CASE STUDY / The Carnegie Dunfermline Trust

Securing a Historic Legacy with Cyber Essentials

Photo credit: Alex Beattie

ggreen
CLIENT The Carnegie Dunfermline and Hero Fund Trust
SERVICE USED Cyber Essentials Certification and Annual Renewal
LOCATION Dunfermline, Scotland

About the Trust

The Carnegie Dunfermline and Hero Fund Trust is an endowment trust established by philanthropist Andrew Carnegie in 1903 to enrich the lives and environment of the Dunfermline community where he was born and raised.

One of more than 20 Carnegie foundations worldwide, it is governed by a Royal Charter and a Board of twenty Trustees.

Today, the Trust brings together three charitable purposes under one organisation. The Dunfermline Trust awards grants to local charities and organisations across arts, education, sport and community projects. The Hero Fund recognises civilian acts of bravery across the UK, and the Trust also runs the Andrew Carnegie Birthplace Museum, preserving the legacy of one of Scotland’s most influential philanthropists.

The Challenge

With responsibility for sensitive data and GDPR compliance, the Trust aimed to strengthen its cyber security posture and reduce the risk of cyber attacks.

Trustees also wanted to minimise the organisation’s exposure to cyber risk and qualify for lower cyber insurance premiums by completing the accreditation.

Although the Trust already partnered with Grant McGregor for day-to-day IT support, Cyber Essentials initially felt complex for a small internal team. They needed a clear, supported route to certification that would improve security without adding pressure.

Our Solution

Grant McGregor provided a guided, clear route to Cyber Essentials certification and annual renewal:

  • One-to-one guidance from an experienced consultant, translating requirements into clear, actionable steps.
  • Policy and documentation support to align existing practices with the scheme.
  • Practical security improvements, including a password manager, multi-factor authentication (MFA) and structured software and device updates.
  • User awareness training with phishing simulations and regular tips to build everyday vigilance.
  • Renewal support each year, explaining question set updates and highlighting areas needing attention.

Our Approach and Results

The process was designed to be straightforward and supportive, raising security standards while keeping the workload manageable for a small team.
Improved-security

Improved Security

Stronger policies, a password manager and enforced updates on all devices used for work.

IT-Asset-Management-Scotland

Better IT asset management

Retiring devices at end of warranty or support to reduce vulnerabilities and unexpected costs.

User-Awareness-Training-Scotland

User awareness and confidence

Staff recognise phishing attempts, understand incident response steps and feel prepared to handle cyber risks.

Cyber-Essentials-Certification-Scotland

Stress-Free Certification

Clear, guided support removed the technical overwhelm and made achieving Cyber Essentials simple.

Cyber-Essentials-Renewals

Simplified Renewals

Each year’s changes are explained early, cutting confusion and speeding up submission.

Long-Term Value

A stronger security posture and eligibility for discounted cyber insurance.

In Their Words

I would definitely go through Grant McGregor instead of trying to do it alone. They make Cyber Essentials efficient, straightforward and stress-free. They answer the technical questions we wouldn’t have known ourselves. It’s been five-star support.

Carnegie-Dunfermline-Trust

Sarah Huxtable

Administrator, Carnegie Dunfermline Trust