ao link

You are viewing 1 of your 2 free articles

How to conduct a cyber security risk assessment

Small charities are at the greatest risk of cyber attack. Here is a simple method to assess cyber risk to your charity

A scale of red, yellow, and green, representing different levels of risk

Risk is an everyday part of charitable activity and managing it effectively is essential if trustees are to achieve their key objectives and safeguard their charity’s funds and assets. For that reason, the Charity Commission recommends that all charity leaders regularly assess the risks faced by their charities in all areas of its work.

 

A cyber security risk assessment can be particularly helpful because it will enable your charity to:

  • Identify any areas of your operations which pose unacceptable cyber security risks
  • Prioritise areas that need cyber security improvements
  • Reduce the chances of cyber security breaches
  • Reduce the likely financial and reputational costs of cyber security breaches
  • Reduce the impact of cyber security breaches on service delivery and fundraising

A cyber security assessment may also be a prerequisite for compliance with regulations such as the General Data Protection Regulation (GDPR).

 

Below, we explore six steps for small charities to carry out their own cyber security risk assessment.

 

 

Understand your IT setup

 

The first step is to identify which IT systems are critical to service delivery, fundraising, financial operations, customer data security, and any other activities which are critical to the functioning of your charity.

 

Once you understand this you are in a position to assess the various cyber security risks that they face.

 

 

Identify cyber security threats

 

Cyber security is all about risk management, and to manage cyber security risks successfully, you need to be able to identify and assess them first. The most common types include:

  • Phishing attacks, malware and ransomware infections: These can lead to financial loss and interruption to operations
  • AI cyber security threats: These can put sensitive beneficiary information at risk and compromise the ability to make well-informed decisions using AI
  • Hacker attacks: Network intrusions can lead to data loss and disrupted operations such as service delivery and fundraising
  • Insider attacks: Disgruntled staff or volunteers with access to digital systems can steal money or delete data
  • Data leakage: Accidental digital data loss through the use of unencrypted USB sticks, emailing sensitive data to the wrong people or losing a laptop can lead to loss of data and regulatory problems

 

 

Determine the impact if a threat actually transpired

 

Using some of the examples above, this step aims to assess how bad it would be for your charity if there was a successful ransomware attack, or if a staff member lost their laptop.

 

In most cases it is sufficient to assign one of three impact levels to an event:

  • High: This would have a substantial impact on the ability of your charity to provide its services or continue to operate at all
  • Medium: The impact would be damaging, or costly, or very inconvenient, but the charity would be able to continue to function
  • Low: There would be very little impact on the charity aside from some inconvenience

You may find it more appropriate to take a more granular approach using four or five levels, e.g.

  • Very high: Could lead to charity ceasing to exist
  • High: Very substantial impact on operations
  • Medium: Impact would be significant, but measures (such as data backups) are in place to ensure that operations would only be affected for a limited period
  • Low: Impact would be of minor concern and inconvenience
  • Very low: Impact would be so small as to be not worth worrying about

 

 

Assess the likelihood of each threat happening

 

The next part of the puzzle is to work out a likelihood rating for each risk.

 

That means, for example, how likely are you to fall victim to ransomware and lose access to your data, despite the anti-ransomware software (if any) that you have, and the data backups (if any) that you have. If you do not have any anti-ransomware software and any backups then your operations are much more likely to be disrupted by ransomware than if you have both of these in place.

 

Rather than an exact figure, you can use a likelihood rating system like:

  • High: The threat source (such as a ransomware criminal) is credible and capable, and your existing security measures are inadequate or non-existent. For example, although ransomware is a clear and present threat, you do not have any security measures to mitigate it
  • Medium: Although the threat source is credible and capable, security measures in place are likely to impede them from being successful. For example, although ransomware is a clear and present threat, you have anti-ransomware software which should detect most ransomware attacks
  • Low: the threat source lacks capability, or your security measures will prevent any disruption from the threat. For example, you have anti-ransomware software, and in any case, you carry out regular data backups to the cloud so that if you fall victim to a ransomware attack you should be able to recover your data within a few hours, causing minimal disruption

As with your impact ratings, you may also choose to use a more granular likelihood rating system with four or five levels, rather than the three described above.

 

 

Work out your risk rating score

 

Your risk rating score for a given risk is the impact multiplied by the likelihood of the risk (impact x likelihood = risk rating score).

 

To calculate this you can assign values to impact, like 100 for high, 50 for medium, and 10 for low, and also to likelihood, such as 1 for high, 0.5 for medium, and 0.1 for low.

 

You will then end up with a table of risk ratings that could look like this:

 

Threat

Impact

Likelihood

Risk rating score

Conclusion

Hacker attack

High (=100)

Medium (=0.5)

100 x 0.5 = 50

Medium/ needs attention

Ransomware

High (=100)

Low (=0.1)

100 x 0.1 = 10

Low/Satisfactory

Emailing data to wrong recipient

Low (=10)

High (=1)

10 x 1 = 10

Low/Satisfactory

Insider attack

High (=100)

High (=1)

100 x 1 = 100

Critical/needs immediate attention

 

 

 

Draw up a risk mitigation action plan

 

The resulting table with risk rating scores is the key takeaway of a cyber risk assessment. That’s because it summarises all the risks you have identified, the impacts they could have, and the likelihood that they will come to pass in spite of any existing cyber security or other mitigation measures you have in place.

 

The risk rating scores allow you to identify the most critical threats that you need to address and focus your resources on mitigating them as a matter of urgency, rather than wasting money and other resources on cyber security activities which are less important.

 


Related Articles

Artificial intelligence and cyber securityArtificial intelligence and cyber security
Cyber security trends to watch out for in 2026Cyber security trends to watch out for in 2026
Ten tips for robust cyber securityTen tips for robust cyber security
The ultimate guide to cyber securityThe ultimate guide to cyber security

More on this topic

The risks of agentic AI

The risks of agentic AI


How AI impacts your service users

How AI impacts your service users

Recommended Products
Norton Small Business Premium: 10 devices. Save 60%

Norton Small Business Premium: 10 devices. Save 60%

More on this topic

How to respond to your users’ needs with digital

How to respond to your users’ needs with digital

The risks of agentic AI

The risks of agentic AI

Charity Digital Academy

Our courses aim, in just three hours, to enhance soft skills and hard skills, boost your knowledge of finance and artificial intelligence, and supercharge your digital capabilities. Check out some of the incredible options by clicking here.

 

Tell me more