Section outline

    • The work of civil society organizations often includes collaborating with diverse communities who may have varying levels of digital experience, awareness, and trust. If your organization works with communities whose comfort level with cybersecurity differs from your own, we've put together these guidelines to help start a respectful and constructive conversation.

      Understand the community you're working with

      Before you start working with a community on a typical project, you would ask questions, do your research, and cultivate relationships. The same process should also apply when collaborating with community members on cybersecurity. Be aware that some communities may struggle to follow cybersecurity best practices due to:

      One effective way to better understand the cybersecurity needs of outside communities is to practice threat modeling. We've discussed using this practice for your internal security, but you can apply the same framework to external groups, too. Consider who within the community you're working with is most at risk—often (but not always) these are outspoken individuals like organizers, activists, journalists, and lawyers.

      Next, identify the most likely threats facing these community members based on historic events. For example, groups like these may have experienced censorship, disinformation, attacks via social media, or even Internet shutdowns in the past. 

      Finally, determine which risks are most likely to occur by using a basic threat modeling framework, such as suggested by the Electronic Frontier Foundation in their handout here

      Practice harm reduction 

      Harm reduction is a process borrowed from public health, in which security experts take whatever steps necessary to minimize risk to communities, even if that means not following standard best practices. 

      For example, if many people in a community rely on a less secure messaging app to communicate, security professionals would usually recommend they switch to a more secure platform. But if using a more secure app would attract unwanted attention or increase risk, it’s often best for the community to continue to use the less secure version as safely as possible. 

      This open-minded approach may require you to deviate from the accepted wisdom in cybersecurity. You may need to modify some of your own best practices to “meet communities where they are” in their cybersecurity journey. In general, it’s safest for a community to utilize the tools they are most accustomed to and comfortable with. You (or a third-party cybersecurity professional) may be able to make recommendations that would help them use these tools more safely, such as enabling encryption (if possible), understanding where their data is stored, and choosing the right tool for the right purpose. Whenever you do give advice, it’s important to remember to provide the rationale behind your thinking, too, so community members can decide for themselves whether that advice applies to their situation. 

      Empower security champions

      Working with communities on cybersecurity doesn’t require your organization to provide all the answers to community members. In fact, the communities you work in are well equipped to provide valuable insights, context, and advice about the security situation they—and by extension, you—face. 

      One way to ensure community voices are heard, recognized, and respected is to designate certain community members as “security champions.” We’ve discussed this concept for your internal teams, but the same principle can be applied for external partners, as well. 

      When selecting security champions, look for individuals who:

      Empowering security champions requires honest, candid conversation. Leave time and space for community members to share their insights, reflect on the risks they face, and offer guidance on your security approach. When training them on cybersecurity best practices, remember the principle of harm reduction that we discussed earlier. In some cases, you may need to be more flexible in your approach to security in order to meet communities where they are. 

       
       

      CHECKLIST

       

      Challenges Facing Communities  

       

      Threat Modeling

       

      Harm Reduction

       

      Security Champions