CRM Data Breach: What UK Small Businesses Must Do

A data breach at a software supplier can quickly become your business problem, even when your own systems were not directly attacked.
That is the practical lesson from a cyber incident involving Beacon, a customer relationship management platform used by charities, and the Royal National Lifeboat Institution. According to reporting published by The Guardian on 20 September 2026, the RNLI warned supporters that names, contact details and records of their interactions with the charity may have been affected by an attack on its CRM provider in late July.
The platform is reportedly used by around 1,500 charities. The incident was not described as an attack specifically aimed at the RNLI. At the time of the report, there was no evidence that the RNLI data had been published, shared or misused. The attacker reportedly claimed the data had been deleted, but a claim from an attacker cannot provide the same assurance as independent evidence.
For a small business owner, the most useful question is not whether a well known charity was affected. It is this: if a supplier holding your customer data suffers a breach, would you know what to do during the first 72 hours?
Why a supplier breach is still your business problem
Small businesses increasingly rely on external platforms for customer records, email marketing, online bookings, payments, accounting, recruitment and file storage. That can improve efficiency and provide capabilities that would otherwise be unaffordable.
However, outsourcing the technology does not remove your responsibilities to customers. If personal information you control is exposed through a supplier, you may still need to assess the risk, document the incident, communicate with affected people and report it to the Information Commissioner’s Office.
This does not mean every supplier incident automatically becomes a reportable breach for every customer. The facts, affected information, number of people and likely consequences all matter. The mistake is waiting passively for the supplier to solve everything before beginning your own assessment.
My view: a supplier can host the system, but it cannot own your relationship with your customers. When something goes wrong, they will judge your response as well as the supplier’s security.
The first 72 hours after a CRM data breach
The ICO says organisations should report a personal data breach when it is likely to create a risk to people’s rights and freedoms. Where reporting is required, it should be made as soon as possible and, where feasible, within 72 hours of becoming aware of the breach. If the risk is high, affected people should also be informed without undue delay.
The 72 hour period is not a reason to rush into an inaccurate public statement. It is a deadline for disciplined assessment and action.
1. Establish what is known and what remains uncertain
Contact the supplier through a verified channel and request a written incident summary. Ask:
- When did the incident begin and when was it detected?
- Which systems, accounts and backups were affected?
- What categories of personal information may have been accessed?
- Which of your records were involved?
- Was the information copied, encrypted, changed or deleted?
- What containment measures have been completed?
- Which regulators and law enforcement bodies have been contacted?
- When will the next verified update be provided?
Keep a record of facts, assumptions, decisions and times. Do not treat an absence of evidence as proof that no information was taken.
2. Protect access and preserve evidence
Reset credentials connected to the affected service, prioritising administrator accounts. Review multifactor authentication, active sessions, application integrations and user permissions. Remove access that is no longer required.
Preserve relevant emails, audit logs, supplier notices and screenshots. Avoid deleting evidence in an attempt to tidy the system. If the incident is serious or technically complex, obtain specialist cyber security and legal advice.
3. Assess the risk to people
Do not assess severity only by counting records. Consider what the information could allow someone to do.
Names and email addresses may create phishing risk. Telephone numbers and service histories may help criminals impersonate your business. Financial, health, identity or employee information can create substantially greater harm. Several ordinary pieces of information can also become sensitive when combined.
Your assessment should consider:
- the sensitivity and volume of the information;
- whether it was encrypted or otherwise protected;
- the people affected and any particular vulnerability;
- the likelihood of fraud, impersonation, discrimination or distress;
- whether the information has already appeared online;
- what effective containment is still possible.
4. Decide whether notification is required
Use the ICO personal data breach guidance to decide whether a report is required. If the assessment cannot be completed immediately, the ICO allows organisations to provide information in phases, provided there is no undue further delay.
Document the decision even if the breach is not reported. The record should explain the evidence considered, the risk assessment and the person responsible for the decision.
5. Communicate calmly and usefully
If customers or employees need to be informed, tell them what happened, what information was involved, what the business has done and what practical steps they should take.
A useful notification may advise people to be alert to targeted emails, avoid sharing passwords or payment details in response to unexpected contact and verify requests through a known telephone number or website.
Avoid vague reassurance and avoid speculation. It is better to say that an investigation is continuing and give a time for the next update than to make a confident statement that may later prove wrong.
How to keep the business operating
A data breach is also an operational continuity problem. If a CRM becomes unavailable, the business may lose access to customer contact details, appointments, sales history, consent records and follow up tasks.
Every small business using a critical cloud platform should know how it would continue for several days without it. That may include:
- an up to date list of essential supplier contacts;
- a secure and tested export of critical business records, where appropriate;
- a manual method for recording urgent enquiries and appointments;
- a process for verifying customer identity without exposing more information;
- named responsibility for customer and regulatory communications;
- a controlled method for restoring records once the platform returns.
A backup is only useful when it is recent, secure and capable of being restored. Exporting personal data into an unprotected spreadsheet can create a second risk, so access and storage must be controlled.
What to check before choosing a CRM supplier
Price and features matter, but a low monthly fee can become expensive if the system fails at a critical moment. Before trusting a supplier with customer information, ask for clear answers about:
- where the data is stored and which subcontractors are involved;
- encryption, multifactor authentication and access controls;
- backup arrangements and recovery targets;
- incident notification times and named contact routes;
- audit logs and the ability to export your information;
- responsibility, liability and assistance following a breach;
- secure deletion when the contract ends.
The ICO’s guidance on controller and processor contracts explains the contractual requirements when another organisation processes personal information on your behalf.
A practical supplier risk test
For each system holding personal or commercially important information, record five things:
- What information does it hold?
- Who can access it?
- How quickly must the supplier notify you?
- How would you operate without it?
- Who in your business makes decisions during an incident?
This does not require a large corporate compliance department. A one page register, reviewed quarterly and whenever a new system is introduced, can expose missing contracts, excessive permissions and services for which nobody has planned an alternative.
My view: resilience is part of customer service
Small businesses cannot eliminate every cyber risk, and they should not pretend that choosing a reputable provider makes an incident impossible. They can, however, choose suppliers more carefully, restrict access, prepare an operating fallback and respond honestly when something goes wrong.
Customers may understand that a supplier was attacked. They are less likely to accept silence, confusion or a business that cannot explain what it is doing to protect them.
Good data protection is therefore not merely a legal exercise. It is part of operational discipline, reputation management and customer service. The strongest response begins before the breach, with clear responsibility and a plan that has already been tested.
This article provides general business guidance and is not legal or cyber security advice. Businesses should obtain appropriate professional advice for their circumstances.
Sources and further guidance
- The Guardian: RNLI warns supporters that personal information may have been accessed
- Information Commissioner’s Office: Personal data breach guidance
- Information Commissioner’s Office: Contracts and liabilities between controllers and processors
For more practical analysis of current business developments, visit the Skills 2 Grow Business Journal.
Join the Skills 2 Grow Business Growth Community
Ongoing business support, increased visibility and valuable professional connections for £25 per month.
Join the Community
