Charities managing the risk of cybercrime

This week is Charity Fraud Awareness Week 2022, an annual event seeking to tackle fraud and cybercrime by raising awareness and sharing good practice among charities. 

It was heralded by the release of the Charity Commission’s new survey exploring charities’ experiences of online cyber-attacks, finding that 12% of charities had experienced cybercrime in the previous 12 months (although that is only the number of charities with an awareness that they had been affected).

The survey suggests a potential lack of awareness of the risks charities face online, when the pandemic has prompted increasing numbers to move to digital fundraising and operating.

Of the charities questioned only 55% reported that cyber security was a fairly or very high priority for their organisation, and only 25% have a formal policy in place to manage the risk – not ideal when there is a need to take action very quickly once there has been an attack.

In July 2022, speakers at a Charity Finance Group conference explained that charities are particularly exposed to ransomware attacks – where hackers use malware to deprive a company of access to its files through encryption and then demand a ransom payment to regain the information –  because they tend to hold sensitive personal data, the disclosure of which over the internet could be catastrophic and result in exposure to very large ICO fines, and because they tend to have limited in-house IT expertise.

Charities cannot count on hackers to leave them alone just because of the valuable work they do. Cybercrime in general and ransomware in particular is big criminal business with no room for sentiment. A Scottish mental health charity reported a ransomware attack in March 2022 and more recently a managed service provider to the NHS was affected.


This information is for general information purposes only and does not constitute legal advice. It is recommended that specific professional advice is sought before acting on any of the information given. Please contact us for specific advice on your circumstances. © Shoosmiths LLP 2024.



Read the latest articles and commentary from Shoosmiths or you can explore our full insights library.