Charity Cyber & Digital Governance Readiness Review

Give trustees a clearer view of digital and cyber risks before they become incidents.

Trustees may lack clear oversight of basic digital, cyber and information risks.

For: Small charities.

£1,250 standard — indicative range £750–£1,750.We confirm the exact fee after checking what you need.

One governance-level digital and cyber readiness review covering oversight, asset and control questions, priority actions, ownership and specialist referrals.

Defined scope · evidence kept separate from assumptions · no unsupported outcome, certification or compliance claims

What changes

Trustees and managers get a governance-level view of the material digital and cyber questions, current evidence, ownership gaps and priority next actions.

Technical testing and certification remain outside the service; specialist issues are referred rather than hidden inside a governance checklist.

What you will receive

Working materials representing Charity Cyber & Digital Governance Readiness Review.
Working materials representing Charity Cyber & Digital Governance Readiness Review.

Governance review

A trustee/management-level review of how digital, information and cyber risk is currently overseen and evidenced.

Asset/control questions

A structured set of questions covering the systems, information, responsibilities and basic controls material to the agreed review.

Priority actions

A proportionate action list separating immediate governance gaps from lower-priority improvements and specialist technical work.

Ownership

Clear ownership for each agreed action so digital and cyber risks do not sit between trustees, staff, volunteers and suppliers.

Referral list

Specific issues that require technical security, legal, privacy, insurance or other specialist input outside this governance-level review.

WORKED EXAMPLE

See how this can work

Example situation: Trustees may lack clear oversight of basic digital, cyber and information risks.

We would start with what is happening now and the information already available, then work through the service described on this page. If the problem needs a different route, we would say so before broadening the work.

A clearer result: Trustees and managers get a governance-level view of the material digital and cyber questions, current evidence, ownership gaps and priority next actions.

What you could receive: Governance review, Asset/control questions, Priority actions, Ownership, and Referral list.

Illustrative example — shown to explain how the service can be applied. It is not a customer testimonial or measured result.

Where this could lead next

This service is complete in its own right. You do not need another service for this one to be worthwhile. If the work uncovers a separate problem worth solving, these are the most likely next steps.

Charity AI Governance Pack & Implementation

If AI use is the specific governance gap that now needs practical trustee visibility, staff rules and implementation, this can help you put the charity AI governance baseline in place.

Explore Charity AI Governance Pack & Implementation →

Decision Rights & Governance Review

If the review shows that digital-risk decisions or escalation routes are unclear, this can help you clarify who decides what and how material issues escalate.

Explore Decision Rights & Governance Review →

If the work resolves the problem and no separate need remains, no further House of Carol service is needed.

Not sure what follows? You do not need to choose another service now. Start with the problem in front of you.

What the engagement looks like

Service type
Advisory service
Delivery
Remote
Pricing
£1,250 standard; indicative range £750–£1,750. Final price confirmed after what you need.
Scope
A defined advisory service centred on governance review, asset/control questions, priority actions and the remaining listed deliverables. The exact boundary is confirmed before commitment.

Before anything is agreed, House of Carol confirms that the customer, problem, available information and requested scope are suitable for this service. If they do not, the work is narrowed, declined or routed rather than stretched beyond the product.

House of Carol — People, Ideas, Solutions, Real Progress. Intelligence for a kinder, more capable world.
What needs to be in place?

Trustee/management participation.

Current systems information.

Only the minimum information and access needed for the agreed work should be provided. Passwords, MFA codes, private keys and unnecessary confidential or personal data are not requested through ordinary messages.

What is outside the scope?

Not penetration testing, technical security audit or certification.

Anything materially outside the agreed boundary becomes a separate decision rather than hidden expansion of the engagement.

Is this the right service?

The organisation fits the intended customer: Small charities.

There is an accountable customer owner able to provide the information and decisions the work depends on.

If the main need falls outside the stated deliverables or requires a specialist judgement House of Carol is not competent or authorised to provide, a different route is required.

What this service does not promise

The review does not guarantee cyber security or compliance and is not a technical security audit or certification. Trustees and managers retain the decisions.

FROM INTEREST TO A CLEAR DECISION

How to get started

Start with the problem, not a purchase decision. We will check whether this service fits before anything is agreed.

1. Tell us what is happening

Share the problem you are trying to solve, what you already have and any deadline or constraint that matters.

2. We check the fit

We check the scope, the information we would need, the fee and whether this is genuinely the right service. If it is not, we will say so.

3. You decide with the facts clear

Nothing starts until you know what is included, what is not, what you need to provide and what happens next.

There is no pressure to add another service. The useful next step is simply to decide whether this one solves the problem in front of you.

Start with the real problem

Trustees may lack clear oversight of basic digital, cyber and information risks.

Tell us what is happening, what a useful result would look like and what information is already available. We will first establish whether this service fits before anything is agreed.

Discuss the review