Digital Security for NGOs: Passwords, Two-Factor Authentication and VPNs

In civil society, digital security has long been treated as "the IT person's job". Yet in a rights-based organisation the weak link is almost never the server: it is a shared password, an old account still logged in on someone's phone, or a list circulating in the field team's WhatsApp group.
This is not a technical guide. It proposes a four-layer setup a team can put in place in one afternoon. None of it costs money.
Why this is different in civil society
In a commercial company, a data breach costs money and reputation. In a rights-based organisation it can cost someone's safety: a refugee client's address, a witness's phone number, the source of an unpublished report.
So make security decisions by asking "who is harmed if this information reaches the wrong person", not "who would attack us anyway". The first question produces serious answers even in a small association.
There is also the access side. You work in an environment where platform access is periodically restricted. When I polled my own community, 57% said they use a VPN to reach Instagram. Security here is not only about protection; it is about being able to keep working.
Layer 1: Passwords
The three habits I see most often: sharing organisational account passwords across the team, using the same password everywhere, and keeping passwords in a spreadsheet.
In order:
- Set up a password manager. Bitwarden's free plan is more than enough for a team; 1Password and browser password vaults also work. What matters is not which one, but having one.
- Use a different password for every account. A password leaked on one site opens the other ten accounts where you reused it.
- Prioritise length. A passphrase of four random words is both stronger and more memorable than an eight-character complex password.
- Check for breaches. Enter your organisational addresses at haveibeenpwned.com. Every result points to a password that needs changing today.
If you must share organisational passwords, use your password manager's shared vault. Then when someone leaves you revoke their access instead of changing one password everywhere.
Layer 2: Two-factor authentication
A password alone is not enough. Two-factor authentication (2FA) is the one practical measure that protects your account even when the password is stolen.
Priority order: organisational email first, then social media accounts, then website and cloud storage. Email comes first because every other account's password reset goes through it. An organisation whose email is compromised loses everything within hours.
On method: app-based codes (Google Authenticator, Authy and similar) are safer than SMS. SMS is vulnerable to SIM-swap attacks and fails during network outages.
Save your recovery codes. The most common 2FA problem is not an attack but a colleague who changed phones and can no longer get in. Store the codes in your password manager.
Layer 3: Access and VPNs
VPNs get explained by mixing up two different jobs. To be clear:
| For whatDoes a VPN help | |
| Reaching a restricted platform | Yes, it is the direct solution |
| Protecting traffic on public wifi | Yes, useful |
| Hiding your identity completely | No, not on its own |
| Protecting against state-level surveillance | No, other tools are needed |
Most free VPN apps build their business model on selling user data. The tool you think is protecting you may be doing exactly what you wanted protection from.
There are two healthier routes: a paid service with an established reputation, or running your own VPN. The second is easier than it sounds; with DigitalOcean and Outline it takes about half an hour and costs roughly the price of a coffee per month. I wrote a step-by-step guide.
Running it yourself has an extra benefit: you are not entrusting your traffic to a company, and you can hand out access keys to colleagues.
Layer 4: Team habits
Technical measures do not work without habits. The four rules that are hardest to apply and highest in impact:
Close a departing colleague's access the same day. In civil society, teams disperse when projects end, but account access stays open for years. Make an exit checklist: email, social media, cloud, website panel, WhatsApp groups.
Do not circulate sensitive data in chat apps. Client details, addresses and ID numbers should not land in a WhatsApp group. Use a folder with limited access and review who can reach it once a year.
Build a reflex against phishing. Civil society organisations are frequent targets of tailored phishing; fake grant calls and fake donor emails are the most common forms. The rule is simple: never log in through a link in an email. Type the address into your browser yourself.
Take backups and test restoring them. Many organisations have backups; very few have ever tried a restore. Try it once a year.
An afternoon checklist
- Turn on two-factor authentication for organisational email and save the recovery codes
- Set up a password manager for the team and move shared accounts into it
- Check all organisational addresses on haveibeenpwned.com
- Review and revoke access for everyone who left in the past year
- Review who has admin rights on your social media accounts
- Verify that your website and database backups are actually running
Where to get help
There is a free, round-the-clock support line for civil society organisations and journalists: the Access Now Digital Security Helpline. If your account has been compromised, you received a suspicious email, or you are under attack, you can write to them.
For self-study, the EFF Surveillance Self-Defense guides are among the best resources explaining this in non-technical language.
Sources
- Have I Been Pwned, email and password breach check
- Access Now Digital Security Helpline, free support for civil society and journalists
- EFF Surveillance Self-Defense, digital security guides
- Kenan Dursun, Set up your own VPN with DigitalOcean and Outline
- Kenan Dursun, Password security guide for civil society organisations and activists
If you would like a digital security workshop or checklist for your organisation, get in touch.
Join my WhatsApp community where we discuss civil society and communications.
Join the Community