The Charity Commission has urged charities affected by the recent data breach at Beacon CRM to clearly communicate with stakeholders to retain trust.
In guidance published today, the regulator told charities it was prioritising cases with the greatest risk, due to the volume of reports it is expecting in relation to the cyber-security incident.
This comes after the customer relationship management company Beacon CRM, which holds data from 1,500 charities, told customers that data on its platform had “likely” been downloaded by an unauthorised third party.
Beacon CRM became aware of the breach last week and alerted customers on Monday, saying its understanding was that “compromised credentials were used to gain access” to its data.
Copies of its database backups were made during the breach, it said, with evidence suggesting these were likely downloaded, although the latter is yet to be confirmed.
Since the incident, many charities have filed reports with the Information Commissioner’s Office and the Charity Commission, as well as informing their supporters.
The ICO and the Charity Commission have not disclosed how many charities have reported the incident, while Beacon refused to reveal how many organisations had been affected.
But the Charity Commission today published guidance for affected charities, which urges trustees to consider their reporting obligations to other regulators, notably the ICO, and to individuals whose data is stored on the Beacon system.
The guidance says: “We know many Beacon customers have moved promptly to inform their supporters about this incident.
“Clear communication with your charity’s stakeholders is crucial to retaining trust and protecting the relationships that sustain your work.”
The commission urged trustees to continue following its guidance on serious incident reporting, which requires trustees to report incidents that result in or risk significant harm, loss or damage to the charity, its beneficiaries, assets, services or reputation.
But the regulator said that due to the volume of reports it expects on this matter, alongside other incoming reports, it is “likely to take longer than usual” for the commission to respond.
“We appreciate your patience and understanding as we prioritise instances of the greatest risk,” it said.
The regulator also suggested trustees consult its guidance for charities on dealing with cyber crime and the ICO’s guidance for organisations.
“We appreciate the additional resources charities will need to devote to addressing this issue and the commission will seek to ensure its own regulatory engagement with affected charities is proportionate, while seeking to ensure trustees are fulfilling their responsibilities,” the regulator said.
A spokesperson for Beacon CRM said: “We recently experienced a cyber-security incident that involved unauthorised access to Beacon systems containing data we process on behalf of our customers.
“We immediately engaged the support of external cyber-security experts who swiftly contained the incident and launched an investigation.”
The spokesperson said that since containing the initial incident it had not identified or observed any ongoing unauthorised access to Beacon’s systems, adding that customers can access services as normal.
“We are taking this incident very seriously,” they said. “We have notified all of our customers and our focus is now on supporting them as much as possible in any onward communication of their own regarding potential data impact.”
