The Charity Commission has issued guidance to charities affected by a cyber security incident involving online donations and supporter management firm Beacon CRM.
Earlier this week the company said that charities’ data may have been downloaded by a third party as part of a cybersecurity breach.
The regulator is urging trustees at affected charities to follow its guidance on serious incident reporting, which requires them to “report incidents which results in or risks significant harm, loss or damage to the charity, its beneficiaries, assets, services or reputation”.
It is also asking charities to consider their obligations to report the incident to the Information Commissioner's Office (ICO), as well as to individuals whose data is stored by Beacon.
Trustees are also being signposted to the Commission’s dealing with cyber crime guidance and the ICO’s guidance.
The advice has been issued after affected a number of charities submitted serious incident reports to the Commission.
“Due to the volume of such reports expected on this matter alongside other incoming reports, it is likely to take longer than usual for the Commission to respond,” said the regulator.
“We appreciate your patience and understanding as we prioritise instances of the greatest risk.”
It added: “We know many Beacon customers have moved promptly to inform their supporters about this incident.
“Clear communication with your charity’s stakeholders is crucial to retaining trust and protecting the relationships that sustain your work.
“We appreciate the additional resources charities will need to devote to addressing this issue and the Commission will seek to ensure its own regulatory engagement with affected charities is proportionate, while seeking to ensure trustees are fulfilling their responsibilities.”
Among charities impacted is the British Deaf Association (BDA), which has advised its supporters that information stored by Beacon may have been involved but said that “there is currently no evidence that the information has been published or misused”.
Details involved could have included records of payments and donations, communication preferences, event attendance and notes or attachments, warned the BDA, which has confirmed the incident has been reported to the ICO.






Recent Stories