The situation
A charity based in London was working with ageing devices and IT habits that had built up over years of tight budgets and stretched teams — including the common but risky practice of staff sharing logins between them. As funders began asking sharper questions about data security, the charity needed to close that gap quickly and credibly.
The challenge
Shared passwords meant there was no reliable way to know who had accessed what, which is a difficult position to defend when a funder asks about data protection as a condition of continued support. On top of that, ageing devices were limiting what staff could do day to day, and the charity's ways of working hadn't caught up with the more flexible, hybrid patterns that staff and volunteers increasingly needed.
What FNS changed
FNS carried out a device refresh so staff were working on hardware that could support modern security tools rather than fighting against them. Multi-factor authentication was rolled out across the organisation, closing off the shared-password problem by giving every person their own secure, individually verified login. Alongside the immediate fixes, FNS put a quarterly roadmap in place, so the charity's technology decisions were made ahead of time rather than in reaction to whatever funder question or device failure came up next.
How we worked together
The priority throughout was to make the changes fit around a small, busy charity team rather than the other way round. The quarterly roadmap gave the charity a regular, predictable point to review progress, raise concerns and plan the next set of changes — including the shift towards hybrid working — without it turning into a series of disruptive one-off projects.
The outcome
Password sharing has been eliminated in favour of individual, MFA-protected logins, giving the charity a clear answer when funders ask about data security. Funder security requirements are now being met as a matter of course rather than a scramble before each review. And with modern devices and proper access controls in place, staff and volunteers can now work in a genuinely hybrid pattern, splitting time between the office and elsewhere without compromising on security.