Become a Member
A working co-op for higher-ed security practitioners
Membership
What we are
The Synaptic Cybersecurity Alliance is a small, vetted co-op of higher-ed security practitioners. We're not a subscription, a content library, or a webinar series. We're a working group that ships things our members can actually use — and we're starting by seeding the library ourselves so members get value on day one.
What members do — and what you get back
1. Seeded today. Grown together.
Founding members get day-one access to the library Synaptic has already built — a starter set of working artifacts across three categories: a library of services for Information Security Programs (ITSM-shaped service definitions for vulnerability management, incident response, vendor risk, access reviews, and security architecture consultation — each with intake flows, SLAs, RACI, and operating metrics), governance and policy templates (data classification, vendor management, incident response — mapped to NIST CSF and CIS), and runbooks for IaC and operations(Terraform modules for Okta provisioning and AWS landing zones, CI/CD security patterns, incident response playbooks). That's the proof we ship before we ask anyone else to. In year one, all we ask is that you show up to the working sessions and contribute where you can. By year two — once the library has real collective weight — the cadence becomes one artifact per quarter per member.
2. Working artifacts, not just conversation.
Most communities trade PDFs and meeting minutes. We trade things you can run. We use the right tool for each artifact type — a member-only Git repo for code-shaped things (Terraform modules, detection rules, scripts), Azimuth for vendor risk artifacts (review notes, vendor experience pooling), and a working knowledge base for written guidance (policies, runbooks, architecture references). No platform marketing; just the right substrate for each kind of work.
3. Move vendors together — with receipts.
When a vendor everyone uses gets compromised — like the recent Instructure/Canvas incident — every institution scrambles in parallel: pull the vendor's HECVAT, compare it to the disclosed facts, draft follow-up questions, hold internal post-mortems on dependency resilience. The alliance does this work once, together. We compare HECVAT responses across member institutions (did the vendor tell everyone the same story?), check the vendor's pre-incident claims against the incident reality (where did their own self-reported posture fail?), pool resilience data (how prepared was each member for this specific vendor failing?), and coordinate the follow-up asks so the vendor gets one well-formed challenge from the alliance instead of two hundred fragmented emails. No other group is structured to do this. We are, because we have Azimuth as the substrate and a member cohort small enough to actually coordinate.
4. Hands on the keyboard.
We review each other's Terraform PRs and IAM designs. We argue about Okta tenant configs and audit-log retention. We don't write SOC 2 narratives together — there are other places for that. If your day is mostly policy and committee work, you'll find this room frustrating; if your day is mostly infrastructure, identity, and pipelines, you'll find your people.
Who's in
Membership is vetted. You're an active practitioner with hands on the keyboard at a higher-ed institution (or a research or regulated peer org). Light verification of current role keeps the room small and the conversation real. Founding membership is capped at 25 institutions, with a path to 50 in year two. When we're full, there's a waitlist, and seats open as members leave or stop shipping.