
If you work in the charity sector, you have probably spent the last few days reading emails about Beacon.
On 29 July, Beacon CRM — a platform used by well over a thousand UK charities to manage donors, supporters, volunteers and beneficiaries — identified a security incident. On 3 August, it told its customers what it had found: an unauthorised third party had used compromised credentials to get into its systems and had made copies of database backups. Beacon’s own assessment is that those copies were likely downloaded.
It has since gone further, advising customers to work on the assumption that everything held in their account, including uploaded attachments, may have been taken.
There has been no service outage. There has been no ransom demand, and at the time of writing no evidence that the data has appeared on the dark web. Beacon brought in external forensic specialists, notified the regulators, and is working with law enforcement. Judged as a supplier's response, it has been fast and unusually candid.
None of which changes the legal position for the charities involved. And that is the part worth talking about, because it is the part that catches organisations out every single time.
You are the controller. That is not paperwork — it decides who is on the hook
Here is the distinction that matters.
Your CRM provider is a data processor. They hold and handle personal data on your behalf, under your instructions. You are the data controller. You decided what data to collect, why, and where to put it.
Under UK GDPR, the obligation to assess and report a personal data breach sits with the controller. Beacon reporting the incident to the ICO as a processor does not discharge your duty. Their report is theirs. Yours is yours.
That means, if you use Beacon:
- You decide whether the breach is likely to result in a risk to people’s rights and freedoms, and therefore whether it is reportable.
- You have 72 hours from becoming aware to report it to the ICO, if it is reportable.
- You decide whether the risk to individuals is high enough that you need to tell them directly.
- If you are a charity, you consider whether this is a serious incident for the Charity Commission (or OSCR in Scotland).
Most Beacon customers became aware on Monday 3 August. Later updates from Beacon give you better information — they do not restart your clock.
One more point that is easy to miss: Beacon has indicated that the copied data may have been decrypted. If that holds, you cannot fall back on the argument that the data was unintelligible to the attacker and therefore poses no real risk. That exemption is not available to you here.
If you use Beacon, here is a sensible order of work
- Rotate everything connected to it. The entry point was compromised credentials. Change passwords, revoke and reissue API keys, integration tokens and connected app permissions — including form tools, email platforms, payment integrations and any Zapier-style connectors. Beacon has published guidance on this. Do it first.
- Appoint one lead contact. One person collates your organisation’s questions and speaks to the supplier. Everyone else routes through them. Support queues in an incident are long, and five colleagues asking five versions of the same question gets you an answer more slowly, not faster.
- Find out what you actually had in there. Contact details and donation history are one risk profile. Safeguarding notes, health information, financial hardship records, or details of vulnerable beneficiaries are entirely different. Your reporting decision and your notification decision both turn on this, so do not guess.
- Read your own policies. Most charities have a Data Breach and Incident Response Policy, a Data Protection Policy, and often a Safeguarding Policy. Whatever you committed to in them, now is when you do it.
- Write it all down. Even if you conclude the breach is not reportable, UK GDPR requires you to document the incident and your reasoning. A regulator looking at this later will want to see that you made a considered decision, not that you quietly hoped it would go away.
- Warn your supporters about what comes next. Contact data in criminal hands means convincing phishing. Expect emails and calls that use real names, real donation amounts and real event attendance to build credibility. Tell people you will never ask them to confirm bank details by email or phone.
If you do not use Beacon, this is still your problem
Beacon is not the story. Beacon is this month’s example.
The UK government’s Cyber Security Breaches Survey 2025/2026 found that 43% of businesses and 28% of charities identified a breach or attack in the previous twelve months. Supply chain assurance was flagged as one of the persistent weak points.
Think about how many organisations hold personal data on your behalf right now. Your CRM. Your email marketing platform. Your donation processor. Your cloud storage. Your finance system. Your HR system. Your website host. Each one is a set of credentials, an integration, and someone else’s security posture that you are quietly relying on.
Three questions worth asking this week, regardless of who your suppliers are:
- Where does our personal data actually live? If you cannot answer this in an afternoon, you cannot respond to an incident in 72 hours.
- Who has access to it, and is multi-factor authentication switched on everywhere? Compromised credentials remain the most reliable way into a system. MFA is the single control that most often stops them from working.
- Do we know what our contracts say? Your processor agreements should set out how quickly a supplier must tell you about an incident and what they must give you. Now is a good time to find out whether you do it.
An honest word about certification
We assess organisations against Cyber Essentials, so we should be straight with you about what it would and would not have done here.
Cyber Essentials would not have prevented Beacon from being breached. No certification you hold protects a third party’s infrastructure. Anyone telling you otherwise this week is selling something.
What the five controls do give you is a disciplined answer to the questions above. Access control and multi-factor authentication reduce the chance that your own credentials become someone else’s route in. Knowing your asset and data inventory means you can answer "what was in there?" quickly rather than spending two of your 72 hours finding out. And going through the assessment process tends to surface the integrations and dormant accounts that nobody has looked at for three years — which, in an incident like this one, is exactly the list you need.
Certification is not a shield. It is a habit of knowing your own environment well enough to respond properly when someone else has a bad week.
If you need a hand
If you are working through a breach assessment and want a second opinion on whether it is reportable, or you would like to review your supplier arrangements before the next incident rather than during one, we are happy to talk it through. No charge for the conversation.
Cyber Security & Data Protection | Certified NCSC Cyber Essentials & IASME Assessor | UK |Forti5 Technologies
Email: janaka.ranasinghe@forti5.tech
IASME-certified Cyber Essentials Certification Body




