Digital security & resilience

Security for causes with real adversaries

Campaigning organisations don't just have audiences — they have opponents. We harden your websites, protect your supporter data and keep you online, because going dark mid-campaign is how causes lose.

What you get

Defence in depth, sized for the third sector

Security audits

A plain-English review of your website, email, accounts and data practices, with fixes ranked by real risk — not fear.

Website hardening

CDN protection, rate limiting, patching discipline and static-first architecture that shrugs off attack traffic.

Supporter data protection

Data minimisation, encryption, access control and retention rules — because the safest data is the data you don't hold.

Incident response planning

A rehearsed, written plan for the bad day — who does what, who's told, and how you're back online in minutes, not days.

Staff security training

Phishing awareness, password managers and two-factor everywhere — the human layer, where most real attacks land.

Account & email security

Domain protection, SPF/DKIM/DMARC, and locked-down admin access — so nobody sends as you or signs in as you.

Why it matters

Your opponents don't need to win the argument if they can take you offline

For most businesses, security is about avoiding embarrassment. For campaigning organisations it's existential: a site takedown during your biggest media moment, a leaked supporter list, a hijacked social account posting in your name — each one damages trust that took years to build.

The good news: most attacks that hit third-sector organisations are preventable with unglamorous, well-executed basics. Strong authentication, hardened hosting, minimal data, trained people, and a plan for the bad day. That's what we implement — defensive security, sized and priced for organisations that run on donations.

We work alongside your existing IT support, and everything we set up is documented so it survives staff turnover.

Black and white photograph of a march with hand-made protest signs
Questions

Digital security FAQs

Would anyone really target a small charity or campaign group?

Unfortunately, yes. Campaigning organisations attract opponents as well as supporters — and beyond targeted harassment, every organisation holding supporter data is a target for ordinary criminal phishing and ransomware. Small usually means less defended, not less interesting.

What does a security audit cover?

Your website and hosting, domain and email configuration, account access and password practices, supporter data storage, and staff-facing risks like phishing. You get a plain-English report with fixes ranked by risk — most organisations can close the worst gaps quickly.

Can you protect our site from being taken down during a campaign?

We harden sites against traffic-based attacks with CDN protection, rate limiting and static-first architecture, and we prepare an incident plan so that if something does happen mid-campaign, recovery is measured in minutes rather than days.

What are our GDPR duties if supporter data is breached?

Serious breaches must be reported to the ICO within 72 hours, and affected supporters may need to be told. The better answer is preparation: minimising the data you hold, encrypting it, controlling access, and having a rehearsed response plan — all things we set up.

Do you work with our existing IT support?

Yes — we're the security specialists alongside whoever runs your day-to-day IT. We audit, recommend and harden; general IT support keeps running the systems. It's a collaboration, not a turf war.

When did someone last check your defences?

A security review is the cheapest insurance your organisation will ever buy.

Get a review
Get in touch

Tell us what you're protecting

Every project starts with a conversation — confidential, jargon-free, and honest about what you do and don't need.

We reply to every message, usually within one working day.