For membership organisations, data is fundamental to almost everything they do. Member records increasingly contain far more than just names and email addresses, bringing together payment histories, professional information, qualifications, event attendance, communications, interests, engagement activity, and sometimes many years of interaction with an organisation.
That makes a membership CRM incredibly valuable operationally. It also makes the information held within it something that organisations have a significant responsibility to protect.
Recent incidents across the CRM and membership technology landscape have provided some uncomfortable reminders of just how broad that responsibility has become. Blackbaud, Beacon CRM, HubSpot, and organisations using the Salesforce ecosystem have all faced different security or data-management issues, while AI is introducing another layer of complexity.
These incidents are all different and it would be wrong to suggest that any one of them proves a particular platform is inherently insecure. What they do show, however, is that modern CRM security is about far more than preventing somebody from simply ‘hacking the database’.
Here are five lessons membership organisations should take from them.
1. How a provider responds to a security incident matters
In 2020, Blackbaud, the company behind Raiser’s Edge and other widely used nonprofit technology, experienced a ransomware attack in which an attacker accessed and removed customer data.
The scale was significant. The US Securities and Exchange Commission later said the attack affected more than 13,000 Blackbaud customers. Its subsequent action against the company also focused on what happened after the breach, finding that information discovered internally about sensitive data being accessed was not communicated effectively to the senior management responsible for the company’s public disclosures. Blackbaud agreed to pay $3 million to settle the SEC charges without admitting or denying its findings.
There is an important distinction here. No technology provider can credibly promise that it will never experience a security incident. What organisations can evaluate is whether appropriate controls are in place to reduce risk, how quickly incidents can be identified and contained, and how effectively the provider will communicate if something does happen.
For a membership organisation, this makes the incident response part of the buying decision. Understanding who would inform you, what information you would receive, how quickly you would receive it, and what support would be available, should not be left until an incident has already occurred.
Lesson: Security is not only about prevention. Detection, response, transparency, and communication matter too.
2. Backups are part of the security perimeter
The recent incident involving Beacon CRM brings the issue particularly close to the membership and charity sector.
On 29 July 2026, Beacon identified unauthorised access to its systems. The Charity Commission subsequently issued guidance for affected charities, while organisations using Beacon reported being informed that compromised credentials had been used and that copies of database backups were likely to have been downloaded.
Some organisations have since reported receiving further information suggesting data contained within affected backups may have been exported in readable form. Beacon’s investigation has been ongoing, so the precise circumstances and impact should continue to be treated carefully as further information emerges.
The wider lesson is already clear, however. Backups are essential to resilience, but the data within a backup can be just as valuable as the information sitting within the live CRM.
That means organisations evaluating membership software should understand not simply whether their data is backed up, but how those backups are protected. Who, or what, can access them? How are the credentials controlling that access managed? Are backups monitored? How quickly can information be restored if needed?
The same principle applies to exports, attachments, archived records, and other copies of member information. Moving data out of the live database does not move it outside the organisation’s security responsibility.
Lesson: Protecting a membership database means protecting every copy of the data, not just the live system.
3. A secure CRM can still be exposed through its connections
Another important lesson comes from attacks involving the Salesforce ecosystem.
In 2025, Google’s Threat Intelligence Group documented campaigns in which attackers impersonated IT support staff, and socially engineered employees into granting access to Salesforce data. One technique involved persuading users to authorise a malicious connected application. Google was explicit that the attackers were manipulating users rather than exploiting inherent vulnerability in Salesforce itself.
Later, the compromise of Salesforce’s Drift integration demonstrated another version of the same problem. Stolen OAuth tokens associated with an integration were used to access connected Salesforce environments.
This matters because modern membership technology is designed to be connected. A membership CRM might exchange information with a website, payment provider, email platform, event technology, reporting tools, finance systems, automation platforms, and increasingly AI applications.
Those connections create significant operational benefits. They also mean that the security perimeter extends beyond the central membership database.
This is not an argument against integration. It’s an argument for understanding it.
Membership organisations should know which applications can access their CRM, what permissions each connection has, and whether access remains appropriate over time. The same principle applies internally: administrators and users should only have the level of access they genuinely need, supported by controls such as multi-factor authentication.
