{"id":285,"date":"2026-06-23T14:04:45","date_gmt":"2026-06-23T13:04:45","guid":{"rendered":"https:\/\/www.cardonet.co.uk\/insights\/?p=285"},"modified":"2026-06-23T14:04:48","modified_gmt":"2026-06-23T13:04:48","slug":"membership-bodies-cyber-risk-why-youre-a-target","status":"publish","type":"post","link":"https:\/\/www.cardonet.co.uk\/insights\/membership-bodies-cyber-risk-why-youre-a-target\/","title":{"rendered":"Membership Bodies and Cyber Risk: Why You are a Target"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Most membership body leaders assume cybercriminals are interested only in banks, retailers, or large corporations. That assumption \u2013 understandable and logical but almost universally wrong &#8211; is why charities and membership organisations make such attractive targets.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>They are targeted by cybercriminals because they hold large volumes of sensitive personal data, operate with lean (often inadequate) IT resources and volunteer access, and rarely have formal cybersecurity defences in place.<\/strong>&nbsp;The combination of valuable data and limited protection is not a gap that sophisticated attackers miss and the organisations most at risk are rarely the ones that know it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Only when you understand the logic of the threat can you create a response that is proportionate, practical, and grounded in what your organisation can actually do. Let&#8217;s start with what you&#8217;re holding.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>You Hold More Than You Think<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Leaders underestimate the value of the data they manage every day.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Consider what a typical membership organisation actually holds.&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Full names and contact details<\/li>\n\n\n\n<li>Professional qualifications and employment history<\/li>\n\n\n\n<li>Payment card information or direct debit mandates for membership fees<\/li>\n\n\n\n<li>Dates of birth, equality monitoring data, and health information collected for events or access requirements<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">For professional bodies and trade associations, there may also be disciplinary records, correspondence relating to complaints, and documentation of individual members&#8217; legal or regulatory standing.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To a cybercriminal, this is not mundane administrative data. It&#8217;s a structured database of professionally verified identities, the kind of information that enables identity fraud, targeted phishing, and extortion. The\u00a0<a href=\"https:\/\/www.ncsc.gov.uk\/files\/Cyber_threat_report-UK-charity-sector.pdf\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">NCSC&#8217;s Cyber Threat Report for the UK Charity Sector<\/a>\u00a0notes that charities are particularly attractive to attackers seeking financial gain because they hold valuable data while often operating without the cyber defences that commercial organisations of comparable size would have in place.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">What makes this harder to grasp is that membership bodies don&#8217;t feel like data businesses. But from a data protection and cybersecurity perspective, they are running operations that would attract regulatory scrutiny if they were in a commercial context. The same obligations, and the same risks, apply.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"683\" src=\"https:\/\/www.cardonet.co.uk\/insights\/wp-content\/uploads\/2026\/06\/why-membership-bodies-are-cyber-risk-cardonet-1024x683.png\" alt=\"\" class=\"wp-image-290\" srcset=\"https:\/\/www.cardonet.co.uk\/insights\/wp-content\/uploads\/2026\/06\/why-membership-bodies-are-cyber-risk-cardonet-1024x683.png 1024w, https:\/\/www.cardonet.co.uk\/insights\/wp-content\/uploads\/2026\/06\/why-membership-bodies-are-cyber-risk-cardonet-300x200.png 300w, https:\/\/www.cardonet.co.uk\/insights\/wp-content\/uploads\/2026\/06\/why-membership-bodies-are-cyber-risk-cardonet-768x512.png 768w, https:\/\/www.cardonet.co.uk\/insights\/wp-content\/uploads\/2026\/06\/why-membership-bodies-are-cyber-risk-cardonet-280x187.png 280w, https:\/\/www.cardonet.co.uk\/insights\/wp-content\/uploads\/2026\/06\/why-membership-bodies-are-cyber-risk-cardonet-1170x780.png 1170w, https:\/\/www.cardonet.co.uk\/insights\/wp-content\/uploads\/2026\/06\/why-membership-bodies-are-cyber-risk-cardonet.png 1200w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Why Attackers Choose Easy Over Lucrative<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">One of the questions we hear most often is a version of:&nbsp;<em>&#8220;Why would anyone bother with us?