Interview

Stéphane Duguin: "Cybersecurity must be a priority for the nonprofit sector"

Image
Stéphane Duguin, CEO of Protect.ngo
Stéphane Duguin, CEO of Protect.ngo. Source: Stéphane Duguin.

Cybersecurity has become an essential challenge for civil society organisations. In this interview, Stéphane Duguin, CEO of Protect.ngo, explains why nonprofits are increasingly targeted by cyberattacks and how collaboration, digital resilience, and artificial intelligence can help strengthen their defenses.

For readers who may not yet be familiar with Protect.ngo, could you introduce your organisation and explain why cybersecurity should be a priority for the nonprofit sector?

Protect.ngo is a non-governmental organisation headquartered in Geneva, Switzerland, dedicated to defending the most vulnerable in cyberspace. Our mission is twofold: we expose the human harm caused by cyberattacks and information manipulation, and we defend the civil society organisations most at risk by providing them with free cybersecurity support.

Cybersecurity must be a priority for the nonprofit sector because these organisations are lifelines for millions. They deliver healthcare, clean water, humanitarian aid; they defend human rights, and ultimately they sustain democratic resilience. However, as their work becomes increasingly digital, a cyberattack is no longer just an IT failure; it is a disruption to their operational continuity that can immediately halt life-saving services and compromise sensitive beneficiary data. Today, we simply cannot fund or sustain the public-interest impact of nonprofits without funding their digital resilience.

Why have nonprofit organisations become increasingly frequent targets of cyberattacks?

Nonprofits have become prime targets due to a dangerous combination of high value and low defense. Operationally, they hold highly sensitive data from the identities of human rights defenders and journalists to medical records and donor financials. At the same time, the vast majority of these organisations lack the budgets, dedicated IT staff, and defenses needed to protect themselves.

Furthermore, as our lives become more digital, many nonprofits increasingly act as critical democratic infrastructure. For instance, under the EU's Digital Services Act (DSA), many civil society groups serve as "Trusted Flaggers" for digital platform moderation. While this expands their public-interest responsibilities, it drastically increases their visibility and makes them identifiable targets for retaliatory cyberattacks and harassment by malicious actors seeking to silence them.

What are the main digital threats that NGOs face today, regardless of their size or the country in which they operate?

Regardless of size or geography, our recent research (see European Demoncy Resilience Network reports here) demonstrate that NGOs are facing a converging threat landscape where information manipulation and cyberattacks are increasingly combined. Malicious actors use a shared technical backbone to deploy information manipulation campaigns and reinforce them with “traditional” technical intrusions.

However, the most common and damaging threats we see today are not new, they include:

Many organisations have limited financial and technical resources. What practical and affordable cybersecurity measures would you recommend they implement first?

Internally, nonprofits can focus on basic, high-impact steps such as:

  • Implement good passwords practice by enabling Multi-Factor Authentication (MFA) across all key platforms, email accounts, and sensitive systems.
  • Create a "First 24-Hours" incident response checklist tailored for non-technical staff so the organisation knows exactly who to call and what to do if breached. This should also include a communication crisis plan to handle in particular the relations with beneficiaries and donors, and maintain trust. 
  • Govern internal AI use to prevent risks caused by staff uploading sensitive beneficiary data into public, ungoverned, AI tools. 

Furthermost, the first step an under-resourced organisation can take is to stop trying to fight alone and connect to a shared defensive ecosystem, such as our Cyber Builders program, which provides support for free. More than 1,800 cybersecurity professionals donate their time in the Cyber Builders to support nonprofits in implementing these best practices and more. 

Protect.ngo works with an international network of cybersecurity volunteers. How does this model work, and what impact has it had on the organisations you support?

Our Cyber Builders program is the operational backbone of our defense pillar. It connects nonprofits with a vetted network of cybersecurity professionals from the private sector who volunteer their time and expertise.

When an NGO needs help whether it is conducting a cyber maturity assessment, recovering from an incident, or setting up secure communications, they request a "mission" through our platform. We then match them with a volunteer equipped to handle that specific technical need. Support can be provided in 38 languages. English is by far the dominant language among volunteers. The next most common languages are French, Spanish, and Hindi, each spoken by fewer than 80 active volunteers. 

