The Charity Commission has issued guidance after a cyber security incident involving Beacon CRM, stating that charities using the service may face governance, reporting and data protection questions. The regulator said it is actively monitoring the position and is already in contact with the Information Commissioner’s Office, which is the lead regulator for information rights and UK data protection law. The Commission also said it recognises the concern the incident will have caused for affected charities and their supporters. Its response indicates that the issue is being treated as a live compliance matter for trustees, rather than only an operational problem for a service provider.
A number of charities have already submitted serious incident reports. The Commission has told trustees to continue using its existing serious incident reporting guidance where an incident results in, or creates a risk of, significant harm, loss or damage to the charity, its beneficiaries, assets, services or reputation. For boards, that means the reporting test is not confined to confirmed financial loss or a completed investigation. Trustees are expected to assess the scale of risk, record their reasoning and decide whether the incident meets the Commission’s threshold for formal notification.
The guidance also points trustees to other reporting duties, especially to the ICO and to individuals whose data is stored on Beacon systems on behalf of the charity. That places personal data handling alongside charity law compliance at the centre of the response. In practice, charities will need to establish what information is currently available, whether personal data may have been affected and whether notification duties have been triggered. The Commission’s wording also points to the importance of timely, accurate communication with supporters and beneficiaries where their information may be involved.
The Commission has warned that response times are likely to be slower than usual. It expects a high volume of Beacon-related serious incident reports alongside other incoming cases and says it will prioritise the matters presenting the greatest risk. For affected charities, the immediate consequence is that submitting a report may not produce a prompt individual response. Trustees therefore remain responsible for taking proportionate action, keeping records and managing the issue while regulatory contact is pending.
Alongside formal reporting, the Commission has directed trustees to its own guidance on dealing with cyber crime and to the ICO’s guidance for organisations. The emphasis is on oversight as well as response: trustees need to understand the risk, check that appropriate internal action is under way and make sure decision-making can be evidenced if regulators ask for it later. The Commission also noted that many Beacon customers have moved quickly to inform their supporters about the incident. It said clear communication is important for retaining trust and protecting the relationships that sustain charitable work.
The closing message is measured. The Commission said it recognises the additional resources charities will need to commit and that its own engagement with affected organisations will be proportionate, while still expecting trustees to fulfil their responsibilities. For the sector, the guidance underlines how a cyber incident affecting a shared digital service can quickly become a trustee issue covering governance, reputation, service delivery and data protection. The Commission has said it will continue to monitor developments and post any significant updates on the same page.