Frequently Asked Questions about Cybersecurity

Patricia Musomba
Nathaly Espitia
Brian Obilo
Lesedi Bewlay

Part of our work with the Cybersecurity Assessment Tool(CAT) involves creating spaces where communities and organizations can learn more about digital resilience. We recently hosted an Ask Us Anything: Cybersecurity Edition session, where community members shared questions and experiences from their work. This FAQ brings together some of those questions with practical guidance to help organizations strengthen their digital resilience.

Q1: What are the most common security risks facing civil society organizations right now?

Security risks vary depending on an organization’s location, work, communities and wider political and social context. Risks may increase during elections, protests, conflicts or periods of political instability. 

Based on our support work and recent threat reports, some of the most common risks include:

  • Online harassment and gendered attacks: Coordinated abuse, threats, doxxing, impersonation and targeted attacks, particularly against women, LGBTQ+ people and other marginalized groups
  • Phishing and account compromise: Attempts to steal login credentials, take over accounts or trick team members into sharing sensitive information
  • Website attacks: Website hacking attempts, distributed denial-of-service attacks, website defacement and the exploitation of outdated software or plugins
  • Spyware and surveillance: The monitoring of devices, communications, locations or online activity by state and non-state actors
  • AI-related security concerns: AI-generated phishing messages, misinformation and the exposure of sensitive information through AI tools

Organizations can build collective resilience by staying informed, connecting with trusted community networks and sharing emerging threats to help others prepare.

Q2: What are some of the best practices to protect sensitive data in our day-to-day operations for a small organization with low resources?

Some things to think about:

  • Know what data you hold. Map what sensitive information you have, where it lives, and who can access it. For many organizations, high-risk data includes contact databases, source identities and beneficiary information about people who could be harmed if exposed
  • Practice data minimization. The safest data is data you don’t hold. Only collect and store what you need, and delete what you no longer need on a regular schedule
  • Control access. Restrict sensitive files and data to people who need them. Review access regularly, especially when someone joins or leaves the team. A simple offboarding checklist prevents unnecessary exposure.

Resources: The Engine Room’s Becoming RAD tipsheet  provides practical guidance on Retention, Archiving, and Disposal (RAD) of data. The Responsible Data Handbook provides guidance on responsible data practices across the project/data lifecycle.

Q3: With many reported website related attacks, what steps can organizations take to protect their websites?

Keep your website infrastructure updated. For managed websites, update WordPress, themes and plugins. For self-hosted websites, update the server operating system and web server software, such as Nginx. Delete unused plugins and themes.

Use an SSL certificate. This encrypts information shared through your website, such as login details.

Review access controls. Limit admin access to people who need it and remove access for former staff, consultants, volunteers and developers. Strong onboarding and offboarding practices are important.

Use strong passwords and two-factor authentication. Enable two-factor authentication wherever the website platform supports it.

Back up your website regularly. The 3-2-1 rule recommends keeping at least three copies, in at least two locations, with one stored separately from the main website environment.

The Engine Room held a community call on website security. Read the full recap here and watch the recording for more information.

Q4: What practical steps actually make a difference in high-risk or resource-constrained contexts?

Start by understanding your threat profile: who you are, the work you do, who you interact with and the risks are most likely to affect you. This helps prioritize the security practices most relevant to your context rather than trying to do everything at once. This guide can help you determine your threat model. 

Some high-impact steps include:

  • Strengthen basic account security: Use strong passwords, password managers, and two-factor authentication.Regularly review access to organizational accounts.
  • Prioritize secure communication: Agree which channels to use for everyday communication, sensitive discussions and emergencies. 
  • Have an incident response process: Make sure everyone knows how to report suspicious activity, who is responsible for responding and what to do during a crisis. 
  • Invest in people: Train teams to recognize phishing attempts, handle sensitive information safely and secure their devices. Create a culture where people can report mistakes without fear of blame.

Q5: What new digital security risks does AI create for civil society organizations and what practical steps can organizations take?

