Recent cyber incidents involving Beacon CRM and CAF Bank have highlighted why cyber security and cyber insurance for charities have never been more important. While the circumstances of each incident were different, both demonstrate that cyber attacks affecting trusted suppliers can have a significant impact on the charities that rely on them.
Two incidents, one important lesson
The recent cyber attack involving Beacon CRM, a customer relationship management (CRM) platform used by charities to manage supporter, donor and fundraising information, highlighted the risks associated with third-party technology providers. Beacon confirmed that unauthorised access to data had occurred, potentially affecting information held on behalf of some charity customers.
Around the same time, CAF Bank, a banking provider used by many charities, experienced disruption after a cyber-related event affected its systems and banking services. Although different in nature to the Beacon incident, it demonstrated how problems affecting a critical service provider can disrupt charities’ day-to-day operations, including accessing accounts, processing payments and managing finances.
Why it’s important to know your suppliers
For charities, cyber resilience is no longer just about protecting internal systems; it’s also about understanding the risks associated with third-party suppliers.
These may include:
- Online donation platforms
- Payment processors
- Cloud storage providers
- Payroll and HR software
- Email marketing platforms
- Customer relationship management (CRM) systems
- Banking providers
- IT support providers
If one of these suppliers experiences a cyber attack, data breach or service disruption, charities could face:
- Exposure of supporter, donor or volunteer information
- Disruption to fundraising activities
- Delays in making or receiving payments
- Temporary loss of access to key systems
- Service interruptions affecting beneficiaries
- Legal or regulatory responsibilities following a data breach
- Reputational damage and reduced supporter confidence
Questions every charity should ask
The recent events provide a useful opportunity to review your organisation’s cyber resilience.
Consider asking:
- Which suppliers hold or process our data?
- Which providers are essential to our day-to-day operations?
- What cyber security measures do they have in place?
- How would they notify us if they experienced a cyber incident?
- Do we have contingency plans if a critical supplier became unavailable?
Strengthening your cyber resilience
Alongside reviewing suppliers, charities should continue to follow good cyber security practices, including:
- Enabling multi-factor authentication (MFA)
- Keeping software and devices up to date
- Training employees and volunteers to recognise phishing emails
- Backing up important data regularly
- Reviewing access permissions
- Testing business continuity and incident response plans
For more practical advice, read our blog, How charities can improve cyber security, which explores these steps in more detail. It also highlights findings from the UK Government’s Cyber Security Breaches Survey 2025/26, which found that 30% of charities identified a cyber security breach or attack in the previous 12 months.
How Cyber Insurance for charities can help
Following a cyber attack or data breach, specialist Cyber Insurance for charities can give organisations immediate access to expert support, helping them respond quickly, minimise disruption and continue delivering vital services.
Depending on the policy, cover may include:
- Incident response specialists
- IT forensic investigations
- Legal and regulatory advice
- Support with data breach notifications
- Public relations assistance
- Business interruption cover (subject to policy terms and conditions)
- Financial protection against certain cyber-related costs
While charities cannot control the cyber security of every organisation they work with, they can reduce their exposure by understanding those risks, strengthening their own cyber security and ensuring they have appropriate insurance in place should the unexpected happen.
Download your Free Charity Cyber Security Guide
Understanding your cyber risks is the first step towards protecting your organisation. Our free Cyber Guide includes practical advice on common cyber threats and how charities can strengthen their cyber defences.
Download our cyber security guide for charities to learn more about the steps your organisation can take to help protect its people, data and operations.
About WRS
With more than 40 years’ experience arranging Charity Insurance, WRS Insurance Brokers understands the unique risks charities face.
If you’d like to discuss your current insurance arrangements or understand whether Cyber Insurance could benefit your organisation, our team is here to help. You can call the team on 01206 760780 or email hello@wrsinsurance.co.uk.
WRS is proudly part of the Benefact Group, a charity-owned, international family of financial services companies that gives all available profits to charity and good causes.