The Charity Commission has issued guidance to charities affected by a cyber security incident involving Beacon, a customer relationship management service used by organisations to manage information about donors and supporters.
The regulator said it was aware of the incident and its potential impact on charities using the platform. It is actively monitoring the situation and is in contact with the Information Commissioner’s Office, which is the lead UK regulator for data protection and information rights.
A number of affected charities have already submitted serious incident reports to the Commission. The regulator is encouraging trustees to follow its reporting guidance and warned that the volume of submissions means some charities may wait longer than usual for a response.
When should a charity report the incident?
The Charity Commission says trustees should report an incident which results in, or risks, significant harm, loss or damage to their charity, its beneficiaries, assets, services or reputation.
That does not mean every organisation using Beacon will necessarily face the same consequences. The information held, the people affected and the potential harm will differ from charity to charity. Trustees must therefore establish what their organisation stored in the system and assess the consequences for the people whose information may have been involved.
The Commission says it is prioritising cases presenting the greatest risk. Its advice also directs trustees to existing guidance on cybercrime and serious incident reporting.
ICO reporting is a separate responsibility
A serious incident report to the Charity Commission does not replace a charity’s responsibilities under data protection law.
The ICO says organisations must notify it of a reportable personal-data breach without undue delay and no later than 72 hours after becoming aware of it. The threshold depends on whether the breach is likely to pose a risk to people’s rights and freedoms.
An organisation which cannot provide every detail within that period should not necessarily wait for its investigation to finish. The ICO allows information to be supplied in stages and expects the reason for any delay to be explained.
Where a breach is likely to create a high risk for affected people, organisations may also have to tell those individuals without undue delay. Charities should record what happened, the decisions they make and the measures taken in response, including a decision that an incident did not meet the reporting threshold.
What is known about the Beacon incident?
Beacon provides customer relationship management software designed for charities and non-profit organisations. Such systems can be used to organise donor, supporter and fundraising records, although the precise categories of information held will depend on how each customer used the service.
Beacon has reportedly told customers that an unauthorised party accessed its systems and that copies of database backups were made and were likely downloaded. Reporting by The Register said the company advised affected customers to work on the assumption that information stored in their accounts may have been copied while its investigation continued.
The full scale of the incident and the exact data affected across individual charities have not been established publicly. It would therefore be wrong to assume that every Beacon customer, supporter or donor has had the same information exposed.
The Molly Rose Foundation is among the charities to have publicly confirmed that it was affected. It said Beacon informed it of the breach on 3 August and that the platform provider’s investigation was continuing. The foundation said it had no evidence at that stage that its information had been misused.
What should affected charities do?
Trustees and charity managers should first examine the information supplied directly by Beacon and identify which records their organisation held on the platform. They should preserve a clear timeline of when the charity became aware of the incident and the actions taken afterwards.
They should then assess the possible effect on beneficiaries, donors, staff, volunteers and other contacts. Information capable of identifying vulnerable people or enabling convincing fraud and phishing attempts may carry a particularly serious risk.
Charities should consider separately whether they need to:
- submit a serious incident report to the Charity Commission;
- notify the ICO of a personal-data breach within the applicable deadline;
- contact affected individuals where the legal threshold is met;
- review passwords, access permissions and any credentials connected with the service; and
- warn staff and supporters to be alert to suspicious emails, calls, links and requests for information.
The National Cyber Security Centre advises organisations responding to a cyber incident to limit further harm, retain relevant evidence and avoid making changes which could inadvertently destroy useful information before it has been secured.
Supporters should remain alert
Anyone contacted by a charity they support should follow the specific information provided by that organisation. People should be cautious about unexpected messages which use genuine personal details to create a sense of trust or urgency.
Passwords, security codes and banking credentials should never be disclosed in response to an unsolicited message. Suspicious links and attachments should not be opened, and a charity should be contacted through independently verified details if a request appears unusual.
The publication of central guidance is welcome because smaller charities may have limited in-house cyber security or data protection expertise. However, the immediate responsibility remains with each organisation’s trustees to understand its own exposure, protect those who may be affected and make any necessary reports promptly.
Sources
- Charity Commission: Guidance for charities affected by the Beacon cyber security incident
- Information Commissioner’s Office: Personal data breaches guide
- Charity Commission: Reporting or updating a serious incident
- The Register: UK charities count the cost of Beacon CRM cyberattack
- Molly Rose Foundation: Statement on the Beacon CRM data breach