IT support for charities & not-for-profits
IT support for charities and not-for-profits
Donor, beneficiary and safeguarding data protected, volunteers and trustees working securely, and a limited budget spent where it reduces the most risk.
- Sector
- Charities
- Typical size
- up to 250 staff
- Coverage
- Herts, Essex, London
- Proof
- Client reviews
In short
Dig IT Solutions provides managed IT support for charities and not-for-profit organisations across Hertfordshire, west Essex and London. We run the helpdesk, help eligible charities apply for Microsoft's nonprofit licensing, secure Microsoft 365 with MFA for staff, volunteers and trustees, protect donor and beneficiary records, back everything up and prepare organisations for Cyber Essentials. It suits charities of up to 250 staff and volunteers with no IT team of their own.
Who this is for: Registered charities, community interest companies, social enterprises, hospices, advice and housing charities, membership bodies, and faith and community organisations with up to 250 staff and regular volunteers. Our contact is usually the chief executive, the finance or operations manager, or the trustee who took on IT by default.
Sector pressures
What keeps charities & not-for-profits up at night
Trustees are accountable for cyber risk
The Charity Commission treats cyber security as part of trustees' duty to protect the charity's assets and reputation, and it expects serious incidents, including significant data breaches and cyber crime, to be reported promptly. Recent GOV.UK Cyber Security Breaches Surveys have found roughly three in ten charities reporting a breach or attack in the previous twelve months, most of it phishing. A volunteer board that meets quarterly needs plain information to act on.
Donor, beneficiary and safeguarding data
A charity can hold health, immigration, financial and family details about the people it helps, safeguarding concerns and DBS information, plus donor records and Gift Aid declarations. Much of that is special category data under UK GDPR, and a breach harms people who are already vulnerable. Case notes in a shared inbox, or a safeguarding folder open to the whole team, are the ordinary ways it goes wrong.
Volunteers and trustees on personal devices and email
Board papers go to trustees' personal Gmail and Hotmail accounts, volunteers share one login on the front desk PC, and the treasurer keeps the accounts on a home laptop. None of it is covered by MFA, backup or a leaver process, and when a volunteer moves on the data stays with them. It is the most common gap in the sector and one of the cheapest to close.
Tight budgets and ageing, donated hardware
Grants rarely cover core IT, so equipment is kept until it fails and donated PCs arrive with unknown histories. Windows 10 reached end of support in October 2025, and many older machines cannot run Windows 11, which leaves them without security updates and a problem for Cyber Essentials. The answer is a plan that says which devices to keep, which to replace first and what it will cost, so trustees can budget for it.
Funders and commissioners asking for evidence
Grant funders, local authority commissioners and corporate partners increasingly ask about cyber security in applications and contract monitoring, and some make Cyber Essentials a condition of funding. Fraudsters target the sector as well, typically with an email that appears to come from the chief executive or treasurer asking for an urgent payment. Both pressures land on a finance or operations manager with no IT training.
What we do
How we support you
A helpdesk for staff, volunteers and trustees
Remote support via Splashtop for everyday faults, and on-site engineers from Hoddesdon when an office, shop or community building needs hands. Everyone gets plain-English help from one accountable team, and managers get a ticket history they can show the board. See managed it support service.
Help applying for Microsoft 365 nonprofit licensing
Microsoft runs a nonprofit programme that offers grants and discounted licensing to eligible organisations. Microsoft decides eligibility, not us, and the offer changes from time to time, but we can help you prepare the application and then choose a licence mix that puts security features where the sensitive data is. See microsoft 365 service.
A charity account for everyone who handles charity data
Trustees and key volunteers move from personal email to charity mailboxes with MFA. Conditional access controls what can be opened from a personal device, SharePoint permissions keep safeguarding, HR and finance folders restricted to named people, and board papers are shared through Teams rather than sent as attachments.
Security sized to the risk and reported to the board
EDR on every device, patching through our remote monitoring and management platform, email security with DMARC on your domain, and short security awareness training that volunteers can complete as well as staff. We summarise the position in writing so trustees can minute that cyber risk has been reviewed.
Backups and records you can retrieve
Microsoft 365 backup for mailboxes, OneDrive and SharePoint, local backup to a Synology appliance for any on-site server or NAS, and cloud copies off-site, with test restores reported. Gift Aid declarations, finance records and case files stay recoverable for as long as you are required to keep them.
