Guidance for charities affected by the Beacon cyber security incident
The Charity Commission has issued guidance to UK charities affected by a cyber security incident involving Beacon’s CRM service, urging trustees to report serious incidents and follow regulatory advice.
The Charity Commission confirmed it is aware of a cyber security incident involving Beacon’s Customer Relationship Management service, which may have impacted charities using its platform. The Commission expressed concern for affected charities and their supporters, noting the incident’s potential scale. It is working with the Information Commissioner’s Office (ICO) as the lead regulator for data protection in the UK. Affected charities are advised to follow serious incident reporting guidance, particularly for incidents causing or risking significant harm to beneficiaries, assets, or reputation.
The Charity Commission anticipates a high volume of incident reports related to this breach, which may delay responses compared to usual timelines. Trustees are urged to consult the Commission’s cyber crime guidance and the ICO’s advice for organisations. They must also consider reporting obligations to other regulators and individuals whose data is stored on Beacon systems. The Commission acknowledges the additional resources required by charities to address this issue.
Trustees are encouraged to communicate promptly and clearly with stakeholders, including supporters, to maintain trust and protect relationships critical to their work. The Charity Commission recognises the burden this incident places on charities and aims to ensure its regulatory engagement remains proportionate. It will prioritise cases presenting the greatest risk while supporting trustees in fulfilling their responsibilities.
The Charity Commission will continue monitoring the situation and provide updates on its dedicated page. Affected charities should stay informed through official guidance and maintain compliance with reporting obligations to relevant authorities.