Tech Translated

IT Security & Technology Blog

Practical IT insights for Australian businesses. Our team covers cybersecurity advisories, compliance updates, and plain-English explainers on the technology your business relies on, published regularly as the landscape shifts.

Teal shield with heart illustrating cyber security for not-for-profits

Home Affairs and the ACNC Launch a Cyber Program for Charities

The federal government has decided charities need help defending themselves online. It’s worth understanding why, and what it actually asks of you.

On Wednesday 26 August, the Department of Home Affairs and the Australian Charities and Not-for-profits Commission launched the Not-for-Profit Cyber Uplift Community of Practice, a national program to lift cyber security across the charity sector. It sits alongside the ACNC’s broader Charity Resilience and Productivity Project with the ATO, which runs from October 2026 to June 2028, and the ACNC’s standing warning to charities to review their cyber security. The message from Canberra is blunt: charities are being targeted, and most aren’t ready.

Why the government is right to worry

Not-for-profits hold exactly the data attackers want, including donor payment details, member records, and sometimes health or welfare information about vulnerable people, but they usually run it on the leanest IT budget in the room. In the NFP environments we support across Australia, the recurring gaps aren’t exotic. They’re shared logins that never get changed, volunteers who keep their access months after they’ve left, and fundraising or CRM platforms plugged in by a well-meaning staff member without anyone checking where the data actually goes. A government webinar won’t close any of those on its own.

What to do while the program spins up

Treat the launch as a prompt, not a solution. A short, practical checklist beats waiting for a training series to roll out:

  • Turn on multi-factor authentication for every account, not just the finance team’s.
  • Write down who has access to what, and remove people the day they leave, paid staff and volunteers alike.
  • Check which third-party platforms hold your donor data, and whether they’d survive a breach.
  • Know your obligations: since 30 May 2025, an NFP turning over more than $3 million must report a ransomware payment to government within 72 hours.
The Oxfam Australia breach and the ACNC’s enforceable undertaking made one thing clear: for a charity, a data incident isn’t just an IT problem, it’s a trust problem. Donors who lose confidence don’t always come back.

How All IT helps

All IT helps Australian charities close these gaps without enterprise budgets, through practical not-for-profit IT support and cybersecurity built for lean teams. Our team cyber safety training turns volunteers from the weakest link into the first line of defence. If you’re not sure where your charity stands, get in touch.

Written by Michael Sacco, All IT Services. All IT is a Sydney-based managed IT provider supporting not-for-profits, hospitality groups and financial services businesses across Australia.

Related Guide

Cybersecurity for Sydney SMBs

Explore our complete guide to protecting your business from cyber threats.

Read the Full Guide →