This month, there has been significant news coverage of the Beacon CRM cyber security incident. Whilst our systems have not been affected by this incident, it has given many of our clients a moment to consider what they can learn from this high profile case to ensure they are better protected and prepared for malicious attacks.
When it comes to cyber security planning, there are two important areas to consider; prevention and response. This article focuses on prevention, I will follow up with a separate post on response planning.
Prevention
Preventing a cyber security incident is an obvious goal for any organisation. There are many areas to be considered, making this a task you'll want to regularly monitor to ensure you're following best practice.
One of my favourite analogies for thinking about security of your IT systems is to consider how you would keep your home secure. You wouldn't lock all the windows, only to leave the front door wide-open. Likewise, there isn't a single action that will prevent your organisation from a cyber security incident - it takes lots of separate actions, which together keep your data secure. Having the right policies, governance and staff training in place is imperative when protecting your data.
The Information Commissioner's Office (ICO) has a 5 question checklist to help quickly assess your organisation's security measures. It's a great place to start and can be used to audit your practices to ensure you have everything in place.
Your partners
IT system management and maintenance is a specialist role, which many organisations understandably outsource. If we currently host your CiviCRM system, we're always happy to share details of all the practices we have in place to keep your data secure. This is included in all our contracts but we don't openly publish this to help keep you safe!
The incident last month at Beacon CRM was reportedly due to a compromised AWS (Amazon Web Services) access key.1
At Red Hot Irons (RHI), we do not use AWS. All our sites are hosted on our own server which is independently owned and managed by RHI and our engineers. This allows us to have increased server security and to restrict access to essential staff who have been cleared (i.e. me!).
I'd also recommend reading Matt Wire's excellent post on the CiviCRM Community Blog, which raises some of the important questions you should be asking as an organisation when considering where any of your data is held and who has access.
Guidance and training
For all the basic information and tools you need to protect your charity, we always recommend The National Cyber Security Centre (NCSC) Cyber Action Toolkit. NCSC is a part of GCHQ and there to help protect the online services and devices that we all depend on.
These resources are available for free or low cost and many can be put in place quickly. As well as using the toolkit to help you take the practical steps in managing your information governance, make sure relevant people, like staff and trustees, also read and use it to create an organisational culture of cyber awareness.
NCSC also offers a free online cyber security training for beginners which takes less than 30 minutes to complete. It includes tips about how to prevent cyber crime, such as how to protect against phishing attacks, how to set strong passwords and ways to keep your devices secure.
You can also download NCSC's 10 Steps to Cyber Security, a single summary page of the key advice for medium to large organisations.
Practical steps
There are a number of practical steps you can take now to start improving your security.
Those of you who know me well, know I'm very passionate about password security! It's a really simple thing you can do to ensure your system is less vulnerable to a brute force attack. A brute force attack is where criminals use trial and error to guess username and password combinations (credentials) or encryption keys. The success rate of an attack increases when credentials are simple and easy to guess.2
The most important thing to ensure, is that you do not reuse passwords. If the same credentials are used across multiple accounts, the risk of attack increases dramatically. As a general rule, create a strong initial password and only change them if there are pressing reasons, such as a breach of your systems that may have resulted in the password hashes being compromised.3
You may wish to read my previous post on keeping your passwords safe for more tips.
You are probably already using two or multi factor authentication in a number of ways. These are often referred to as 2FA, TFA or MFA and mean that along with your username and password, you will also need to authenticate your log in with a second factor. This may be via SMS or an authenticator app. It means that even if a username and password was compromised, without the second factor, an account can not be accessed.
If you aren't using TFA on your CiviCRM log in, we certainly recommend you do so! Please reach out and we are happy to support the roll out on your system.
References
- Beacon CRM, accessed August 2026 https://www.beaconcrm.org/incident-faqs
- Information Commissioner's Office, accessed August 2026 https://ico.org.uk/about-the-ico/research-reports-impact-and-evaluation/research-and-reports/learning-from-the-mistakes-of-others-a-retrospective-review/brute-force-attacks/
- Information Commissioner's Office, accessed August 2026 https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/security/a-guide-to-data-security/passwords-in-online-services/#expirations