Charities & Funds

Information security for charities and funds

Kynexis Information Security helps non-profits, charities and NGOs to manage digital risks proportionally. The approach connects societal impact, trust, donor data, payment flows and suppliers with the CBF Recognition Scheme 2026 and, where appropriate, the Partos Code of Conduct.

Worker organises reliefs for a social organisation
Sectoral approachDigital resilience protects trust and societal impact.

Your context

Digital reliability supports societal impact

Charities and NGOs process data from donors, volunteers, employees, participants and sometimes vulnerable target groups. Websites, CRM, payment platforms, cloud systems and international partners together form a digital chain that requires careful governance and clear agreements.

A proportionate approach targets capacity at the risks that can most affect trust, revenue and service. Kynexis Information Security concretely develops these priorities and translates them into ownership, action and board-level reporting.

Focus areas

Reducing digital risks to manageable choices

The scope is tailored to the organisation, its societal mission, critical processes and digital dependencies.

Donators, participants and CRM

Privacy, access, data sharing, fundraising platforms, retention periods and reliable communication.

Payment flows and fraud

Strong authentication, function separation, change control and incident reports.

International chains

Suppliers, local partners, sensitive data flows and workable arrangements.

Continuity

Critical processes, recovery, crisis roles and accessibility for stakeholders.

Governance and digital resilience

CBF Recognition Scheme 2026 and Partos for NGOs

The CBF Recognition Scheme 2026 sets standards for risk management, privacy and information security. For category C, D and E, standard 3.5.1 requires current privacy and information security policies with organisational and technical measures. Kynexis Information Security connects these requirements with actual processes and evidence.

For organisations in development cooperation and humanitarian aid, the 2019 Partos Code of Conduct provides an additional framework for organisational quality, integrity and public confidence. Partos is only relevant to this NGO sub-target group. Digital risks are carefully linked to international chains, suppliers, GDPR and sensitive data.

Read about the CBF Recognition Scheme 2026 and information securityView the Partos Code of Conduct and integrity informationRead the customer case information security at a social organisation

Your result

Clear priorities and demonstrable progress

Kynexis Information Security translates research into decision-making information for the board and executive management and into concrete actions for those responsible in the organisation.

  • Risk picture of data, payment flows, suppliers and continuity
  • Board-level summary in the language of impact and trust
  • Improvement plan that connects to CBF and relevant NGO frameworks
  • Demonstrable follow-up with ownership and evaluation moments
KYNEXISInsight and direction
  1. Investigations
  2. Prioritize
  3. Run
  4. Embed
View the governance GAP analysis →

Insight and execution

Research and support related to this

The appropriate route follows from your steering question, desired security and the current maturity of the organisation.

Governance and assurance

Governance gap analysis

Key the translation of governance principles into ownership, digital risks, reporting and demonstrable follow-up.

View Governance gap analysis
Policies and arrangements

Information security policy

Develop workable policies from critical processes, dependencies and the risks of the organisation.

View Information security policy
Structural support

CISO as a Service

Organize direction, reporting, supplier control and a fixed improvement cycle with experienced guidance.

View CISO as a Service
Preparing to act

Incident management

Work out roles, decision-making, communication and recovery before speed and overview make the difference.

View Incident management

Frequently Asked Questions

Practical Answers for Charities & Funds

When is the Partos Code of Conduct relevant?

The Partos Code of Conduct is relevant to Partos members and organisations in development cooperation and humanitarian aid that apply this framework. For other non-profits, the focus is usually on CBF, GDPR and its own governance context.

What CBF standard is about information security?

Within the Recognition Regulation 2026, standard 3.5.1 contains concrete requirements on privacy and information security. The applicable depth is related to the category of the organisation.

Can Kynexis take into account limited capacity?

Yes. Scope, priorities and measures are tailored to size, data, digital dependencies and available people and resources.

Wouter Parent

Protect personal data, payment flows and social services. This also protects the trust on which fundraising rests.

Current
WebinarFree webinars on NIS2, cyber risk management and oversight

Choose a live session for the board, executive team, supervisory board or board of trustees and register directly.

View webinars and dates