Phishing is not just one of the risks to your charity. It is very nearly all of them
Security awareness training that costs a few minutes a week, for organisations whose every dollar is accounted for to somebody.
A charity holds donor records, payment details and the goodwill of people who chose to trust it. It usually holds them with a fraction of the staff, and none of the security team, that a company of the same size would have.
The UK government surveys this every year, and the shape of the answer is unusually clear. Almost everything that goes wrong for charities arrives the same way: somebody is sent a message and believes it.
The evidence, and where it comes from
Every figure below links to the source it came from. We have quoted what each number counts, because a percentage without its denominator is not evidence, it is decoration.
of charities reported experiencing any kind of cyber security breach or attack in the previous 12 months.[1]
of all charities experienced phishing specifically, the most prevalent type of breach or attack by far. Set against that 28%, phishing accounts for very nearly the whole category.[1]
of charities that experienced a breach or attack named phishing as the most disruptive type they faced.[1]
These are UK figures, because the UK publishes the clearest official statistics on charities specifically. We have not found an equivalent Canadian series, and we would rather cite the real thing from elsewhere than dress a guess up as local data.
Why this one fits a charity in particular
A few minutes a week, not an afternoon
Nobody has a spare afternoon. The daily round is one message to judge, built to fit a coffee break, and a short set of questions once a week.
Free for individuals, so volunteers cost nothing
Anyone can play free, forever, so most of a volunteer-heavy organization is covered before you pay for anything. For the staff seats that are left, talk to us. We price charities case by case.
Nobody is shamed for speaking up
Nobody is embarrassed for a wrong call. In a small organisation the person who speaks up is the entire control, and a programme that humiliates them is worse than none. What we train is the judgement to know which is which.
No simulated attacks on your people
We do not send fake phishing to real inboxes. Ambush tests teach staff to distrust the people running them. Daily practice teaches them to spot the scam.
Charity pricing is a conversation
The list price is $4 CAD per person per month, and registered charities are priced case by case. Tell us how many staff seats you actually need and we will start there.
What your people will practise, explained free
These are the same scams this page is about, written for the person who has to spot one on a Tuesday morning. No account needed to read them.
What is true in every sector
of breaches involved the human element, up from 60% the year before, across more than 22,000 confirmed breaches in 145 countries.[2]
of breaches began with vulnerability exploitation, which this year overtook credential abuse (down to 13%) as the single most common way in. People are involved in most breaches, but they are not the most common entry point, and we are not going to tell you otherwise.[2]
of breaches came through social engineering, the third most common pattern. In simulations, the median click rate for voice and text lures runs 40% higher than for email.[2]
And the uncomfortable part, which we would rather you heard from us
One of the largest field studies of phishing training ever published followed roughly 19,500 staff at a large health system through ten simulated campaigns over eight months. It did not flatter the industry we are in.
was the entire effect of embedded phishing training on the likelihood of clicking a phishing link. Having recently completed annual mandatory security training showed no significant relationship with falling for phishing at all.[3]
of the people who landed on the training page spent a minute or less on it, and about a third closed it immediately. That is a finding about attention, not about people being careless.[3]
We read that as the strongest argument for how BadgerQuest is built, not against it. What the study measured is the industry standard: an annual module, an ambush simulation, and a training page served to somebody who has just been told they failed. Nobody reads that page. Training that gets skimmed for forty seconds is not a smaller dose of training that works, it is a different thing entirely.
So the daily round is two minutes and it is a game, because that is the version people voluntarily finish. We do not send simulated phishing to real inboxes, because being ambushed by your own IT department is what produces the closed tab. Nobody is shamed for a wrong call, and what we train is the judgement to tell the two apart rather than a reflex to flag everything. Topics somebody keeps missing come back around instead of being marked complete.
The study's authors also recommend refocusing on technical countermeasures, specifically two-factor authentication and password managers that only fill on the correct domain. They are right, and those will stop more attacks than any training will. Do them first. We will say the same on a sales call. Training is for the part those controls do not cover, and it should be honest about being exactly that.
Sources
Read them yourself. That is the entire habit we are trying to teach, and it would be a strange thing for us to ask of your staff and not of ourselves.
- UK Department for Science, Innovation and Technology, and Home Office. Cyber security breaches survey 2025/2026 Official Statistic, published 30 April 2026. United Kingdom only.
- Verizon Business. 2026 Data Breach Investigations Report, Executive Summary 19th edition, published May 2026. More than 31,000 security incidents, of which more than 22,000 were confirmed data breaches, across organisations in 145 countries. Figures quoted here are from the executive summary PDF.
- Ho et al., University of Chicago, UC San Diego and UC San Diego Health. Understanding the Efficacy of Phishing Training in Practice 46th IEEE Symposium on Security and Privacy, May 2025. Roughly 19,500 staff at UC San Diego Health, ten simulated campaigns over eight months. Findings summarised by UC San Diego Today, 17 September 2025.
Start free and see the first week
Free for individuals, forever. Teams are $4 CAD per person per month, month to month, no minimum, cancel whenever you like. Schools, charities and public bodies are priced case by case, so ask us.