The impact is measurable: to date, we have mobilized over 1,800 cybersecurity experts to protect over 700 nonprofits worldwide. In 2025 alone, this volunteer network delivered $9.5 million in commercial cybersecurity value entirely for free.

Your organisation also investigates cyberattacks against civil society. What have you learned about the human and social consequences of these incidents beyond their financial impact?

Through our Harm Methodology, we have learned that cyberattacks against civil society systematically inflict human, institutional, and societal damage far beyond the immediate financial cost or data loss. We track this human impact of cyber attacks in our Cyber Tracer. 

When a hospital is hit by ransomware, patient care is delayed. When a humanitarian group's data is breached, vulnerable refugees and activists are put in physical danger because their personal data is leaked. Furthermore, attacks frequently result in profound psychological harm, including burnout and trauma for victims and staff facing relentless online harassment. Ultimately, these attacks erode public and donor trust, silence democratic watchdogs, and create a chilling effect that degrades the civic space globally. 

Artificial intelligence is rapidly transforming the digital landscape. What opportunities does it offer nonprofits, and what new risks should organisations be aware of?

AI is a double-edged sword for nonprofits. We recently co-published an open letter, Racing the Cyber Clock, calling for coordinated measures to support nonprofits in the face of AI. The reality explained in the letter is that frontier AI models can now autonomously discover vulnerabilities and execute complex cyberattacks in just a few minutes. This accelerates attack timelines beyond the capacity of human response, leaving under-resourced nonprofits drastically outpaced. There are also internal risks where staff inadvertently leak sensitive data into ungoverned AI tools, creating new exposure.

However, the open letter also describes how AI presents an unprecedented opportunity for collective defense. At Protect.ngo, we already use it to accelerate our support and reduce the burden on our staff and volunteers. By using AI agents to collect massive amounts of data and automate threat analysis, we free our technical staff’s time to focus on what is most urgent and drastically lower the marginal cost of defense which enables us to provide protection to nonprofits for free.

International cooperation is one of the pillars of your work. What role should governments, technology companies and civil society organisations play in creating a safer digital environment?

Cybersecurity demands collective vigilance and action. The intelligence we gather in our Cyber Tracer, our platform measuring the human harm of cyber threats to civil society, feeds our advocacy at international forums, shifting policy debate from theoretical risk to problems we can demonstrate and measure. All stakeholders play a role. 

Governments must recognise civil society as the critical democratic infrastructure it is and fund long-term, shared defensive infrastructure. 
Technology companies need to integrate civil society into their collective defense ecosystems, sharing threat intelligence, supporting open-source defensive tools, and offering scalable, pro-bono enterprise licenses.

Many nonprofits are deploying cybersecurity and conducting public-interest research, many of which are coordinated through networks like Nonprofit Cyber. More generally, all Civil Society Organisations, regardless of the sector they operate in, must abandon the mindset that they can defend themselves in isolation or that they are not concerned because they are. The question is not ‘if’ they will be a target, it is ‘when’. Nonprofits need to join collaborative networks to not only be protected but to safely share anonymised incident data, so that an attack on one becomes a lesson that hardens the defenses of all.

Your organisation recently became Protect.ngo. What does this new identity represent, and what are your main goals for the coming years?

Becoming Protect.ngo reflects our operational focus. "Protect" is our concrete mandate.

Our main goals for the coming years are centered on accelerating and scaling what works before AI Frontier models change the threat landscape. We aim to mass-deploy our shared defensive infrastructure to provide real-time, automated incident response to thousands of nonprofits. Simultaneously, through initiatives like H-ARMOR, we aim to bridge the gap between technical cyber investigations and information manipulation, providing the necessary evidence to actively disrupt hostile ecosystems, and create a more resilient infrastructure for civil society. 

What message would you like to share with organisations that still believe cybersecurity is an issue that only concerns large institutions?

If your organisation relies on digital tools to communicate, raise funds, or deliver services to vulnerable people, you are a target. Threat actors do not care about your size; they care that you have data and money, and they use automated tools to exploit everything they can. 

A cyberattack shouldn’t be seen as an "IT problem" for the tech team to handle alone; it is a direct threat to your operational continuity, your reputation, and your mission’s beneficiaries. Digital resilience must be viewed as an operational strategic decision.
 

Add new comment

The content of this field is kept private and will not be shown publicly.