Why Remote Staff and Volunteers Increase Cyber Risk for Charities – And What You Can Do About It

Why Remote Staff and Volunteers Increase Cyber Risk for Charities – And What You Can Do About It

The way charities work has changed dramatically over the past few years. Many organisations now have a mix of office-based staff, home workers, volunteers, trustees and contractors accessing systems from different locations and devices.

This flexibility has helped charities recruit talent, reduce costs and continue delivering services. But it has also created a challenge that many leadership teams underestimate: every person, device and location connecting to your systems increases the potential opportunities for cyber criminals.

For CEOs and CFOs, this isn’t just an IT issue—it’s a governance issue that affects your reputation, finances and the people who rely on your services.

Why charities are particularly vulnerable

Unlike many commercial organisations, charities often rely on a combination of employees, volunteers and trustees, all with different levels of technical knowledge.

Some use organisation-owned laptops, while others access emails and files from personal devices. Volunteers may only need temporary access, yet accounts are sometimes left active long after they leave.

At the same time, charities hold valuable information, including donor records, beneficiary details, payroll data and financial information. That makes them an attractive target for cyber criminals looking to steal data or commit fraud.

The more people accessing your systems, the more important it becomes to know who has access to what—and whether they still need it.

Five practical steps every charity should take

1. Know who has access

Start by reviewing every account that can access your systems.

Remove access for former employees, volunteers and contractors who no longer need it, and regularly check that current users only have access to the information required for their role.

2. Secure every login

Passwords alone are no longer enough.

Adding Multi-Factor Authentication (MFA) provides an extra layer of protection by requiring users to verify their identity before accessing systems. It’s one of the simplest and most effective ways to reduce the risk of unauthorised access.

3. Protect every device

Whether someone works from the office, home or while travelling, the device they use should meet the same security standards.

Keeping laptops updated, encrypted and protected helps reduce the impact if a device is lost, stolen or compromised.

4. Train staff and volunteers

Cyber security isn’t just about technology—it’s about people.

Regular, practical training helps staff and volunteers recognise phishing emails, suspicious links and common scams before they become costly incidents.

Even a short annual training programme can significantly improve awareness across the organisation.

5. Plan for people joining and leaving

Every charity has staff turnover and changing volunteer roles.

Having a simple process for creating, changing and removing user accounts ensures that people only have access while they genuinely need it.

This reduces unnecessary risk and demonstrates good governance.

Good security supports your mission

Cyber security shouldn’t make it harder for people to do their jobs. Done well, it enables your teams to work safely from anywhere while protecting your charity’s reputation and the trust placed in you by donors, beneficiaries and partners.

The goal isn’t to lock everything down—it’s to give the right people secure access to the right information at the right time.

How Bunker can help

If your charity has staff, volunteers or trustees accessing Microsoft 365 from different locations, now is the time to make sure your security controls are keeping pace.

Bunker’s Microsoft 365 Security Framework for Charities is designed specifically for organisations like yours. We assess your Microsoft 365 environment against security best practices, identify gaps that could expose your organisation to unnecessary risk, and provide a clear, prioritised roadmap to improve your security without disrupting day-to-day operations.

Whether you’re concerned about unauthorised access, protecting sensitive donor and beneficiary data, or giving trustees greater confidence in your cyber resilience, our framework provides practical recommendations tailored to the charity sector.

Book a Microsoft 365 Security Framework Assessment and discover how you can build a more secure, resilient and compliant Microsoft 365 environment that supports your mission.

Ready to Strengthen Your Charity's Microsoft 365 Security?

Logo
We've got IT covered.

Reviewing your MSP? Concerned about Cyber Security? Preparing for Ai?