Beacon CRM cyber incident: what charities must do

In guidance published on GOV.UK, the Charity Commission says it is aware of a recent cyber security incident involving Beacon CRM and that charities using the service could be affected. For many organisations, that will bring an immediate worry: if supporter or beneficiary data was stored on Beacon systems on behalf of your charity, what happens next? This is the part worth slowing down for. A charity cyber incident is not only an IT problem. It can also become a governance issue, a data protection issue and a trust issue, all at the same time.

The Commission says it has been actively monitoring the situation and is in contact with the Information Commissioner’s Office, which is the UK regulator responsible for information rights and data protection law. That matters because it shows how these incidents are usually handled in real life: one regulator may be looking at charity governance, while another looks at personal data and legal duties. **What this means:** if your charity uses Beacon CRM, trustees should be asking early questions rather than waiting for a perfect picture. What information was stored there? Who may be affected? Is there any sign of harm, service disruption or reputational damage?

A number of affected charities have already sent serious incident reports to the Charity Commission, and the regulator is urging trustees to keep following its usual guidance. In simple terms, you should report an incident if it has caused, or risks causing, significant harm, loss or damage to the charity, its beneficiaries, assets, services or reputation. That can sound formal, but it helps to think of it as part of responsible oversight. A serious incident report is not the same as saying your charity has failed. It is a record that trustees recognised a serious risk and acted on it.

The Commission has also warned that, because many reports may arrive about this issue at the same time, it could take longer than usual to respond. It says it will prioritise the cases with the greatest risk, and charities are being asked for patience while that happens. There is an important lesson here for trustees. Your responsibilities do not stop while you wait for a regulator to reply. If the incident may involve personal data, you should still consider whether you need to report to the ICO and whether people whose information is held on Beacon systems should be told directly.

The guidance points charities towards two main sources of help: the Charity Commission’s advice on cyber crime and the ICO’s guidance for organisations. Read together, those two sets of advice give a clear picture of what trustees are expected to do. You need to understand the risk to your charity, keep records, check your reporting duties and make careful decisions about communication. **What it means for you:** the immediate job is practical. Work out what data may have been involved, what systems or teams relied on Beacon CRM, whether any beneficiaries or supporters face a risk, and what your charity can honestly say right now.

The Commission says many Beacon customers have already moved quickly to inform supporters, and it presents that as an important part of the response. Clear communication matters because charities depend so heavily on trust. People are more likely to stay with an organisation when they feel it is being open, calm and accurate. For readers outside the sector, this is one of the biggest differences between a charity incident and a private inconvenience. A charity’s relationships with donors, volunteers, beneficiaries and local communities are part of how it works day to day, so silence can carry its own risk.

The final message from the Commission is measured but firm. It recognises that affected charities will need to spend extra time and resources dealing with the issue, and it says its own regulatory engagement will be proportionate while still making sure trustees meet their duties. Taken together, the guidance is a public-interest checklist: assess the risk, report where needed, consider your data protection duties, communicate clearly and keep good records. The Charity Commission says it will continue to monitor the Beacon CRM cyber incident and post any significant updates on the same GOV.UK page.

← Back to Stories