Developer docs
API playgroundTry for free, no card

Search company profiles

CYBER DEFENCE ALLIANCE LIMITED

Full company profile

uuid028t8os

Namestring
CYBER DEFENCE ALLIANCE LIMITED
Legal namestring
Cyber Defence Alliance Limited
Company typeenum
Private
Founded yearint
2015
Descriptiontext

Cyber Defence Alliance Limited (CDA) is a member-owned, UK-headquartered international nonprofit organisation founded in 2015 by a coalition of four international banks with law enforcement support. It operates as an operational alliance rather than a software vendor, delivering collaborative cyber threat intelligence, cybercrime investigations, insider threat analysis, geopolitical intelligence, supply chain assurance, and collective incident response services to financial institutions and adjacent sectors. Its core capability is synthesising open-source and partner-platform data (via integrations with Recorded Future, Dark Owl, Constella, Flashpoint, Censys, Silobreaker, WMC Global, ThreatFabric, Cleafy, and Replica Cyber) into high-confidence, actionable intelligence for members, underpinned by an Article V collective defence principle that mobilises the alliance when any member faces extreme pressure.

CDA's technology stack combines third-party threat intelligence platforms with bespoke automation tools that identify, enrich, analyse, and securely share insight at scale, including real-time monitoring and automated alerting across online environments. Notably, it does not sell packaged software; rather, it delivers capabilities through structured membership engagement, working groups, special interest action groups, daily intelligence channels, and co-developed operational initiatives such as the SMS firewall proof-of-concept that has blocked over 2 million fraudulent banking SMS messages since August 2025.

The business model is a two-tier recurring subscription structure. Core Membership (for financial organisations) provides complete access to CDA services and full working-group participation; Associate Membership is open to organisations across financial and wider sectors and delivers essential cyber services including core intelligence, monthly trend analysis, and brand protection. Go-to-market is community-led and referral-driven, with no traditional marketing or sales infrastructure. The organisation is governed by a board of executive directors drawn from member institutions (RBC, Deutsche Bank, Lloyds, AIB, Bank of Ireland) on three-year rotations, supplemented by an Independent Non-Executive Director Chair appointed in May 2026. Revenue figures are not publicly disclosed.

Short descriptiontext

Cyber Defence Alliance Limited is a London-based, member-owned international nonprofit founded in 2015 that delivers collaborative cyber threat intelligence, cybercrime investigations, and collective incident response to financial institutions and adjacent sectors through a tiered membership model.

Operating statusenum
Operating
Ownership categoryenum
Headcount rangeband
1–10
akta.pro rankint
HeadquartersLondon, United Kingdom
HQ citystring
London
HQ countrystring
United Kingdom
HQ regionstring
Europe
Markets served

Serves global market

Offices1 record

Each record includes

City, Country, Type, Description, Source

Keyword5 values
cyber threat intelligence, incident response services, financial sector security, fraud prevention alliance, membership coalition
Industry4 codes
1Cyber Defense & Information Security (National Security)
CodeBPAIAHAEPrimaryYes
2Intelligence (Strategic, Tactical & Technical)
CodeBPAIAHADPrimaryNo
3Privacy, Data Protection & Cyber Governance (GRC)
CodeBPAHAFAFPrimaryNo
4Security Diplomacy & Defense Cooperation (Arms Control, Counterterrorism)
CodeBPAIAIAHPrimaryNo
NAICS code1 code
  • National Security928110
SIC code1 code
  • Services-Membership Organizations8600
Product category
Cyber Threat Intelligence Services
Social media profiles1 record
GTM motion1 record

Each record includes

Type, Description, Source

Revenue model2 records
1Core Membership Fees
TypeSubscription Recurring
Description

CDA operates as a member-owned international nonprofit organisation. Core Membership provides complete access to CDA core services and full participation across all working groups and special interest action groups. Designed for financial organisations.

cyberdefencealliance.org
2Associate Membership Fees
TypeSubscription Recurring
Description

Open to organisations across financial and wider sectors, Associate Membership delivers essential cyber services including core intelligence, monthly trend analysis, connection to cross-sector network, and brand protection.

cyberdefencealliance.org
Marketing channels4 records

Each record includes

Title, Type, Stage, Description, Source

Distribution channels1 record

Each record includes

Title, Type, Scope, Target buyer, Description, Source

Cost components5 values
Personnel, Technology or R&D, Operations, Infrastructure, Marketing or Sales
GTM typeB2B
B2B
Offering typeServices
Services
Core offering1 text field

Cyber Defence Alliance operates as a member-owned international nonprofit organisation that generates and shares high-confidence, actionable cyber threat intelligence for financial institutions through Core and Associate membership tiers. It delivers network defence intelligence, cybercrime investigations, cross-sector collaboration, insider threat analysis, and geopolitical intelligence using bespoke tools and integrated third-party platforms. The alliance mobilises collective defence under its Article V principle, supporting members, law enforcement partners, and telecommunications providers with operational activities such as fraud prevention.