\u201d<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Cybercriminals, particularly those deploying ransomware or phishing campaigns at scale, are not worried about prestige. They&#8217;re optimising for effort versus return. A large bank is protected by multiple security teams, sophisticated monitoring tools, and massive investment in cyber resilience. A membership body with 3,000 members, two part-time staff, and a handful of volunteers running operations from personal laptops is a fundamentally different proposition.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">According to the\u00a0<a href=\"https:\/\/www.gov.uk\/government\/statistics\/cyber-security-breaches-survey-2025\/cyber-security-breaches-survey-2025\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">UK Government&#8217;s Cyber Security Breaches Survey 2025<\/a>, 30% of UK charities reported experiencing a cyber breach or attack in the past year. This is about 61,000 organisations. The average cost of the most disruptive breach for a charity reached \u00a38,690, though some organisations faced losses as high as \u00a3350,000.\u00a0<a href=\"https:\/\/www.abi.org.uk\/news\/news-articles\/2025\/11\/nearly-200-million-paid-in-cyber-claims-to-help-uk-businesses-recover\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">The Association of British Insurers reported<\/a>\u00a0that UK cyber insurance payouts jumped from \u00a359 million in 2023 to \u00a3197 million in 2024, with ransomware and malware accounting for over half of all claims.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The logic of opportunistic cybercrime is straightforward: low resistance for real reward. A membership body that has never run a penetration test, has no incident response plan, and relies on volunteers to handle sensitive data access is a path of least resistance. Although the data has value the defences are often minimal. That drives targeting decisions, not the headline name on the door.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>The Three Threat Types That Matter Most<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Not every cyber threat is equally relevant to membership bodies. What follows is a plain-English briefing on the three attack types that show up most consistently in the sector.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Phishing and business email compromise.<\/strong><br>This is by far the most common threat. Phishing attacks (emails designed to trick recipients into clicking malicious links, revealing passwords, or transferring money) accounted for 86% of the breaches reported by charities in the\u00a0<a href=\"https:\/\/www.gov.uk\/government\/statistics\/cyber-security-breaches-survey-2025\/cyber-security-breaches-survey-2025\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">DSIT Cyber Security Breaches Survey 2025<\/a>. Business email compromise, where an attacker impersonates a senior figure or trusted supplier to authorise a fraudulent payment, accounted for 35% of reported incidents. The\u00a0<a href=\"https:\/\/www.ncsc.gov.uk\/news\/charities-offered-latest-insight-into-key-cyber-threats-to-help-keep-out-attackers\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">NCSC documented a case<\/a>\u00a0in which a hospice in the West Midlands lost \u00a317,000 to a single business email compromise incident. For a membership body operating on tight margins, that kind of loss is not a footnote &#8211; it&#8217;s a crisis.<\/li>\n\n\n\n<li><strong>Ransomware.<\/strong><br>Ransomware attacks encrypt an organisation&#8217;s files and demand payment for their release. They are less frequent than phishing but significantly more disruptive. The\u00a0<a href=\"https:\/\/www.ncsc.gov.uk\/news\/charities-offered-latest-insight-into-key-cyber-threats-to-help-keep-out-attackers\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">NCSC reported<\/a>\u00a0that a ransomware attack on the Edinburgh Festival Fringe Society cost \u00a395,000 to resolve. For a membership body, the consequences extend beyond the financial as years of member records, event history, communications, and governance documentation can be destroyed or made inaccessible overnight. The operational disruption before any ransom is even considered can be enough to threaten an organisation&#8217;s continued functioning.<\/li>\n\n\n\n<li><strong>Data exfiltration.<\/strong><br>This is less visible than ransomware and involves an attacker quietly extracting information from systems over time without triggering obvious alarms. This is the threat that&#8217;s hardest to detect and, in GDPR terms, potentially the most consequential. If member data is accessed and exported without your knowledge, you have a reportable breach under the ICO&#8217;s 72-hour notification requirement, even if your systems never went offline.