Securing a Historic Legacy with Cyber Essentials
Photo credit: Alex Beattie
About the Trust
The Carnegie Dunfermline and Hero Fund Trust is an endowment trust established by philanthropist Andrew Carnegie in 1903 to enrich the lives and environment of the Dunfermline community where he was born and raised.
One of more than 20 Carnegie foundations worldwide, it is governed by a Royal Charter and a Board of twenty Trustees.
Today, the Trust brings together three charitable purposes under one organisation. The Dunfermline Trust awards grants to local charities and organisations across arts, education, sport and community projects. The Hero Fund recognises civilian acts of bravery across the UK, and the Trust also runs the Andrew Carnegie Birthplace Museum, preserving the legacy of one of Scotland’s most influential philanthropists.
The Challenge
With responsibility for sensitive data and GDPR compliance, the Trust aimed to strengthen its cyber security posture and reduce the risk of cyber attacks.
Trustees also wanted to minimise the organisation’s exposure to cyber risk and qualify for lower cyber insurance premiums by completing the accreditation.
Although the Trust already partnered with Grant McGregor for day-to-day IT support, Cyber Essentials initially felt complex for a small internal team. They needed a clear, supported route to certification that would improve security without adding pressure.
Our Solution
Grant McGregor provided a guided, clear route to Cyber Essentials certification and annual renewal:
- One-to-one guidance from an experienced consultant, translating requirements into clear, actionable steps.
- Policy and documentation support to align existing practices with the scheme.
- Practical security improvements, including a password manager, multi-factor authentication (MFA) and structured software and device updates.
- User awareness training with phishing simulations and regular tips to build everyday vigilance.
- Renewal support each year, explaining question set updates and highlighting areas needing attention.
Our Approach and Results
Improved Security
Stronger policies, a password manager and enforced updates on all devices used for work.
Better IT asset management
Retiring devices at end of warranty or support to reduce vulnerabilities and unexpected costs.
User awareness and confidence
Staff recognise phishing attempts, understand incident response steps and feel prepared to handle cyber risks.
Stress-Free Certification
Clear, guided support removed the technical overwhelm and made achieving Cyber Essentials simple.
Simplified Renewals
Each year’s changes are explained early, cutting confusion and speeding up submission.
Long-Term Value
A stronger security posture and eligibility for discounted cyber insurance.
In Their Words
I would definitely go through Grant McGregor instead of trying to do it alone. They make Cyber Essentials efficient, straightforward and stress-free. They answer the technical questions we wouldn’t have known ourselves. It’s been five-star support.
Sarah Huxtable
Administrator, Carnegie Dunfermline Trust