Beacon security incident – What charities should do next

Beacon CRM has issued guidance following a recent cyber security incident affecting its platform. This practical guide explains what charities should do next, where to find official information, how to assess their GDPR responsibilities, and the key steps organisations should now be considering to protect their supporters and digital infrastructure.
Facebook
Twitter
LinkedIn
WhatsApp
Email

If your charity uses Beacon CRM, you’ve probably seen the recent communications regarding the security incident.

News of a cyber security incident involving one of your suppliers can understandably raise questions, particularly when that supplier stores supporter, donor or volunteer information on your behalf.

While Beacon continues its investigation with external cyber security specialists, it has already provided detailed guidance to help customers understand their responsibilities and the practical steps they should now consider taking.

Rather than relying on speculation or commentary shared online, this article explains the current position, highlights the official guidance available from Beacon and outlines the practical actions charities should now be considering.

What has happened?

Beacon has confirmed that it recently experienced a cyber security incident in which an unauthorised third party gained access to its systems using compromised credentials.

According to Beacon’s latest update, copies of database backups were created and, while exfiltration has not been conclusively confirmed, the evidence currently available suggests those copies were likely downloaded. Beacon has engaged external cyber security specialists, implemented containment measures and confirmed that the platform remains fully operational.

At the time of writing, Beacon’s investigation remains ongoing and further updates may be published.

For the latest information, charities should refer directly to Beacon’s official resources:

Start by following Beacon’s guidance

Every charity’s use of Beacon is different.

Some organisations use it purely for fundraising, while others manage volunteers, events, memberships, Gift Aid, service users or wider supporter relationships.

Because of this, there isn’t a single response that’s appropriate for every charity.

Beacon has published a structured response guide that recommends organisations appoint a lead contact, review relevant internal policies, update Beacon applications and API integrations, consider regulatory obligations and assess whether individuals may need to be informed.

Working methodically through that guidance is the best starting point before making any wider decisions.

Review your internal policies

Incidents involving third-party suppliers are exactly why organisations have governance policies.

Beacon recommends reviewing documentation such as your Data Breach and Incident Response Policy, Data Protection and GDPR Policy, Business Continuity Plan, Third-Party Supplier Risk Management Policy and IT Acceptable Use Policy.

Even if these documents haven’t been needed for some time, now is the appropriate moment to ensure they’re being followed consistently.

Consider your GDPR responsibilities

One of the most important parts of Beacon’s guidance relates to data protection.

As the organisation using Beacon, your charity remains the Data Controller for the information stored within the platform. That means your organisation must assess whether the incident meets the threshold for reporting to the Information Commissioner’s Office (ICO). Beacon cannot make that decision on your behalf.

The ICO provides detailed guidance to help organisations determine whether a personal data breach needs to be reported and what information should be included if a report is required.

Useful resources include:

Registered charities should also consider whether the incident is reportable to the relevant charity regulator, as highlighted within Beacon’s own guidance.

Think about the people behind the data

While it’s natural to focus on systems and compliance, it’s equally important to consider the individuals whose information may have been affected.

Beacon explains that organisations should assess whether there is likely to be a high risk to the rights and freedoms of individuals before deciding whether direct notification is required. The ICO provides further guidance on making this assessment.

If communication with supporters, donors or volunteers does become necessary, it should be timely, factual and transparent.

This is also a good opportunity to review wider security

Although this incident relates specifically to Beacon, it serves as a reminder that every charity depends on multiple third-party platforms.

Your CRM is only one part of your wider digital infrastructure.

You may also rely on your website, online donation platform, email marketing software, cloud storage, payment providers and collaboration tools.

Incidents involving suppliers are uncommon, but they reinforce the importance of reviewing user permissions, enabling multi-factor authentication, maintaining strong passwords and ensuring internal policies remain up to date.

Good cyber resilience isn’t built during an incident. It’s built long before one happens.

Keep monitoring official updates

Cyber security investigations take time.

Beacon has stated that it will continue publishing updates as new information becomes available and encourages customers to monitor its Security Incident Response Guide for the latest advice.

For that reason, charities should avoid relying on rumours or second-hand information and instead continue referring to Beacon’s official communications.

Supporting your charity’s digital infrastructure

Modern charities rely on a growing number of digital platforms to deliver services, engage supporters and manage fundraising activity.

While incidents such as this are thankfully uncommon, they highlight the importance of strong governance, clear internal processes and well-managed digital systems.

At Blake Mark Productions, we support charities with their wider digital infrastructure, from charity website design and WordPress Care Plans to digital marketing strategy and ongoing technical support. Although we don’t provide cyber security consultancy, we understand how closely these systems work together and the importance of maintaining a secure, resilient digital environment.

If you’d like to discuss your charity’s website or wider digital strategy, you can book a free discovery call below.