Differentiator
Functional benefit
Problem solved
Quantifiable outcome1 of 4 values shown
  • 2+ million fraudulent SMS messages blocked since August 2025
+3 more records
Product overview1 text field

CDA is a member-owned international nonprofit organisation and operational alliance headquartered in the UK, founded in 2015. Rather than offering a packaged software product, CDA delivers collaborative cyber defence and threat intelligence services to its financial institution members and partners. Its core operational capabilities include network defence and cyber threat intelligence (vulnerability analysis, threat infrastructure hunting, threat modelling, domain analysis and blocking), cybercrime investigations (trend analysis, target intelligence, law enforcement collaboration), cross-sector collaboration (telecommunications, supply chain resilience, third-party assurance), insider threat (trend analysis and good practice sharing), geopolitical intelligence (global event analysis for cyber threat landscape insight), and collective defence infrastructure with daily engagement channels. CDA facilitates collaboration forums that enable its members and telecom/banking partners to exchange high-confidence, actionable intelligence and develop joint operational initiatives such as the SMS firewall proof-of-concept. CDA does not operate a traditional product-with-modules architecture; its offerings are delivered through membership participation and alliance collaboration rather than discrete software products.

Product and service3 records
1Core Membership
CategoryMembership service
Description

Core Membership provides complete access to CDA core services and full participation across all working groups and special interest action groups, designed for financial organisations. Members receive bespoke onboarding, access to working groups, and direct influence on CDA strategy under the Article V collective defence principle.

2Associate Membership
CategoryMembership service
Description

Associate Membership is open to organisations across financial and wider sectors, delivering essential cyber services including core intelligence, monthly trend analysis, connection to a cross-sector network, and brand protection. Provides essential cyber services to strengthen protection and resilience for non-core members.

3SMS Firewall Proof-of-Concept (Banking SMS Anti-Fraud Initiative)
CategoryOperational fraud prevention initiative
Description

Cross-sector proof-of-concept initiative developed through CDA's collaboration forum that helps participating organisations identify and block fraudulent SMS messages while preserving legitimate customer communications. Delivered through partnership between VodafoneThree, Barclays, The Co-operative Bank, TSB, MEF, and CDA.

Scale indicator10 records

Each record includes

Type, Value, Description, Source

Partnership19 partners
Strategic tierCoreTypeStrategic or Co-development PartnerAnnounced on2026-05-01
Description

Operation Seraphim was led by City of London Police in collaboration with CDA. Intelligence held by CDA was utilised to identify online offenders, with machine automation used to assess intelligence at scale. The operation led to 31 arrests including 26 in the UK and 5 in Nigeria. This represents the first time CDA investigators and City of London Police detectives worked side-by-side in a fully integrated operational environment.

Strategic tierCoreTypeStrategic or Co-development PartnerAnnounced on2025-08-01
Description

VodafoneThree partnered with CDA, MEF, and major UK banks (Barclays, Co-operative Bank, TSB) to develop an SMS firewall proof-of-concept that has blocked over 2 million fraudulent banking SMS messages since August 2025. This represents a 25% increase in blocked banking scam messages on the VodafoneThree network. The initiative demonstrates cross-sector collaboration between telecom and banking sectors to address growing SMS phishing threats.

Strategic tierCoreTypeStrategic or Co-development PartnerAnnounced on2025-08-01
Description

MEF partnered with VodafoneThree, Barclays, and CDA to support the SMS fraud prevention initiative. MEF provides the SMS Sender ID Protection Registry that processes 318 million A2P SMS messages monthly. MEF developed the first Sender ID Registry to block fraudulent messages and provides expertise and coordination for the initiative.

Strategic tierCoreTypeStrategic or Co-development Partner
Description

Barclays is the lead banking partner in the SMS firewall proof-of-concept initiative with VodafoneThree, MEF, and CDA. Barclays noted that APP scams originating via SMS rose approximately 40% year-over-year in 2025. Barclays has been instrumental in spearheading and driving the proof of concept.

Strategic tierCoreTypeStrategic or Co-development Partner
Description

The Co-operative Bank joined the SMS firewall proof-of-concept initiative, expanding the cross-sector collaboration to strengthen fraud prevention and protect banking customers from malicious SMS impersonating legitimate bank communications.

