Beacon CRM Security Incident: Supporting charities through a difficult time

The recent cyber-security incident affecting Beacon CRM has understandably caused concern across the charity sector. While Beacon’s investigation is ongoing, customers have been advised that their data held within the CRM could potentially have been affected until the forensic review is complete. This uncertainty means many charities are now facing urgent decisions about whether the incident presents a risk to individuals’ rights and freedoms and whether it needs to be reported to the ICO within the 72-hour reporting window.

At this stage, organisations should be reviewing the personal data held within Beacon, carrying out a documented breach risk assessment, considering whether ICO notification is required, assessing whether affected individuals need to be informed, and ensuring that all decisions are properly recorded. Even where the full facts are not yet known, the ICO expects organisations to make timely, evidence-based decisions using the information available and to update their assessment as further information emerges.

This is a challenging and evolving situation, particularly for charities with limited in-house data protection resources. A number of organisations affected by the incident are currently seeking our support to assess their reporting obligations, complete risk assessments, prepare ICO notifications and navigate the wider response process. If your organisation has been impacted and would like independent guidance, we are here to help.

Website Asset

Get in touch

Login / Register
If you would like to manage your Organisations access to our courses and invite members via group code.

If you want to take courses as an individual.