Charity Commission Risk Assessment 2026: What Trustees Need to Know About Cyber Security and Ai
-
20/08/2026
- 9 minutes Read
The Charity Commission has published its Charity Sector Risk Assessment 2026, highlighting the pressures and risks facing charities across England and Wales.
For charity leaders and trustees, one section deserves particular attention: “Emerging technology and cyber risk.”
The Commission reports that 30% of charities experienced a cyber attack in the past year, with phishing the most common and disruptive form of attack. It also highlights an increase in ransomware attacks and warns that misuse of artificial intelligence could create additional risks for beneficiaries and employees.
But perhaps the most important message is this:
Trustees remain responsible for ensuring appropriate safeguards, oversight and risk management are in place.
Technology may be changing quickly. Trustee responsibility isn’t.
So what does that mean in practice?
Why Cyber Risk Matters Even More When Charity Budgets Are Under Pressure
One of the clearest themes running through the Commission’s assessment is financial pressure.
In 2024, charities collectively generated £102 billion in income and spent £100 billion. But beneath those headline figures, 41% of charities spent more than they received, and smaller charities were operating on particularly narrow margins.
The Commission also recorded a 27.7% increase in casework relating to insolvency and financial difficulties between October 2024 and September 2025 compared with the previous equivalent period.
That matters to cyber security.
When budgets are stretched, replacing technology, improving security, reviewing Microsoft 365 or providing staff training can easily be postponed.
But a serious cyber incident can create exactly the costs and disruption a financially stretched charity is least equipped to absorb.
The question therefore shouldn’t simply be:
“How much does better cyber security cost?”
It should also be:
“What would a significant cyber incident cost us?”
That includes downtime, recovery costs, lost productivity, reputational damage and the impact on beneficiaries.
1. Start With the Cyber Security Basics
The Commission says 30% of charities reported experiencing a cyber attack in the past year, with phishing the most common and disruptive type.
You don’t necessarily need an enormous cyber-security programme to start reducing risk.
For most charities, we’d first want to answer questions such as:
- Is Multi-Factor Authentication enabled for everyone?
- Are laptops and other devices centrally managed and protected?
- Are security updates being applied?
- Are administrators using separate, appropriately protected accounts?
- Can the charity recover its information if ransomware strikes?
- Are staff and volunteers trained to recognise phishing attempts?
These aren’t particularly glamorous projects.
They’re foundations.
And that’s precisely why they’re important.
2. Understand Where Your Sensitive Information Lives
Cyber security isn’t only about preventing someone from breaking into Microsoft 365.
Charities can hold extremely sensitive information about donors, employees, volunteers, beneficiaries, finances and safeguarding.
Ask a seemingly simple question:
Where is all of that information?
The answer might include SharePoint, Teams, OneDrive, Exchange, a CRM, employees’ laptops and potentially other cloud applications.
Then ask:
Who can access it?
That question becomes increasingly important as organisations adopt AI.
Before trying to protect sensitive information, charities need to understand what they have, where it lives, who has access and how it is being shared.
That’s the first stage of the Bunker Microsoft 365 Data Protection Framework we’re currently developing:
3. Treat AI as a Governance Issue, Not Just a Productivity Tool
The Charity Commission is positive about AI’s potential.
It says AI could help charities improve efficiency, accessibility and impact. But it also warns that misuse of AI could increase risks to beneficiaries and employees.
That’s an important distinction.
The conversation shouldn’t be:
“Should charities use AI?”
It should be:
“How can our charity use AI while managing the risks appropriately?”
For example, staff may already be using ChatGPT or other AI tools to:
- draft fundraising communications;
- summarise documents;
- analyse information;
- prepare reports;
- research topics;
- create presentations.
The risk isn’t necessarily the tool itself.
It’s unmanaged use.
A charity should know which AI tools staff are permitted to use, what information can be entered into them, what requires human review and who is accountable for AI governance.
4. Prepare Your Data Before Rolling Out Microsoft Copilot
Microsoft Copilot introduces another consideration.
One of Copilot’s strengths is its ability, depending on the product and configuration, to help users work with information across Microsoft 365.
But that makes existing information governance increasingly important.
Imagine an employee has access to an old SharePoint site containing information they no longer need.
That was already a permissions problem.
Making organisational information easier to discover doesn’t create the underlying problem — but it can make poor information governance more visible and consequential.
Before expanding Copilot, charities should therefore review areas such as:
SharePoint and Teams permissions → external sharing → sensitive information → data classification → retention → ownership.
This is why we believe AI readiness starts before the AI licence is purchased.
5. Put Cyber and AI Risk on the Trustee Agenda
This may be the biggest takeaway from the Commission’s report.
Cyber security and AI shouldn’t sit exclusively with whoever “does the IT.”