6TSB
Strategic tierCoreTypeStrategic or Co-development Partner
Description

TSB (part of Santander Group) participates in the SMS firewall proof-of-concept, extending the initiative's reach to additional banking customers for collective protection against messaging-enabled fraud.

thefastmode.com
Strategic tierCoreTypeStrategic or Co-development Partner
Description

NCA participated in Operation Seraphim alongside City of London Police and CDA, supporting the international crackdown on online fraud groups.

8National Police Force - National Cybercrime Centre (NPF-NCCC) Nigeria
Strategic tierCoreTypeStrategic or Co-development Partner
Description

Nigerian police participated in Operation Seraphim, enabling international collaboration that resulted in 5 arrests in Nigeria as part of the crackdown on online fraud targeting UK victims.

cyberdefencealliance.org
Strategic tierMinorTypeStrategic or Co-development Partner
Description

CIFAS participated in Operation Seraphim, contributing to the cross-agency and cross-border collaboration needed to successfully tackle online fraud.

Strategic tierMinorTypeStrategic or Co-development Partner
Description

UK Finance participated in Operation Seraphim alongside law enforcement and CDA, representing the financial sector's contribution to tackling online fraud.

Strategic tierMinorTypeStrategic or Co-development Partner
Description

Santander hosted the Insider Threat Conference (Knowledge eXchange) with CDA on 10th June 2026, contributing expertise on the growing impact of insider threat. TSB is part of the Santander Group.

Strategic tierCoreTypeTechnology or Integration
Description

ThreatFabric is a leading company in online fraud, mobile malware, and threat intelligence based in Amsterdam. Founded in 2015, they provide timely intelligence on mobile banking threats and allow CDA to brief members and provide nuanced mitigation advice. CDA has conducted open-source information gathering for years and identified ThreatFabric as the leader in mobile malware and related banking threats.

Strategic tierCoreTypeTechnology or Integration
Description

Recorded Future is the world's largest threat intelligence company, providing the ideal threat intelligence platform for CDA. The platform enables intelligence on relevant threat actors, their infrastructure, tactics, techniques and procedures (TTPs), to better mitigate threats and identify & target offenders for disruption. Headquartered in Boston with offices around the world, they work with over 1,700 businesses and government organisations across more than 75 countries.

Strategic tierCoreTypeTechnology or Integration
Description

WMC Global provides access to threat intelligence on phish kit creators, sellers/disseminators, and end users, leading to blocking of threats and arrest/disruption of offenders. They are a market leader in digital threat intelligence and mobile investigations, fighting malicious text messages, eradicating phishing and smishing attacks. Headquarters in Fairfax, VA, with offices in London.

Strategic tierCoreTypeTechnology or Integration
Description

Silobreaker provides a security and threat intelligence technology platform used by CDA to produce its daily report, geo-political reporting, and other threat and situational awareness products. Their near-real time collection, intuitive platform, and support for bespoke reporting makes them a valuable CDA partner.

Strategic tierCoreTypeTechnology or Integration
Description

Established in 2023, the partnership with Censys provided a step-change in CDA's capabilities for identifying attacker-led infrastructure. The platform's rich data sources identify malicious internet devices with high confidence, and automation allows 24/7/365 alerting. Censys is the leading Internet Intelligence Platform for Threat Hunting and Attack Surface Management, founded in 2017 in Ann Arbor, Michigan.

Strategic tierCoreTypeTechnology or Integration
Description

Constella provides access to their breach and infostealer data lake enabling CDA to attribute online offenders who assumed their online entity was unattributable to their real world identity. This has led to disruption of online threats and hundreds of arrests in the UK and internationally. Constella is a global leader in Identity Risk Intelligence.

Strategic tierMinorTypeStrategic or Co-development Partner
Description

SASIG is a cross-sector forum for capability and doctrinal development in cybersecurity. CDA participates in this networking community that supports industry development through physical events, webinars and masterclasses.

Strategic tierCoreTypeStrategic or Co-development Partner
Description

City of London Police (national lead force for fraud) collaborated with CDA on Operation Seraphim. This is the latest in a series of significant law enforcement activities either based on or supported by intelligence from CDA collaborative investigations. The operation demonstrates the cross border and cross agency collaboration needed to successfully tackle online fraud.

Recent move6 records

Each record includes

Date, Type, Title, Description, Source

Expansion highlight6 records

Each record includes

Type, Description

Peers10 records
TypeDirect peer
Description

An international coalition unifying the global response to cybercrime and fraud including phishing and smishing — directly comparable in addressing the SMS firewall and cross-bank fraud use cases CDA operates in.