<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"683\" src=\"https:\/\/www.cardonet.co.uk\/insights\/wp-content\/uploads\/2026\/06\/most-dangerous-membership-body-cyber-threats-cardonet-1024x683.png\" alt=\"\" class=\"wp-image-289\" srcset=\"https:\/\/www.cardonet.co.uk\/insights\/wp-content\/uploads\/2026\/06\/most-dangerous-membership-body-cyber-threats-cardonet-1024x683.png 1024w, https:\/\/www.cardonet.co.uk\/insights\/wp-content\/uploads\/2026\/06\/most-dangerous-membership-body-cyber-threats-cardonet-300x200.png 300w, https:\/\/www.cardonet.co.uk\/insights\/wp-content\/uploads\/2026\/06\/most-dangerous-membership-body-cyber-threats-cardonet-768x512.png 768w, https:\/\/www.cardonet.co.uk\/insights\/wp-content\/uploads\/2026\/06\/most-dangerous-membership-body-cyber-threats-cardonet-280x187.png 280w, https:\/\/www.cardonet.co.uk\/insights\/wp-content\/uploads\/2026\/06\/most-dangerous-membership-body-cyber-threats-cardonet-1170x780.png 1170w, https:\/\/www.cardonet.co.uk\/insights\/wp-content\/uploads\/2026\/06\/most-dangerous-membership-body-cyber-threats-cardonet.png 1200w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Where the Gaps Usually Are<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Vulnerabilities in membership bodies tend to follow a consistent pattern, regardless of size or sector.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Volunteer access on personal devices.<\/strong><br>Many membership organisations rely on volunteers to do the key work. Treasurers, committee members, event coordinators can access sensitive systems from their own laptops, tablets, and mobile phones. Those devices may have outdated software, no endpoint protection, and a history of personal browsing that creates additional risk. Imagine a volunteer treasurer accessing your membership database and finance system from a home laptop that hasn&#8217;t had a security update in two years. That&#8217;s not a hypothetical, it&#8217;s a structural feature of how the sector operates.<\/li>\n\n\n\n<li><strong>No formal access controls.<\/strong><br>In organisations without dedicated IT support, access permissions often accumulate by default rather than by design. Former volunteers may still have live credentials, staff who&#8217;ve changed roles may retain access they no longer need and systems purchased years ago may have default administrator passwords that were never changed. Each of these represents an open door.<\/li>\n\n\n\n<li><strong>Unpatched software and ageing infrastructure.<\/strong><br>Deferred IT investment creates a direct cybersecurity exposure. Software that hasn&#8217;t received security updates is software with known vulnerabilities and attackers actively scan for organisations running unpatched systems; it&#8217;s one of the primary tools of automated threat campaigns.<\/li>\n\n\n\n<li><strong>No incident response plan.<\/strong><br><a href=\"https:\/\/www.gov.uk\/government\/statistics\/cyber-security-breaches-survey-2025\/cyber-security-breaches-survey-2025\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">The DSIT survey found<\/a>\u00a0that board-level responsibility for cyber security is actively declining across the sector, and formal incident response plans remain rare in resource-constrained organisations. What this means in practice is that when something goes wrong, and eventually it probably will, the organisation has to make decisions in real time, under pressure and without a rehearsed process. That&#8217;s the worst possible moment to work out what to do.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>What a Proportionate Response Looks Like<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">You do not need enterprise-level security to meaningfully reduce your exposure.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Cyber Essentials certification<\/strong>\u00a0is the natural starting point for any membership body. Developed by the UK government and certified by the\u00a0<a href=\"https:\/\/www.ncsc.gov.uk\/cyberessentials\/overview\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">National Cyber Security Centre<\/a>, it covers the five foundational controls that address the majority of commodity cyber attacks:\u00a0<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Firewalls<\/li>\n\n\n\n<li>Secure configuration<\/li>\n\n\n\n<li>Access control<\/li>\n\n\n\n<li>Malware protection<\/li>\n\n\n\n<li>Patch management.\u00a0<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Crucially, it also demonstrates to funders, insurers, and enterprise partners that your organisation has met a recognised standard, something increasingly expected in grant applications and procurement processes.