• News
    • Latest news
    • News search
    • Health
    • Finance
    • Food
    • Career news
    • Content series
    • Try Devex Pro
  • Jobs
    • Job search
    • Post a job
    • Employer search
    • CV Writing
    • Upcoming career events
    • Try Career Account
  • Funding
    • Funding search
    • Funding news
  • Talent
    • Candidate search
    • Devex Talent Solutions
  • Events
    • Upcoming and past events
    • Partner on an event
  • Post a job
  • About
      • About us
      • Membership
      • Newsletters
      • Advertising partnerships
      • Devex Talent Solutions
      • Contact us
Join DevexSign in
Join DevexSign in

News

  • Latest news
  • News search
  • Health
  • Finance
  • Food
  • Career news
  • Content series
  • Try Devex Pro

Jobs

  • Job search
  • Post a job
  • Employer search
  • CV Writing
  • Upcoming career events
  • Try Career Account

Funding

  • Funding search
  • Funding news

Talent

  • Candidate search
  • Devex Talent Solutions

Events

  • Upcoming and past events
  • Partner on an event
Post a job

About

  • About us
  • Membership
  • Newsletters
  • Advertising partnerships
  • Devex Talent Solutions
  • Contact us
  • My Devex
  • Update my profile % complete
  • Account & privacy settings
  • My saved jobs
  • Manage newsletters
  • Support
  • Sign out
Latest newsNews searchHealthFinanceFoodCareer newsContent seriesTry Devex Pro
    • News
    • Data Security

    What NGOs can do to mitigate cybersecurity risks

    As humanitarian and development organizations face increasing cybersecurity threats, experts share what they can do to protect themselves.

    By Adva Saldinger // 11 June 2021
    While cybersecurity may not have traditionally been seen as an essential part of operations for humanitarian and development organizations, an increasing incidence of malicious efforts online has spotlighted the importance of information security policies and practices. A recent phishing attempt by a person or group mimicking the U.S. Agency for International Development’s email marketing account to target aid groups has brought renewed attention to the issue. But there are steps that organizations can take to prepare themselves to better detect breaches and respond to them — even if preventing them outright may not be possible, experts tell Devex. The first thing that organizations need is not fancy technology but a commitment from management and recognition of the real risks related to cybersecurity, said Dianna Langley, senior director of engagement at NetHope, a technology-focused global consortium of nonprofit organizations. Boards of directors and executives — not just chief information officers — need to view these as critical threats, discuss them, and ensure that cybersecurity is adequately resourced, she added. If organizations haven’t had conversations about cybersecurity with their boards or trustees, they should do so now, said James Eaton-Lee, data protection officer and the head of information security at Oxfam. Another key step is appointing a senior employee — preferably a technologist or risk manager who has a relevant track record — to own cybersecurity issues, he said. That person’s job should be to lead a response if a potential breach does arise. Small NGOs would need a different system and response mechanism, so they need to focus their resources. They should carefully evaluate needs, including whether they work with vulnerable clients or in hostile spaces, and ensure their teams and systems match their threat profile, Eaton-Lee said. Some systems can be easily implemented and do not require additional technology, such as requiring multifactor authentication on every system and device. Having that authentication in place stops many potential hacks, Langley said. A challenge for organizations that have far-flung or virtual teams may be the ability to maintain devices — including remotely patching issues and sending antivirus updates — but this is critical for cybersecurity efforts and understanding potential vulnerabilities, Langley said. Training for employees is essential so they know how to identify potential threats, and organizations should also ensure their systems have strong fundamentals, such as email management, she said. Once organizations have systems in place, they should validate them by benchmarking against peer organizations or having third-party evaluations and tests performed — including through simulated phishing exercises, Eaton-Lee said. Having systems in place is important, but organizations also need to have incident management processes — which few working in this sector do — said Stuart Campo, team lead for data responsibility at the United Nations Office for the Coordination of Humanitarian Affairs. Learning from challenges, detecting vulnerabilities, and ensuring thorough documentation are all difficult without data incident management, he said. Before starting a new service or using a new technological tool, groups should work to reduce their vulnerability as much as possible. One way to do that is to assess where data is hosted and how interconnected or isolated systems are, Campo said. For example, client data shouldn’t be sent via email, and access between systems should be limited, he said.

    While cybersecurity may not have traditionally been seen as an essential part of operations for humanitarian and development organizations, an increasing incidence of malicious efforts online has spotlighted the importance of information security policies and practices.

    A recent phishing attempt by a person or group mimicking the U.S. Agency for International Development’s email marketing account to target aid groups has brought renewed attention to the issue.

    But there are steps that organizations can take to prepare themselves to better detect breaches and respond to them — even if preventing them outright may not be possible, experts tell Devex.

    This story is forDevex Promembers

    Unlock this story now with a 15-day free trial of Devex Pro.

    With a Devex Pro subscription you'll get access to deeper analysis and exclusive insights from our reporters and analysts.

    Start my free trialRequest a group subscription
    Already a user? Sign in
    • Innovation & ICT
    • Institutional Development
    Printing articles to share with others is a breach of our terms and conditions and copyright policy. Please use the sharing options on the left side of the article. Devex Pro members may share up to 10 articles per month using the Pro share tool ( ).
    Should your team be reading this?
    Contact us about a group subscription to Pro.

    About the author

    • Adva Saldinger

      Adva Saldinger@AdvaSal

      Adva Saldinger is a Senior Reporter at Devex where she covers development finance, as well as U.S. foreign aid policy. Adva explores the role the private sector and private capital play in development and authors the weekly Devex Invested newsletter bringing the latest news on the role of business and finance in addressing global challenges. A journalist with more than 10 years of experience, she has worked at several newspapers in the U.S. and lived in both Ghana and South Africa.

    Search for articles

    Related Stories

    Artificial intelligenceAI in development recruitment: Time-saver or barrier to inclusion?

    AI in development recruitment: Time-saver or barrier to inclusion?

    Devex Pro LivePhilanthropy, blended finance, and the evolving role of NGOs

    Philanthropy, blended finance, and the evolving role of NGOs

    TechnologyOpinion: The internet was once a tool for justice. It can be again

    Opinion: The internet was once a tool for justice. It can be again

    HumanitarianNGOs say that new Gaza aid model is undermining lifesaving work

    NGOs say that new Gaza aid model is undermining lifesaving work

    Most Read

    • 1
      The power of diagnostics to improve mental health
    • 2
      Lasting nutrition and food security needs new funding — and new systems
    • 3
      Opinion: Urgent action is needed to close the mobile gender gap
    • 4
      Supporting community-driven solutions to address breast cancer
    • 5
      How to use law to strengthen public health advocacy
    • News
    • Jobs
    • Funding
    • Talent
    • Events

    Devex is the media platform for the global development community.

    A social enterprise, we connect and inform over 1.3 million development, health, humanitarian, and sustainability professionals through news, business intelligence, and funding & career opportunities so you can do more good for more people. We invite you to join us.

    • About us
    • Membership
    • Newsletters
    • Advertising partnerships
    • Devex Talent Solutions
    • Post a job
    • Careers at Devex
    • Contact us
    © Copyright 2000 - 2025 Devex|User Agreement|Privacy Statement