TypeDirect peer
Description

A cross-industry trade body and operational partner of CDA — operates the SMS Sender ID Protection Registry that processes 318M A2P SMS messages monthly, directly powering the SMS firewall initiative CDA helped orchestrate.

TypeDirect peer
Description

A nonprofit organization that operationalizes cyber threat intelligence sharing across cybersecurity vendors and organizations; comparable member-owned nonprofit model with intelligence aggregation and cross-sector collaboration.

TypeDirect peer
Description

An international nonprofit cross-sector coalition focused on reducing cyber risk, with similar convening power across industries, governments, and law enforcement — comparable mission and member-driven governance.

TypeDirect peer
Description

The Financial Services Information Sharing and Analysis Center is the most direct global peer — a member-driven nonprofit focused on cyber threat intelligence sharing among financial institutions, with similar operational mission, member model, and law enforcement collaboration.

TypeBroad incumbent
Description

The broader ISAC ecosystem (covering healthcare, energy, etc.) provides the organizational template CDA operates within, with similar member-driven intelligence sharing models and US-centric governance.

TypeBroad incumbent
Description

The collective voice for the UK banking and finance industry, with extensive fraud and cyber intelligence workstreams — a cross-sector convening body that overlaps with CDA's banking-sector coordination mandate.

TypeOthers
Description

The world's largest commercial threat intelligence provider and a CDA technology partner — an adjacent ecosystem enabler whose platform underpins much of CDA's intelligence work rather than a direct competitor.

TypeDirect peer
Description

UK-based nonprofit fraud prevention data-sharing organization with a membership model across financial institutions; co-participant in Operation Seraphim and directly comparable in fraud intelligence sharing.

10NCRCG (National Cyber Resilience Coordination Group)
TypeRegional player
Description

UK government-coordinated cyber resilience body with overlapping intelligence-sharing functions and UK financial sector focus, though operating under government rather than member-owned governance.

Market position
Strengths4 records

Each record includes

Headline, Details, Source

Weaknesses4 records

Each record includes

Headline, Details, Source

Competitive moat6 records

Each record includes

Type, Details

Key risks6 records

Each record includes

Headline, Details, Source

Key highlights7 records

Each record includes

Headline, Details, Source

Customer concentration

Classification, Details

Named customers14 records

Each record includes

Name, Industry, Type, Use case, Source, UUID

Segment5 records

Each record includes

Title, Type, Primary, Description, Pain point addressed, Use case, Source

Ideal customer profile3 records

Each record includes

Profile, Firmographic size, Sales motion, Sales cycle length, Buying structure, Purchase trigger, Buyer persona, Geography, Industry vertical, Primary use case, Description, Pain points, Evidence proof points, Target buyer

Technology focused
No
API detail
Has APIbool
No

Docs URL, Description

Integration10 records

Each record includes

Title, Type, Description, Source

AI maturity
App detail

Has app

Feature5 records

Each record includes

Title, Differentiator, Description, Source

Core technology
Revenue estimate
Valuation estimate
Number of profiles
Profiles8 records

Each record includes

Name, Designation, Designation category, Overview, Profile commentary, Source

No data
No data
Funding overview

Funding stage, Last funding date, Total funding USD

Funding rounds

Each record includes

Round, Amount USD, Date, Pre money valuation, Total investors, Investors, News

Investors

Each record includes

Name, Type, Date of entry, Rounds participated, Website

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

M&A

Each record includes

Name, Acquisition type, Announced date, Completed date, Status, Website, News

Investment

Each record includes

Name, Round, Announced date, Lead investor, Website, News

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

CYBER DEFENCE ALLIANCE LIMITED

Cyber Threat Intelligence Servicescyberdefencealliance.org

Cyber Defence Alliance Limited is a London-based, member-owned international nonprofit founded in 2015 that delivers collaborative cyber threat intelligence, cybercrime investigations, and collective incident response to financial institutions and adjacent sectors through a tiered membership model.

What CYBER DEFENCE ALLIANCE LIMITED does

Cyber Defence Alliance Limited (CDA) is a member-owned, UK-headquartered international nonprofit organisation founded in 2015 by a coalition of four international banks with law enforcement support. It operates as an operational alliance rather than a software vendor, delivering collaborative cyber threat intelligence, cybercrime investigations, insider threat analysis, geopolitical intelligence, supply chain assurance, and collective incident response services to financial institutions and adjacent sectors. Its core capability is synthesising open-source and partner-platform data (via integrations with Recorded Future, Dark Owl, Constella, Flashpoint, Censys, Silobreaker, WMC Global, ThreatFabric, Cleafy, and Replica Cyber) into high-confidence, actionable intelligence for members, underpinned by an Article V collective defence principle that mobilises the alliance when any member faces extreme pressure.