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Staff and volunteer awareness training<\/strong>\u00a0addresses the human layer, which is where most attacks succeed. Phishing and business email compromise work because people are deceived, not because technical defences fail. A simple, well-run awareness programme doesn&#8217;t require specialists to deliver it and reduces susceptibility significantly. The\u00a0<a href=\"https:\/\/www.ncsc.gov.uk\/collection\/top-tips-for-staying-secure-online\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">NCSC offers free resources<\/a>\u00a0specifically designed for small organisations and charities.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Access control and offboarding discipline.<\/strong>&nbsp;Every person with access to your systems should have the minimum permissions required for their role and nothing more. Every departure, whether staff or volunteer, should trigger an immediate access review. This is just good governance.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Managed IT support with security monitoring.<\/strong>&nbsp;For organisations without in-house IT capability, a managed service provider that includes security monitoring such as watching for unusual activity, managing updates, and providing a response capability fundamentally changes the risk profile. It means that the signals of an attack are less likely to go undetected until the damage is done.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Cybersecurity is a governance issue, not an IT afterthought.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Why This Matters<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The consequences of a cyber incident reach well beyond the immediate disruption. For membership bodies, trust is key. Members share personal data, professional credentials, and financial information because they trust the organisation will protect it. A breach, especially a poorly handled one, can break that trust in ways that can take years to repair, if repair is even possible.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The ICO&#8217;s enforcement record shows that charities and membership bodies are not exempt from regulatory action. A failure to implement reasonable security measures, followed by a reportable breach, can result in formal reprimand, mandatory remediation, and in some cases financial penalty. The reputational damage of a public enforcement notice can be more damaging than the fine itself.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">There is also the practical question of operational continuity. Many membership bodies are running processes including financial administration, event management, and member communications that depend entirely on systems that have never been properly assessed for resilience. If a ransomware attack takes those systems offline for a week, this is not a minor inconvenience. It can compromise annual conferences, disrupt renewal cycles, and leave the organisation unable to meet its obligations to members and funders.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.gov.uk\/government\/statistics\/cyber-security-breaches-survey-2025\/cyber-security-breaches-survey-2025\">The DSIT<\/a><a href=\"https:\/\/www.gov.uk\/government\/statistics\/cyber-security-breaches-survey-2025\/cyber-security-breaches-survey-2025\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"> <\/a><a href=\"https:\/\/www.gov.uk\/government\/statistics\/cyber-security-breaches-survey-2025\/cyber-security-breaches-survey-2025\">2025 survey<\/a>\u00a0found that the average most-disruptive breach cost a charity \u00a38,690. But averages obscure the range. Some organisations have absorbed losses in the hundreds of thousands. The asymmetry matters: the cost of basic prevention is modest; the cost of recovering from a significant incident is not.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Protecting Your Membership Body: Next Steps<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The starting point is honest assessment. Most membership bodies have never had an independent review of their cyber posture, not because it&#8217;s expensive but because no one has pushed for it. That review is worth having before an incident makes it urgent.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Three things worth doing over the next 90 days:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Commission a basic security audit.<\/strong>\u00a0Understand what access exists, where your data lives, what software is unpatched, and what gaps exist in your access control processes. A focused audit from a provider experienced with resource-constrained organisations will surface more than a self-assessment checklist.<\/li>\n\n\n\n<li><strong>Start the Cyber Essentials process.<\/strong>\u00a0It&#8217;s the recognised baseline for UK organisations, it&#8217;s achievable without specialist staff, and it addresses the majority of commodity threats. Cardonet&#8217;s\u00a0<a href=\"https:\/\/www.cardonet.co.uk\/cyber-security-services-business.php\" target=\"_blank\" rel=\"noreferrer noopener\">cybersecurity services<\/a>\u00a0include Cyber Essentials support designed for organisations at exactly this stage.