IT support for charities and non-profit organisations

In May 2025, Microsoft ended the grant of ten free Microsoft 365 Business Premium licences that tens of thousands of UK charities had quietly run on for years. Around 45% of affected small charities moved everyone to the free Business Basic tier. That saved the money. It also stripped device management, conditional access, and endpoint protection from organisations holding child protection notes and domestic abuse case files.

Nothing visibly broke. The exposure just went up. Which is why IT support for charities has to start from sector reality rather than a standard SME service menu.

Fewer than 12% of charities under 50 staff employ anyone in IT, so technology decisions land on a finance manager who did not ask for them. Budgets get justified line by line to a board. And the data in your case management system is often more sensitive than anything a commercial business of the same size will ever touch.

Computercentric has supported West Midlands organisations for over 20 years, including social enterprises and CICs such as Goodwill Solutions CIC. This page covers the licensing trap, the security position, what trustees are liable for, and how to fund it.

Talk to us about IT support for your charity. Call 01922 830000, WhatsApp or email.

Team of IT professionals providing reliable and tailored IT support for small businesses in Birmingham, ensuring smooth operations and robust cybersecurity.

What charity IT support should cover

A proper managed service goes well beyond a number to ring when something breaks:

  • Helpdesk support for paid staff, volunteers and trustees
  • Microsoft 365 administration, nonprofit licensing and security configuration
  • Cyber security: MFA, conditional access, email authentication and endpoint protection
  • Cyber Essentials certification support, and the evidence funders now ask for
  • Backup and disaster recovery for Microsoft 365, servers and case management data
  • Support for the platforms you run, from Charitylog and Beacon to Donorfy and Salesforce
  • Connectivity and WiFi across head office, community sites, shops and outreach locations
  • Data protection controls for donor records, Gift Aid and safeguarding files
  • Joiner and leaver processes built for a workforce that includes unpaid volunteers
  • Hardware supply, leasing and certified secure disposal

The Microsoft licensing change that caught out thousands of charities

Microsoft withdrew both the ten-seat free Business Premium grant and the free Office 365 E1 grant from 1 July 2025. The single free grant for small and mid-sized non-profits is now Microsoft 365 Business Basic, up to 300 seats.

Existing grants did not vanish on that date. They expire at each charity’s first contractual renewal on or after it, and unless an administrator intervenes, the ten free Business Premium licences convert automatically to paid at £4.20 per user per month plus VAT, producing an unexpected £504 annual bill. 

Microsoft emails warnings at 90, 60 and 30 days, and those emails routinely go to a mailbox nobody monitors.

What Business Basic quietly removes

Business Basic is not a cut-down Premium. It is a different product. You keep email, Teams, OneDrive, SharePoint and the browser versions of Word and Excel, and lose the desktop apps.

The security losses are the serious ones. Microsoft Intune goes, so nobody can enforce disk encryption, push patches or wipe a lost laptop. Entra ID P1 goes, taking conditional access with it. Defender for Office 365 goes, which means no Safe Links or Safe Attachments, the two controls that catch credential-harvesting phishing. And without Purview data loss prevention, nothing stops a volunteer emailing safeguarding notes outside the tenant.

Getting the licence mix right

The answer is rarely all-Basic or all-Premium. Around 35% of charities landed on the sensible middle: Business Premium for executive, finance and safeguarding leads, free Business Basic for sessional staff, shop volunteers and trustees who only need a mailbox and Teams.

Check one thing while you are in there. A conditional access policy that requires a Premium licence does not delete itself when the licence lapses. It stops applying, while continuing to look perfectly healthy in the admin console.

Independent audits suggest small and mid-sized charities waste 25% to 40% of their annual licensing budget on redundant subscriptions, with 12% to 18% of paid Microsoft 365 licences assigned to people who have already left. Buying retail rather than through the nonprofit programme adds a 300% to 400% premium on top. 

Our IT consultancy work usually starts here.

Computercentric — Independent IT Consultancy
Birmingham & West Midlands
Birmingham City Centre Jewellery Quarter Aston Erdington Digbeth Bordesley Green Moseley Selly Oak Edgbaston Harborne Sutton Coldfield Lichfield Walsall Solihull Bournville Aldridge HQ

Cyber security: the sector is getting less prepared, not more

The DSIT Cyber Security Breaches Survey published on 30 April 2026 surveyed 1,085 UK charities. It found that 28% identified a breach or attack in the previous twelve months, roughly 57,000 organisations.

The number that should worry trustees is a different one. Cyber security was treated as a high priority by senior management in 60% of charities, down from 68% the year before. Among charities under £100,000 income it collapsed from 64% to 53%.