CDA's technology stack combines third-party threat intelligence platforms with bespoke automation tools that identify, enrich, analyse, and securely share insight at scale, including real-time monitoring and automated alerting across online environments. Notably, it does not sell packaged software; rather, it delivers capabilities through structured membership engagement, working groups, special interest action groups, daily intelligence channels, and co-developed operational initiatives such as the SMS firewall proof-of-concept that has blocked over 2 million fraudulent banking SMS messages since August 2025.

The business model is a two-tier recurring subscription structure. Core Membership (for financial organisations) provides complete access to CDA services and full working-group participation; Associate Membership is open to organisations across financial and wider sectors and delivers essential cyber services including core intelligence, monthly trend analysis, and brand protection. Go-to-market is community-led and referral-driven, with no traditional marketing or sales infrastructure. The organisation is governed by a board of executive directors drawn from member institutions (RBC, Deutsche Bank, Lloyds, AIB, Bank of Ireland) on three-year rotations, supplemented by an Independent Non-Executive Director Chair appointed in May 2026. Revenue figures are not publicly disclosed.

CYBER DEFENCE ALLIANCE LIMITED firmographics

Firmographics
Name
CYBER DEFENCE ALLIANCE LIMITED
Legal name
Cyber Defence Alliance Limited
Website
https://cyberdefencealliance.org
Company type
Private
Founded year
2015
Operating status
Operating
Headcount range
1–10 employees
Short description
Cyber Defence Alliance Limited is a London-based, member-owned international nonprofit founded in 2015 that delivers collaborative cyber threat intelligence, cybercrime investigations, and collective incident response to financial institutions and adjacent sectors through a tiered membership model.
Ownership category
akta.pro rank

CYBER DEFENCE ALLIANCE LIMITED industry classification

Industry
Product category
Cyber Threat Intelligence Services
NAICS
National Security (928110)
SIC
Services-Membership Organizations (8600)
akta.pro primary industry
Cyber Defense & Information Security (National Security) (BPAIAHAE)
akta.pro secondary industries
Intelligence (Strategic, Tactical & Technical) (BPAIAHAD), Privacy, Data Protection & Cyber Governance (GRC) (BPAHAFAF), Security Diplomacy & Defense Cooperation (Arms Control, Counterterrorism) (BPAIAIAH)

Keywords

  • Cyber threat intelligence
  • Incident response services
  • Financial sector security
  • Fraud prevention alliance
  • Membership coalition

Where CYBER DEFENCE ALLIANCE LIMITED is headquartered

Location

Headquarters

HQ city
London
HQ country
United Kingdom
HQ region
Europe

Offices1 record

Markets served

CYBER DEFENCE ALLIANCE LIMITED business model

Business model
GTM type
B2B
Offering type
Services
Cost components
Personnel, Technology or R&D, Operations, Infrastructure, Marketing or Sales

Revenue model

  1. Core Membership Fees: CDA operates as a member-owned international nonprofit organisation. Core Membership provides complete access to CDA core services and full participation across all working groups and special interest action groups. Designed for financial organisations.
  2. Associate Membership Fees: Open to organisations across financial and wider sectors, Associate Membership delivers essential cyber services including core intelligence, monthly trend analysis, connection to cross-sector network, and brand protection.

Go-to-market motion1 record

Distribution channels1 record

Marketing channels4 records

CYBER DEFENCE ALLIANCE LIMITED product offering

Product offering

Core offering

Cyber Defence Alliance operates as a member-owned international nonprofit organisation that generates and shares high-confidence, actionable cyber threat intelligence for financial institutions through Core and Associate membership tiers. It delivers network defence intelligence, cybercrime investigations, cross-sector collaboration, insider threat analysis, and geopolitical intelligence using bespoke tools and integrated third-party platforms. The alliance mobilises collective defence under its Article V principle, supporting members, law enforcement partners, and telecommunications providers with operational activities such as fraud prevention.