<\/li>\n\n\n\n<li><strong>Put cybersecurity on the board agenda.<\/strong>\u00a0This is not a technical item but a governance question: what data do we hold, who can access it, what would happen if we lost it, and what reasonable steps are we taking? That conversation, held annually, is one of the most cost-effective risk management decisions a membership body can make.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">For a clearer picture of where your organisation stands right now, Cardonet&#8217;s\u00a0<a href=\"https:\/\/www.cardonet.co.uk\/cyber-security-audit-business.php\" target=\"_blank\" rel=\"noreferrer noopener\">cyber security audit<\/a>\u00a0provides an independent, plain-language assessment of your risk exposure without requiring technical knowledge to act on the findings. To find out more, contact us at\u00a0<a href=\"https:\/\/www.cardonet.co.uk\/index.php\" target=\"_blank\" rel=\"noreferrer noopener\">cardonet.co.uk<\/a>\u00a0or call +44 203 034 2244.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>FAQs: Cybersecurity for Membership Bodies and Charities<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>1. Are membership bodies and charities legally required to have cybersecurity measures in place?<\/strong><br>Yes. Under UK GDPR and the Data Protection Act 2018, any organisation that processes personal data &#8211; which includes all membership bodies &#8211; is legally required to implement appropriate technical and organisational measures to protect that data. What counts as &#8220;appropriate&#8221; is assessed in proportion to the sensitivity of the data held and the resources available, but the obligation exists regardless of organisational size. Failure to meet this obligation and then experiencing a breach can trigger\u00a0<a href=\"https:\/\/ico.org.uk\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">ICO<\/a>\u00a0enforcement action.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>2. What is the most common type of cyber attack against charities and membership bodies?<\/strong><br>Phishing is consistently the most prevalent threat. According to the\u00a0<a href=\"https:\/\/www.gov.uk\/government\/statistics\/cyber-security-breaches-survey-2025\/cyber-security-breaches-survey-2025\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">UK Government&#8217;s Cyber Security Breaches Survey 2025<\/a>, 86% of charities that reported a breach identified phishing as the attack vector. Business email compromise &#8211; a targeted form of phishing designed to impersonate trusted individuals and authorise fraudulent transactions &#8211; accounted for 35% of reported incidents.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>3. What is Cyber Essentials, and is it suitable for small membership organisations?<\/strong><br>Cyber Essentials is a UK government-backed certification scheme that covers five foundational security controls: boundary firewalls, secure configuration, access controls, malware protection, and patch management. It is specifically designed to be achievable by organisations without dedicated IT teams, and the\u00a0<a href=\"https:\/\/www.ncsc.gov.uk\/cyberessentials\/overview\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">NCSC<\/a>\u00a0offers a funded route for qualifying small charities. It is widely recognised by funders, insurers, and enterprise procurement teams as a baseline standard.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>4. We rely on volunteers who use their own devices. How should we manage this risk?<\/strong><br>Personal devices represent one of the most significant structural vulnerabilities in the membership body sector. The proportionate response involves a combination of policy and technical controls: a clear acceptable use policy covering what volunteers can and cannot access, multi-factor authentication on all systems they connect to, and where possible, web-based access rather than direct system connections that minimise what can be exposed if a personal device is compromised. This doesn&#8217;t require expensive technology &#8211; it requires clear rules that are communicated and enforced during onboarding.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>5. If we experience a cyber incident, what are our immediate obligations?<\/strong><br>Under UK GDPR, if a personal data breach is likely to result in risk to individuals&#8217; rights and freedoms, you must notify the\u00a0<a href=\"https:\/\/ico.org.uk\/for-organisations\/report-a-breach\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">ICO<\/a>\u00a0within 72 hours of becoming aware of it. If the breach is likely to result in high risk to individuals, you must also inform the affected individuals without undue delay. In parallel, you should isolate affected systems, preserve evidence, and engage your IT support provider to contain the incident. Having a simple, rehearsed incident response plan in place before something happens is significantly better than working this out in the moment.