An Open Letter from Civil Society Leaders

We represent organisations deeply committed to the public good. Whether addressing humanitarian crises, ensuring access to clean water, combating hunger, providing healthcare in remote areas, fighting violence against women, or combating child sexual abuse and human trafficking, we all face common threats: cyberattacks and information manipulation. In 2024, through the Nonprofits’ Call for Cybersecurity, we called on governments, corporations, and philanthropies to recognise civil society as critical infrastructure and invest in its digital resilience. Because of recent advances in frontier AI models, that call now has a deadline. We have a few months to act.

AI models, such as Anthropic’s Mythos, have shown that systems can identify software vulnerabilities and accelerate cyber operations at unprecedented speed and scale. Those capabilities are not yet widely available, but they eventually will be. This creates what we call the “Mythos Window”: a brief 6-12-month period during which defenders have a temporary advantage. It is a rare opportunity to strengthen systems and deploy AI-powered defences before comparable capabilities become widely available, including to cybercriminals. Major technology companies are already investing heavily in defensive AI. Civil society must too, or our organisations will be the least protected facing the fastest-growing threats.

Whilst cybercriminals and malicious state actors accelerate their adoption of AI, the digital resilience of our organisations remains underfunded. Data governance, AI implementation and cybersecurity are treated as overhead rather than essential capacity. In the age of AI, you cannot fund human impact without funding digital resilience.

We do welcome the AI industry initiatives to build the AI capacity of nonprofits. Still, helping nonprofits to use AI is not the same as protecting them from AI-enabled attacks. Our organisations need another level of ambition, both in speed and scale. The investments made over the next 6–12 months will determine whether thousands of nonprofits are equipped to defend themselves or remain vulnerable to AI-fueled threats.

It would be a civilisational failure to protect the world’s largest companies with defensive AI while leaving the organisations protecting the world’s most vulnerable people exposed. We therefore call on governments, philanthropies, AI companies, cybersecurity providers, and technology leaders to fund digital resilience, equip civil society for the age of AI, build shared defensive capabilities, and connect civil society to broader collective defence efforts.

1. Fund digital resilience as a core component of civil society organisational development

We call on donors to integrate digital resilience into their organisational development strategies and funding models, and we commit to making it a priority within our own organisations. Digital resilience is a strategic foundation for mission delivery, just as governance or financial sustainability. It is not an operational overhead or a technical afterthought. It is a strategic leadership decision that directly affects our ability to protect the people we serve, preserve trust, and deliver impact. Donors without ready-to-use organisational development strategies can use a dedicated funding instrument such as the Common Good Cyber fund.

2. Strengthen civil society organisations for the age of AI

We call on donors, AI companies, and technology partners to help us strengthen our workforce, processes, governance, and operational resilience. We stand ready to lead this transformation. Adopting technology alone is not enough. With the right support, we will invest in cyber talent, modern resilience training, continuous testing and exercises, responsible and secure AI adoption, and stronger governance practices that help identify emerging risks such as unmanaged “Shadow AI”, insecure AI use, and the exposure of sensitive information.

3. Build shared cyber capabilities for civil society

We call on donors to invest in shared defensive capabilities that enable our organisations to identify vulnerabilities, exchange threat intelligence, detect attacks earlier, and respond more effectively. This includes strengthening and expanding Information Sharing and Analysis Centres (ISACs), trusted communities through which civil society organisations share threat intelligence, warnings, expertise, and incident response support. It also includes deploying AI-enabled capabilities that improve vulnerability management, accelerate incident response, and provide access to expertise and services that no single organisation can build or afford alone.

4. Connect civil society to collective digital defence

We call on public, private, and philanthropic partners to connect the civil society sector to collective defence ecosystems, including threat-intelligence-sharing communities, joint crisis exercises, and coordinated incident-response efforts. As AI accelerates cyber threats, the value of collective defence is growing just as quickly. Governments, technology companies, cybersecurity providers, and critical infrastructure operators are increasingly sharing intelligence, coordinating responses, and building common defences. Civil society must not be left behind. When one organisation identifies a threat, hundreds of others should benefit from that knowledge. In the age of AI, resilience will increasingly depend not on how fast any one organisation can respond, but on how fast entire communities can learn and act together.

