Cyber Security

Your Business Data Is Everywhere. Do You Know Who Is Protecting It?

The Beacon CRM breach shows why supplier risk is not somebody else’s problem. Understand what your cloud services hold, who can access them and how your business recovers.

10 min read — Altitude IT Security Team

Most businesses no longer keep all their important information on systems they directly control.

Customer records may sit in a CRM. Employee data may sit in an HR platform. Financial information may sit in cloud accounting software. Marketing data may sit in a campaign platform. Files may sit in Microsoft 365, Google Workspace or specialist cloud applications.

That creates a simple security problem:

Your business can suffer a data breach even when nobody attacks your own network.

The recent cyberattack against Beacon CRM, used by more than 1,500 organisations, is a useful example of how one supplier incident can create security and data-protection problems for many customers at once.

A business connected to multiple cloud suppliers, with one compromised supplier sending risk back towards the organisation
Your security boundary includes the cloud suppliers, integrations and credentials connected to your business.

What happened at Beacon?

Beacon discovered a security incident on 29 July 2026. The company later said copies of customer database backups had been created and were likely downloaded by an unauthorised third party.

Customers with accounts created before 27 July were advised to assume that information they stored in Beacon, including attachments, may have been downloaded. The data potentially affected varied between customers and may have included names, addresses, email addresses, telephone numbers, dates of birth, donation records, payment-related information, supporter records, beneficiary or service-user information, documents and attachments.

This does not mean every Beacon customer definitely lost data. The appropriate wording is that information was potentially exposed, may have been downloaded or was reported as affected, depending on the customer and the investigation.

Later reporting indicated that Beacon believed an AWS access key exposed in publicly accessible JavaScript build files may have provided the route into its environment. That is a useful warning because credentials are not only passwords. They can also be API keys, cloud access keys, application secrets, service accounts, automation credentials, admin tokens and app registrations.

These credentials connect systems together and can have significant access. They need the same level of control and review as human accounts.

Your technology estate is bigger than your network

Traditional IT support focused heavily on PCs, servers, networks, firewalls and email. Modern businesses have a much wider estate.

Important information may sit across Microsoft 365, CRM platforms, accounting software, HR systems, helpdesk systems, backup platforms, marketing applications, cloud storage, payment services, industry-specific software, automated workflows and third-party integrations.

A business may have dozens of systems holding or accessing important information. That means cyber security needs to include the whole technology estate, not simply the devices in the office. A wider technology estate review can help turn an organically grown collection of services into an owned and prioritised picture.

Start by knowing what you use

One of the simplest improvements is also one of the most overlooked: create an inventory of your important cloud services.

For each platform, record:

  • what it does;
  • who owns it internally;
  • what information is stored there;
  • who has administrator access;
  • whether MFA is enabled;
  • which applications connect to it;
  • how data is backed up;
  • what happens if the supplier fails; and
  • what happens when the service is cancelled.

This does not need to become a huge compliance exercise. Even a simple register is considerably better than relying on somebody remembering every platform the business uses.

Admin access deserves special attention

Most organisations gradually accumulate administrator accounts. Common problems include former staff retaining access, too many users with admin rights, shared administrator accounts, old supplier accounts, test accounts left active and MFA missing on privileged accounts.

For important systems:

  • use named accounts;
  • enable MFA;
  • separate admin access where practical;
  • remove leavers promptly;
  • avoid unnecessary privileges; and
  • record who is responsible for the platform.

If nobody knows who owns a system, that is already a warning sign. Microsoft 365 is often the most important identity platform in a small business, so a Microsoft 365 Security Baseline Review can establish whether authentication, privileged access and related controls are configured as intended.

Integrations are part of the attack surface

Modern applications rarely operate alone. A CRM might connect to Microsoft 365, Mailchimp, accounting software, Zapier, Power Automate, payment systems, a website, reporting tools or an AI platform.

Every integration may require some form of credential or permission. Ask:

  • what connects to this system?
  • what permissions does it have?
  • is the integration still used?
  • who created it?
  • can the credentials be rotated or revoked?; and
  • what would happen if that integration was compromised?

Unused integrations should not remain connected indefinitely. App registrations, service accounts and API keys deserve an owner, an expiry or review date and a clear revocation process.

