Research & Analysis

NGO Cyber Duty of Care Brief

Protecting staff, beneficiaries and programme data in surveillance-exposed and conflict-affected environments, practical measures for organisations without a security engineering team.

Author
Mowlid Ali
Published
Q3 2026
Country / region
Africa-wide
Threat category
Digital safety · Surveillance · Data protection
Length
22 pages
CyberEthiopiaSudanSomaliaMaliDR CongoKenya
Listen · 3 minReady to play · about 3 min

Executive summary

For humanitarian and development organisations, cyber risk is a protection issue before it is an IT issue: beneficiary lists, staff movements and partner identities carry direct physical consequences if exposed.

The realistic threats are device seizure at checkpoints and borders, account compromise through phishing, mobile surveillance of staff, and data loss through unmanaged tools adopted by field teams under pressure.

Most of the effective control set requires policy and habit rather than budget, which makes it achievable for small organisations that will never have a dedicated security function.

Sources · [3] UN OCHA / ReliefWeb · [6] NASA FIRMS / Copernicus

Full report

Data minimisation as protection

Collect the least data required for the programme, hold it for the shortest defensible period, and know where every copy lives. Every additional field and every unnecessary export is future exposure.

Pseudonymise where the programme allows, keep identifying keys separate from operational datasets, and treat photographs and GPS metadata as identifying data because they are.

Sources · [12] INSO · [1] ACLED

Devices and travel

Enforce full-disk encryption and screen locks on all devices holding programme data. For travel through high-scrutiny environments, issue clean devices with only the data needed for the trip and a documented handling procedure for seizure.

Brief staff on what to do if a device is taken: comply, do not resist, report immediately, and treat every account on that device as compromised until credentials are rotated.

Sources · [14] URLhaus / AbuseIPDB · [3] UN OCHA / ReliefWeb

Accounts, communications and partners

Use organisation-managed accounts with multi-factor authentication rather than personal accounts; the ability to revoke access on departure or after an incident is the core of the control.

Agree a single approved channel for sensitive coordination and enforce it. Where partners hold shared data, include data-handling obligations in the agreement and offer practical support rather than an audit demand.

Sources · [13] AlienVault OTX · [2] UCDP

Incident response for small teams

Write a one-page plan: who to call, what to isolate, who decides on notification, and how to communicate when email is untrusted. Rehearse it once a year with the country teams that would actually run it.

Where a breach affects affected populations, notification and mitigation duties are ethical before they are legal. Plan for the protection response, not only the regulatory one.

Sources · [5] FEWS NET · [8] Institute for Security Studies (ISS Africa)

Key findings

  • Beneficiary data collected on personal devices and shared through consumer messaging apps is the most common and most consequential exposure in the sector.
  • Device seizure at checkpoints, airports and borders is a routine occurrence in several operating environments and should be planned for as an expected event.
  • Targeted phishing against country directors and finance staff frequently precedes both fraud and, in some contexts, state-linked surveillance activity.
  • Data protection law now applies to humanitarian data collection in most African jurisdictions, and donor requirements increasingly test it during audit.
  • Partner organisations frequently hold the same sensitive data with weaker controls, which makes partner capability an organisational risk rather than a partner problem.

Analyst assessment

We assess with high confidence that a small, well-enforced control set, managed accounts, MFA, encrypted devices, defined data-handling rules and clean-device travel, would prevent the majority of incidents seen in the sector.

We assess with moderate confidence that surveillance pressure on civil society organisations in restrictive environments will increase, alongside regulatory scrutiny of data held on affected populations.

The highest-consequence realistic incident is exposure of a beneficiary or informant list in a conflict environment, not financial loss.

Related reports

Footnotes & sources

  1. [1] ACLED Armed Conflict Location & Event Data — Africa event recordsL1 Conflict · reliability A
  2. [2] UCDP Uppsala Conflict Data Program — organised violence datasetL1 Conflict · reliability A
  3. [3] UN OCHA / ReliefWeb Situation reports, access snapshots and humanitarian updatesL2 Early warning · reliability A
  4. [4] GDACS Global Disaster Alert and Coordination System alertsL2 Early warning · reliability B
  5. [5] FEWS NET Food security outlooks and alertsL2 Early warning · reliability A
  6. [6] NASA FIRMS / Copernicus Active fire detections and open satellite imagery for corroborationL3 GEOINT · reliability B
  7. [7] GDELT Project Global media event and tone monitoringL5 Strategic · reliability C
  8. [8] Institute for Security Studies (ISS Africa) Regional political and security analysisL5 Strategic · reliability B
  9. [9] INGO ADVISORY analyst desk Practitioner interviews, field reporting and imagery verificationL6 Verification · reliability B
  10. [10] UKMTO Maritime incident advisories — Gulf of Aden and Red Sea approachesL2 Early warning · reliability A
  11. [11] IOM DTM Displacement Tracking Matrix — movement and displacement flowsL2 Early warning · reliability A
  12. [12] INSO NGO safety incident reporting and access advisoriesL1 Conflict · reliability A
  13. [13] AlienVault OTX Open threat exchange indicatorsL4 Cyber · reliability B
  14. [14] URLhaus / AbuseIPDB Malicious infrastructure and abuse reportingL4 Cyber · reliability B

Supporting capability statement

Horn of Africa security capability pack

Download the experience summary, applied risk frameworks and sample operational brief supporting this country threat assessment.

Independent research

Explore the research

Open-source analysis of security developments, operational risk and emerging threats across Africa, with a focus on East Africa and the Horn of Africa.