The challenge
The charity used a mix of staff and volunteer accounts, with inconsistent MFA and limited visibility of forwarding rules and dormant access.
The security approach
The representative engagement secures administrator roles, enforces MFA, reviews mailbox rules, closes dormant accounts and adds email threat reporting and awareness training.
The outcome
The charity reduces account takeover risk while keeping onboarding and offboarding manageable for a changing volunteer population.
Security that respects limited resources
The design favours simple controls with clear ownership: strong identity, prompt leaver processing, secure email and a repeatable checklist for volunteers and trustees.