On 7 August 2026, the Charity Commission published a notice for charities affected by the cyber security incident involving Beacon's customer relationship management service. The regulator said it was aware of the incident's potential effect on charities using the platform and was monitoring events with the Information Commissioner's Office, which it identified as the lead regulator for information rights and data protection law in the UK. (gov.uk) The notice frames the event as more than a supplier-side technical problem. For affected charities, the immediate question is whether the incident has created governance, reporting and communications duties at organisational level, particularly where supporter or beneficiary data may be involved. (gov.uk)
The Charity Commission said affected organisations have already begun filing serious incident reports and told trustees to keep using the Commission's existing reporting guidance. That guidance requires a report where an incident has caused, or risks, significant harm, loss or damage to the charity, its beneficiaries, assets, services or reputation. (gov.uk) For trustees, the threshold matters. The Commission's wider guidance says prompt reporting remains important even when other agencies are involved, and that charities should explain what happened, the scale of any harm and the steps being taken to address it. (gov.uk)
The data protection track sits alongside charity law. The ICO's guidance says organisations must notify the regulator within 72 hours of becoming aware of a personal data breach where it is likely to result in a risk to individuals' rights and freedoms, and must inform affected individuals without undue delay where the risk is high. The same guidance says all personal data breaches must be documented, whether or not they are reportable. (ico.org.uk) That is why the Commission's notice points trustees towards two audiences beyond the charity regulator itself: the ICO and the individuals whose data is stored on Beacon systems on the charity's behalf. Where a charity uses a software supplier as a processor, the ICO's guidance also makes clear that the charity still needs to assess its own duties as controller, including any notification requirement. (gov.uk)
The Charity Commission's cyber guidance puts responsibility squarely at trustee level. It says trustees should decide what standards they expect on preventing cyber crime, make sure those standards are met, and plan how the charity will respond to an attack, including who is informed and how records are kept. (gov.uk) In practical terms, trustees should be able to show an audit trail: when the charity became aware of the Beacon incident, what data or services may have been affected, what advice was taken, whether donors or beneficiaries were notified, and what immediate controls were introduced to reduce further exposure. The Commission's serious incident guidance says it looks for evidence that trustees have limited the immediate effect and taken steps to prevent a repeat. (gov.uk)
The Commission has also warned that response times may be slower than usual because it expects a high volume of reports and will prioritise the cases carrying the greatest risk. At the same time, it said its own engagement with affected charities would be proportionate, while still checking that trustee duties are being met. (gov.uk) For charities, that means an acknowledgement delay from the Commission does not remove the reporting duties set out in the Commission's and ICO's guidance. Trustees are still expected to assess seriousness, keep records and make any necessary notifications while the regulator triages incoming cases. (gov.uk)
Communication with supporters is another explicit part of the Commission's message. The regulator said many Beacon customers had already moved quickly to inform supporters and stressed that clear communication with stakeholders is important for retaining trust and protecting the relationships on which charities depend. (gov.uk) The ICO's breach guidance takes a similar approach from a data protection standpoint. It says individuals should be informed without undue delay when a breach is likely to result in a high risk to their rights and freedoms, and that organisations should provide information that helps people protect themselves from the effects. (ico.org.uk)
Recent government survey data suggests incident response planning remains uneven across the sector. The Cyber Security Breaches Survey 2025/2026 found that 84 per cent of charities said they would inform directors or trustees after a breach, but only 19 per cent had a formal incident response plan in place and 30 per cent had guidance on when to report externally. The same survey found that cyber security was treated as a high priority by senior management in 60 per cent of charities. (gov.uk) For charities affected by the Beacon incident, the immediate test is therefore not only technical remediation. It is whether trustees can show prompt governance, accurate breach assessment, timely regulatory reporting and credible communication with supporters while the Charity Commission continues to monitor the situation and post any significant updates. (gov.uk)