Protect sensitive data. Avoid uploading information that could harm staff, partners, communities, or others whose information appears in documents or conversations. Practice data minimization by providing only the information needed for the task and avoiding names, identifying details, sensitive organizational information or unnecessary context.

Choose AI tools carefully. Before using an AI tool, consider whether it adds real value and what information you are putting into it. Review its privacy policy, data collection practices and retention settings. Where possible, choose tools with privacy-protective settings or that do not retain data. Be transparent about how and why AI is used, what information will be processed, and what will be shared afterwards.

Avoid over-reliance on AI outputs. People should make decisions, review information and question what the tool produces. AI-generated content can contain errors, bias, missing context or assumptions shaped by the people, systems and data behind the tool. 

The Engine Room held a community call on AI safety for nonprofits. Read the full recap for more information.

Q6: How can we implement new practices and build a security culture with care within our organization?

Center the people. Introducing new tools, guidelines and practices should be a process of collective learning that considers differences in access, knowledge, technical proficiency and context. Invite the team to reflect on the  risks they face, what feels difficult and what support they need.

Culture takes time. Introduce changes gradually and focus first on the most urgent risks. Explain why each practice matters, provide opportunities to learn and avoid blaming individuals when mistakes happen.

Shared responsibility. A care-centered security culture should not place responsibility on one person. Regular check-ins, peer learning and open conversations about mistakes and emerging threats can make security more manageable and relevant.

Encourage learning from trusted sources. Provide resources that encourage curiosity and learning.This article When your tech tools just aren’t working for you any more offers guidance on reviewing and changing tools your organization uses.

Q7: What anti-virus tools can we use?

Most operating systems include built-in antivirus protection that is sufficient for many threat models, including Microsoft Defender for Windows and XProtect for macOS. Organizations with higher-risk threat models that may need additional protection, such as Bitdefender.

Q8: How can organizations and individuals respond to online bullying, harassment, and coordinated attacks?

Online harassment can pose serious threats to safety, morale and operations. Key steps to help prevent, respond to and recover from online harassment include:

  • Have a response plan: Agree how to report and escalate incidents and what support is available when someone is targeted.
  • Protect accounts and reduce exposure: Enable two-factor authentication, review privacy settings, remove sensitive personal information from public profiles and consider pseudonyms or separate accounts for public engagement where appropriate.
  • Prepare for public attacks: Register key domains and social handles, and prepare responses to false claims, impersonation or coordinated harassment. Avoid engaging directly with trolls; use reporting and blocking features instead. 
  • Document and report abuse: Keep records of harassing messages or content for reporting to platforms or, where necessary, legal action. Where possible, ask trusted community members to help if documentation could be retraumatizing. 
  • Support affected people: Provide appropriate support and create safe spaces for people to debrief after harassment incidents. 

Online Harassment Field Manual and Online Harassment Resources – Right To Be  provide further guidance.

Q9: Many nonprofit organizations use Google forms for creating surveys. Are there alternatives to Google Forms organizations can explore?

There are alternatives to Google Forms, but the right option depends on your infrastructure, budget, team size, technical capacity and risk profile. Some organizations may need a simple, low-cost tool, while others may need stronger privacy protections or more control over where data is stored.

The most important first step is to understand what data you will collect, how sensitive it is and whether you have the capacity to self-host and maintain the tool. Some alternatives to explore include Nextcloud Forms (self-hosted), LimeSurvey, Cryptpad forms and My LiberaForms.  

If you’re collecting sensitive information from communities, partners or staff, seek tailored support through our  CATio spaces and LightTouch Support. 

Q10: What resources can we use as we navigate our security journey?

Here are some resources to strengthen digital security and responsible data practices: 

We also asked our community to share their favorite resources. Explore the curated list of digital security resources.  

This FAQ was put together by Patricia Musomba, Nathaly Espitia Diaz, Brian Obilo, Lesedi Bewlay, Narrira Lemos and Doreen Ochung, and made possible through our work with the Cybersecurity Assessment Tool.

MORE