Product overview

CDA is a member-owned international nonprofit organisation and operational alliance headquartered in the UK, founded in 2015. Rather than offering a packaged software product, CDA delivers collaborative cyber defence and threat intelligence services to its financial institution members and partners. Its core operational capabilities include network defence and cyber threat intelligence (vulnerability analysis, threat infrastructure hunting, threat modelling, domain analysis and blocking), cybercrime investigations (trend analysis, target intelligence, law enforcement collaboration), cross-sector collaboration (telecommunications, supply chain resilience, third-party assurance), insider threat (trend analysis and good practice sharing), geopolitical intelligence (global event analysis for cyber threat landscape insight), and collective defence infrastructure with daily engagement channels. CDA facilitates collaboration forums that enable its members and telecom/banking partners to exchange high-confidence, actionable intelligence and develop joint operational initiatives such as the SMS firewall proof-of-concept. CDA does not operate a traditional product-with-modules architecture; its offerings are delivered through membership participation and alliance collaboration rather than discrete software products.

Differentiator

Problem solved

Functional benefit

Products and services

  • Core Membership Core Membership provides complete access to CDA core services and full participation across all working groups and special interest action groups, designed for financial organisations. Members receive bespoke onboarding, access to working groups, and direct influence on CDA strategy under the Article V collective defence principle.
  • Associate Membership Associate Membership is open to organisations across financial and wider sectors, delivering essential cyber services including core intelligence, monthly trend analysis, connection to a cross-sector network, and brand protection. Provides essential cyber services to strengthen protection and resilience for non-core members.
  • SMS Firewall Proof-of-Concept (Banking SMS Anti-Fraud Initiative) Cross-sector proof-of-concept initiative developed through CDA's collaboration forum that helps participating organisations identify and block fraudulent SMS messages while preserving legitimate customer communications. Delivered through partnership between VodafoneThree, Barclays, The Co-operative Bank, TSB, MEF, and CDA.

Quantifiable outcome

  • 2+ million fraudulent SMS messages blocked since August 2025
  • +3 more outcomes

Companies that use CYBER DEFENCE ALLIANCE LIMITED

Customer profile

Named customers14 records

Segments5 records

Ideal customer profiles3 records

CYBER DEFENCE ALLIANCE LIMITED technology and API

Technology

Technology focussed No

API detail

Has API
No
API docs
API detail

Core technology

AI maturity

App detail

Integration10 records

Feature5 records

CYBER DEFENCE ALLIANCE LIMITED partnerships and signals

Strategic signal

Partnerships

19 partnerships are on record, tiered core and minor.

