Filling the Silence
Why the Third Sector Needs Its Own Cyber Intelligence Report
Charities, non-profits, and voluntary organisations hold some of the most sensitive data in modern society. From lived-experience notes and safeguarding records to donor financial details and vulnerable beneficiary files, our sector protects information that touches human lives at their most critical moments.
Yet, when it comes to defending this data, the odds are uniquely stacked.
Most third sector organisations operate under conditions that commercial enterprises rarely face: constrained funding, legacy infrastructure, lean teams, and fluid workforces composed of volunteers, part-time staff, and partner agencies. Some frontline organisations are entirely volunteer-led. Managing cybersecurity in this environment is less like typical corporate risk management and more like trying to conduct a complex orchestra with missing sheet music and half the players absent.
Despite these challenges, public expectations remain rightfully high. Recent research shows that 57% of the public holds high trust in charities—outperforming almost all other institutions. But that trust is fragile. When a charity suffers a breach, the fallout isn’t just financial. It halts vital services, exposes people already in vulnerable situations, and shatters the social licence organisations spend decades earning.
The Reality Behind the Screen
The numbers across the sector paint a stark picture:
Around 30% of UK charities experienced a cyber breach or attack in the past year which represents roughly 61,000 organisations.
Phishing remains pervasive, hitting 95% of charities that reported cyber incidents.
Data incidents are rising rapidly, with the Information Commissioner’s Office (ICO) recording a 51% surge in charity-related incidents since 2020 (compared to 26% across all other sectors).
Foundational defenses remain low, with only 35% having multi-factor authentication (MFA) enabled and just 19% possessing a formal incident response plan.
Despite these stakes, there is currently no dedicated, annual strategic intelligence report built specifically for the third sector.
While the Government’s annual DSIT Cyber Security Breaches Survey provides valuable national macro-benchmarks, it is designed primarily to shape government policy—not to equip charity CEOs, Trustees, and CIOs with actionable, sector-tailored strategies. Furthermore, after the National Cyber Security Centre (NCSC) published a one-off voluntary sector threat report in January 2023, no subsequent editions followed.
The sector was left without its own voice, relying on borrowed corporate benchmarks that simply do not reflect the day-to-day realities of mission-led work.
Introducing: The State of Cybersecurity in the Third Sector Annual Report 2026
To fill this void, Cybility Consulting has partnered with Charity IT Leaders (CITL) to create the UK’s first annual benchmark publication dedicated entirely to voluntary organisations, housing associations, and social enterprises.
Launching on 12 November 2026 at the CITL Connect: Cybersecurity conference in London, this report is designed to be as readable and actionable for a board of trustees as it is for an IT operations lead.
Rather than technical jargon, the publication will explore:
Practical Strategic Recommendations: Actionable steps prioritized for lean teams.
The Human Factor & Culture: Moving past blame to build resilience across staff and volunteer teams.
The Governance Reality: Equipping trustees and executive teams to navigate cyber and AI risk with confidence.
Emerging Threat Horizons: Practical breakdowns of AI-enabled phishing, supply chain exposure, and deepfake fraud.
Real Sector Spotlights: Honest case studies demonstrating what resilience looks like when budgets are tight—and the true lessons learned when incidents happen.
How You Can Get Involved
This report is built by the sector, for the sector. To make it truly representative, we need your insight and support:
Share Your Voice in the Benchmark Survey (Closes 18 September):
Whether you are a sole IT lead, a trustee, an operations director, or an accidental tech lead, your input directly shapes the report findings. Taking 10 minutes to complete the survey ensures our analysis reflects your organisation’s real frontline reality. As a thank you, all survey participants have the opportunity to enter an exclusive prize draw.
Sponsor the Initiative:
Show your organisation’s commitment to strengthening civil society. Align your brand with high-impact, independent research and support our mission to bring clarity and security to non-profits nationwide.
Become an Official Media Partner:
Help amplify these vital findings across sector networks so charities of all sizes can protect the communities they serve.
Cybersecurity shouldn’t be about fear or confusion; it’s about giving social causes the confidence and capability to deliver their missions safely.
Help us write the score that the whole third sector can play from.