Login

Governance360 logo

Charities, Sports, Housing Associations, Credit Unions and more

Perfect for any size and type

Find out more about our partnership options

Explore our range of features

Board Meeting Portal

Risk Register Tool

Board Accountability Tools

Board Compliance Tools

Director Academy

Start a free trial in less than 12 minutes

More about Governance360

Pricing Plans

Find a Partner

Run better board meetings

Manage and mitigate risk

Build board accountability

Upskilling Directors

Platform overview

Trial Governance360

Start your free trial today

About Governance360

Pricing Plans

Resources / Insights

Three Places Cyber Risk May Be Hiding in Your Charity’s Boardroom

Three Places Cyber Risk May Be Hiding in Your Charity's Boardroom

Recent figures from the UK Government show 28% of charities reported a cyber breach or attack in the past year, with phishing the most common cause. All three risks thrive in the same conditions: nobody owns access, and there’s no record built around governance events – which is a structural gap cloud storage doesn’t fix easily, however carefully it’s organised.

  • Trustees have a duty to protect charity assets and data (for example the Charity Commission treats cybercrime as a fraud risk, not just an IT one)
  • Three risks most boards overlook include: informal AI use, permission drift on shared drives, and papers circulated by email
  • SharePoint and personal Google Drive are file storage, not governance tools – access sits with IT or an individual, not the board admin
  • A governance-specific audit trail records decisions and declarations, not just file access – which is what a regulator actually wants to see

Why This Matters More Than It Feels Like It Does

Cybercrime doesn’t feel like a boardroom issue. It feels like something the IT team, or the bank, or the finance manager deals with. But the Charity Commission treats it as a governance matter, not a technical one – and for good reason. Trustees have a duty to protect the charity’s assets and manage its resources responsibly, and the regulator, working with the National Cyber Security Centre, has published dedicated guidance reminding trustees that this duty covers digital assets and data as much as it covers money in the bank.  (It is great guidance btw – on a personal front i’d certainly recommend you investigate it using the links at the bottom of this article).

The scale is bigger than most boards assume. The Charity Commission opened over 600 fraud cases and around 100 separate cybercrime cases in a single year, and government’s own Cyber Security Breaches Survey found 28% of charities reported a breach or attack in the past 12 months – with phishing by far the most common route in. The median cost of a UK cyber-attack now sits above £22,000, a sum that would derail the annual budget of many smaller charities outright.

None of this requires a charity to have done anything wrong. It requires three very ordinary habits, present on most boards, that quietly add up to risk.

Three Places Cyber Risk May Be Hiding in Your Charity’s Boardroom

AI tools working on board papers, without anyone deciding they should

It’s worth asking plainly: has anyone on your board or staff team already pasted a set of board papers into an AI tool to summarise, draft or check them? For most organisations, the honest answer is probably yes.

This isn’t a fringe behaviour. UK research on workplace AI use found that 62% of senior leaders use unapproved “Shadow AI” tools at work, compared with 31% of employees below decision-maker level – senior staff are, if anything, more likely to work around the rules than junior colleagues, often because they have the broadest access to sensitive material. On a charity board, that means the person most likely to paste a confidential set of papers into a personal AI account is often the chair, the CEO or the treasurer.

The issue isn’t AI itself. It’s that nobody’s decided where it’s appropriate, so it happens quietly and inconsistently, with no record of what went in or where it ended up.

Shared drive permissions that have quietly drifted

Most boards start with good intentions on a shared drive – a folder for papers, sensible permissions, maybe a naming convention. Eighteen months and three staff changes later, former trustees can often still open last month’s finance papers, volunteers have access nobody remembers granting, and no one is quite sure who can currently see what.

This isn’t negligence. It’s what happens by default when access is managed manually and nobody owns the job of tidying it up. The fix isn’t a stricter policy – it’s a system where access is tied to a person’s actual current role, and automatically removed when that role ends.

Board papers still arriving on email

Even boards that have a “proper” system often fall back on email the moment something’s urgent – papers sent as attachments, chased in reply-all threads, forwarded to a personal address because someone’s struggling to log in from their phone. Each forward creates another copy, in another inbox, outside anyone’s control.

This is the same pattern covered from the meeting-quality angle in our piece on moving your board off email – but the cyber security version of the problem is arguably more serious, since every forwarded copy is a new place sensitive material can be lost, stolen, or accessed by someone who’s since left the organisation.

