The Beacon incident isn't the IT story it looks like
If you find this useful, I share practical tools and insights by email Sign up to the newsletter
In August, a cyber security incident at Beacon CRM affected charities right across the UK. Beacon holds the kind of information most charities can't function without: details about supporters, donors, volunteers, beneficiaries, fundraising activity. The Charity Commission thought it serious enough to issue specific guidance on 7 August, and it's now working with the Information Commissioner's Office on the fallout.
It would be easy to read that as an IT story. A supplier had a problem, some charities were affected, the specialists will sort it out.
It's not what you think.
Handing your data to a supplier doesn't hand away the responsibility for it
When a charity uses an external CRM, an accounting package, cloud storage or a fundraising platform, the data itself moves. The responsibility for it doesn't.
Trustees don't need to understand how any of these systems work under the bonnet. Nobody is asking for a board full of software engineers. What trustees do need is a working grasp of the risk sitting behind the convenience — because that risk belongs to the charity, whoever built the system.
The scale makes the point for you. The government's 2026 Cyber Security Breaches Survey found that 28% of charities had identified a cyber security breach or attack in the previous twelve months. That's not a fringe concern for large, high-profile organisations. It's a governance issue for almost a third of the sector, most of whom probably didn't see it coming.
Five questions do more work than any policy document
The Beacon incident is a useful prompt, whether or not your charity has ever touched the platform. Ask your board these five questions and you'll learn more than any glossy cyber policy will tell you:
- What personal and sensitive information does our charity hold?
- Which external organisations and systems hold that information on our behalf?
- Are we storing more than we actually need?
- If one of our suppliers were breached tomorrow, who in our organisation would take responsibility for the response?
- Do we know when we'd need to report an incident to the ICO or the Charity Commission?
None of those require a technical expert at the table. They require trustees who understand their own organisation — which is, after all, the job.
The clock starts before you have all the facts
If a personal data breach is likely to put people's rights and freedoms at risk, it normally has to be reported to the ICO without undue delay, and within 72 hours where feasible. That sounds like a demand for certainty you won't have yet.
It isn't. The ICO is explicit that it would rather organisations report early with partial information and add detail later than wait for a complete picture that may never arrive.
Separately, charities need to weigh up whether an incident counts as a serious incident for the Charity Commission. Its guidance on Beacon asks trustees to consider whether the incident has caused, or risks causing, significant harm, loss or damage to the charity, its beneficiaries, its assets, its services or its reputation. Two different reporting duties, two different thresholds, and both worth knowing before you need them.
The lesson isn't "get off the cloud"
Small charities need external technology, and a good system usually offers far better security than a patchwork of spreadsheets, personal inboxes and documents scattered across trustees' laptops. Retreating from digital tools would be the wrong lesson entirely.
The real governance question is this: what happens to our charity if one of the organisations we depend on has a problem?
That question applies to your CRM. It applies to online banking, payroll, accounting software, cloud storage, fundraising platforms — anywhere a supplier is holding something your charity can't afford to lose. Supplier failure and cyber risk need a seat at the table alongside the risks boards are already comfortable discussing.
One question is enough to start with
You don't need a major cyber security project to get moving on this. You need one question on the agenda at your next trustee meeting:
If one of our main digital systems was compromised tomorrow, would we know what to do?
If the honest answer is no, you've already learned something useful about the state of your governance.
Good governance was never about preventing every problem. It's about being ready when one arrives.
Want more like this? I send practical tools, funding ideas, and honest insights straight to your inbox for small and medium charities. Sign up to the newsletter
