SOC status:Duty analyst on shift

UK Cyber Defence

Sectors · Trade bodies and membership organisations

Thousands of members' trust,held by a team of ten.

Trade associations, professional institutes, learned societies and membership charities. You hold member data, run events, take payments and represent an industry — with a small team and a big mailing list. We provide the security operation you cannot staff yourselves.

Member dataEvents and portalsUK GDPRCharity CommissionCyber Essentials Plus

01The threat picture

Membership organisations aggregate exactly what criminals and hacktivists want.

A trade body's member database is a ready-made target list for phishing an entire industry, its events platform holds attendee and payment data, and its public position on policy makes it a target for hacktivist disruption. Business email compromise aimed at subscription and event payments, ransomware and data extortion against the CRM and document systems, credential harvesting of members through look-alike portals, and the exploitation of ageing website platforms and plugins are the recurring patterns in our weekly report for the sector. The organisations affected rarely have a security team; they have an IT partner and a chief executive who is accountable to a council or a board of trustees.

Obligations
UK GDPR and the ICO · Charity Commission guidance · Cyber Essentials Plus · supplier questionnaires from members
Estate
CRM and membership platforms · events and payment systems · public websites and portals · Microsoft 365 · outsourced IT
Intelligence
NCSC · CISA KEV · leak-site and hacktivist monitoring · our own honeypots and IP Insights
Weekly report
Trade bodies and membership organisations — every Friday

What we watch for

Where membership organisations get hit

01Phishing

Member-list phishing

Your database used to phish your members in your name.

02BEC

Subscription and event BEC

Payment diversion around renewals, conferences and sponsorship invoices.

03Extortion

CRM and document extortion

Member and committee data taken from CRM, SharePoint and file-transfer platforms.

04Web

Website platform exploitation

CMS, plugin and hosting-panel vulnerabilities on member-facing sites.

05Availability

Hacktivist disruption

DDoS and defacement timed to policy positions and events.

06Supply chain

Outsourced IT compromise

The IT partner's remote-access tooling as the way into many clients at once.

Weekly report

Trade body and membership organisation threat intelligence

All insights →

Questions

What membership organisations ask us

We have an IT partner. Why would we need a SOC as well?

Your IT partner keeps things running; a SOC watches for the things that should not be happening and acts on them at 3 a.m. Most of our membership clients keep their IT partner and add SOC365 alongside it.

Can you help us reassure members after an incident?

Yes — including the regulatory notifications, the member communications and the evidence that the cause has been fixed.

What does it cost for an organisation our size?

SOC365 is priced on the estate we monitor, not on enterprise tiers; for most membership organisations it costs less than one events sponsorship a year.

Start a conversation

Protect the membership, keep the trustees calm.

Thirty minutes on your systems, your suppliers and what your members would expect you to have in place.