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Most membership body leaders assume cybercriminals are interested only in banks, retailers, or large corporations. That assumption \u2013 understandable and logical but almost universally wrong &#8211; is why charities and membership organisations make such attractive targets. They are targeted by cybercriminals because they hold large volumes of sensitive personal data, operate with lean (often inadequate)<\/p>\n","protected":false},"author":3,"featured_media":287,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"class_list":["post-285","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cyber-ssecurity"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.9 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Membership Bodies and Cyber Risk: Why You&#039;re a Target<\/title>\n<meta name=\"description\" content=\"Charities and membership bodies hold sensitive member data but rarely have formal cyber defences. Here&#039;s why that makes you a target - and what to do about it.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.cardonet.co.uk\/insights\/membership-bodies-cyber-risk-why-youre-a-target\/\" \/>\n<meta property=\"og:locale\" content=\"en_GB\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Membership Bodies and Cyber Risk: Why You&#039;re a Target\" \/>\n<meta property=\"og:description\" content=\"Charities and membership bodies hold sensitive member data but rarely have formal cyber defences. Here&#039;s why that makes you a target - and what to do about it.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.cardonet.co.uk\/insights\/membership-bodies-cyber-risk-why-youre-a-target\/\" \/>\n<meta property=\"og:site_name\" content=\"Insight\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Cardonet\" \/>\n<meta property=\"article:published_time\" content=\"2026-06-23T13:04:45+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-06-23T13:04:48+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.cardonet.co.uk\/insights\/wp-content\/uploads\/2026\/06\/membership-bodies-cyber-risk-target-cardonet.png\" \/>\n\t<meta property=\"og:image:width\" content=\"600\" \/>\n\t<meta property=\"og:image:height\" content=\"334\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Viki Asimov\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@cardonetit\" \/>\n<meta name=\"twitter:site\" content=\"@cardonetit\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Viki Asimov\" \/>\n\t<meta name=\"twitter:label2\" content=\"Estimated reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"1 minute\" \/>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Membership Bodies and Cyber Risk: Why You're a Target","description":"Charities and membership bodies hold sensitive member data but rarely have formal cyber defences. Here's why that makes you a target - and what to do about it.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.cardonet.co.uk\/insights\/membership-bodies-cyber-risk-why-youre-a-target\/","og_locale":"en_GB","og_type":"article","og_title":"Membership Bodies and Cyber Risk: Why You're a Target","og_description":"Charities and membership bodies hold sensitive member data but rarely have formal cyber defences. Here's why that makes you a target - and what to do about it.","og_url":"https:\/\/www.cardonet.co.uk\/insights\/membership-bodies-cyber-risk-why-youre-a-target\/","og_site_name":"Insight","article_publisher":"https:\/\/www.facebook.com\/Cardonet","article_published_time":"2026-06-23T13:04:45+00:00","article_modified_time":"2026-06-23T13:04:48+00:00","og_image":[{"width":600,"height":334,"url":"https:\/\/www.cardonet.co.uk\/insights\/wp-content\/uploads\/2026\/06\/membership-bodies-cyber-risk-target-cardonet.png","type":"image\/png"}],"author":"Viki Asimov","twitter_card":"summary_large_image","twitter_creator":"@cardonetit","twitter_site":"@cardonetit","twitter_misc":{"Written by":"Viki Asimov","Estimated reading time":"1 minute"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.cardonet.co.uk\/insights\/membership-bodies-cyber-risk-why-youre-a-target\/#article","isPartOf":{"@id":"https:\/\/www.cardonet.co.uk\/insights\/membership-bodies-cyber-risk-why-youre-a-target\/"},"author":{"name":"Viki Asimov","@id":"https:\/\/www.cardonet.co.uk\/insights\/#\/schema\/person\/36a7d06561738c35ed9474545767e727"},"headline":"Membership Bodies and Cyber Risk: Why You are a Target","datePublished":"2026-06-23T13:04:45+00:00","dateModified":"2026-06-23T13:04:48+00:00","mainEntityOfPage":{"@id":"https:\/\/www.cardonet.co.uk\/insights\/membership-bodies-cyber-risk-why-youre-a-target\/"},"wordCount":2335,"commentCount":0,"publisher":{"@id":"https:\/\/www.cardonet.co.uk\/insights\/#organization"},"image":{"@id":"https:\/\/www.cardonet.co.uk\/insights\/membership-bodies-cyber-risk-why-youre-a-target\/#primaryimage"},"thumbnailUrl":"https:\/\/www.cardonet.co.uk\/insights\/wp-content\/uploads\/2026\/06\/membership-bodies-cyber-risk-target-cardonet.png","articleSection":["Cyber