Many Scottish charities use Beacon CRM to manage relationships with donors, supporters, volunteers, and beneficiaries. On 3 August, Beacon informed their customers of a cyber security incident involving unauthorised access to copies of customer database backups.
The latest specific information from Beacon is on their website, and this page is being updated as they have more details, including technical steps you need to take to mitigate further risks.
While investigations continue, there are some practical steps organisations should take now. Even if you’re not a Beacon CRM customer, these principles will help you respond should an incident affect one of your suppliers.
If you have a data breach procedure, incident response plan or data protection policy, now is the time to use it.
Ensure there is a clear lead within your organisation coordinating activity, gathering information, and communicating with the supplier, trustees, regulators, and staff as required. Keeping records of decisions and actions taken will also be important.
Every charity uses its CRM differently. The most important question is not simply whether your organisation uses the affected system but what information was stored within it.
Consider:
Your response should be based on the data your organisation held and the risks it creates for the people affected.
Following high-profile breaches, cyber criminals may use stolen information to create convincing phishing emails, text messages or phone calls.
Remind staff and volunteers to be cautious about unexpected requests, particularly those involving payments, passwords, donations or personal information. If supporter contact details have been exposed, affected individuals should also be alert to suspicious communications claiming to come from your charity or trusted partners.
Cyber security is a governance issue as well as an operational one.
Trustees should understand:
Good governance includes documenting decisions and lessons learned from incidents such as this.
This incident is a reminder that charities increasingly rely on third-party suppliers to store and process important information.
Once the immediate response is complete, it may be useful to review:
If your organisation is affected, follow the guidance provided by Beacon and consider your data protection and regulatory obligations carefully. Here are some other sources of guidance:
Cyber incidents can be unsettling, but a calm, structured response focused on understanding the risks and protecting the people you support is the best way forward.
SCVO's cyber resilience resources, incident response planning guidance, and sources of support can be found at scvo.scot/support/digital/cyber-resilience.