Blog from Jonathon Allard, Cosmic’s Technical and Security Lead
Cyber resilience for charities is about more than protecting office computers or choosing strong passwords. It also means preparing for problems involving the suppliers, platforms and services your organisation depends on.
Two separate incidents affecting the UK charity sector in July and August 2026 have brought this into sharp focus.
Beacon CRM reported unauthorised access to copies of customer database backups. Separately, CAF Bank suspended online banking after detecting attempted fraud and identifying a vulnerability involving third-party software.
There is no evidence that the incidents are connected. However, together they highlight an important issue.
A charity can face serious data, financial and service disruption even when the original problem begins outside its own systems.
What happened in the Beacon CRM cyber incident?
Beacon CRM is a customer relationship management platform used by charities and other purpose-led organisations.
On 3 August 2026, Beacon told customers that it was investigating unauthorised access to copies of customer database backups.
The Scottish Council for Voluntary Organisations, known as SCVO, reported that charities should assume information stored in Beacon may have been downloaded. This includes attachments.
However, each organisation may face a different level of impact.
What information may have been involved?
One charity might have used its CRM for basic contact information, such as:
- Names
- Email addresses
- Telephone numbers
- Organisation details
Another might have stored more sensitive information linked to donors, volunteers, beneficiaries, service users or casework.
Attachments can also contain sensitive information including correspondence, forms, notes or documents relating to personal circumstances.
Every affected charity must understand what its own organisation stored in the system.
Why does the data involved matter?
The potential harm from a data breach depends on the type of information involved, who it relates to, and how it could be misused.
Basic contact information may not allow someone to take money directly. However, it can make fraud attempts much more convincing.
For example, criminals could use real names, job roles or charity details to create:
- Phishing emails that appear trustworthy
- Fake donation or payment requests
- Calls pretending to come from a colleague or supplier
- Messages asking someone to reset a password
- Attempts to collect further personal information
SCVO has warned charities that criminals could use stolen information to create believable emails, texts and calls.
These messages may involve payments, passwords, donations or personal information.
Charities should therefore remind staff, volunteers and affected contacts to pause and check unexpected requests, even when a message includes familiar information.
What happened with CAF Bank?
CAF Bank provides financial services to more than 14,000 charities.
In July 2026, it suspended its online banking service after detecting suspicious activity affecting a small number of accounts.
During its investigation, the bank identified a previously unknown vulnerability in the way some third-party software connected to its online banking portal.
CAF Bank said its core banking system was not affected and that money remained safe.
However, the loss of online access still created significant problems.
How the disruption affected charities
As a result of the outage, some charities could not make payments through their normal online processes.
Telephone banking remained available. However, increased demand caused delays.
CAF Bank prioritised urgent transactions, including payroll.
At the time of writing on 6 August 2026, CAF Bank’s website stated that its online banking service remained unavailable until further notice.
Therefore, charities using the service should check CAF Bank’s latest guidance before submitting or repeating payment requests.
Cyber resilience for charities includes service continuity
The CAF Bank disruption shows why cyber resilience is not only about whether money or information has been stolen.
A supplier may keep its main system secure but still lose access to an online service.
When that happens, everyday operations can stop or slow down.
For a charity, losing access to online banking can affect:
- Staff wages
- Supplier payments
- Grants and project spending
- Venue or equipment costs
- Payments linked to frontline services
- Staff time and wellbeing
This is a business continuity issue.
Charities need practical contingency plans for essential tasks when a key digital service becomes unavailable.
Those plans should be agreed before an incident, rather than created under pressure.
The shared lesson: understand your supplier risk
Beacon CRM and CAF Bank provide different services, and the incidents are not believed to be linked.
However, both demonstrate third-party cyber risk.
Third-party cyber risk means the risk created by suppliers and platforms your organisation relies on.
Most charities depend on outside organisations for essential systems, including:
- CRM and fundraising platforms
- Cloud storage
- Email and collaboration tools
- Payroll services
- Online banking
- Website hosting
- Donation platforms
- Case-management systems
These suppliers often hold important information or support daily operations.
The National Cyber Security Centre advises organisations to understand how suppliers could expose them to security weaknesses or cyberattacks.
It also recommends checking whether suppliers have suitable security measures in place.
This does not mean charities should avoid external platforms. For most organisations, that would be unrealistic.
Instead, charities need to know what they rely on, what could go wrong and how they would respond.
Six practical steps charities can take now
Charities do not need to solve every issue at once.
Instead, start with the systems, suppliers and information that matter most.
1. Create a list of critical suppliers
Record the platforms and providers your charity relies on.
For each one, note:
- What service it provides
- What information it holds
- Who manages the relationship
- How to contact the supplier urgently
- What would happen if the service stopped
- Whether a backup process exists
Start with services linked to personal data, payments and frontline delivery.