Trustees don’t need to become cyber-security engineers or AI experts.
But they should be able to ask sensible questions.
For example:
- When did we last independently review our Microsoft 365 security?
- Is MFA enforced for everyone?
- What would happen if we lost access to our systems tomorrow morning?
- What sensitive information does our charity hold?
- Who has access to it?
- Are employees and volunteers using AI?
- Which AI platforms have we approved?
- What information are staff prohibited from entering into them?
- Who is accountable for cyber security and AI governance?
If nobody can confidently answer those questions, that’s useful information in itself.
Cyber Security, Data Protection and AI Readiness Are Becoming Connected
One thing we think the Charity Commission’s 2026 assessment makes particularly clear is that charities shouldn’t look at technology risks in isolation.
At Bunker, we increasingly think about this in three layers:
1. Secure the environment
Our Microsoft 365 Security Framework focuses on the security foundations around identities, devices and the Microsoft 365 environment.
2. Protect the information
Our forthcoming Microsoft 365 Data Protection Framework goes deeper into the information itself:
DISCOVER → CLASSIFY → PROTECT → MONITOR → GOVERN
3. Prepare the organisation for AI
Our AI Readiness Framework considers the data, security, people, processes and governance required to adopt AI responsibly.
Together, these help answer three different questions:
- Is our Microsoft 365 environment secure?
- Is the information inside it properly protected?
- Are we ready to use AI responsibly?
What Should Charity Trustees Do Next?
You don’t need to solve everything at once.
I’d start with five actions over the next 30 days:
- Review cyber risk at your next trustee or leadership meeting.
- Confirm MFA is properly deployed across the organisation.
- Find out which AI tools employees and volunteers are already using.
- Identify where your most sensitive information is stored and who can access it.
- Create a prioritised cyber, data protection and AI improvement plan.
The Commission’s report isn’t saying charities should stop adopting technology.
Quite the opposite: it recognises that digital technology and AI can create efficiencies and improvements.
The challenge is adopting those technologies with appropriate safeguards, oversight and risk management.
And for trustees, that is increasingly becoming part of good governance.
How Bunker Can Help
Bunker Technical Solutions helps charities make Microsoft 365, cyber security and AI easier to understand and manage.
Our approach isn’t to start with a list of products.
We start by understanding where you are today, where the risks are and what you should prioritise next.
Through our Microsoft 365 Security Framework, forthcoming Microsoft 365 Data Protection Framework, and AI Readiness Framework, we’re building a practical approach to help charities strengthen their technology foundations and prepare for what’s coming next.
If the Charity Sector Risk Assessment 2026 has prompted questions about your own charity’s cyber security or AI readiness, talk to Bunker.
What does the Charity Commission say about cyber security in 2026?
The Charity Commission says charities face escalating cyber risks. Its 2026 assessment reports that 30% of charities experienced a cyber attack in the past year, with phishing the most common and disruptive type.
Are charity trustees responsible for cyber security?
The Commission states that trustees remain responsible for ensuring appropriate safeguards, oversight and risk management are in place as charities adopt digital technology and AI. Trustees don’t need to personally manage IT, but they should have appropriate oversight.
What does the Charity Commission say about AI?
The assessment recognises that AI can improve efficiency, accessibility and impact, while warning that misuse could increase risks to beneficiaries and employees.
Should charities stop staff using AI?
A blanket ban isn’t necessarily the answer. Charities should understand which tools are being used and establish appropriate policies, safeguards, training and oversight.
What cyber-security controls should charities prioritise?
Priorities will depend on the charity’s circumstances, but areas worth assessing include MFA, account security, device management, patching, email protection, backup/recovery, staff awareness and Microsoft 365 permissions.
How can Bunker help charities respond?
Bunker can help charities assess their Microsoft 365 security, data protection and AI readiness, identify gaps and develop a prioritised improvement roadmap.
Ready to Strengthen Your Charity's Microsoft 365 Security?
What Is Microsoft Secure Score? A Guide for UK Charities
Charity Commission Risk Assessment 2026: What Trustees Need to Know About Cyber Security and Ai
Why Remote Staff and Volunteers Increase Cyber Risk for Charities – And What You Can Do About It
Cyber Essentials Isn’t Enough: Why Charities Need a Microsoft 365 Security Strategy
Microsoft Copilot vs ChatGPT: Which Is Better for Charities? Make Ai work for your mission
What the Beacon CRM Cyber Incident teaches Charities about Cloud Software
Is Your Charity’s Microsoft 365 Really Secure? Here’s How to Find Out
Which CRM Is Best for Your Charity? Comparing the Leading CRM Systems for UK Charities in 2026
How Should UK Charities Prepare for Changing Data Protection Requirements?
What 15 Years of building an IT business has taught me about Leadership
The three types of Ai Organisations should think about







