Security Fundamentals • Charity Sector

Beacon CRM Cyberattack: Practical Lessons for UK Charities

Reports of disruption and financial consequences for charities using a shared CRM are a timely reminder: outsourcing a service does not outsource operational risk. Charities need proportionate supplier assurance, usable continuity arrangements and a rehearsed response.

Trends4You Editorial

Incident context

Why this matters beyond one supplier

On 5 August 2026, The Register reported on the impact of a cyberattack involving Beacon CRM and UK charities. A charity CRM may support fundraising, supporter relationships, communications and service delivery, while holding personal and financially sensitive information. Loss of availability or confidence in that system can therefore become an operational, financial, data-protection and reputational issue at the same time.

Keep facts and assumptions separate

Affected organisations should rely on direct supplier communications and their own evidence. Public reporting is useful for awareness, but incident details can change as investigation and recovery continue.

Practical lessons

The supplier may host the system; the charity still owns the risk

Cloud services can give smaller charities access to capabilities they could not operate alone, but they also concentrate important data and processes. Proportionate assurance should cover more than a supplier's certifications. The charity should understand what information is held, who can access it, how incidents will be communicated, what can be recovered and how essential work continues during an outage. The RACF-CC Supplier and Third-Party Risk guide provides a practical method for recording and reviewing those dependencies.

Know the dependency

Record the services, integrations, information flows and charity activities that depend on the CRM.

Protect access

Use MFA, named accounts, least privilege and prompt removal of unnecessary staff, volunteer and supplier access.

Plan for unavailability

Maintain tested exports, recovery expectations and safe manual arrangements for genuinely essential work.

Agree incident routes

Know who contacts the supplier, who assesses harm, who briefs trustees and who considers regulatory reporting.

What to do now

An eight-step checklist for charity leaders

1

Confirm your exposure

Identify whether your charity uses the affected service directly or through an integration. Nominate one person to obtain verified updates from the supplier and record decisions.

2

Map data and critical processes

Document the personal data, financial information, credentials and attachments held in or connected to the CRM. Note which fundraising, communications or care processes cannot operate without it.

3

Review accounts and integrations

Check administrators, dormant users, API keys, connected applications and shared accounts. Do not make destructive changes without evidence, but be ready to revoke or rotate access when justified.

4

Preserve evidence

Keep supplier notices, relevant logs, timelines, decisions and observed impacts. Avoid deleting records that may be needed for technical, insurance or regulatory assessment.

5

Activate continuity arrangements

Prioritise essential services and use approved manual workarounds. Keep temporary records secure and plan how they will be reconciled when normal service returns.

6

Assess harm and reporting duties

Involve the data-protection lead and trustees. Consider contractual notices, cyber insurance, the ICO, law enforcement and whether the impact meets the Charity Commission's serious-incident threshold.

7

Communicate carefully

Prepare factual messages for staff, volunteers, donors and service users where appropriate. State what is known, what action recipients should take and when the next update will be provided.

8

Strengthen assurance after recovery

Review the supplier's incident findings, recovery commitments and control improvements. Update the risk register, continuity plan, contract requirements and future testing.

RACF-CC context

A cross-domain resilience test

This scenario connects RACF-CC Domain 1 for account security, Domain 5 for data protection and recoverability, Domain 6 for evidence and detection, Domain 7 for coordinated response, and Domain 8 for supplier risk, trustee oversight and accountable decisions.

Minimum viable outcome

The charity can name its critical suppliers, explain what data and services depend on them, reach the right supplier contact, continue priority work safely, assess reporting duties and evidence every important decision.

Sources and further guidance

Verify developments and use authoritative guidance

This article provides general cybersecurity guidance, not legal or regulatory advice. Use current official guidance and obtain specialist advice where necessary.

Voluntary support

Found this useful? Support Trends4You

Trends4You's practical guides, RACF-CC resources and downloadable tools are provided free of charge. If they've helped you or your organisation, you can support the time and hosting that keeps them freely available.

Support is optional, handled securely by Stripe and does not provide additional access.