As civil society faces AI-powered cyberthreats, NGOs are asking donors to help the sector prepare. Geneva-based cyber expert Stéphane Duguin warns that that window is rapidly closing.
From ransomware to leak campaigns, a barrage of automated attacks is targeting non-profits ill-equipped to fight back. That threat is set to escalate further with the arrival of advanced AI frontier models from companies like Anthropic, already being tested in the wild. In an open letter from this month, over 50 NGO representatives, including from Trial International and Terre des Hommes, urged governments and donors to help the sector build resilience against this wave.
Stéphane Duguin, chief executive of Protect.ngo, is also among the signatories. The organisation he leads from Geneva monitors these threats and helps NGOs defend themselves. Since November 2018, Protect.ngo’s cyberthreats tracker has documented 1,050 publicly recorded attacks, including ransomware, identity theft, hack-and-leak operations and DDoS, affecting over 900 organisations globally.
Geneva is no exception. In an interview with Geneva Solutions, Duguin lays out what the sector, already reeling from funding cuts, is up against.
Geneva Solutions: How is AI worsening the cyber risks that NGOs have to deal with?
Stéphane Duguin: AI is accelerating the threat landscape. It gives almost anyone on the globe the capacity to increase the speed, the scale and the reach of attacks – good old cyber attacks like ransomware, spyware, phishing, but also fraud and information manipulation. We see a lot of non-profits that are now victim of impersonation attacks to hurt their reputation.
What puts civil society especially at risk?
The civil society ecosystem is quite unique in the sense that it’s targeted both for the good old financial intent and geopolitical reasons. NGOs are vulnerable to wide-ranging campaign attacks, where an attacker tries to get whoever, wherever to click on the wrong link, because of their lack of digital resilience. They are living under the cyber poverty line. NGOs are also specifically targeted because of the fact that they have to be public about the money they get. You paint a target on your back for any cybercriminal by explaining publicly everything that you’re going to do, with who and in what timeline of delivery.
Read also: Conflicts and humanitarian crises heighten cyber threats for international Geneva’s NGOs
Then there is geopolitics. Because of where they work and what they work on – and it can range from curbing climate change to protecting refugees in Ukraine to investigating infringement of human rights in Gaza – civil society organisations have very resourced enemies, criminal groups working for states or states themselves.
The letter warns of a 6-12 month Mythos window before these more sophisticated models become available to the public, referring to Anthropic’s frontier AI model.
The window was to say it would close the day Mythos ends up in the hands of anyone at a very cheap cost. If anyone has this capacity at cheap cost and at scale to detect weaknesses in your systems and create weapons to enter them, and if, in that time frame, donors do not allocate enough funds and capacity for non-profits to be secured, then it’s game over. And what’s forgotten is that this capacity will not be solely in the hands of centralised companies – which would be bad enough, but you can imagine at least a way to regulate and hold people accountable. I’m a fierce defender of open source – knowledge should be empowering human beings, especially on the tooling level – but if that capacity to find vulnerabilities in any system is open source, then it starts to be extremely problematic to defend the community.
We hear often about advanced US-based AI models, but do you worry about what may be developed elsewhere, such as China or Russia?
We know about the US models because companies sometimes disclose what they do to create hype about their alleged technical capabilities, or when something problematic happens, like the Hugging Face incident. But when it comes to other parts of the world, we’re not exactly sure about the capacity of the models being developed. What we know is that it’s a race – I would argue a race to the bottom.
How prepared are NGOs in Geneva to face such cybersecurity risks, let alone in their magnified versions?
To be prepared, you need talent, time and funds. Funding for civil society in international Geneva has been destroyed at unprecedented levels, so it’s not the best time to discover that you need to invest heavily in cybersecurity. Even if the funding levels of three to four years ago were still there, the mechanics of funding for civil society are flawed. When donors give money for projects, they give a little bit for overhead – it can be from seven to 20 per cent, and there you can include governance, accounting, fundraising and IT. With that, you cannot put in place a strategy of digital resilience. We don’t ask donors who want to save the children to suddenly only think about cyber. That’s not the point. We’re just asking them: think of securing your grants. Otherwise, your money will go to criminals.
But even when you have the funds, there’s not enough talent on the planet to fill all the AI and cybersecurity positions needed for the non-profit sector. That’s why we created the Cyber Builders programme. We have now 1,800-plus volunteers – experts in cyber, in AI or in data protection giving their time for free to non-profits globally, and we have more than 700 non-profits that are data protected. International Geneva is no different from others in these gaps. What you have in Geneva is a consciousness. We’ve had interesting discussions with Swiss foundations and the University of Geneva, including some local entities that are very much into organisational development.
There’s a push in Europe and elsewhere to move away from US tools amid mistrust of the influence of US legislation like the AI Cloud Act. How should NGOs approach this issue?
Defending yourself means having the possibility to strategise which supplier you want to use or not to use. We service more than 700 NGOs, and for each one of them, this decision is theirs to make. The country where they operate, the type of data that they process, the sensitivity of that data and how much they want to be subject to a cloud act request. Or the other way around – perhaps they want to have everything based in the US because of the subsidy opportunities it can open. I don’t judge any choice, but it has to be an informed one.