Only 30% have a named trustee with formal responsibility, and just 13% have ever consulted an external IT or cyber security provider, against 27% of businesses. Meanwhile, the average cost of the most disruptive breach was £8,690, well above the £3,550 commercial SME average, because charities pay for forensics and lose donations while they recover.

Where the attacks actually come from

Phishing is the whole story. Of charities reporting a breach, 85% identified phishing. Impersonation attacks have fallen to 7% from 11%, and account takeovers to 1% from 3%, largely because MFA adoption has improved.

Charities get targeted in a specific way. Criminals exploit a culture built on trust and helpfulness, sending urgent requests that appear to come from a chief executive or trustee. Add a volunteer workforce on shared personal laptops and the attack surface looks nothing like a commercial office of the same headcount.

Supply chain risk has moved from theory to experience. The Beacon CRM breach in August 2026 saw attackers download database backups holding supporter names, donation histories and Gift Aid declarations across multiple non-profits, yet only 9% of charities review their suppliers’ security.

The defences are not exotic: MFA everywhere, conditional access blocking unmanaged devices, DMARC set to reject, endpoint protection on volunteer laptops too, patching within 14 days, and access removed the day someone leaves.

What it needs is someone whose job includes checking that it still works, which is the difference between proactive and reactive IT support.

Local coverage

IT support for charities across the West Midlands & Staffordshire

We support charities, CICs and non-profits in each of the areas below, keeping costs predictable, licensing right and systems secure wherever your teams and volunteers work.

West Midlands

Birmingham

  • Managed IT support
  • Cybersecurity & EDR
  • Cloud & Microsoft 365
IT services in Birmingham
West Midlands

Walsall

  • Managed IT support
  • Backup & disaster recovery
  • Proactive monitoring
IT services in Walsall
West Midlands

Wolverhampton

  • Managed IT support
  • Cybersecurity & compliance
  • Network management
IT services in Wolverhampton
West Midlands

Sutton Coldfield

  • Managed IT support
  • Microsoft 365 management
  • Business continuity
IT services in Sutton Coldfield
Staffordshire

Lichfield

  • Managed IT support
  • Cybersecurity & EDR
  • Backup & recovery
IT services in Lichfield
West Midlands

Aldridge

  • Managed IT support
  • Cloud services & hosting
  • IT consultancy
IT services in Aldridge
West Midlands

Bournville

  • Managed IT support
  • Endpoint protection
  • Business continuity
IT services in Bournville

Cyber Essentials and why funders are asking

Cyber Essentials covers five controls: boundary firewalls, secure configuration, user access control, malware protection and patching within 14 days. Fees are fixed by size, at £320 plus VAT for under ten employees and £440 for ten to 49, and certification includes £25,000 of cyber liability insurance for organisations turning over under £20m.

It has stopped being optional in several places. Ministry of Justice and Probation frameworks require valid certification throughout the contract term, Crown Commercial Service contracts mandate it, and NHS-commissioned charities must complete the Data Security and Protection Toolkit, which maps onto the same controls. National Lottery Community Fund applications over £100,000 now carry governance questions where it counts as evidence of good practice.

The honest budgeting point is that the fee is the small part. If devices are unmanaged and MFA is not enforced across volunteer accounts, remediation typically adds £1,000 to £3,000 before you can certify.

Donor data, safeguarding records and trustee liability

Charity data protection gets discussed as if donor records were the whole problem. For any charity delivering services to people, they are the easier half.

The fundraising consent trap

Commercial businesses can use the PECR soft opt-in to market to existing customers without explicit consent. That exemption has historically not applied to non-profit fundraising or campaigning, so emailing or texting an individual donor needs prior, explicit consent. Event attendees and one-off donors cannot simply be added to a list.

Postal and telephone fundraising can run on legitimate interests, but only with a documented assessment and numbers screened against the TPS every 28 days.

Safeguarding data raises the bar

If your charity works with children, vulnerable adults, refugees or survivors of domestic abuse, you are processing special category data. That needs an Article 6 basis and an Article 9 condition, usually Schedule 1, Part 2, Condition 18 of the Data Protection Act 2018, which permits safeguarding processing without consent where seeking it would prejudice protection. Relying on it legally requires an Appropriate Policy Document.

The consequences of exposure are not financial. Mermaids was fined £25,000 after an internal working group set up a file share without access restrictions, publishing 780 pages of special category data about 550 vulnerable young people. The failing was configuration, not attack.

That changes what good looks like: access restricted at record level so a fundraiser cannot browse case notes, access logs somebody actually reviews, and a Data Sharing Agreement plus a DPIA before high-risk sharing with a council or an ICB. Retention schedules differ too, with child safeguarding files carrying a 75-year expectation following IICSA against six years for Gift Aid declarations.

