Two people sit at a desk, working on laptops, with a large screen behind them showing a CRM system labelled “CRM” listing contact records. A red warning triangle with an exclamation mark overlays the CRM screen, and stacked database icons appear beside it, indicating a data or system issue. On the desk are a padlock symbol, an envelope, and a document titled “DONORS,” suggesting sensitive donor data and communications at risk. Both people look serious and focused, highlighting concern about a CRM security or availability problem caused by a supply‑chain incident.

When your supply chain gets hacked, your mission takes the hit

Over the past few weeks, UK charities have been dealing with two stark reminders that you can do “everything right” internally and still be knocked sideways by someone else’s security failure.

Beacon CRM (a specialist platform built for charities) has confirmed a security incident involving compromised credentials and copies of its database backups being made and likely downloaded. Beacon markets its software to charities and says it has more than 1,500 customers. In parallel, CAF Bank suspended its online banking portal for over 10 days after detecting attempted fraud linked to a vulnerability in third‑party software, leaving some of the 14,000 charities it serves struggling to pay staff or suppliers.

These are not edge cases. They are mainstream infrastructure for the sector. And when they fail, the impact is devastating precisely because charities don’t have much slack in the system.

Beacon CRM: data about donors, service users and supporters in the crosshairs

Beacon’s incident centres on attackers using compromised credentials to access its systems and make copies of database backups. Because Beacon is designed specifically for charities, almost everyone affected is a charity or non‑profit. 

Public statements from organisations like the Centre for Sustainable Energy, PANS PANDAS UK, and The Upper Room paint a consistent and sobering picture. 

Contact and supporter data exposed
Names, email addresses, and where provided postal addresses and phone numbers, donation amounts and dates, and in some cases uploaded files and contact form messages were likely included in the backups, based on statements from affected charities.

No card numbers, but still high‑risk
Several charities have been clear that bank account details and card numbers were not stored in Beacon. That helps, but it doesn’t remove the risk.  Contact details plus donation history and sensitive messages can still be used for targeted fraud, social engineering, and reputational harm.

Deleted doesn’t always mean gone
PANS PANDAS UK, for example, had previously deleted their data from Beacon, but later learned that records of that deleted data were retained in backups and may have been accessible during the breach. That’s a harsh lesson in how retention and backup practices at suppliers directly affect your risk – and in why questions about “what happens to deleted data?” belong in procurement, not just in incident response.

Regulatory and psychological impact
Charities are having to investigate, inform donors and service users, and report to the ICO – all while reassuring already anxious communities and managing the internal emotional load of “we trusted this system and it failed”, as CSE, PANS PANDAS UK and others have described.

This is what “supply chain breach” looks like from a charity’s point of view: it’s not a neat line on a risk register, it’s a very real fear that people who rely on you may now be at greater risk of fraud, harassment or exposure.

Three people stand in front of two computer screens that both show a “Banking portal” page with a large message reading “Service unavailable.” One person on the left wears a headset and looks concerned while taking a call, the person in the middle holds an “Invoice” document and a “Payslip” card with a worried expression, and the person on the right points to dates circled and crossed out on a wall calendar. Icons of a bank building, a power outlet strip, and a metronome appear above them, symbolising financial services, infrastructure, and timing. The illustration represents a banking or payroll disruption caused by a supply‑chain incident and its impact on staff and payments.

CAF Bank: when payments stop, everything stops

CAF Bank’s incident is different in technical detail but similar in impact. After detecting attempted fraud, CAF suspended its online banking portal on 24 July to address a vulnerability in the way third‑party software connects to its systems. Online access has since been restored, but many charities experienced over 10 days of disruption.

Core banking functions remained intact and funds were said to be secure, but for many charities, the immediate reality was brutally simple:

Staff and suppliers can’t be paid
Some charities reported being unable to process payroll and routine payments and spending hours trying to get through by phone.

Uncertainty and planning chaos
During the outage, CAF could not give a firm date for when online access would be safely restored. That uncertainty created planning chaos for organisations already juggling tight cashflow and multiple funding constraints.

Dependency revealed in one move
The outage exposed how deeply the sector depends on a single provider’s portal and integrations. When that portal stops, the operational tempo of thousands of organisations drops, instantly.

Again, the charities weren’t the ones “breached” – but they were absorbing the operational shock, reputational risk, and staff stress.

Why this hits the third sector so hard

Supply chain security is a known issue in every sector. For charities and non‑profits, a few factors make these incidents particularly punishing:

High dependence on a small number of sector‑specific suppliers
Platforms like Beacon and CAF exist because generic tools don’t always fit charity needs. That specialisation concentrates risk: when one of them has a bad day, a huge slice of the sector feels it at once.

Thin margins and limited contingency
Few charities have spare capacity to absorb days of disruption, run parallel systems, or spin up alternative providers at short notice. Outages quickly translate into delayed services, cashflow crunches, and pressure on staff wellbeing.

Sensitive communities and trust‑based relationships
The data held in these systems isn’t just “customer” data. It often includes vulnerable service users, volunteers, campaign supporters, and donors with lived experience of trauma or discrimination. The trust that underpins those relationships is fragile, and incidents like Beacon’s force charities into difficult conversations about risk and privacy.