Do not forget leavers

SaaS sprawl creates a common leaver problem. A company may disable Microsoft 365, the Windows login and the VPN, but forget CRM accounts, marketing systems, cloud accounting, project tools, supplier portals or specialist applications.

A proper leaver process should cover the whole technology estate, not just Microsoft 365. The owner of each important service should know when somebody leaves, which access needs removing and whether data or ownership needs transferring.

Backup needs a closer look

Businesses often assume that because an application is cloud-based, everything is automatically recoverable. That is not always true.

For important SaaS platforms, understand:

  • what the supplier backs up;
  • how long backups are retained;
  • whether individual records can be restored;
  • whether deleted data can be recovered;
  • whether ransomware or malicious deletion is covered;
  • whether you can maintain an independent copy; and
  • how quickly recovery can happen.

“Hosted in the cloud” is not the same as “we have a tested recovery plan”. A Microsoft 365 Backup arrangement is one part of the picture, but the same questions should be asked of other critical SaaS suppliers.

Data retention reduces the blast radius

The more historical data a platform contains, the bigger the potential breach. Businesses should periodically ask:

  • do we still need this information?
  • are old customers still in the system unnecessarily?
  • are attachments being retained indefinitely?
  • are former employee records being kept appropriately?; and
  • do we have a retention policy?

Reducing unnecessary data reduces both compliance exposure and security impact. Retention is not only a legal or administrative question; it changes how much information is available to an attacker if a supplier is compromised.

Supplier due diligence should be proportionate

You do not need to perform a forensic audit of every SaaS supplier. Important platforms do deserve basic due diligence.

For critical suppliers, consider MFA support, security certifications, encryption, data location, backup approach, breach notification process, sub-processors, support arrangements and exit or data-export options.

Certifications such as ISO 27001 can provide useful assurance. They do not guarantee that a supplier cannot be breached. Security is about reducing risk, not eliminating it.

What happens if your supplier is breached?

This is the part many organisations never plan for. Imagine receiving an email tomorrow saying:

“Assume the data you store with us has been downloaded.”

What happens next? You need to know:

  • who investigates;
  • what data was involved;
  • who contacts the supplier;
  • who contacts the insurer;
  • whether legal advice is required;
  • whether the ICO needs to be notified;
  • whether customers need to be informed;
  • whether passwords or credentials need changing;
  • whether integrations need revoking; and
  • how the business continues operating.

A supplier incident can become your incident very quickly. An incident response plan should include supplier contacts, access owners, recovery decisions and the technical steps needed to revoke or rotate credentials.

Cyber Essentials and supplier risk

Cyber Essentials focuses primarily on the technical controls within your own organisation. Those controls remain important, but supplier risk sits alongside them.

A business can have secure devices, MFA, good patching, strong endpoint protection and proper firewalls, and still experience an incident because an external platform holding its data is compromised.

The right approach is not either/or. You need strong internal controls and visibility of external dependencies. Cyber Essentials provides a useful baseline for the systems you control; a supplier register and proportionate due diligence extend that thinking across the services you rely on.

The Altitude IT view

Modern IT support should answer more than “Are the laptops working?” It should help answer:

Where does our data live, who has access to it and what happens when something goes wrong?

Businesses increasingly depend on dozens of cloud services and integrations. The challenge is not to avoid them. It is to know what you use, what data each service holds, who has access, what connects to it, what security controls are in place, how you recover and what happens when the supplier fails.

If you cannot answer those questions, your technology estate probably needs a review. Altitude IT can help connect Microsoft 365 support, email security, endpoint and access controls with a wider view of suppliers, integrations, backup and incident response.

Sources and Further Reading

This article responds to recent reporting and does not reproduce the source material. The Beacon CRM reporting and background source are:

Reporting remains subject to the supplier’s investigation and customer-specific facts. The account above uses cautious wording and focuses on the practical implications for business security and resilience.

Do you know where your business data actually lives?

Altitude IT helps businesses understand and secure their wider technology estate — from Microsoft 365 and endpoints to cloud applications, supplier access, integrations, backup and incident response. If your systems have grown organically over time, we can help you work out what you have, where the risks sit and what needs fixing first.

Talk to an Expert Read More Security Guides