 44% of the best-known charities and 55% of the largest by income, according to the research.

Meanwhile, the research found that emails could be sent in a charity’s name at roughly one in three organisations examined, with forged appeals and payment requests that appear to come from a recognised charity remaining “one of the most effective frauds available”.

The consultancy also found that the size of a charity’s budget did not equal better protection, with the better-funded charities being “more likely, not less” to have staff credentials and internal login pages already exposed on their webpages.

The research noted that “some openings are rare but serious”, with 4% of charities examined having a database port reachable from the public internet.

It found that nine out of 10 charities surveyed did not have any published route for reporting a vulnerability and no restrictions on who may issue certificates.

However, it also found that none of the charities reviewed appeared on ransomware leak sites or browser-safety lists, which the research described as “a genuinely positive result”.

The report authors recommended that “non-technical teams” should focus on resetting exposed staff and supplier accounts and turning on multi-factor authentication.

They also advised instructing mail providers to reject forged emails; closing ports that do not need to be public, and maintaining clear records of awareness and response.

Earlier this month, it was reported that charities’ data held by software firm Beacon CRM had likely been downloaded by a third party as part of the cybersecurity breach.

For more news, interviews, opinion and analysis about charities and the voluntary sector, sign up to receive the free Civil Society daily news bulletin here.

More on