Information Security in a Changing Threat Landscape

We hate to be proved right, but our judgement earlier in the year that AI introduces lots of new information security risks seems to be right. Of course there are plenty of old-fashioned security risks too.

Right now:

  • Updates to browsers, operating systems, and anti-virus products are coming thick and fast. The statistics show a striking rise in CVE’s (Common Vulnerabilities and Exposures) from 173 in Feb 2026 to 2,005 CVE’s in July 2026! Sometimes these updates unintentionally break things.
  • AI companies are hacking other companies. Some think this is a marketing strategy. I’m unclear why it’s not seen as a crime. Also they seem to think they may be the horsemen of a soon-to-come apocalypse.
  • AI models are getting rapidly more capable, and dishonest.
  • The charity sector was significantly affected as Beacon CRM had a serious breach over the summer, although we’re all keeping our fingers crossed that the thieves’ statement that they’ve deleted all the data is true.
  • My weekly review of Threat Intelligence sources is taking about three times as long as it did last year, as the number of threats increases.

We’ve had a number of questions from customers following the Beacon breach in particular, asking about our security practices in the light of it.

In short:

  • We’re reviewed their incident report to understand how it happened. Their starting point – the inclusion of AWS Access Keys in public javascript – is something we automatically check for before every update. If there’s anything that looks like security credentials, the update process stops automatically. The same attack path wouldn’t be possible with Lamplight.
  • They also acknowledged that their logging was insufficient to understand fully what happened. We’ve reviewed our logging practices to make sure we’d have the data we’d need in the event of a suspected or actual breach. 
  • We have reviewed, updated, and tested our Major Incident response procedure to make sure we can respond promptly and effectively if there is an incident.
  • Our Terms require us to notify you within 24 hours of an incident.
  • We had an external security assessment of the Lamplight product in June, and carry out and monitor automated internal and external security testing.
  • We are seeking external partners who can provide additional capacity and expertise to support our environments on an on-going basis. We will notify you with 30 days notice if we proceed as they will be sub-processors.
  • We have been in touch with Beacon and other sector suppliers to see if we can establish some kind of information security forum, ideally with engagement from the Charity Commission and other agencies. These conversations are at an early stage but there seems to be an appetite for it.
  • From the information we have, we do not assess that the charity sector generally has been specifically targeted.
  • We have signed the Cyber Resilience Pledge committing us to additional security measures.

Broadly speaking, they were doing things right – like us their ISMS is compliant with ISO27001 and they have Cyber Essentials. We feel awful for the charities, the people affected, and for Beacon, all who’ve had to deal with this over the summer. Our view is that the incident was proof of the old security adage that the attackers only have to succeed once, but the defenders have to do so every time. 

An Information Security Management System means that you are regularly reviewing the threats and risks you face, monitoring the controls you have in place, and updating them as needed. In other words, we have an established process to monitor and review our information security controls. This incident has highlighted the importance of this work, and we are continuing to identify and implement additional controls in response to the risks we face.

What should you do? For our customers, our next Development Webinar will be an Information Security Ask-Us-Anything – no particular agenda from us. Turn up with questions or listen to the conversation.

For now, here’s some starters:

  • Get the basics in place. Multi-factor authentication on everything. Use a password manager to make it easier to use strong, different passwords. Make sure auto-updates of your software are turned on and working, especially your anti-virus. Get some staff training going (there’s stuff on YouTube that’s fine for starters).
  • Do you have a procedure if there is a breach of your systems? Do you know who you have to notify, and when (hint: ICO, Charity Commission, Data Subjects, maybe Fundraising Regulator or others). 
  • Get your Board to consider signing up to the Cyber Resilience Pledge
  • Don’t use software or systems for personal data if the providers don’t have ISO27001 and Cyber Essentials (or something equivalent). It doesn’t guarantee security, but in our view it should be considered a basic requirement. Lists of security measures and assertions that things are secure aren’t worth anything – you have no assurance at all that the controls are in place, or that they are effective, or that they are sufficient. And it’s not enough to say it’s hosted by a provider that’s secure (e.g. AWS or Azure) – that’s necessary, but only tells you the front door has a lock – the back door may be propped wide open.

Photo by freestocks on Unsplash

Sign Up to Our Email Community

If you have enjoyed this blog, sign up to our email community to receive our valuable charity-focused content straight to your inbox.

This field is for validation purposes and should be left unchanged.
Name(Required)
Email(Required)

Read our latest blogs...