Cybersecurity for charities: how a small IPC charity found a practical way to strengthen cybersecurity, without an IT team or a large budget

This case study has been anonymised upon request.

We are a Singapore charity that supports the development and wellbeing of children, particularly children from disadvantaged backgrounds and children with disabilities.

Our work also recognises the important role adults play in children's lives. We work with parents, educators and community practitioners, building their capability to create environments where children can thrive.

We are a small team with no dedicated IT person.

Get Started
Illustration of a charity staff member at their desk in the charity's office, with the organisation's heart logo on the wall behind them
0
People on the team who work in IT
1
Subscription across the team's work computers
US$39 (S$49)
A month, on annual billing

Cybersecurity became part of our responsibility, but we had no IT team

Over the past few years, the National Council of Social Service (NCSS) has increasingly highlighted cybersecurity and data protection as important aspects of good governance for charities. As an organisation entrusted with information about children and families, as well as donations and public funds, we have always sought to handle this responsibility with care. These growing expectations also prompted us to consider how we could further strengthen our cybersecurity practices.

The challenge was figuring out what good cybersecurity could look like for an organisation of our size, and finding something we could realistically afford and manage.

The push to strengthen our cybersecurity came from recognising that this was increasingly part of being a responsible charity.

For two or three years, NCSS had been running sessions for charities on protecting data and strengthening organisational practices. Cybersecurity was increasingly discussed alongside financial sustainability, risk management and board governance.

What made the issue more real were the stories we heard through sector sessions and conversations with other charities: real examples of organisations experiencing cybersecurity breaches and the consequences that followed.

"When NCSS shares real-life stories about cyber breaches... it's really scary how the breaches happen. If there's no protection, you can lose not only information, but also people's trust and your reputation."

Staff of the Charity

We knew cybersecurity mattered. We just didn't know where our gaps were.

Like many small charities, our systems had grown organically.

Being a small team with no dedicated IT person with everyone's plate already full, we knew cybersecurity was important, but it was difficult to know where to begin.

"To be fair, I think we didn't know where we needed to be protected, or what was exposing us."

Executive Director

Our first step was not to buy a product.

Instead, we reached out to a contact who works in cybersecurity. We engaged him with an honorarium to facilitate a half-day workshop with the team.

We talked through our everyday practices and the kinds of risks a small organisation like ours needs to consider. He helped us identify areas where our cybersecurity practices could be strengthened.

One of the most useful insights was that cybersecurity was not simply about buying software. Some of the areas for improvement were rooted in everyday habits and practices.

The workshop also gave us a clearer sense of what we needed. Based on the recommendations, we then researched the options available in the market and considered what would be appropriate for an organisation of our size, needs and resources.

Finding something simple enough for a small team to manage

The ED had previously heard StrongKeep co-founder Gaurav Keerthi speak at a sector event. One thing had stayed with her: there might be a cybersecurity option designed with smaller organisations and their budgets in mind.

"I listened to a talk with Gaurav and I thought, this could be an option, because it's affordable. You always think of cybersecurity as very expensive."

Executive Director

The invitation into the world of cybersecurity prompted us to think more carefully about how our team actually works.

Most of the week, staff are not sitting together in one office. We work across programme spaces, community settings, meetings and from home. Protecting only an office network therefore did not necessarily reflect the way our organisation operates.

We needed something that could travel with our laptops and support the everyday behaviour of our team.

StrongKeep addressed several of the gaps identified during our cybersecurity workshop.

The ED also explored larger consumer cybersecurity brands. But for a small charity without an IT department, the question was not simply whether the technology worked. It was whether we could understand it, manage it and get support when we needed it.

And, of course, cost mattered.

StrongKeep offered protection for devices at US$39 (S$49) per month on annual billing, with its pricing published openly rather than requiring an individual quotation.

"It's affordable and the offering was important."

Executive Director

We now know what we have in place, and can explain it

When our Board, funders or partners ask what we are doing about cybersecurity, we can now clearly explain what is in place, what it protects and what it costs.

A colleague within the team is able to manage the platform without needing to be an IT specialist, making it practical for our small team.

The process has helped us build on our existing cybersecurity practices, adding several additional layers of protection across our work computers. More importantly, it has helped the team better understand where some of our vulnerabilities were and the role each of us plays in keeping the organisation and the information we hold safe.

It did not remain theoretical for long.

One morning, one of our staff received an email from one of their actual partners. It came from the partner's real email address and asked her to click a link to update her details.

The partner's email account had been compromised.

Nobody at our charity clicked the link. Instead, the team stopped, checked and contacted the partner. The issue was dealt with that morning.

For us, that moment reinforced something important: cybersecurity is not only about technology. It is also about creating awareness and habits within the team, knowing when to pause, question and check.

Asked whether she would recommend StrongKeep, we came back to two things: affordability and having a level of protection that makes sense for a small organisation.

"I would say yes, I would recommend it. Because it's affordable... and the technical components, it's good. It's good enough."

Executive Director

Company Profile

  • Organisation in Singapore: IPC Charity
  • What we do: Support children's development and wellbeing, while building the capability of the adults in their lives
  • Team size: Less than 10 staff
  • Before StrongKeep: No organisation-wide cybersecurity product
  • Also considered: Home antivirus with a separate firewall and VPN, as well as two other suppliers
  • Our goal: Strengthen cybersecurity as part of our broader governance responsibilities in a way that a small charity without an IT team could realistically manage

What our charity has now

  • Additional layers of cybersecurity protection through one subscription
  • A system that a team member can manage without being an IT expert
  • Greater awareness of cybersecurity across the organisation
  • A clearer answer when our Board and funders ask how we protect the information entrusted to us
  • Most importantly, a stronger shared understanding that protecting our organisation and its data is everyone's responsibility

When your board asks about cybersecurity, have an answer.

Get Started