Lesson: The security of a connected platform depends partly on the security of everything connected to it.
4. Data security also means responsible data stewardship
Not every data issue starts with an attacker.
In July 2026, HubSpot announced changes to its terms connected with a planned Contact Discovery product and its enrichment capabilities. The proposals included using certain business contact information from participating customers to help maintain a shared commercial dataset, alongside email engagement information used for enrichment purposes.
The announcement prompted substantial customer concern. Four days later, HubSpot reversed the proposed terms, acknowledged that it had made a mistake, and committed to making future enrichment capabilities involving customer data transparently opt-in.
This was not a data breach. But for organisations responsible for other people’s information, it raises an equally important question:
What is our technology provider allowed to do with our data?
Traditionally, conversations about CRM security have focused heavily on protecting data from unauthorised access. The rise of enrichment services, AI, and increasingly sophisticated data products, means buyers also need to understand how information may legitimately be processed once it’s inside a supplier’s ecosystem.
That includes understanding subprocessors, enrichment services, analytics, AI functionality, and any circumstances in which a provider acts as a controller rather than simply processing data on behalf of its customer.
For membership organisations, whose members may have provided information for very specific purposes, those distinctions matter.
Lesson: A responsible data strategy considers not only who might steal your data, but also how authorised organisations and technologies are allowed to use it.
5. AI makes understanding data access even more important
AI adds another dimension to all of this.
The UK’s National Cyber Security Centre has assessed that cyber threat actors are already using AI to improve activities including reconnaissance, social engineering, vulnerability research, and the analysis of stolen data. It expects AI to increase the volume and impact of cyber intrusions as those capabilities become more widely available.
But there is another side to the AI question for membership organisations.
Teams are increasingly experimenting with AI assistants, automation platforms, analytics tools, and agents that can interact with existing organisational systems. Used well, those tools have enormous potential to reduce administration and help teams extract more value from their data.
Before connecting them to a CRM, however, organisations need to understand exactly what information an AI system can access, where that information is processed, whether it’s retained, and what controls exist around its use.
An AI tool does not necessarily need access to an organisation’s entire membership database to perform a useful task. The principle of giving users and integrations only the access they genuinely need becomes even more important as AI tools become capable of acting on information rather than simply displaying it.
Lesson: AI governance and data security are rapidly becoming part of the same conversation.
So, how secure is your membership management software?
There is no single question that can establish whether a membership platform is secure. Certifications, infrastructure, and technical controls matter, but so do people, permissions, processes, integrations, data policies, and the provider’s approach when something unexpected happens.
Organisations evaluating a membership CRM should be prepared to ask questions such as:
- Where is our data stored and processed?
- Who can access it and how is privileged access controlled?
- Is multi-factor authentication available and how is access managed?
- How are backups secured and how quickly could our data be restored?
- How are vulnerabilities identified and addressed?
- What happens if you experience a security incident, and how would we be informed?
- Which third parties and subprocessors may have access to our data?
- How are APIs and integrations secured?
- What happens to our information when our contract ends?
- How is AI used within the platform?
- Can AI services access our data, and if so, how is that information processed?
- Can you provide appropriate security and data processing documentation as part of our evaluation?
These questions should not be reserved for an organisation’s IT team once a preferred supplier has already been selected. Security and data governance deserve to sit alongside functionality, implementation, usability, and price, when membership technology is being evaluated.
Security should be a procurement conversation, not an afterthought
The recent incidents involving Beacon CRM, Blackbaud, and the wider CRM ecosystem should not lead membership organisations to conclude that technology is becoming impossible to trust. Nor should organisations assume that choosing the biggest provider, the newest platform, or the longest list of security credentials, removes risk entirely.
The more useful conclusion is that scrutiny matters.
At VeryConnect, we are seeing security and data governance become a more prominent part of membership platform evaluations, and we welcome that development. Organisations entrusting a technology provider with their member data should expect that provider to explain how information is hosted, protected, accessed, backed up, and managed, and to be comfortable answering detailed questions about those arrangements.
As membership technology becomes more connected and AI becomes more deeply embedded in everyday operations, those conversations are only going to become more important.
Your membership database may be one of the richest sources of organisational knowledge you have. Understanding how it’s protected should be part of choosing the platform that holds it.