Charity Commission guidance after Beacon cyber incident
In guidance published on GOV.UK, the Charity Commission says it is aware of the recent cyber security incident involving Beacon CRM and the possible effect on charities using the service. That may sound procedural, but the real issue is simple. When a system used by charities is caught up in a cyber incident, the harm does not stop at software. It can reach supporters, staff, beneficiaries and the public trust that keeps a charity going.
The Commission says it is actively monitoring the situation because many charities may be affected. It is also in contact with the Information Commissioner's Office, better known as the ICO. **What this means in practice:** the ICO is the UK's lead regulator for information rights and data protection law. The Charity Commission has a different job. It looks at whether trustees are protecting the charity, responding properly to risk and meeting their legal duties. One incident can therefore bring more than one regulator into the picture at the same time.
For trustees, the immediate question is not only whether something has happened on a supplier's system. The Charity Commission says you should continue to follow its guidance on serious incident reporting. If an incident has caused, or could cause, significant harm, loss or damage to your charity, its beneficiaries, assets, services or reputation, it may need to be reported. That matters because a serious incident report is not just paperwork. It is the way a charity tells the regulator that a problem could affect the people it serves or the trust it depends on.
The Commission also reminds trustees to think beyond one form or one regulator. Charities may have reporting duties to others, especially the ICO, and may also need to contact the individuals whose data is stored on Beacon systems on the charity's behalf. This is where communication becomes part of good governance. The Commission notes that many Beacon customers moved quickly to inform their supporters. Clear, early updates can help people protect themselves, reduce confusion and show that a charity is being open rather than hiding behind technical language.
There is also a practical warning in the guidance. Because the Commission expects a high number of reports about this incident, alongside its usual casework, it says responses are likely to take longer than normal. It will prioritise the cases carrying the greatest risk. For affected charities, that may feel difficult, especially for small teams already giving extra time and money to deal with the problem. The Commission says its own engagement will be proportionate, but it still expects trustees to fulfil their responsibilities. While charities work through the incident, it is directing them to its own guidance on dealing with cyber crime and to the ICO's guidance for organisations.
The wider lesson is bigger than Beacon. Cyber security is sometimes treated as a specialist issue for an IT supplier or the most confident digital member of staff. The Charity Commission's message points somewhere else: for charities, cyber governance is a trustee issue because data, reputation and public confidence all sit at board level. **Why this matters:** if you care about how charities are run, this is a reminder that good intentions are not enough on their own. A charity needs to know what data it holds, who is responsible when systems go wrong, when to tell regulators and when to speak directly to supporters. The Commission says it will keep monitoring the situation and post any significant updates on the same GOV.UK page.