  • City of London PolicecoreStrategic or Co-development Partner · 1 May 2026Operation Seraphim was led by City of London Police in collaboration with CDA. Intelligence held by CDA was utilised to identify online offenders, with machine automation used to assess intelligence at scale. The operation led to 31 arrests including 26 in the UK and 5 in Nigeria. This represents the first time CDA investigators and City of London Police detectives worked side-by-side in a fully integrated operational environment.
  • VodafoneThreecoreStrategic or Co-development Partner · 1 August 2025VodafoneThree partnered with CDA, MEF, and major UK banks (Barclays, Co-operative Bank, TSB) to develop an SMS firewall proof-of-concept that has blocked over 2 million fraudulent banking SMS messages since August 2025. This represents a 25% increase in blocked banking scam messages on the VodafoneThree network. The initiative demonstrates cross-sector collaboration between telecom and banking sectors to address growing SMS phishing threats.
  • Mobile Ecosystem Forum (MEF)coreStrategic or Co-development Partner · 1 August 2025MEF partnered with VodafoneThree, Barclays, and CDA to support the SMS fraud prevention initiative. MEF provides the SMS Sender ID Protection Registry that processes 318 million A2P SMS messages monthly. MEF developed the first Sender ID Registry to block fraudulent messages and provides expertise and coordination for the initiative.
  • BarclayscoreStrategic or Co-development PartnerBarclays is the lead banking partner in the SMS firewall proof-of-concept initiative with VodafoneThree, MEF, and CDA. Barclays noted that APP scams originating via SMS rose approximately 40% year-over-year in 2025. Barclays has been instrumental in spearheading and driving the proof of concept.
  • The Co-operative BankcoreStrategic or Co-development PartnerThe Co-operative Bank joined the SMS firewall proof-of-concept initiative, expanding the cross-sector collaboration to strengthen fraud prevention and protect banking customers from malicious SMS impersonating legitimate bank communications.
  • TSBcoreStrategic or Co-development PartnerTSB (part of Santander Group) participates in the SMS firewall proof-of-concept, extending the initiative's reach to additional banking customers for collective protection against messaging-enabled fraud.
  • National Crime Agency (NCA)coreStrategic or Co-development PartnerNCA participated in Operation Seraphim alongside City of London Police and CDA, supporting the international crackdown on online fraud groups.
  • National Police Force - National Cybercrime Centre (NPF-NCCC) NigeriacoreStrategic or Co-development PartnerNigerian police participated in Operation Seraphim, enabling international collaboration that resulted in 5 arrests in Nigeria as part of the crackdown on online fraud targeting UK victims.
  • CIFASminorStrategic or Co-development PartnerCIFAS participated in Operation Seraphim, contributing to the cross-agency and cross-border collaboration needed to successfully tackle online fraud.
  • UK FinanceminorStrategic or Co-development PartnerUK Finance participated in Operation Seraphim alongside law enforcement and CDA, representing the financial sector's contribution to tackling online fraud.
  • SantanderminorStrategic or Co-development PartnerSantander hosted the Insider Threat Conference (Knowledge eXchange) with CDA on 10th June 2026, contributing expertise on the growing impact of insider threat. TSB is part of the Santander Group.
  • ThreatFabriccoreTechnology or IntegrationThreatFabric is a leading company in online fraud, mobile malware, and threat intelligence based in Amsterdam. Founded in 2015, they provide timely intelligence on mobile banking threats and allow CDA to brief members and provide nuanced mitigation advice. CDA has conducted open-source information gathering for years and identified ThreatFabric as the leader in mobile malware and related banking threats.
  • Recorded FuturecoreTechnology or IntegrationRecorded Future is the world's largest threat intelligence company, providing the ideal threat intelligence platform for CDA. The platform enables intelligence on relevant threat actors, their infrastructure, tactics, techniques and procedures (TTPs), to better mitigate threats and identify & target offenders for disruption. Headquartered in Boston with offices around the world, they work with over 1,700 businesses and government organisations across more than 75 countries.
  • WMC GlobalcoreTechnology or IntegrationWMC Global provides access to threat intelligence on phish kit creators, sellers/disseminators, and end users, leading to blocking of threats and arrest/disruption of offenders. They are a market leader in digital threat intelligence and mobile investigations, fighting malicious text messages, eradicating phishing and smishing attacks. Headquarters in Fairfax, VA, with offices in London.
  • SilobreakercoreTechnology or IntegrationSilobreaker provides a security and threat intelligence technology platform used by CDA to produce its daily report, geo-political reporting, and other threat and situational awareness products. Their near-real time collection, intuitive platform, and support for bespoke reporting makes them a valuable CDA partner.
  • CensyscoreTechnology or IntegrationEstablished in 2023, the partnership with Censys provided a step-change in CDA's capabilities for identifying attacker-led infrastructure. The platform's rich data sources identify malicious internet devices with high confidence, and automation allows 24/7/365 alerting. Censys is the leading Internet Intelligence Platform for Threat Hunting and Attack Surface Management, founded in 2017 in Ann Arbor, Michigan.
  • ConstellacoreTechnology or IntegrationConstella provides access to their breach and infostealer data lake enabling CDA to attribute online offenders who assumed their online entity was unattributable to their real world identity. This has led to disruption of online threats and hundreds of arrests in the UK and internationally. Constella is a global leader in Identity Risk Intelligence.
  • The Security Awareness Special Interest Group (SASIG)minorStrategic or Co-development PartnerSASIG is a cross-sector forum for capability and doctrinal development in cybersecurity. CDA participates in this networking community that supports industry development through physical events, webinars and masterclasses.
  • City of London PolicecoreStrategic or Co-development PartnerCity of London Police (national lead force for fraud) collaborated with CDA on Operation Seraphim. This is the latest in a series of significant law enforcement activities either based on or supported by intelligence from CDA collaborative investigations. The operation demonstrates the cross border and cross agency collaboration needed to successfully tackle online fraud.

Scale indicators10 records

Recent moves6 records

Expansion highlights6 records

CYBER DEFENCE ALLIANCE LIMITED competitors and assessment

Company assessment

Direct peers

  • Anti-Phishing Working Group (APWG): An international coalition unifying the global response to cybercrime and fraud including phishing and smishing — directly comparable in addressing the SMS firewall and cross-bank fraud use cases CDA operates in.
  • MEF (Mobile Ecosystem Forum): A cross-industry trade body and operational partner of CDA — operates the SMS Sender ID Protection Registry that processes 318M A2P SMS messages monthly, directly powering the SMS firewall initiative CDA helped orchestrate.
  • Cyber Threat Alliance: A nonprofit organization that operationalizes cyber threat intelligence sharing across cybersecurity vendors and organizations; comparable member-owned nonprofit model with intelligence aggregation and cross-sector collaboration.
  • Global Cyber Alliance: An international nonprofit cross-sector coalition focused on reducing cyber risk, with similar convening power across industries, governments, and law enforcement — comparable mission and member-driven governance.
  • FS-ISAC: The Financial Services Information Sharing and Analysis Center is the most direct global peer — a member-driven nonprofit focused on cyber threat intelligence sharing among financial institutions, with similar operational mission, member model, and law enforcement collaboration.
  • CIFAS: UK-based nonprofit fraud prevention data-sharing organization with a membership model across financial institutions; co-participant in Operation Seraphim and directly comparable in fraud intelligence sharing.