Regulatory load without big‑firm resourcing
Charities have to navigate ICO reporting, donor communications, Data Protection Impact Assessments (DPIAs), and board oversight with far fewer in‑house specialists than a bank or large corporate. Every hour spent on supplier incident response is an hour not spent directly on their mission.

In musical terms, the sector is playing a complex piece with minimal rehearsal time and no spare players. When one of the amplifiers blows (your CRM, your bank portal), the whole performance is suddenly at risk.

 

 

So what now? From passive dependency to active ‘Cybility’

As much as we wish we could, we can’t remove supply chain risk completely. Both incidents are still under investigation, and neither Beacon nor CAF set out to harm the sector.  However, this does show how important it is to treat third‑party services as part of your own security posture, not an invisible backdrop.

For boards, CEOs, and senior leaders in the third sector, some pragmatic moves:

Prepare: know your critical dependencies
Map out which suppliers are genuinely “single points of failure” – CRMs, banks, payment gateways, case management systems, email platforms. Understand what data they hold, what integrations they run, and what your options are if they go offline or get breached.

Participate: practise supplier‑led incident response
Don’t wait for the next incident to find out who does what. Run tabletop exercises based on scenarios like “Our CRM provider suffers a breach” or “Our bank portal goes down for a week”. Use these to test decision‑making, communications, and coordination with suppliers and regulators.

Probe: ask harder questions of your suppliers
Challenge assumptions about backups, retention and deletion, integration security, and incident communication. If “deleted” data is still in backups, how long is it retained, who can access it, and how is it protected? If fraud in an integration can take your portal offline, what contingency plans exist, and how are they tested?

Don’t expect to achieve all green on the risk register, it’s unrealistic.  However, there are steps you can take to gain clarity, build capability and increase confidence around the risks that matter most.

A diverse group of four people sit around a table in a meeting room, looking at an open workbook that mixes music notation and diagram-style layouts, while a facilitator at the front points to a large wall display. The display shows a simplified system map linking icons for CRM, bank, email, case management, and a payment gateway, with three labelled buttons underneath: “Prepare,” “Participate,” and “Probe.” On the right, a large screen shows four people in a video call with speech bubbles above them, suggesting remote participation. The scene conveys collaborative learning about a supply‑chain incident using musical metaphors and a mix of in‑person and virtual training.
Map out the supply chain so you know the score

Where Charity IT Leaders (CITL) and Cybility are stepping up

The good news is that you’re not alone in trying to navigate all this.

At Charity IT Leaders (CITL), I co‑chair the Cybersecurity Special Interest Group alongside Neil and Phil. Our aim is simple: create a space where charity CIOs, CTOs, IT leads, CEOs and trustees can talk frankly about incidents like Beacon and CAF, share what’s worked (and what hasn’t), and build sector‑specific practice rather than generic “best practice” that doesn’t fit your reality.

In practical terms, the CITL Cybersecurity SIG is:

  • Curating and sharing plain‑English guidance on supplier incidents, drawing on real cases like Beacon and CAF.
  • Facilitating peer‑to‑peer sessions where leaders can compare notes on vendor management, incident communications, and board engagement.
  • Feeding lived experience back into suppliers and policymakers so the sector’s voice is heard when decisions are made.
 

Behind the scenes, we at Cybility are supporting this work by:

  • Turning lessons from Beacon and CAF into play‑based incident exercises.  Think CSIRTxp‑style ‘gigs’ where your team rehearses supplier breach scenarios without blame or fear.
  • Helping charities map their critical supplier landscape and align it with Cybility’s Cybersecurity Conductor Companion™ framework, so supply chain risk sits alongside internal controls, not in a separate box.
  • Advising on incident communications and ICO reporting, so leaders can respond quickly without sacrificing psychological safety for staff or service users.
 

If you’re a charity leader looking at Beacon and CAF and thinking “we could easily be next”, you’re exactly who this work is for.

Call to action

Whether you want support in making sense of your own supply chain exposure, or you’d like to join peers in the CITL Cybersecurity Special Interest Group, there are two simple next steps:

  1. Connect with Charity IT Leaders and register your interest in the Cybersecurity SIG.
  2. Reach out to Cybility to explore a short, focused engagement – from a supplier risk review to a tailored incident rehearsal using CyberDeck8D™ (our own card deck system).

Even if you don’t use Beacon or CAF, the same principles apply to whatever CRMs, banks and platforms sit behind your mission. Supply chain breaches are not going away. However, with the right conversations, practice, and support, the sector can move from being collateral damage to being ready, rehearsed and resilient.

Cartoon mascot with a purple polyhedral dice-shaped head wearing orange glasses, smiling and waving with its left hand. The character has a box-shaped white and orange body decorated with colorful icons: a handshake, gears, a robot head, a circular arrow with a heart, an alert symbol, a person conducting at a podium, and a music note. The figure stands facing slightly left on two purple legs and feet against a plain white background, representing a friendly, game-themed guide for learning or facilitation.

Sources: