Charity IT runs on a contradiction: the sector handles some of the most sensitive data there is (donors’ finances, beneficiaries’ circumstances, safeguarding records) on some of the tightest budgets and oldest laptops in the economy, supported by whoever on the team is least afraid of computers. Every pound spent on IT feels like a pound taken from the mission, right up until the incident that costs the mission far more.
We support charities, social enterprises and non-profits across Scotland with IT that respects both sides of that contradiction: professional-grade security and reliability, priced and structured for organisations that answer to funders and trustees rather than shareholders, from our base at Dundee Technology Park.
What makes charity IT different
The licensing is genuinely different, and most charities miss it. Microsoft operates a nonprofit programme offering charity pricing on Microsoft 365 that commercial businesses cannot access. The programme’s shape has changed recently (Microsoft retired several of its long-standing free grant offers in 2025 in favour of deep discounts across more tiers), which caught many charities mid-budget and makes this exactly the kind of thing an IT partner should track for you. The net position remains: an eligible charity paying full commercial rates for Microsoft licensing is donating money to Microsoft, and registration for the nonprofit programme is usually the fastest saving in the sector. Our licence audit approach applies with extra force here.
Donor and beneficiary data carries the trust of the whole organisation. A commercial firm that leaks customer data loses customers; a charity that leaks donor or beneficiary data loses the thing it runs on. Where beneficiary records touch health, children or vulnerable adults, the data is special category with safeguarding obligations attached. The technical response is the standard stack done properly (encryption, per-role access, enforced MFA, tested backup) plus disciplined access control across a workforce that includes volunteers.
Volunteers and part-timers multiply the edges. High turnover, personal devices, shared logins born of licence scarcity: the classic charity IT estate is a security audit’s worst morning. The fixes are process-shaped rather than expensive: proper joiner/leaver handling for volunteers, role-scoped accounts, and the nonprofit licensing above, which removes the cost excuse for shared logins.
Governance is watching. Trustees carry responsibility for the charity’s assets and risks (OSCR’s guidance for Scottish charities includes exactly this kind of stewardship), funders increasingly ask about data protection and cyber security in grant applications and monitoring, and Cyber Essentials is appearing in public-sector grant conditions the same way it did in supply chains. IT competence has quietly become a fundraising asset.
Every pound is scrutinised. Charity budgets need predictability and defensibility: costs a treasurer can put in front of trustees and a funder without wincing. Fixed monthly per-user support with the nonprofit licensing savings offsetting part of it is usually a presentable story; surprise invoices are not.
What our charity IT support covers
- Nonprofit licensing, claimed and optimised. Eligibility registration, the right mix of discounted tiers for staff and lighter licences for volunteers, and re-checking at renewal as the programme shifts.
- Fully managed support at charity-realistic pricing. Help desk, monitoring, patching, security and backup for a fixed monthly figure your treasurer can budget years ahead; the cost guide rates apply, with the estate sized honestly rather than gold-plated.
- Security proportionate to the data. Enforced MFA, managed endpoint protection, phishing training that includes volunteers at induction, and Cyber Essentials when funders or contracts ask, which they increasingly do.
- Donor and case data protection. Backup with retention matched to your obligations, access controls that mirror safeguarding boundaries, and plain-English incident readiness via our incident response template, because a charity’s 72-hour ICO clock runs at the same speed as anyone’s.
- Hand-me-down estate management. Honest triage of donated and aged hardware: what can serve safely, what is a liability wearing a donation sticker, and a refresh path that fits grant cycles, per the budgeting guide.
- Grant-application support. The data protection, security and continuity paragraphs funders ask for, answered accurately from how your systems actually run, with evidence.
Sized for the sector’s reality
Our charity clients range from a handful of staff plus volunteers to multi-site operations. What they share: no IT staff, an “accidental techie” who deserves relief, and governance that needs the IT story to be tellable. Support is priced per user like any SME arrangement, with volunteer-scale access handled sensibly rather than billed like employees, and we will say plainly when the cheaper tier is the right one, because overselling a charity is a poor look and worse practice.
Frequently asked questions
Do charities get free or discounted Microsoft 365?
Eligible charities get significant nonprofit discounts across Microsoft 365 tiers. The programme changed shape recently (several historic free-grant offers were retired in 2025 in favour of broader discounts), so current entitlements are worth checking rather than assuming; we handle registration and the optimal mix as standard.
What should a small charity spend on IT?
A defensible pattern: standard per-user managed support rates for staff, offset by nonprofit licensing savings, plus a modest planned hardware provision instead of crisis purchases. The realistic total is usually less than the charity fears and more than the nothing it has been spending, and we will put the actual number in writing for trustees.
Do funders really ask about cyber security?
Increasingly, yes: data protection and security questions appear in grant applications, monitoring returns and public-sector funding conditions, with Cyber Essentials sometimes named. Good answers, evidenced, are becoming part of fundraising competence.
How do we handle volunteers’ access safely?
Individual accounts (nonprofit licensing makes this affordable), scoped to role, created and removed through a simple process, with MFA on everything. Shared logins are the sector’s most common bad habit and the first thing we retire.
Can you work with donated or old computers?
Yes, honestly: we assess what can serve safely (with supported software and encryption) and what cannot, then plan replacement around grant cycles. Unsupported machines holding beneficiary data are the one place we will not compromise; the Windows 10 arithmetic applies to charities too.
Are charities really targets for cyber attacks?
Attackers automate; they do not check charitable status. Charities hold donor payment data and personal records behind lighter defences, and sector incident reporting confirms regular targeting. The protections are the standard ones, made affordable by the licensing and priced for the sector.
Spend an hour, save a budget line
The free IT health check pays for itself unusually fast in this sector: unclaimed nonprofit licensing alone often covers a chunk of proper support. We audit your estate, your licensing position and your data protections, and give trustees a plain-English report with fixed prices. Get in touch; the mission deserves IT that will not embarrass it.