Small charities rely heavily on volunteers. In many cases, they also rely on volunteers using their own laptops, phones and tablets to help keep things running.
It’s practical, flexible and often necessary – especially for organisations working with limited budgets.
But there’s a side to this that many charities overlook: personal devices can quietly introduce significant security and data protection risks.
The issue usually isn’t bad intentions or careless people. It’s that personal devices are difficult to monitor, difficult to secure consistently, and often sit outside the charity’s normal processes altogether.
Volunteers now regularly access:
Charity email accounts
Donor information
Financial systems
Shared documents
Internal messaging platforms
CRM databases
Online banking or payment tools
At the same time, many smaller charities do not have formal IT policies, dedicated IT staff, or visibility over how those devices are being used.
That can create a perfect gap for problems to develop unnoticed.
A volunteer’s personal laptop may work perfectly well day to day, but still be running outdated software or unsupported operating systems.
Without regular security updates, devices become far more vulnerable to malware, phishing attacks and account compromise.
This is particularly common where:
Older laptops are being “kept going”
Devices are shared with family members
Antivirus software has expired
Updates are regularly postponed
Many volunteers work from home using shared household computers.
That can mean:
Multiple people using the same login
Charity documents stored alongside personal files
Browser passwords saved automatically
Children or other family members accidentally accessing sensitive information
Even small charities often hold highly sensitive data – including personal details, safeguarding information or donor records.
One of the most common issues seen in smaller organisations is former volunteers still having access to systems long after they have left.
This might include:
Email accounts
Shared drives
Dropbox or OneDrive folders
WhatsApp groups
CRM systems
Password managers
Usually this happens simply because nobody remembers to remove access.
Over time, this creates growing security and compliance risks.
When people use their own devices, they also tend to use their own habits.
That may mean:
Reused passwords
Weak passwords
Passwords written down
No multi-factor authentication (MFA)
Shared logins between volunteers
For attackers, compromised passwords remain one of the easiest ways into an organisation.
There are operational risks too.
When charities rely heavily on unmanaged personal devices:
Important information can become scattered
Documents may only exist on one person’s laptop
Knowledge becomes tied to individuals
Replacing volunteers becomes harder
Recovering after problems takes longer
In some cases, charities discover too late that critical files were never backed up properly at all.
This is one of the biggest misconceptions around cybersecurity.
Attackers are rarely choosing targets because they are famous or wealthy. More often, they are looking for organisations with:
Limited security controls
Older technology
Shared accounts
Busy teams
Little formal oversight
Unfortunately, smaller charities can fit that profile very easily.
The good news is that improving security does not need to be complicated or expensive.
Small steps can make a significant difference.
Know:
Who has access to what
Which devices are being used
Where important data is stored
Which volunteers still need access
Encourage or require:
Device updates
Antivirus protection
Screen locks
MFA on email and cloud systems
Every volunteer should ideally have their own login.
This makes access easier to manage and improves accountability.
Create a simple checklist for when volunteers leave:
Disable accounts
Remove shared folder access
Change shared passwords
Remove mailing list access
This does not need to be complicated or overly formal.
A short, clear policy can help volunteers understand:
What systems they can access
How charity data should be handled
Expectations around passwords and devices
What to do if something goes wrong
Most charities are not trying to build enterprise-level IT systems – and they shouldn’t need to.
But as more volunteering becomes digital, personal devices are becoming part of the charity’s infrastructure whether organisations realise it or not.
The important thing is not perfection. It’s awareness, sensible processes and reducing avoidable risk before problems arise.