This website uses cookies for anonymised analytics and for account authentication. See our privacy and cookies policies for more information.

 




Supporting Scotland's vibrant voluntary sector

Scottish Council for Voluntary Organisations

The Scottish Council for Voluntary Organisations is the membership organisation for Scotland's charities, voluntary organisations and social enterprises. Charity registered in Scotland SC003558. Registered office Caledonian Exchange, 19A Canning Street, Edinburgh EH3 8EG.

Beacon CRM cyber incident: what Scottish charities should do now

Many Scottish charities use Beacon CRM to manage relationships with donors, supporters, volunteers, and beneficiaries. On 3 August, Beacon informed their customers of a cyber security incident involving unauthorised access to copies of customer database backups.

The latest specific information from Beacon is on their website, and this page is being updated as they have more details, including technical steps you need to take to mitigate further risks.

While investigations continue, there are some practical steps organisations should take now. Even if you’re not a Beacon CRM customer, these principles will help you respond should an incident affect one of your suppliers. 

Co-ordinate your incident response

If you have a data breach procedure, incident response plan or data protection policy, now is the time to use it.

Ensure there is a clear lead within your organisation coordinating activity, gathering information, and communicating with the supplier, trustees, regulators, and staff as required. Keeping records of decisions and actions taken will also be important.

Start with your own risk assessment

Every charity uses its CRM differently. The most important question is not simply whether your organisation uses the affected system but what information was stored within it.

Consider:

  • What categories of personal data were held?
  • Did records include any sensitive information?
  • Could the information increase risks for vulnerable individuals or communities?
  • What impact could disclosure have on supporters, volunteers, staff, or beneficiaries?

Your response should be based on the data your organisation held and the risks it creates for the people affected.

Watch out for phishing and scams

Following high-profile breaches, cyber criminals may use stolen information to create convincing phishing emails, text messages or phone calls.

Remind staff and volunteers to be cautious about unexpected requests, particularly those involving payments, passwords, donations or personal information. If supporter contact details have been exposed, affected individuals should also be alert to suspicious communications claiming to come from your charity or trusted partners.

Keep your trustees informed

Cyber security is a governance issue as well as an operational one.

Trustees should understand:

  • What has happened
  • Whether personal data may be affected
  • Any regulatory reporting considerations
  • What actions are being taken to reduce risk

Good governance includes documenting decisions and lessons learned from incidents such as this.

Use this as an opportunity to strengthen supplier assurance

This incident is a reminder that charities increasingly rely on third-party suppliers to store and process important information.

Once the immediate response is complete, it may be useful to review:

  • Which suppliers hold your organisation's data
  • What security assurances they provide
  • How and when they would notify you of a breach
  • Whether contracts include appropriate security and reporting requirements

How to report and update people affected by an incident

If your organisation is affected, follow the guidance provided by Beacon and consider your data protection and regulatory obligations carefully. Here are some other sources of guidance:

Cyber incidents can be unsettling, but a calm, structured response focused on understanding the risks and protecting the people you support is the best way forward.

SCVO's cyber resilience resources, incident response planning guidance, and sources of support can be found at scvo.scot/support/digital/cyber-resilience.

Last modified on 4 August 2026