Civil society organizations like yours face many risks thanks to your important work. In fact, even risks that may not seem directly linked to your organization can actually be warning signs for bigger security challenges ahead. Threats like cyberbullying, doxxing, or physical and digital harassment of your staff can all indicate a shift in your risk level—not to mention take a hefty toll on the wellbeing of your staff and community.
We call these threats "associated risks," because they are linked to the safety and security of your organization even if they aren't directly attacking your work.
Who's Most Often At Risk
While anyone can face cyberbullying, harassment, or other digital harm, certain groups of people often face more intense threats than others. These include:
-
Outspoken individuals (organizers, activists, journalists)
-
Women
-
LGBTQ individuals
-
Black or brown communities
-
Ethnic or religious minorities
Consider whether any of your staff members who identify with these groups are coping with undue stress from online threats. This can be especially true if they also maintain a high profile professionally, such as presenting or giving speeches at conferences or online events. If they are active in social movements or organizing outside of work, they may carry that profile with them into their professional life, also.
As an organization, you have a duty of care for the health, wellbeing, and safety of your staff. While some of these risks may occur when a staff member is outside of working hours, you can still provide resources to help. Some of the safeguards and best practices you may want to consider include:
-
Updated technology and devices
-
Organizational policies on bullying and harassment
-
Training to cope with online threats
-
A culture of security where staff can raise concerns and provide feedback
Let's get started first by understanding the risks your staff are likely to face.
Start With Threat Modeling
There is no one-size-fits-all solution for associated risks because everyone's context, profile, and activities are different. But, generally, we see these risks fall into the following categories:
-
Doxxing, or having personal information shared online without consent
-
Threats to reputation
-
Harassment, stalking, and bullying online
-
Threats of physical or sexual violence
-
Campaigns to force individuals offline or from social media
To understand the risks that are facing your staff in particular, it's helpful to practice threat modeling, or the use of available information to determine risk. A basic threat modeling exercise for your staff could include asking the following questions—understand that the answers may vary across your staff.
While predicting future risks is always challenging, we do have information at our disposal to begin tackling these questions. For example, study what adversaries have done in the past and ask your staff what types of harassment and threats they have previously experienced. You may also want to track threats against organizations or individuals who do similar work as your own.
Building a Culture of Care
We can't always stop online harassment from happening, but we can support our staff and community when it does occur. Building a culture of care allows you to create an environment where people feel valued and heard, as well as encouraged to share difficult personal or professional experiences.
Fostering such a culture doesn't happen overnight but rather through incremental steps. One major step you can take as an organization is to acknowledge the impact of online harassment, as well as the stress and anxiety that can come from civil society work. If you see staff disengaging from work, self-censoring themselves or their expression online, or disconnecting from online platforms entirely, note these warning signs. Many organizations now provide psychosocial support and resources for employees, while others designate different days of the week as "meeting-free" times for staff to unplug and focus. Others create resource libraries to help staff navigate challenging experiences like these.
Safeguarding Personal Information
When adversaries want to silence a member of your staff or community, they often weaponize their personal information. This practice, known as doxxing, involves the release of personal information—such as home addresses or phone numbers—on the public Internet to shame or silence an individual.
Depending on where your organization is based globally, there may be varying levels of legal protection and regulation of personal data. For example, the United States and Canada have relatively lax data protection laws when compared to the European Union. In countries with loose data protection, data broker companies are able to amass significant amounts of personal data which anyone with a subscription can access. This data is often used for opposition research or by private investigators but can also be leaked online by people seeking to do harm.
All data broker firms do provide methods to opt out of having your data collected—many of which are documented here—but this process can be complicated and time-consuming. An alternative is to pay a service to remove personal information from the web, which obviously comes at a price.
It's difficult to avoid data collection online, but there are steps you can take to lessen your footprint, such as using aliases (including dummy emails) and virtual phone numbers when signing up for online services.
Crisis Management Basics
If online harassment turns into a security crisis, there are steps you can take to respond. Crisis management is a rich topic worth exploring in more detail, but to summarize, here is a basic guide to get started.
Prevent: Take steps (such as threat modeling) to determine your risks and develop a list of steps you can take to reduce the likelihood of these threats.
Plan: Develop an incident response plan, including identifying which team members will respond to a crisis and how, then make sure to keep that plan continually updated.
Practice: Test your incident response plan through tabletop exercises and other scenarios to ensure that your workflow will work properly during an incident.
Perform: When an incident does occur, follow the steps on your incident response plan—including taking time to evaluate how your plan performed once the crisis has passed.
As civil society organizations, we face a variety of risks to our mission, some of which will be directed at our staff and communities. It's important to be proactive in addressing these associated risks so your staff can continue with their impactful mission.