Executive summary
For humanitarian and development organisations, cyber risk is a protection issue before it is an IT issue: beneficiary lists, staff movements and partner identities carry direct physical consequences if exposed.
The realistic threats are device seizure at checkpoints and borders, account compromise through phishing, mobile surveillance of staff, and data loss through unmanaged tools adopted by field teams under pressure.
Most of the effective control set requires policy and habit rather than budget, which makes it achievable for small organisations that will never have a dedicated security function.
Sources · [3] UN OCHA / ReliefWeb · [6] NASA FIRMS / Copernicus
Full report
Data minimisation as protection
Collect the least data required for the programme, hold it for the shortest defensible period, and know where every copy lives. Every additional field and every unnecessary export is future exposure.
Pseudonymise where the programme allows, keep identifying keys separate from operational datasets, and treat photographs and GPS metadata as identifying data because they are.
Devices and travel
Enforce full-disk encryption and screen locks on all devices holding programme data. For travel through high-scrutiny environments, issue clean devices with only the data needed for the trip and a documented handling procedure for seizure.
Brief staff on what to do if a device is taken: comply, do not resist, report immediately, and treat every account on that device as compromised until credentials are rotated.
Sources · [14] URLhaus / AbuseIPDB · [3] UN OCHA / ReliefWeb
Accounts, communications and partners
Use organisation-managed accounts with multi-factor authentication rather than personal accounts; the ability to revoke access on departure or after an incident is the core of the control.
Agree a single approved channel for sensitive coordination and enforce it. Where partners hold shared data, include data-handling obligations in the agreement and offer practical support rather than an audit demand.
Sources · [13] AlienVault OTX · [2] UCDP
Incident response for small teams
Write a one-page plan: who to call, what to isolate, who decides on notification, and how to communicate when email is untrusted. Rehearse it once a year with the country teams that would actually run it.
Where a breach affects affected populations, notification and mitigation duties are ethical before they are legal. Plan for the protection response, not only the regulatory one.
Sources · [5] FEWS NET · [8] Institute for Security Studies (ISS Africa)
Key findings
- Beneficiary data collected on personal devices and shared through consumer messaging apps is the most common and most consequential exposure in the sector.
- Device seizure at checkpoints, airports and borders is a routine occurrence in several operating environments and should be planned for as an expected event.
- Targeted phishing against country directors and finance staff frequently precedes both fraud and, in some contexts, state-linked surveillance activity.
- Data protection law now applies to humanitarian data collection in most African jurisdictions, and donor requirements increasingly test it during audit.
- Partner organisations frequently hold the same sensitive data with weaker controls, which makes partner capability an organisational risk rather than a partner problem.
Analyst assessment
We assess with high confidence that a small, well-enforced control set, managed accounts, MFA, encrypted devices, defined data-handling rules and clean-device travel, would prevent the majority of incidents seen in the sector.
We assess with moderate confidence that surveillance pressure on civil society organisations in restrictive environments will increase, alongside regulatory scrutiny of data held on affected populations.
The highest-consequence realistic incident is exposure of a beneficiary or informant list in a conflict environment, not financial loss.
Related reports
Footnotes & sources
- [1] ACLED — Armed Conflict Location & Event Data — Africa event recordsL1 Conflict · reliability A
- [2] UCDP — Uppsala Conflict Data Program — organised violence datasetL1 Conflict · reliability A
- [3] UN OCHA / ReliefWeb — Situation reports, access snapshots and humanitarian updatesL2 Early warning · reliability A
- [4] GDACS — Global Disaster Alert and Coordination System alertsL2 Early warning · reliability B
- [5] FEWS NET — Food security outlooks and alertsL2 Early warning · reliability A
- [6] NASA FIRMS / Copernicus — Active fire detections and open satellite imagery for corroborationL3 GEOINT · reliability B
- [7] GDELT Project — Global media event and tone monitoringL5 Strategic · reliability C
- [8] Institute for Security Studies (ISS Africa) — Regional political and security analysisL5 Strategic · reliability B
- [9] INGO ADVISORY analyst desk — Practitioner interviews, field reporting and imagery verificationL6 Verification · reliability B
- [10] UKMTO — Maritime incident advisories — Gulf of Aden and Red Sea approachesL2 Early warning · reliability A
- [11] IOM DTM — Displacement Tracking Matrix — movement and displacement flowsL2 Early warning · reliability A
- [12] INSO — NGO safety incident reporting and access advisoriesL1 Conflict · reliability A
- [13] AlienVault OTX — Open threat exchange indicatorsL4 Cyber · reliability B
- [14] URLhaus / AbuseIPDB — Malicious infrastructure and abuse reportingL4 Cyber · reliability B
Supporting capability statement
Horn of Africa security capability pack
Download the experience summary, applied risk frameworks and sample operational brief supporting this country threat assessment.
Free operational toolkit
Act on this assessment
Six free operational tools for NGO and charity teams — no sign-up, nothing leaves your browser.
- Travel risk authorisationRisk-tiered approval form with control verification before movement is signed off.
- Vehicle & convoy check13-point pre-departure inspection with go / no-go clearance logic.
- Safeguarding / PSEA referralAnonymised referral log for PSEA and misconduct concerns.
- Cyber hygiene assessmentScored self-assessment producing a prioritised remediation workplan.
- Staff accountability roll callReal-time headcount and status tracking during an incident.
- Endurance calculatorContingency stock planning for water, food, fuel and cash.