
How Devon Firms and Charities Should Protect Themselves Online
Most charities and small firms across Devon don't see themselves as targets. They're running food banks, sorting out volunteers, keeping community halls going or selling locally made products. But attackers don't care about size or purpose. The UK Government's Cyber Security Breaches Survey 2025/2026 found that 28% of charities had experienced a breach or attack in the past twelve months, and phishing was behind the vast majority of those.
Meanwhile, only 17% of charities ran any kind of staff cyber security training, which is actually down from 21% the year before. That's a worrying gap. So let's get into the stuff that actually helps, from quick wins any volunteer can handle to the more advanced testing that bigger organisations should be thinking about.
Why Charities and Small Firms Get Caught Out
Charities hold a lot of sensitive data. We're talking donor bank details, beneficiary records, Gift Aid information, safeguarding files. That makes them appealing to criminals. But many still rely on a part-time volunteer for IT, share passwords between staff, and run outdated software because there's no money for upgrades.
Small businesses have the same problem. A three-person accountancy firm in Exeter or a family-run B&B near Dartmouth won't have a dedicated IT team. When resources are tight, blind spots appear, and attackers will always go after the easiest way in.
Start With Two-Factor Authentication
If you only do one thing after reading this, turn on two-factor authentication (2FA) across every account that supports it. That means email, cloud storage, social media, banking, your website CMS and any donor management platform.
2FA adds a second step when you log in. It's usually a code sent to your phone or generated by an app. So even if someone gets hold of your password through a phishing email, they still can't access your account without that second code. It takes about five minutes to set up per account, it's free, and platforms like Mailchimp, JustGiving and Xero already have it built in.
Keep Software and Devices Updated
Outdated software is one of the easiest ways into any system. When a developer releases a security update, they're fixing a vulnerability that's already been found. If you don't install it, you're leaving a known weakness sitting there for anyone to exploit.
This applies to everything. Your operating system, web browser, antivirus, WordPress plugins, your router firmware. Set devices to update automatically wherever you can. If your charity manages its own website, someone should be checking for plugin and theme updates at least once a week.
Train Your Team (Even If They're Volunteers)
The government's Breaches Survey found that training levels among charities actually dropped this year. That matters, because phishing is still the most common attack type, and it only works when someone clicks a link or opens an attachment they shouldn't.
You don't need to spend a fortune on this. A 30-minute session covering how to spot suspicious emails and who to report them to will go a long way. Run it once a quarter, and make sure new volunteers go through it on day one. Hammer home the basics: check sender addresses carefully, hover over links before clicking, and be wary of any message that tries to create urgency or asks for payment details.
Back Up Your Data Properly
Ransomware attacks lock you out of your own files and demand payment to get them back. The best defence against this is a reliable backup you can restore from without paying anyone.
The 3-2-1 rule is a good one to follow: keep three copies of your data, on two different types of storage, with one copy stored off-site or in the cloud. And test your backups regularly. There's no point discovering your backup doesn't work on the day you actually need it.
When Larger Organisations Need to Go Further
The steps above will cover the basics for most small firms and community groups. But if your organisation has its own IT setup, processes online payments, handles large volumes of personal data, or runs across multiple sites, you'll want to go beyond the fundamentals.
Penetration testing is a solid next step. It means hiring a certified professional to try and find weaknesses in your systems, basically stress-testing your defences before a real attacker gets the chance to. For organisations with more complex digital operations, red teaming services take it even further by simulating a full attack scenario across people, processes and technology. They'll show how a real threat actor would move through your environment and where your defences would actually hold up.
This kind of testing isn't reserved for banks and government departments. Any Devon-based charity or firm with significant digital infrastructure, whether that's a large CRM, an online fundraising platform, or remote access for staff, will benefit from understanding where the real gaps are.
Have a Plan for When Things Go Wrong
Even with solid defences in place, breaches can still happen. Every organisation should have a basic incident response plan. It can be as simple as a single sheet answering four questions: who do we contact first, how do we contain the problem, what do we need to report, and how do we communicate with affected people.
If your charity handles personal data, you may have a legal obligation under UK GDPR to report certain breaches to the Information Commissioner's Office within 72 hours. Knowing that before an incident happens will save you a lot of panic and wasted time.
Small Steps, Big Difference
A single phishing email can undo years of trust and fundraising work. But most attacks succeed because of gaps that are genuinely easy to fix. Turn on 2FA, keep your software current, train your people, and back up your data.
Those four things alone will put you ahead of most organisations in the country. If you've got a bigger digital footprint, proper security testing will reveal what you can't spot from the inside.













