🟠 High | Source: The Register — Security
Beacon, a cloud-based CRM platform used by UK charities, has suffered a cyberattack in which database backups are believed to have been stolen. The breach potentially exposes sensitive personal data belonging to donors, supporters, and vulnerable service users across multiple charitable organisations. The incident highlights the significant third-party risk posed by shared SaaS platforms serving the non-profit sector.
Security Architect’s Take: Review your organisation’s contractual and technical due diligence for any SaaS CRM providers handling sensitive personal data — ensure backup encryption, data residency controls, and breach notification SLAs are explicitly defined. If you use Beacon or a similar multi-tenanted charity CRM, assess your exposure now and prepare to notify affected data subjects in line with ICO obligations.
Original advisory: UK charities count the cost of Beacon CRM cyberattack