Guidance for charities affected by the Beacon cyber security incident
The Charity Commission has issued guidance to UK charities affected by a cyber security incident involving Beacon’s CRM service, urging trustees to report serious incidents and follow data protection obligations.
The useful question is what changes for users, developers or buyers, and whether the announcement stays industry context or becomes something people can actually use.
The Charity Commission is aware of a cyber security incident involving Beacon’s Customer Relationship Management service and is providing guidance to affected charities. The Commission acknowledges the concern this incident has caused and is monitoring the situation closely. It is working with the Information Commissioner’s Office (ICO), the UK’s data protection regulator, to address the impact on charities using Beacon’s services.
A number of affected charities have submitted serious incident reports to the Commission, which encourages trustees to follow its guidance on reporting incidents that risk significant harm, loss, or damage to the charity, its beneficiaries, or reputation. Due to the expected volume of reports, responses may take longer than usual, and the Commission has asked for patience as it prioritises the most critical cases.
The Commission advises trustees to consult its guidance on cyber crime and the ICO’s guidance for organisations handling data breaches. Trustees must also consider their reporting obligations to regulators, including the ICO, and to individuals whose data is stored on Beacon systems on behalf of their charity.
The Charity Commission recognises the additional resources charities will need to address this incident and will ensure its regulatory engagement remains proportionate. It urges charities to maintain clear communication with stakeholders to retain trust and will continue to monitor the situation, posting updates on its official page.