Skip to main content

The Beacon CRM breach: a good moment for UK charities to ask “where does our data actually live?”

If you work in a UK charity, you’ve probably already seen the emails. On 3 August, Beacon CRM told its customers — over 1,500 charities use the platform — that someone had used stolen credentials to access copies of its database backups, and that the data had likely been downloaded. Organisations including the Upper Room, English National Ballet and Chiswick House and Gardens Trust have since written to their own supporters warning that names, addresses, emails, phone numbers and, in some cases, dates of birth may have been exposed. Beacon says there’s no evidence yet of the data being sold or shared, and it’s working with cyber-security specialists, law enforcement, and the ICO. SCVO and other sector bodies have published guidance for affected organisations. (The Register; Civil Society News; SCVO)

If your charity uses Beacon, our sympathy is with you this week — this kind of incident is stressful, time-consuming, and not really anyone’s “fault” in a simple sense. Credential-stuffing and phishing attacks succeed against well-run organisations all the time. But it’s also a genuinely good moment to ask a question that’s easy to put off in normal times: if our CRM provider had a bad week, what would actually happen to our supporters’ data — and is there a setup that makes that question less scary?

This is where we think CiviCRM has a real, practical advantage for charities, and it’s the platform we’ve specialised in implementing and supporting for UK nonprofits for years.

Your data isn’t sitting in a shared pool with a thousand other charities. Beacon, like most modern charity CRMs, is a multi-tenant SaaS product — everyone’s data lives in the same infrastructure, managed entirely by one vendor. That’s efficient, but it also means one compromised set of credentials can, in principle, touch a huge number of organisations at once. CiviCRM is self-hosted: it runs on infrastructure you or your hosting partner control, separate from every other charity using CiviCRM. There’s no single “honeypot” holding your supporters’ details alongside everyone else’s.

You know exactly who’s responsible, and for what. With a SaaS vendor, your data protection compliance ultimately rests on their internal security, their staff, and their incident response — which you can ask about but can’t fully audit. With a self-hosted CiviCRM, the chain of responsibility for hosting, backups, and access control is one you set up and can see end-to-end, which tends to make GDPR accountability conversations with your board or trustees a lot more concrete.

Open source means the code has been reviewed by more than one company’s engineers. CiviCRM’s source is public, its security issues are disclosed through a transparent security advisory process, and a global community of implementers has eyes on it. That’s a genuinely different security model to a closed, proprietary product where you have to take one vendor’s word for it.

No single vendor’s bad week becomes the whole sector’s bad week. Because CiviCRM can be hosted by many different providers — including, if you’d like, one we help set up and support — an incident at one hosting company doesn’t cascade across every CiviCRM user in the country the way it can with a single dominant SaaS platform.

To be fair to Beacon and to the sector generally: switching CRM is a real project, self-hosting requires a competent partner rather than a “set and forget” assumption, and no system is risk-free. We’re not going to pretend a CRM migration is trivial, and we wouldn’t recommend anyone rush a decision this significant purely off the back of a news cycle.

But if this week has you and your trustees genuinely reconsidering your CRM setup — or just wanting a second opinion on your current data protection arrangements, whatever platform you’re on — we’d be glad to have a no-obligation conversation about what a CiviCRM setup could look like for your organisation, including realistic costs and timelines. You can reach us at info@mjwconsult.co.uk or via the contact page.