Incident context
Why this matters beyond one supplier
On 5 August 2026, The Register reported on the impact of a cyberattack involving Beacon CRM and UK charities. A charity CRM may support fundraising, supporter relationships, communications and service delivery, while holding personal and financially sensitive information. Loss of availability or confidence in that system can therefore become an operational, financial, data-protection and reputational issue at the same time.
Keep facts and assumptions separate
Affected organisations should rely on direct supplier communications and their own evidence. Public reporting is useful for awareness, but incident details can change as investigation and recovery continue.
Practical lessons
The supplier may host the system; the charity still owns the risk
Cloud services can give smaller charities access to capabilities they could not operate alone, but they also concentrate important data and processes. Proportionate assurance should cover more than a supplier's certifications. The charity should understand what information is held, who can access it, how incidents will be communicated, what can be recovered and how essential work continues during an outage. The RACF-CC Supplier and Third-Party Risk guide provides a practical method for recording and reviewing those dependencies.
Know the dependency
Record the services, integrations, information flows and charity activities that depend on the CRM.
Protect access
Use MFA, named accounts, least privilege and prompt removal of unnecessary staff, volunteer and supplier access.
Plan for unavailability
Maintain tested exports, recovery expectations and safe manual arrangements for genuinely essential work.
Agree incident routes
Know who contacts the supplier, who assesses harm, who briefs trustees and who considers regulatory reporting.
What to do now
An eight-step checklist for charity leaders
Confirm your exposure
Identify whether your charity uses the affected service directly or through an integration. Nominate one person to obtain verified updates from the supplier and record decisions.
Map data and critical processes
Document the personal data, financial information, credentials and attachments held in or connected to the CRM. Note which fundraising, communications or care processes cannot operate without it.
Review accounts and integrations
Check administrators, dormant users, API keys, connected applications and shared accounts. Do not make destructive changes without evidence, but be ready to revoke or rotate access when justified.
Preserve evidence
Keep supplier notices, relevant logs, timelines, decisions and observed impacts. Avoid deleting records that may be needed for technical, insurance or regulatory assessment.
Activate continuity arrangements
Prioritise essential services and use approved manual workarounds. Keep temporary records secure and plan how they will be reconciled when normal service returns.
Assess harm and reporting duties
Involve the data-protection lead and trustees. Consider contractual notices, cyber insurance, the ICO, law enforcement and whether the impact meets the Charity Commission's serious-incident threshold.
Communicate carefully
Prepare factual messages for staff, volunteers, donors and service users where appropriate. State what is known, what action recipients should take and when the next update will be provided.
Strengthen assurance after recovery
Review the supplier's incident findings, recovery commitments and control improvements. Update the risk register, continuity plan, contract requirements and future testing.
RACF-CC context
A cross-domain resilience test
This scenario connects RACF-CC Domain 1 for account security, Domain 5 for data protection and recoverability, Domain 6 for evidence and detection, Domain 7 for coordinated response, and Domain 8 for supplier risk, trustee oversight and accountable decisions.
Minimum viable outcome
The charity can name its critical suppliers, explain what data and services depend on them, reach the right supplier contact, continue priority work safely, assess reporting duties and evidence every important decision.
Sources and further guidance
Verify developments and use authoritative guidance
- The Register: UK charities count the cost of Beacon CRM cyberattack
- National Cyber Security Centre: Supply chain security guidance
- Charity Commission: Protect your charity from cyber crime
- Charity Commission: How to report a serious incident
This article provides general cybersecurity guidance, not legal or regulatory advice. Use current official guidance and obtain specialist advice where necessary.
Voluntary support
Found this useful? Support Trends4You
Trends4You's practical guides, RACF-CC resources and downloadable tools are provided free of charge. If they've helped you or your organisation, you can support the time and hosting that keeps them freely available.
Support is optional, handled securely by Stripe and does not provide additional access.