2. Check what data each platform holds
Do not rely only on a supplier’s general description of its service.
Do not rely only on a supplier’s general description of its service.
Check:
- Database fields
- Notes
- Uploads
- Attachments
- Exports
- Archived information
Look at how your own team uses it.
Then, remove data you no longer need in line with your retention policy.
Holding less unnecessary data means exposing less information if a breach occurs.
3. Review permissions and accounts
Then, check who can access each system.
Remove accounts belonging to former staff, trustees or volunteers.
Also, make sure people only have the level of access they need.
Use multi-factor authentication wherever possible.
Finally, avoid shared accounts. Shared access makes it harder to control permissions and investigate unusual activity.
4. Agree an incident response process
After that, agree what staff and volunteers should do when a supplier reports an incident.
Your plan should identify:
- Who leads the response?
- Who contacts the supplier?
- Who assesses the data involved?
- Who informs trustees?
- Who considers regulatory reporting?
- Who manages communications?
- Who records decisions and actions?
Keep the process short, accessible and easy to find.
5. Prepare alternative ways to deliver essential work
In addition, identify the services that cannot simply stop.
Could you still pay staff if online banking became unavailable?
Would frontline teams still have access to essential contact information if your CRM went offline?
Finally, how would people continue working if email or cloud storage failed?
Document safe alternatives and test them.
However, avoid insecure workarounds. For example, do not move sensitive data into personal email accounts or unapproved spreadsheets.
6. Practise clear communication
Finally, plan how your charity will communicate during an incident. People need accurate information without unnecessary alarm.
Communications should explain:
- What has happened?
- What information or services may be affected?
- What the charity is doing?
- What people should look out for?
- What action they need to take?
- Where they can find updates?
Avoid speculation.
Instead, be clear about what you know, what you are still investigating and when you will provide another update.
Data protection and trustee responsibilities
When a supplier experiences a breach, the charity may still have responsibilities for the personal information involved.
Therefore, affected charities should consider how the incident could harm people.
This includes reviewing:
- The sensitivity of the information
- The people affected
- The possible consequences of misuse
Some personal data breaches must be reported to the Information Commissioner’s Office without undue delay.
Where possible, organisations should report a qualifying breach within 72 hours of becoming aware of it.
However, the need to report depends on the level of risk created by the breach.
Meanwhile, the incident response lead should keep trustees informed about significant incidents and the organisation’s response.
Charities should also record their decisions. This includes why they reported or did not report a breach.
In some cases, charities may need specialist legal or data-protection advice. This is especially important when an incident involves sensitive information or vulnerable people.
Questions to ask technology suppliers
Supplier checks do not need to begin with a long technical questionnaire.
Start with clear, practical questions:
Questions about data and access
- What information will you hold for us?
- Where will that information be stored?
- Who can access it?
- Do you use multi-factor authentication?
Questions about incidents and recovery
- How do you back up and restore information?
- How quickly will you tell us about an incident?
- What support will we receive during an outage?
Questions about contracts and suppliers
- Can we export our information in a usable format?
- What happens to our data when the contract ends?
- How do you assess your own suppliers?
The NCSC’s guidance on assessing supply-chain cyber security provides a useful starting point for organisations reviewing third-party risk.
How can Cosmic support charity cyber resilience?
Cosmic works with charities, community organisations and social enterprises to improve their technology, security and digital confidence.
Our support includes:
- Cybersecurity reviews and practical action plans
- Cyber Essentials and Cyber Essentials Plus support
- Information security management
- Managed IT and responsive technical support
- Microsoft 365 support
- Business continuity and disaster recovery planning
- Staff cyber-awareness training
- Digital strategy and leadership support
Explore Cosmic’s cybersecurity and digital resilience support to see how we can help you identify risks and build a practical plan.
Cosmic’s services include Cyber Essentials guidance, information-security support and preparation for unexpected events such as cyberattacks and system failures.
You do not need to know exactly what support you need before getting in touch.
A useful first step is to identify your most important systems, suppliers and services.
Final thoughts on cyber resilience for charities
The Beacon CRM cyber incident and CAF Bank disruption remind us that cyber resilience for charities reaches beyond internal computers and passwords.
It includes:
- The data held by suppliers
- The services your team relies on
- The decisions trustees may need to make
- The plans that keep essential work moving
Finally, start small.
List your critical suppliers, check what they hold and agree what your organisation would do if one became unavailable.
That simple work can make the next difficult situation clearer, calmer and safer.
Take the next step
Would a practical review help your organisation understand its supplier, data and service risks?
Explore Cosmic’s tech support for charities and take the next step towards a clear, manageable resilience plan.
