Beacon cyber incident: what charities must do now
On Friday 7 August 2026, the Charity Commission published guidance for organisations affected by the Beacon cyber incident. The regulator said it is monitoring the situation, knows a number of charities may be affected and is already in contact with the Information Commissioner's Office, which leads on UK information rights and data protection law. (gov.uk) That matters because this is not only a technical disruption. If your charity uses Beacon, this becomes a question about trustee oversight, supporter trust and whether personal data may have been put at risk. **What this means:** a cyber story can quickly become a governance story. (gov.uk)
Beacon describes itself as a charity CRM, and its own website and help guide show the platform is used for managing databases, supporter data, payments, forms and reporting. In other words, the kind of system at the centre of this incident may sit very close to a charity's everyday work and its relationship with supporters. (beaconcrm.org) That is why the Commission's update feels bigger than a routine notice. When a system like this is affected, the concern is not just whether staff can log in. It is whether people's information, a charity's services and the reputation that keeps public confidence alive may have been harmed. (gov.uk)
The line trustees need to read carefully is the one on serious incident reporting. The Charity Commission says you should report an incident if it results in, or risks, significant harm, loss or damage to the charity, its beneficiaries, assets, services or reputation. It also says reporting helps the regulator check that trustees are handling the problem responsibly and taking steps to limit immediate impact. (gov.uk) So the first questions are practical ones. What data may have been involved? Who could be affected? Have services been interrupted? Has the charity taken action to contain the problem and record what happened? **What this means:** you do not wait for perfect certainty before you start your assessment. (gov.uk)
The Commission also says trustees must think about duties beyond the Charity Commission itself, especially duties to the ICO and to people whose data is stored on Beacon systems for the charity. The ICO's current guidance says a reportable personal data breach must be notified without undue delay and within 72 hours of discovery. (gov.uk) For readers outside charity governance, that timing point matters. The clock starts when you discover the breach, not when the original incident happened, and the ICO advises organisations to begin a log straight away, even if they later decide the threshold for reporting was not met. (ico.org.uk)
There is another part of the Commission's message that deserves more attention than it usually gets: speak clearly to the people who trust you. The regulator says many Beacon customers moved quickly to inform supporters, and it stresses that clear communication with stakeholders is vital if a charity wants to protect trust and the relationships that sustain its work. (gov.uk) For charities, that usually means being plain rather than polished. Tell people what you know, what you do not yet know, what action has been taken and where supporters can go for help. **What this means:** silence can feel safer in the moment, but uncertainty without communication can do its own damage. (gov.uk)
Charities should also be ready for a slower regulatory reply than usual. Because the Commission expects a large volume of reports on this incident, it has warned that responses may take longer while it prioritises the cases carrying the greatest risk, though it says its approach to affected charities will be proportionate. (gov.uk) That is one reason record-keeping matters. The Commission's cyber crime guidance tells charities to act quickly, decide who needs to be informed, keep a record of what happened and report cyber crime to Report Fraud. If contact from regulators takes time, your own timeline, decisions and evidence trail become even more important. (gov.uk)
The immediate job is response, but the longer lesson is preparedness. The Charity Commission's cyber guidance points charities towards National Cyber Security Centre tools for small, medium and large organisations, including the Cyber Action Toolkit, board guidance, response planning resources and Cyber Essentials. (gov.uk) If you are a trustee or volunteer reading this, the useful takeaway is simple. Cyber security is not a specialist issue that sits out of sight until something goes wrong. It is part of how a charity protects people, money, services and public trust, and the Beacon incident is a sharp reminder that those duties begin well before the next headline. (gov.uk)