What trustees are actually on the hook for

Under section 1 of the Trustee Act 2000 and Charity Commission guidance CC25, trustees must take reasonable care to safeguard the charity’s property, money and data, and ignorance of digital security is not accepted as a defence. CC8 now requires dual authorisation on all electronic bank transfers and mandate changes, a direct response to mandate fraud.

Reporting runs on two tracks. A personal data breach means ICO notification within 72 hours. A Serious Incident Report goes to the Charity Commission promptly for anything causing significant harm to the charity, its assets, beneficiaries or reputation, including cyber fraud losses over £25,000. Anything meeting the ICO threshold is automatically a Serious Incident as well.

That framing is what gets security spending approved at board level. It is not an overhead competing with frontline delivery. It is part of a duty trustees already hold.

Multi-site charities, shops and volunteers

Most IT providers picture a charity as one office with fifteen desks. The reality is usually a head office, two delivery sites, a couple of shops, a van, and staff at home on Fridays.

Charity shops are their own problem: degraded ADSL, no structured cabling, and an EPOS till that stops taking money the moment the line drops. Cloud-managed 4G or 5G failover routers with dual SIMs fix most of it cheaply. Community hubs need VLAN segmentation so public WiFi is genuinely isolated from the network carrying casework and safeguarding databases, which is one of the most common gaps we find on a first site survey.

Volunteers are where the real weakness usually sits. High turnover is structural, not a failing, so the answer is process rather than restriction.

Every volunteer gets a named account, which the free Business Basic seats make affordable, because shared logins like [email protected] destroy the audit trail data protection depends on. Access is granted by role, personal devices are handled with Intune mobile application management so charity data can be wiped selectively without touching family photos, and offboarding is automated so access ends when the placement does.

Trustees deserve separate thought. They are often the least technical users, frequently on personal email, and publicly listed on the Charity Commission register, which makes them an obvious impersonation target. Board papers going to personal Gmail accounts is a risk worth closing.

The systems charities run

Charity software is a distinct ecosystem, and general IT providers often have not met any of it.

Charitylog dominates social care and case management, with complex permissioning that makes disciplined offboarding essential. Beacon runs from around £33.50 a month for fundraising and Gift Aid, and Donorfy is free under 500 records. At the larger end, Salesforce Nonprofit Cloud gives ten free licences but regularly demands £10,000 to £40,000 in implementation before anyone logs in.

Finance sits mostly in Xero or QuickBooks, with Sage where restricted fund accounting gets complicated. The friction is Gift Aid: donations arrive through JustGiving, Stripe, a website form and a card reader at an event, then get re-keyed by hand. Beacon and Donorfy file schedules to HMRC by API, but submissions fail silently where donor records lack complete postcodes or valid declarations.

We look after the environment these platforms run in and the connections between them

Where a fault sits inside a vendor’s application, we deal with the vendor rather than leaving your operations manager running two support conversations at once.

Making the IT budget work harder

UK charities spend on average 2% to 3.5% of total expenditure on IT and digital, and micro charities under £100,000 income spend under 1%, leaning heavily on donated equipment and volunteer labour.

The Charity Digital Exchange, operating as TechSoup UK, is the main route to donated and discounted software, with Cisco, Adobe, Bitdefender, Zoom, Box and Norton participating. It runs on cost recovery, so you pay an admin fee of roughly 5% to 15% of retail value. Google Workspace for Nonprofits is free for up to 2,000 users, and Adobe Express is free outright.

The trap is enthusiasm. Claiming free licences from six vendors produces six systems, four of which overlap, all of which someone has to administer.

Several funders will write hardware into a bid: National Lottery Awards for All up to £20,000, the Clothworkers’ Foundation up to £25,000 for capital only, and The Fore up to £30,000 for core capacity. Ongoing support fees and annual licences almost always come from unrestricted reserves, which is why they are harder to fund than the kit.

Leasing turns a capital request into a predictable monthly cost, though under CC8 a lease counts as a credit commitment needing explicit board sign-off. Our TechPlan IT leasing exists for this, and how to reduce IT costs covers the wider review.

Disposal carries a legal duty. WEEE Regulations require an Environment Agency licensed carrier, and a factory reset does not destroy data.

Any device that has held safeguarding records needs cryptographic erasure to ADISA or NIST 800-88 standard, with a Certificate of Data Destruction, which our secure data and green equipment disposal service provides.

AI: adoption has outrun governance

The Charity Digital Skills Report 2026 found 88% of charities using AI day to day, up from 76% in 2025 and 61% in 2024, mostly for reporting and drafting funding bids. Governance has not kept pace, and 49% cite data privacy risk as a barrier.

