What happens when UK charities talk honestly about cyber security?
2 minute read
Greg Dean
May 27th, 2026
Cyber security conversations in the charity sector often happen in isolation. An IT lead trying to make the case for Multi-factor Authentication (MFA). A governance team unsure who owns the risk register. A senior leader nodding along to a threat briefing without fully understanding what it means for their organisation.
That’s exactly why we brought a group of cyber and IT leaders from across the UK charity sector together for our Phoenix Protect Roundtable, to create space for an open conversation.
Read the full report
We’ve captured the key themes and takeaways in a post-event report.
What we heard
Turnout was strong, and so was the honesty. Attendees came from a wide range of organisations; some early in their cyber journey, others with more established programmes. That mix made for richer conversation, because the challenges were broadly shared even when the starting points weren’t.
A few themes kept resurfacing:
The basics aren’t as basic as they sound. Getting fundamentals like access controls and authentication properly embedded takes time, resource, and internal buy-in. For many organisations, that’s a bigger ask than it looks.
Governance, risk, and compliance feel overwhelming. Not because people don’t understand why they matter, but because translating good intentions into operational practice is genuinely hard, especially with lean teams.
Incident preparedness is a gap most organisations quietly acknowledge. What happens when something goes wrong? Who decides what? Who communicates what, to whom? These questions deserve answers before the moment arrives.
Leadership buy-in remains one of the hardest problems in the room. Getting boards and senior leaders to understand cyber risk (and act on it) without either over-alarming or underselling the threat is a skill in itself.
You don’t need to be an expert to start
One of the most encouraging threads throughout the day was this: organisations at very different levels of maturity were making progress. Not by tackling everything at once, but by being clear about where they were starting from and what mattered most.
Cyber resilience isn’t about perfection. It’s about reducing the gaps that matter, knowing what you’d do when something goes wrong, and making sure the right people in your organisation understand why it all matters.
If the conversations we had are any guide, plenty of charities are closer to a stronger security posture than they realise. They just need a clearer path forward.
Want the full picture?
The post-event report goes deeper into the governance and compliance challenges the sector is navigating, how to talk about cyber risk at board level, and practical guidance on where to start.