Why “Just Store It Somewhere Safe” Doesn’t Fix This

The instinctive fix is to move everything onto SharePoint or a shared Google Drive and call it done. That helps a little, but it doesn’t solve the actual problem, because both are general-purpose file storage, not governance tools.

Two things in particular don’t transfer:

Access ownership. On SharePoint, permissions typically sit with IT, not the board admin. Adding or removing a board member usually means raising a ticket – which is exactly why access quietly drifts, since nobody day-to-day actually owns keeping it current. A personal Google Drive is a step worse again: it’s tied to one individual’s own account, not the organisation, so if that person leaves, the papers, the version history and the access control all leave with them.  Which is something that we’ve seen a few times in real life – and it is painful.

A governance-specific audit trail. SharePoint and Google Drive log file access – who opened what, and when. Neither knows what a declaration of interest is, or that a particular upload was the paper behind a specific board decision. A regulator or auditor asking “how was this decision reached, and who saw the papers behind it” wants a governance record, not a generic file log. That’s a structural difference, not a storage one – it’s about the workflow understanding what a board actually does, not just where a document happens to sit.

Put together, this is why the three risks earlier in this article aren’t really about storage location at all. AI tools, permission drift and email chains all thrive specifically where access isn’t owned by anyone and there’s no record built around governance events – which describes most SharePoint and Drive setups by default, however well-intentioned the original folder structure was.

Pro Tip: If you can’t currently answer “who has access to our board papers right now, and why?” in under a minute, that’s usually the clearest sign this needs attention – and a sign that whatever is storing your papers isn’t actually managing your governance.

Governance360 holds Cyber Essentials Plus certification, the UK government-backed scheme that independently verifies an organisation’s cyber security controls – one factor worth considering alongside ease of use when comparing board portals.

Frequently Asked Questions

Do charities really get targeted by cybercrime, or is this mostly a business problem?

Charities are targeted directly. Government figures show 28% of charities reported a cyber breach or attack in the past year, and the Charity Commission opened around 100 cybercrime-related cases in a single year, alongside over 600 fraud cases.

What’s the most common way charities are attacked?

Phishing – where someone is tricked into clicking a malicious link or revealing sensitive information, often by an email impersonating a trustee, supplier or the charity’s own bank.

Is it wrong for trustees to use AI tools at all?

No. The problem is informal, undecided use – papers going into a personal AI account with no agreed boundary. A charity that decides where AI is appropriate and gives people a proper, controlled place to work from removes most of the risk without banning the tools.

How do we know if our shared drive permissions have drifted?

If you can’t quickly list who currently has access to board papers and confirm each person still needs it, permissions have likely drifted. This is common and rarely deliberate – it’s simply what happens when access isn’t reviewed as people join and leave.

We already use SharePoint or Google Drive – isn’t that secure enough?

Both can be configured securely, but neither is built for governance specifically. Permissions on SharePoint typically sit with IT rather than the board admin, which is why access tends to drift. Personal Google Drive is tied to one individual’s account rather than the organisation. Neither logs governance events – declarations of interest, decisions, who saw which paper before a vote – in the way a board portal’s audit trail does.

Do we need a big budget to fix this?

No. Most of the risk here comes from habits and access sprawl, not from a lack of security spend. A single controlled home for board papers, with access tied to current roles, addresses the bulk of it.

Key Takeaways

  1. Cyber risk is a governance issue, not just an IT one: The Charity Commission treats it as part of a trustee’s duty to protect charity assets.
  2. The real risk is rarely a dramatic hack: It’s AI tools, drifting permissions and email chains – all quiet, all common, all fixable.
  3. Senior figures are often the biggest risk: Chairs, CEOs and treasurers are statistically more likely to use unapproved tools than junior staff.
  4. File storage isn’t governance: SharePoint and personal Google Drive can hold documents, but neither owns access the way a board admin needs to, or records governance events the way a regulator expects.

The bottom line: Protecting a charity from cybercrime isn’t really about where papers are stored – it’s about who owns access and what record exists of how decisions were reached, which is a workflow question, not a storage one.

Sources

Reading Time: 7 minutes

Some of the research and drafting for this article may have been produced with assistance from Claude, Anthropic’s AI assistant. Content is then reviewed, edited and augmented with the experience of the Governance360 team before publication. Sources are provided at the foot of this article so you can verify the information directly.

© 2026 Governance360, a trading name of Board Secure Ltd (Company No. 11363367), registered office: Cardiff, Wales. Governance360 is Board Secure Ltd's flagship product. Board Secure Ltd is the sole parent of Governance360 Limited, a separate dormant company held for brand protection.