
Practical security lessons for charities from the Beacon data breach - seven habits any organisation can adopt, and the standards we hold ourselves to.
What happened
In late July 2026, Beacon, a customer relationship management platform used by more than 1,000 United Kingdom charities, suffered a data breach. An attacker used an access key that had been accidentally left in code on a public website to download supporter data: names, contact details and correspondence. No bank or card details were involved, and there is no suggestion that anyone at an affected charity did anything wrong. Our first thought is for the teams now working through a difficult few weeks - many affected charities have responded quickly and openly, and that deserves recognition.
The Charity Commission has issued guidance for affected organisations, and the Information Commissioner’s Office is receiving reports. For the wider sector, the incident carries one clear lesson: the breach did not need a sophisticated attacker. One leaked credential was enough. That is worth acting on, whatever platform you use.
Salesforce and shared responsibility
Several of our customers have asked what this means for their Salesforce environment. The honest answer has two parts.
Salesforce’s side of the platform is among the most heavily defended in the world: independently audited infrastructure, encryption of data in transit and at rest, continuous monitoring, and a public trust site (trust.salesforce.com) documenting its compliance certifications. Charities on Salesforce benefit from a level of security investment no single organisation could fund alone.
The second part matters day to day: security on any cloud platform is shared. Salesforce secures the platform; each organisation is responsible for how its own environment is set up - who has access, what connected tools can do, and where credentials are kept. The Beacon incident was a credential failure, not a platform failure, and that category of risk applies everywhere, Salesforce included. The good news is that these controls are in your hands, most of them are free, and none of them needs a big project.
Seven practices for any charity
Turn on multi-factor authentication for every user - and our recommendation is a phishing resistant method, a passkey or a physical security key, for everyone, not just administrators.
Refresh keys and credentials regularly. Rotate integration keys, passwords and certificates on a schedule - every 90 days for high privilege access, at least annually otherwise - and immediately when anyone with access leaves. A leaked key that has already been replaced is worthless to an attacker.
Give every connected tool the minimum access it needs, through its own dedicated user. Never share an administrator login between tools or people.
Keep credentials in a password manager - never in spreadsheets, documents, email or code.
Review who and what is connected each quarter: users, connected apps and installed packages. Remove anything no longer needed.
Watch for the unusual. Review login history, and run Salesforce Security Health Check, the free tool that scores your settings and lists what to fix. Where budget allows, Salesforce Shield goes further: event monitoring to spot anomalous activity, a long-term audit trail of data changes, and stronger encryption.
Know your duties. Report qualifying breaches to the Information Commissioner’s Office within 72 hours, consider a serious incident report to the Charity Commission, and remind supporters that you will never ask them for passwords or verification codes.
The standard we hold ourselves to
Advice is easier to trust when the adviser follows it. A few of the standards Cirrico has held for some time:
Every member of our team signs in with a physical security key - a hardware device that defeats phishing - and has done since 2025.
Every credential we hold, including for customer environments, lives in an encrypted vault protected by zero-knowledge encryption, meaning not even the vault provider can read it. Credentials never sit in code, documents, spreadsheets or email.
We adopted phishing resistant authentication for customer Salesforce environments ahead of Salesforce’s 2026 enforcement for privileged users.
Anything code related that is public facing or touches an integration passes a second person quality assurance review before deployment, checking specifically that no keys or secrets are exposed.
Cirrico is certified to ISO 27001, the international standard for information security management, is independently assessed under the National Health Service Data Security and Protection Toolkit, and our whole team completes security training every year.
More on how we work securely is on our Trust hub.
If you would like to talk
Security is not a one-off project; it is a set of habits kept up over time. That is why we are careful with promises: no partner can look at an environment once and declare it secure, and you should be wary of anyone who says otherwise. What we can do is work through the practices above with you - run the Health Check together, map your connected tools and their credentials, and agree a rotation schedule that sticks. If that would help, talk to your Cirrico team, or reach us through the contact page on cirrico.com.