Hardware planned, and shops and sites connected
A device-by-device replacement plan so spending is predictable, HP and Dell hardware supplied ready to use, and honest advice on which donated equipment is worth keeping. For charity shops, cafes and community venues, UniFi networking keeps tills and card terminals apart from volunteer and visitor Wi-Fi.
Software we work alongside
Systems charities commonly run on
- Donorfy
- Beacon CRM
- Salesforce Nonprofit Cloud
- Raiser's Edge NXT (Blackbaud)
- Lamplight and Charitylog for case management
- Xero, Sage or QuickBooks for fund accounting
- JustGiving, Enthuse and other online giving platforms
- Microsoft 365 including Teams and SharePoint
Listed to show familiarity, not as vendor partnerships. We support the platform your software runs on and work with each vendor’s support team on your behalf.
Compliance and expectations
Charity Commission guidance and serious incident reporting
The Commission expects trustees to manage cyber risk as they would any other risk to the charity, and to report serious incidents promptly. Its guidance includes cyber crime and data breaches that cause significant loss or harm. In IT terms trustees need to know what controls are in place, who is responsible for them, and that logging exists to establish what happened if something goes wrong.
Charity Commission for England and WalesUK GDPR, special category data and the ICO
Beneficiary records often include health, ethnicity, immigration or criminal offence information, which carries stricter conditions than ordinary personal data. The ICO expects access limited to those who need it, secure devices, retention limits and breach assessment within 72 hours. Safeguarding records need particular care over who can open them and how long they are kept.
Information Commissioner's OfficeGift Aid records and card payments
HMRC requires Gift Aid declarations and supporting records to be kept for six years after the most recent donation claimed on, so they need to survive staff changes, CRM migrations and hardware failures. Where you take card payments in shops or at events, your acquirer expects PCI DSS basics: terminals and tills on a maintained network, separate from public Wi-Fi.
HM Revenue & CustomsNCSC Small Charity Guide
The National Cyber Security Centre publishes a short guide for charities covering backups, malware, devices, passwords and phishing, written for trustees and managers rather than technicians. Our standard build follows it, which gives the board a recognised reference point to measure against.
NCSC Small Charity GuideCyber Essentials
Some funders, commissioners and public sector contracts require Cyber Essentials, and others accept it as evidence that the basics are covered. Its five technical controls are the baseline we run for every organisation, and we help you prepare the self-assessment when the board decides to certify.
NCSC Cyber Essentials
What clients say about working with us
“Vince provided a high-quality computer at a great price. His support has always been excellent: fast, affordable, and thoughtful. I'm grateful for his help and happy to recommend his services to friends, family, and business contacts.”
Switching to us
How the handover works
Switching a charity usually starts with establishing who owns what. We record every device, account, licence and login, and check who controls the domain name, the Microsoft 365 tenant and the fundraising CRM, because these are often registered to a former volunteer or a trustee's personal email. We document it in a form the board can keep, run alongside any outgoing provider or volunteer through handover, and schedule changes away from appeals, events and year end. Staff and volunteers get a short, plain briefing, and we can talk trustees through the findings. The full process is at our switching IT provider guide.
FAQ
Charities & Not-for-Profits: questions we are asked
What IT support does a charity need?
Can we get Microsoft 365 free or at a discount as a charity?
What are trustees' responsibilities for cyber security?
Should volunteers and trustees use personal devices and personal email?
Do we need Cyber Essentials to apply for grants or contracts?
How much does IT support cost for a charity?
Insights
Guides for charities & not-for-profits
Cyber Security
BYOD security risks: how to let staff use personal devices for work safely
The real risks of staff using personal phones and laptops for work, and how UK small businesses control them with Intune, app protection and a BYOD policy.
Cyber Security
How much does Cyber Essentials cost in 2026?
Cyber Essentials fees in 2026: IASME size bands from around £320 plus VAT, what Cyber Essentials Plus costs, and the remediation costs that really vary.
Cyber Security
UK GDPR: the IT controls a small business actually needs
The IT controls UK GDPR expects of a small business: access control, MFA, encryption, retention, backups, processor contracts and 72-hour breach reporting.
Next step
Talk to an engineer, not a sales script
Tell us what is not working, or what you are planning, and we will give you a straight view on what it would take to fix.