The danger is easy to state. Free consumer AI models use prompts to retrain, so a support worker pasting case notes into a public chatbot has created a personal data breach under UK GDPR, and nobody will notice for months.

The fix is architectural rather than disciplinary. Run AI inside your tenant, where Microsoft Copilot’s commercial data protection keeps prompts out of the public model, then write a short policy covering approved tools, a flat ban on entering names or case details into any prompt, and human review before anything reaches a funder. 

Our guide to AI for small businesses suits staff and trustees who want the basics.

IT support for charities in Birmingham and the West Midlands

The West Midlands has between 10,500 and 11,200 registered charities, roughly 2,600 to 2,850 of them in Birmingham, plus about 400 each in Walsall and Wolverhampton. Around 72% are micro or small organisations with no dedicated IT support of any kind.

The regional pressure is real. Following Birmingham City Council’s Section 114 notice, municipal grants and non-statutory contracts were cut, and BVSC surveys indicate over half of small-to-mid West Midlands charities hold under three months of reserves. There is no margin for an £8,690 breach recovery.

Computercentric is based in Aldridge, near Walsall, so Birmingham, Wolverhampton, Sutton Coldfield, Lichfield, Bournville and the Black Country are all easy reach. Most support runs remotely, and when a site needs an engineer we attend without the travel surcharges that come with providers based further out.

Goodwill Solutions CIC is a good example of the work. A community interest company running logistics across multiple sites while delivering vocational training, they rely on us for IT support, their phone system, connectivity, hosting, anti-ransomware protection, Microsoft 365 and their physical network and WiFi.

We support charities in BirminghamWalsallWolverhamptonSutton ColdfieldLichfieldAldridge and Bournville.

Frequently asked questions about IT support for charities

How much does IT support for a charity cost in the UK?

Managed IT support for UK charities generally runs at £45 to £65 per user per month under ten users, £35 to £50 for ten to 49, and £28 to £40 above that. It normally covers unlimited remote helpdesk, Microsoft 365 management, patching, managed endpoint protection, backup monitoring and joiner and leaver processes.

Major hardware purchases, cabling and out-of-hours callouts usually sit outside the monthly fee.

What changed with Microsoft 365 nonprofit licences in 2025?

Microsoft ended the ten free Business Premium licences and the free Office 365 E1 grant from 1 July 2025, replacing them with a single free grant of up to 300 Business Basic seats.

Paid plans carry discounts of up to around 77%, putting Business Premium at £4.20 per user per month. Grants expire at each charity’s first renewal after that date and convert automatically to paid unless an administrator acts.

Is Microsoft 365 Business Basic enough for a charity?

For volunteers and sessional staff who need email, Teams and a shared calendar, yes. For anyone handling donor data, finance or safeguarding records, no, because Business Basic excludes Intune device management, Entra ID P1 conditional access, Defender for Office 365 and Purview data loss prevention.

A mixed model, with Business Premium for staff in sensitive roles, is normally the right balance.

How do charities handle donor consent and fundraising emails?

The PECR soft opt-in that commercial businesses rely on has historically not applied to charitable fundraising, so email and SMS appeals to individual donors need prior, explicit consent. Event attendees and one-off donors cannot simply be added to a list.

Postal and telephone fundraising can run on legitimate interests with a documented assessment, and phone numbers screened against the TPS every 28 days.

Can you support volunteers and trustees as well as paid staff?

Yes, and it is where charity IT differs most from commercial IT. Volunteers need named accounts rather than shared logins, access scoped to their role, and mobile application management on personal devices so charity data can be wiped selectively when a placement ends.

Trustees need a mailbox on the charity domain with MFA enforced, because board members are publicly listed and routinely impersonated.

Talk to us about IT support for your charity

If your charity is running on lapsed Microsoft licences, has volunteer accounts nobody has reviewed since 2023, or has never tested a restore, none of that is unusual. It is what happens when nobody’s job includes looking.

The reason to deal with it now is that the sector is moving the wrong way. Board attention on cyber security fell eight points in a single year while phishing accounted for 85% of breaches, and over half of West Midlands charities hold under three months of reserves. Funders are asking harder questions about data resilience than they were two years ago.

A conversation costs nothing. We will review your licensing, security position and backup arrangements and give you an honest picture of the gaps and what closing them costs.

Call us on 01922 830000 or contact us online to arrange a review. If you are still comparing providers, our guides to choosing the best IT support provider and why organisations outsource IT support cover the questions worth asking first.

Join our mailing list

If you’d like to receive useful information, news and advice to help you stay smart and ahead of the game when it comes to IT in business, then let us know below!  We won’t spam you, and you can opt-out any time.

Latest from Instagram