Many Scottish charities use Beacon CRM to manage relationships with donors, supporters, volunteers, and beneficiaries. On 3 August, Beacon informed their customers of a cyber security incident involving unauthorised access to copies of customer database backups.

The latest specific information from Beacon [is on their website](https://www.beaconcrm.org/incident-guidance), and this page is being updated as they have more details, including technical steps you need to take to mitigate further risks.

While investigations continue, there are some practical steps organisations should take now. Even if you’re not a Beacon CRM customer, these principles will help you respond should an incident affect one of your suppliers. 

Co-ordinate your incident response
----------------------------------

If you have a data breach procedure, incident response plan or data protection policy, now is the time to use it.

Ensure there is a clear lead within your organisation coordinating activity, gathering information, and communicating with the supplier, trustees, regulators, and staff as required. Keeping records of decisions and actions taken will also be important.

Start with your own risk assessment
-----------------------------------

Every charity uses its CRM differently. The most important question is not simply whether your organisation uses the affected system but what information was stored within it.

Consider:

*   What categories of personal data were held?
*   Did records include any sensitive information?
*   Could the information increase risks for vulnerable individuals or communities?
*   What impact could disclosure have on supporters, volunteers, staff, or beneficiaries?

Your response should be based on the data your organisation held and the risks it creates for the people affected.

Watch out for phishing and scams
--------------------------------

Following high-profile breaches, cyber criminals may use stolen information to create convincing phishing emails, text messages or phone calls.

Remind staff and volunteers to be cautious about unexpected requests, particularly those involving payments, passwords, donations or personal information. If supporter contact details have been exposed, affected individuals should also be alert to suspicious communications claiming to come from your charity or trusted partners.

Keep your trustees informed
---------------------------

Cyber security is a governance issue as well as an operational one.

Trustees should understand:

*   What has happened
*   Whether personal data may be affected
*   Any regulatory reporting considerations
*   What actions are being taken to reduce risk

Good governance includes documenting decisions and lessons learned from incidents such as this.

Use this as an opportunity to strengthen supplier assurance
-----------------------------------------------------------

This incident is a reminder that charities increasingly rely on third-party suppliers to store and process important information.

Once the immediate response is complete, it may be useful to review:

*   Which suppliers hold your organisation's data
*   What security assurances they provide
*   How and when they would notify you of a breach
*   Whether contracts include appropriate security and reporting requirements

How to report and update people affected by an incident
-------------------------------------------------------

If your organisation is affected, follow [the guidance provided by Beacon](https://www.beaconcrm.org/incident-guidance) and consider your data protection and regulatory obligations carefully. Here are some other sources of guidance:

*   [The ICO assessment tool](https://ico.org.uk/for-organisations/report-a-breach/personal-data-breach-assessment/) helps you decide on the severity of a data breach and what you will need to report
*   [The Scottish Charity Regulator OSCR have updated their incident reporting regime](https://www.oscr.org.uk/news/the-notifiable-events-process-has-been-replaced-changes-in-the-way-charities-report-important-issues-to-oscr/) in 2024. This article sets out when and how you will need to report an incident to OSCR.
*   The National Cyber Security Centre have [a guide on effective communication during a cyber incident](https://www.ncsc.gov.uk/guidance/effective-communications-in-a-cyber-incident).
*   The Cyber incident response line offers free support for organisations experiencing a cyber attack: 0800 1670 623

Cyber incidents can be unsettling, but a calm, structured response focused on understanding the risks and protecting the people you support is the best way forward.

_SCVO's cyber resilience resources, incident response planning guidance, and sources of support can be found at [scvo.scot/support/digital/cyber-resilience](https://scvo.scot/support/digital/cyber-resilience)._

---

## About SCVO

SCVO (Scottish Council for Voluntary Organisations) is the national membership organisation for Scotland's voluntary sector.

Our role is to champion the role of voluntary organisations in Scotland and to support them to do work that has a positive impact.

SCVO supports members and the wider voluntary sector with all aspects of setting up and running a voluntary organisation. SCVO represents the needs and concerns of the voluntary sector to the Scottish government in Holyrood and UK government and Westminster. Through our learning and events programme SCVO offers training and development opportunities to the sector.

Members access an extensive membership benefits package including specialist, in-depth, 1-to-1 guidance from our Information Services team and from professional service partners.

Access to exclusive membership networks (including comms, employers, governance and policy) supports members to grow their connections, stay up to date, exchange ideas and views with peers, and learn through tailored, learning opportunities.

SCVO members enjoy free access to Funding Scotland Premium to stay on top of funding opportunities to support their organisation’s financial resilience.

Discounts and savings savings on SCVO products and services (including our HR service, managed IT support, payroll service and events and training) and partner offers provide members with support to allow them to focus on delivering their organisation’s goals. Further SCVO products and services include [extensive digital support](https://scvo.scot/support/digital), a climate action resource [Growing Climate Confidence](https://climateconfident.scot), a voluntary sector publication [Third Force News](https://tfn.scot) and a voluntary sector jobs and recruitment service [Goodmoves](https://goodmoves.org).

For more information on SCVO membership, visit [SCVO membership](https://scvo.scot/membership)
