Charities urged to review reporting obligations following Beacon CRM incident
Northern Ireland charities affected by the recent Beacon CRM cyber-security incident are being encouraged to assess the impact on their organisation and consider whether a serious incident report should be submitted to the Charity Commission for Northern Ireland.
On 4 August, Beacon CRM, a customer relationship management (CRM) platform designed specifically for charities and non-profit organisations, announced that they had become aware they may have experienced a cyber-security incident. You can read Beacon’s announcement here: Incident Guidance.
While the number of Northern Ireland charities which may be impacted is not known, the Commission would advise any charity that is affected to take action as soon as possible – including assessing the incident and considering what their legal duties are regarding reporting the incident to the Commission and the Information Commissioner’s Office (ICO).
Prompt action and clear record-keeping will help trustees demonstrate appropriate governance and compliance during this developing situation.
For further information on when and how to report a serious incident to the Commission, please see our guidance: Serious incident reporting