This browser is not actively supported anymore. For the best passle experience, we strongly recommend you upgrade your browser.
| 1 minute read

Beacon CRM cyber incident highlights third-party supplier risk for charities

Given the recent focus on cyber incidents affecting the charity and education sectors, Beacon's notification of a potential large-scale CRM data breach is likely to be of particular interest to charities reviewing their supplier and cyber risk arrangements.

Beacon CRM has warned that charity data hosted on its platform was "likely" accessed and copied during a cybersecurity incident affecting its systems. According to reports, the incident came to light on 31 July, with notifications to affected charities following several days later. Beacon has published updates and FAQs on its website, and investigations remain ongoing.

A number of charities have since issued communications to supporters, illustrating the wider consequences that can arise from a supply chain cyber incident, even where an organisation's own systems have not been directly compromised.

The incident serves as a timely reminder that charities should not only focus on their own cyber security controls, but also ensure they have appropriate due diligence and incident response arrangements in place for key third-party suppliers that process personal data on their behalf.

With regulatory reporting obligations potentially arising where personal data has been compromised, affected organisations will be monitoring developments closely as further information emerges regarding the scope of the incident and the data involved.

Based on current reporting, it appears Beacon became aware of the incident on 31 July and notified affected charities on 3 August. If personal data has been compromised, many organisations will be considering whether any notification obligations arise under the UK GDPR. Given the timing of notifications, it is likely that the 72-hour window for any required reporting to the Information Commissioner's Office (ICO) will be a key focus for affected charities over the coming days.

A takeaway from this is that cyber risk increasingly sits within the supply chain. Charities should review supplier contracts, incident notification provisions and data protection arrangements to ensure they are prepared to respond quickly when a third-party breach occurs. 

If your charity has been affected by the Beacon incident, Stone King can advise on data protection, regulatory notifications, and wider incident response considerations. Please get in touch with a member of our Information Law team to discuss how we can assist.

Tags

academies and mats, charity