Security"],"inLanguage":"en-GB","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.cardonet.co.uk\/insights\/membership-bodies-cyber-risk-why-youre-a-target\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.cardonet.co.uk\/insights\/membership-bodies-cyber-risk-why-youre-a-target\/","url":"https:\/\/www.cardonet.co.uk\/insights\/membership-bodies-cyber-risk-why-youre-a-target\/","name":"Membership Bodies and Cyber Risk: Why You're a Target","isPartOf":{"@id":"https:\/\/www.cardonet.co.uk\/insights\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.cardonet.co.uk\/insights\/membership-bodies-cyber-risk-why-youre-a-target\/#primaryimage"},"image":{"@id":"https:\/\/www.cardonet.co.uk\/insights\/membership-bodies-cyber-risk-why-youre-a-target\/#primaryimage"},"thumbnailUrl":"https:\/\/www.cardonet.co.uk\/insights\/wp-content\/uploads\/2026\/06\/membership-bodies-cyber-risk-target-cardonet.png","datePublished":"2026-06-23T13:04:45+00:00","dateModified":"2026-06-23T13:04:48+00:00","description":"Charities and membership bodies hold sensitive member data but rarely have formal cyber defences. Here's why that makes you a target - and what to do about it.","breadcrumb":{"@id":"https:\/\/www.cardonet.co.uk\/insights\/membership-bodies-cyber-risk-why-youre-a-target\/#breadcrumb"},"inLanguage":"en-GB","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.cardonet.co.uk\/insights\/membership-bodies-cyber-risk-why-youre-a-target\/"]}]},{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/www.cardonet.co.uk\/insights\/membership-bodies-cyber-risk-why-youre-a-target\/#primaryimage","url":"https:\/\/www.cardonet.co.uk\/insights\/wp-content\/uploads\/2026\/06\/membership-bodies-cyber-risk-target-cardonet.png","contentUrl":"https:\/\/www.cardonet.co.uk\/insights\/wp-content\/uploads\/2026\/06\/membership-bodies-cyber-risk-target-cardonet.png","width":600,"height":334,"caption":"membership bodies cyber risk target"},{"@type":"BreadcrumbList","@id":"https:\/\/www.cardonet.co.uk\/insights\/membership-bodies-cyber-risk-why-youre-a-target\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.cardonet.co.uk\/insights\/"},{"@type":"ListItem","position":2,"name":"Membership Bodies and Cyber Risk: Why You are a Target"}]},{"@type":"WebSite","@id":"https:\/\/www.cardonet.co.uk\/insights\/#website","url":"https:\/\/www.cardonet.co.uk\/insights\/","name":"Insight","description":"IT Services from Cardonet","publisher":{"@id":"https:\/\/www.cardonet.co.uk\/insights\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.cardonet.co.uk\/insights\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-GB"},{"@type":"Organization","@id":"https:\/\/www.cardonet.co.uk\/insights\/#organization","name":"Cardonet IT Support","url":"https:\/\/www.cardonet.co.uk\/insights\/","logo":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/www.cardonet.co.uk\/insights\/#\/schema\/logo\/image\/","url":"https:\/\/www.cardonet.co.uk\/insights\/wp-content\/uploads\/2022\/06\/cardonet-it-support-logo.svg","contentUrl":"https:\/\/www.cardonet.co.uk\/insights\/wp-content\/uploads\/2022\/06\/cardonet-it-support-logo.svg","width":1,"height":1,"caption":"Cardonet IT Support"},"image":{"@id":"https:\/\/www.cardonet.co.uk\/insights\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Cardonet","https:\/\/x.com\/cardonetit","https:\/\/www.linkedin.com\/company\/cardonet"]},{"@type":"Person","@id":"https:\/\/www.cardonet.co.uk\/insights\/#\/schema\/person\/36a7d06561738c35ed9474545767e727","name":"Viki Asimov","sameAs":["http:\/\/www.cardonet.co.uk"]}]}},"_links":{"self":[{"href":"https:\/\/www.cardonet.co.uk\/insights\/wp-json\/wp\/v2\/posts\/285","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cardonet.co.uk\/insights\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cardonet.co.uk\/insights\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cardonet.co.uk\/insights\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cardonet.co.uk\/insights\/wp-json\/wp\/v2\/comments?post=285"}],"version-history":[{"count":2,"href":"https:\/\/www.cardonet.co.uk\/insights\/wp-json\/wp\/v2\/posts\/285\/revisions"}],"predecessor-version":[{"id":291,"href":"https:\/\/www.cardonet.co.uk\/insights\/wp-json\/wp\/v2\/posts\/285\/revisions\/291"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.cardonet.co.uk\/insights\/wp-json\/wp\/v2\/media\/287"}],"wp:attachment":[{"href":"https:\/\/www.cardonet.co.uk\/insights\/wp-json\/wp\/v2\/media?parent=285"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cardonet.co.uk\/insights\/wp-json\/wp\/v2\/categories?post=285"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}