Small charities rely heavily on volunteers. In many cases, they also rely on volunteers using their own laptops, phones and tablets to help keep things running.

It’s practical, flexible and often necessary – especially for organisations working with limited budgets.

But there’s a side to this that many charities overlook: personal devices can quietly introduce significant security and data protection risks.

The issue usually isn’t bad intentions or careless people. It’s that personal devices are difficult to monitor, difficult to secure consistently, and often sit outside the charity’s normal processes altogether.

Why this matters more than ever

Volunteers now regularly access:

  • Charity email accounts

  • Donor information

  • Financial systems

  • Shared documents

  • Internal messaging platforms

  • CRM databases

  • Online banking or payment tools

At the same time, many smaller charities do not have formal IT policies, dedicated IT staff, or visibility over how those devices are being used.

That can create a perfect gap for problems to develop unnoticed.

The risks charities often don’t realise they have

Devices may not be properly updated

A volunteer’s personal laptop may work perfectly well day to day, but still be running outdated software or unsupported operating systems.

Without regular security updates, devices become far more vulnerable to malware, phishing attacks and account compromise.

This is particularly common where:

  • Older laptops are being “kept going”

  • Devices are shared with family members

  • Antivirus software has expired

  • Updates are regularly postponed

Shared family devices can create unexpected exposure

Many volunteers work from home using shared household computers.

That can mean:

  • Multiple people using the same login

  • Charity documents stored alongside personal files

  • Browser passwords saved automatically

  • Children or other family members accidentally accessing sensitive information

Even small charities often hold highly sensitive data – including personal details, safeguarding information or donor records.

Leavers can retain access for months

One of the most common issues seen in smaller organisations is former volunteers still having access to systems long after they have left.

This might include:

  • Email accounts

  • Shared drives

  • Dropbox or OneDrive folders

  • WhatsApp groups

  • CRM systems

  • Password managers

Usually this happens simply because nobody remembers to remove access.

Over time, this creates growing security and compliance risks.

Password habits are often weaker on personal devices

When people use their own devices, they also tend to use their own habits.

That may mean:

  • Reused passwords

  • Weak passwords

  • Passwords written down

  • No multi-factor authentication (MFA)

  • Shared logins between volunteers

For attackers, compromised passwords remain one of the easiest ways into an organisation.

The problem isn’t just cybersecurity

There are operational risks too.

When charities rely heavily on unmanaged personal devices:

  • Important information can become scattered

  • Documents may only exist on one person’s laptop

  • Knowledge becomes tied to individuals

  • Replacing volunteers becomes harder

  • Recovering after problems takes longer

In some cases, charities discover too late that critical files were never backed up properly at all.

“We’re only a small charity”

This is one of the biggest misconceptions around cybersecurity.

Attackers are rarely choosing targets because they are famous or wealthy. More often, they are looking for organisations with:

  • Limited security controls

  • Older technology

  • Shared accounts

  • Busy teams

  • Little formal oversight

Unfortunately, smaller charities can fit that profile very easily.

Practical ways to reduce the risk

The good news is that improving security does not need to be complicated or expensive.

Small steps can make a significant difference.

Start with visibility

Know:

  • Who has access to what

  • Which devices are being used

  • Where important data is stored

  • Which volunteers still need access

Introduce basic security standards

Encourage or require:

  • Device updates

  • Antivirus protection

  • Screen locks

  • MFA on email and cloud systems

Avoid shared accounts

Every volunteer should ideally have their own login.

This makes access easier to manage and improves accountability.

Remove access promptly

Create a simple checklist for when volunteers leave:

  • Disable accounts

  • Remove shared folder access

  • Change shared passwords

  • Remove mailing list access

Create a simple acceptable use policy

This does not need to be complicated or overly formal.

A short, clear policy can help volunteers understand:

  • What systems they can access

  • How charity data should be handled

  • Expectations around passwords and devices

  • What to do if something goes wrong

What this means for charities

Most charities are not trying to build enterprise-level IT systems – and they shouldn’t need to.

But as more volunteering becomes digital, personal devices are becoming part of the charity’s infrastructure whether organisations realise it or not.

The important thing is not perfection. It’s awareness, sensible processes and reducing avoidable risk before problems arise.