The Growing Cyber Threat to High-Risk Actors
Journalists, dissidents, activists, human rights defenders, and NGOs are on the frontlines of advocacy and reform. Their work exposes corruption, challenges oppressive regimes, and amplifies voices that might otherwise go unheard. However, these efforts often make them prime targets for cyberattacks.
Malicious threat actors — whether state-sponsored or independent — have increasingly weaponized digital tools against civil society. Sophisticated surveillance software, phishing campaigns, and denial-of-service attacks (DoS) are used to infiltrate networks, silence critics, and disrupt advocacy work. The consequences can be severe: sensitive information is stolen, sources are compromised, and entire organizations can be rendered inoperable.
Cybersecurity is no longer just a technical issue for high-risk actors — it is essential for protecting freedom of expression, human rights, and democratic institutions. Without proper defenses, those fighting for change remain exposed to digital threats that can have real-world consequences.
Addressing the Cybersecurity Needs of High-Risk Actors
Targeting Support to Actors at Highest Risk
Many high-risk actors operate under challenging conditions, often with limited resources or expertise to defend against cyber threats. Their adversaries, however, often have access to advanced tools, intelligence, and seemingly unlimited budgets, making the digital battlefield vastly unequal. Below are just a few examples of threats faced by high-risk actors.
Journalists under surveillance – Investigative reporters uncovering corruption have had their mobile devices compromised by spyware like Pegasus, allowing adversaries to monitor their communications and track their movements.
NGOs targeted by state-sponsored cyberattacks – Organizations documenting human rights abuses have faced DoS attacks and hacking attempts aimed at erasing evidence and disrupting operations.
Phishing campaigns targeting activists – Human rights defenders have been tricked into revealing login credentials via phishing attacks, giving attackers access to sensitive networks and contact lists.
Expanding Cybersecurity Assistance and Capacity
Despite the clear need, many cybersecurity organizations – many of them nonprofits themselves – struggle to provide sufficient resources to high-risk actors. Training programs, security audits, and access to encrypted communications are indispensable, but gaps remain due to limited funding and operational capacity.
Other examples of how nonprofits play a role in bridging this divide include:
- Securing the core infrastructure of the Internet, like the Domain Name Service (DNS), routing protocols, and threat intelligence systems.
- Providing digital security education tailored to civil society organizations.
- Offering infrastructure support, such as VPNs, secure DNS resolvers, encrypted messaging services, and secure hosting.
- Advocating for policies that protect at-risk actors from digital surveillance and censorship.
However, these efforts require broader cooperation beyond nonprofits. Governments, tech companies, and cybersecurity organizations must work together to ensure that these protective measures are not only available and effective, but also sustainable in the long term.
Strategic Support for Cybersecurity Nonprofits
One of the most challenging hurdles in this space is fragmented funding. Many cybersecurity initiatives for civil society rely on short-term grants and donations, making it difficult to scale solutions or provide long-term support. A coordinated funding mechanism could streamline resources, reduce duplication of efforts, and ensure that nonprofits can continue their mission without constant financial uncertainty.
With a more strategic approach to funding in place, organizations would be better positioned to expand security services to reach a larger number of high-risk actors as well as invest more in the research and development of tools specifically designed for civil society. Ultimately, ensuring cybersecurity nonprofits have sustainable support is just as necessary as providing direct assistance to at-risk actors. Investing in cybersecurity prevention reduces the potentially astronomical costs associated with crisis response, cyber breaches, and prolonged recovery. Preventive funding now helps avoid far greater social, economic, and security costs later.
The Role of Common Good Cyber in Strengthening Cybersecurity for High-Risk Groups
Common Good Cyber was established to address many of these cybersecurity challenges. Its mission is “identifying and implementing innovative models for sustaining groups, organizations, and individuals involved in critical cybersecurity functions for the broader Internet community.” This mission aligns with the goal of ensuring that those on the frontlines of human rights advocacy have the tools and knowledge to safeguard their work against cyber threats. We recommend checking out the Common Good Cyber library of reports for more information around their work.
Bridging the Gap: A Collaborative Effort to Secure Civil Society
This week, Common Good Cyber and the UK’s Foreign, Commonwealth & Development Office (FCDO) will host “Bridging the Gap: Delivering Cybersecurity to High-Risk Actors.” This closed-door event will bring together cybersecurity experts, nonprofit leaders, and policymakers to discuss solutions for strengthening digital defenses for civil society. The event’s discussion panels will focus on three primary topics:
- Identifying effective support for high-risk actors
- Growing the capacity of network defenders
- Strategic support for the nonprofit ecosystem
The goal of this collaborative event is to highlight the urgent need for a more coordinated and sustainable approach to defending at-risk actors from digital threats. Its outcomes could help shape future cybersecurity initiatives designed to protect those most in need.
The Takeaway | Strengthening Cyber Resilience for Those Who Need It Most
For members of civil society, cybersecurity is more than just a technical issue — it can be a matter of survival. Without proper defenses, journalists can be silenced, NGOs can be dismantled, and human rights defenders can be put at risk. Ensuring their digital safety means safeguarding the very principles of free speech, transparency, and justice.
Protecting these high-risk actors and organizations requires sustained commitment. It demands investment in cybersecurity solutions, collaboration among stakeholders, and innovative funding models for long-term resilience. Initiatives like Common Good Cyber are a crucial step in this direction, but the challenge is far from over.
Cyber threats will continue to evolve, but so must our defenses. By bridging gaps, strengthening partnerships, and prioritizing cybersecurity for those who need it most, we can create a safer digital ecosystem where civil society can continue its critical work — without fear.



