Every pound you spend on IT is a pound that came from a donor, a funder or a member. We make that pound work properly — discounted Microsoft licensing put to full use, volunteers managed safely, and assurance your trustees can actually rely on.
Charities run on a harder version of the SME problem: the same data-protection obligations as any business (often with more sensitive data — beneficiaries, donors, safeguarding records), the same attackers (impersonation and payment fraud aimed at organisations known to move donated money), but thinner budgets, small teams wearing several hats, and a rotating cast of volunteers, trustees and part-time staff who all need some access to something. Meanwhile funders and grant-makers increasingly ask about data governance before they’ll release money, and trustees carry personal responsibility for getting this right.
The good news is disproportionate: Microsoft’s nonprofit programme gives eligible charities genuinely substantial licensing grants and discounts, and most charities we meet are using a fraction of what they’re entitled to — or paying for things they could have free. Sorting that alone often funds the security improvements.
Where charities and membership bodies lean on us hardest.
Eligible charities get significant Microsoft grants and discounts. We sort eligibility, claim what you’re entitled to, and configure it properly — often cutting spend while improving security.
Impersonation fraud and mailbox compromise hit charities hard because the money moves on trust. Practical defences sized to your budget — MFA, mailbox controls, verification habits.
When there’s no IT person, everything lands on whoever’s nearest. We become the IT function — patient, plain-English help for staff and volunteers alike.
Membership systems, donor records and casework backed up and recoverable — because losing a donor database is an existential event for a charity, not an IT incident.
Three principles that shape every charity we look after.
Right-sized kit, grant licensing claimed in full, nothing gold-plated. We’ll tell you when the cheaper option is genuinely fine — and when it isn’t, we’ll show you exactly why.
Volunteers and trustees get access that fits the role, starts when they do, and expires rather than lingers. The goodwill stays; the standing risk of forgotten accounts goes.
Plain-English reporting your board can actually use: what’s protected, what’s outstanding, what it costs — so trustees can evidence they’ve met their governance duty without translating jargon.
Yes, and it’s often the highest-value hour a charity spends with us. Microsoft’s nonprofit programme offers eligible organisations granted and heavily discounted licensing that many charities either don’t know about or have only partially claimed. We handle eligibility registration, work out the most cost-effective mix for your size, migrate you onto it, and configure the security features included — which are frequently better than what the charity was previously paying for.
Treat it like employment access, with expiry dates. Each volunteer or trustee gets their own account (never shared logins), scoped to what the role actually needs — a trustee reading board papers doesn’t need the donor database. Access is set to expire and be re-confirmed rather than living forever, and departures trigger same-day removal. It sounds bureaucratic; in practice it’s a few well-designed defaults, and it removes one of the most common ways charity data leaks.
Honestly, yes — but not because anyone singles you out. Most attacks are automated and indiscriminate: they look for weak passwords, missing MFA and unpatched systems wherever they exist. Charities then suffer a second, targeted layer: impersonation fraud, because attackers know charities move donated money on trust and goodwill. The UK government’s own breach surveys consistently show around a quarter to a third of charities detecting attacks each year — and the basics (MFA, patching, verification habits, tested backups) prevent the great majority of them.
Usually the honest comparison isn’t “managed IT versus nothing” — it’s managed IT versus the hidden costs of struggling: staff time lost to problems, a part-time volunteer “IT person” who’s become a single point of failure, licensing you’re overpaying for, and the uninsured risk of a data incident. Between nonprofit licensing savings and right-sizing what you already have, the net cost is often far smaller than expected. We’ll give you a clear figure up front — and if the honest answer is that you don’t need us yet, we’ll say so.
A straight conversation about what you’re running, what you’re entitled to under nonprofit licensing, and what your trustees need to see. No jargon, no upsell.