These calls aim to trigger urgent action and achieve long-term impact. We do not start from scratch. Civil society invested in its digital resilience for years. We need to strengthen, connect, and scale what already works before the Mythos Window closes.

The cost of inaction will be measured not only in compromised systems, but in disrupted humanitarian operations, weakened democratic institutions, threatened human rights defenders, and vulnerable communities left unprotected.

Together, we can ensure that the organisations protecting the world’s most vulnerable people are not left defenceless in the age of AI.

Our message is simple, you cannot fund human impact without funding digital resilience. If civil society organisations are expected to respond to the world's biggest challenges, they must have the tools to operate safely in the digital environment. As AI makes cyberattacks faster and more sophisticated, investing in digital resilience is no longer optional, it is essential to protecting the people these organisations serve.

Stéphane Duguin, CEO, Protect.ngo

As AI escalates and intensifies cyber threats, digital resilience for civil society organisations is an imperative. We need collective action and support from funders, governments and technology companies to ensure civil society organisations can operate safely, tackle global challenges and strengthen an open civil society.

Rachel Wilkinson, Co Interim ED, International Civil Society Centre

Signatories

Michel Awad, Internal Audit Manager, Canada Post

Laura Baker, Executive Director, CyberWyoming

Carlotta Besozzi, Director, Civil Society Europe

Sarah Bly, Founder and CEO, Pathwarden

Anastasia Carayanides, Executive Director, Global Affairs, Plan International

Gabriella Civico, Director, Centre for European Volunteering (CEV)

Aaron Cohen, CTO, Poster House

Matthew Cua, Innovation Director, Help.NGO

Alistair Davison, Board Member, Cordoba Peace Institute

Stéphane Duguin, CEO, Protect.ngo Foundation

Sandra Ferrer Aranda, Director, La Coordinadora de Organizaciones Desarrollo–España

Suman Garai, Tech Risk Associate, EY GDS India

Daniel García, Managing Director, ISMS Forum

Philip Grant, Executive Director, TRIAL International

Micah Grzywnowicz, Regional Director, IPPF European Network

Casey Harden, CEO/General Secretary, World YWCA

Caroline Harper, CEO, Sightsavers

Claire Hatfield, Director, Creative Sustainability CIC

Patrizia Heidegger, Dpt Secretary General, European Environmental Bureau

Mathieu HERVIN, Digital, Innovation and ICT Director, Terre des hommes

Catherine Holland, Chief Operating Officer, GripTape Org, Inc.

Liana Hoornweg, Director, Partos

Génon Jensen, Executive Director, Health and Environment Alliance

Erik Jonkers, Chair, Trifecta Tech Foundation

Sheila Kelly, Director of Operations, Education For All Children

Kathrin Kirste, Interim Co-Executive Director, International Civil Society Centre

Jean-Christophe Le Toquin, President, CyAN

Rita Leote, Executive Director, Portuguese Platform of Development NGOs

Mikael Leyi, Secretary General, SOLIDAR

Raphael Maldague, Director, ACODEV

Kim McDonald, CEO, 3 Steps Data

Horia Mosadiq, Director, Safety and Risk Mitigation Organisation

Peter Osazuwa, CEO, HyperSeureIT Sàrl

Simon Papuashvili, Co-Chair of the Board, Civil Society Forum e. V.

Jeff Ravage, Chief Science and Technology Officer, Coalitions and Collaboratives

Oleksii S, tech lead, Ukraine War Archive

Piotr Sadowski, Secretary General, Volonteurope

Mayank Saxena, Manager, Mannai Infotech

Kamal SEDRA, Managing Director, eduCYBER

Charbel-Raphael Segerie, Executive Director, CeSIA – Centre pour la Sécurité de l’IA

Camille Stewart Gloster, Co-Founder & Board Chair, Foundation Layer Institute

Greg Wenner, Executive Director, Good Heart Tech

Jill Wilkinson, Managing Director, Stichting The Hague Humanity Hub

Rachel Wilkinson, Interim Co-Executive Director, International Civil Society Centre

Brikena Xhomaqi, Director, Lifelong Learning Platform – European Civil Society for Education

 

The open letter and list of signatories are also available at: https://protect.ngo/racing-the-cyber-clock

 

Press and Additional Queries 

For more information about the initiative, or to sign the letter, please contact [email protected].

In collaboration with