Broad incumbents

  • Information Sharing and Analysis Centers (ISACs): The broader ISAC ecosystem (covering healthcare, energy, etc.) provides the organizational template CDA operates within, with similar member-driven intelligence sharing models and US-centric governance.
  • UK Finance: The collective voice for the UK banking and finance industry, with extensive fraud and cyber intelligence workstreams — a cross-sector convening body that overlaps with CDA's banking-sector coordination mandate.

Others

  • Recorded Future: The world's largest commercial threat intelligence provider and a CDA technology partner — an adjacent ecosystem enabler whose platform underpins much of CDA's intelligence work rather than a direct competitor.

Regional players

  • NCRCG (National Cyber Resilience Coordination Group): UK government-coordinated cyber resilience body with overlapping intelligence-sharing functions and UK financial sector focus, though operating under government rather than member-owned governance.

Market position

Strengths4 records

Weaknesses4 records

Competitive moat6 records

Key risks6 records

Key highlights7 records

Customer concentration

CYBER DEFENCE ALLIANCE LIMITED social profiles

Digital presence

CYBER DEFENCE ALLIANCE LIMITED financial estimates

Financial estimate

Revenue estimate

Valuation estimate

CYBER DEFENCE ALLIANCE LIMITED leadership team

Management profile

Number of profiles

Profiles8 records

CYBER DEFENCE ALLIANCE LIMITED funding detail

Funding detail

Funding overview

Funding rounds

Investors

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

CYBER DEFENCE ALLIANCE LIMITED M&A and investment

M&A and investment

M&A

Investments

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

Frequently asked questions about CYBER DEFENCE ALLIANCE LIMITED

What does CYBER DEFENCE ALLIANCE LIMITED do?

Cyber Defence Alliance operates as a member-owned international nonprofit organisation that generates and shares high-confidence, actionable cyber threat intelligence for financial institutions through Core and Associate membership tiers. It delivers network defence intelligence, cybercrime investigations, cross-sector collaboration, insider threat analysis, and geopolitical intelligence using bespoke tools and integrated third-party platforms. The alliance mobilises collective defence under its Article V principle, supporting members, law enforcement partners, and telecommunications providers with operational activities such as fraud prevention.

Is CYBER DEFENCE ALLIANCE LIMITED a public or private company?

CYBER DEFENCE ALLIANCE LIMITED is a private company. It is classified as nonprofit foundation owned and is currently operating.

When was CYBER DEFENCE ALLIANCE LIMITED founded?

CYBER DEFENCE ALLIANCE LIMITED was founded in 2015. It employs 1 to 10 people.

Where is CYBER DEFENCE ALLIANCE LIMITED based?

CYBER DEFENCE ALLIANCE LIMITED is headquartered in London, United Kingdom, in the Europe region.

How does CYBER DEFENCE ALLIANCE LIMITED make money?

Two revenue lines are on record. Core Membership Fees are the primary driver. The others are associate Membership Fees.

Who are CYBER DEFENCE ALLIANCE LIMITED's main competitors?

Direct peers on record are Anti-Phishing Working Group (APWG), MEF (Mobile Ecosystem Forum), Cyber Threat Alliance, Global Cyber Alliance, FS-ISAC and CIFAS. Broad incumbents are Information Sharing and Analysis Centers (ISACs) and UK Finance. Recorded Future is listed as an others. NCRCG (National Cyber Resilience Coordination Group) is listed as a regional player.

Does CYBER DEFENCE ALLIANCE LIMITED have an API?

No public API is recorded for CYBER DEFENCE ALLIANCE LIMITED.

What industry is CYBER DEFENCE ALLIANCE LIMITED in?

CYBER DEFENCE ALLIANCE LIMITED's product category is Cyber Threat Intelligence Services. Its primary akta.pro industry code is BPAIAHAE, Cyber Defense & Information Security (National Security), with a secondary code of BPAIAHAD, Intelligence (Strategic, Tactical & Technical). Its NAICS code is 928110 and its SIC code is 8600.

Unlock the full company data

50 free credits on sign-up, no credit card required.

Contact sales
Live signals