Cloudflare: civil society organisations are attacked more often than others

Cloudflare has published a report on attacks against civil society in 2025, drawing on data from Project Galileo. It shows that civil society organisations were targeted more frequently, and often more intensely, than other Internet users. Four attack types are highlighted: denial-of-service attacks, exploitation of website vulnerabilities, phishing and Internet shutdowns. Project Galileo provides free cybersecurity protection to organisations working in human rights, journalism, environmental protection, humanitarian aid and democracy building.

What this means for your organisation

Norwegian non-profits, newsrooms and aid organisations fall into the same category, but usually have no security function and a budget that will not stretch to new tooling. At the same time they handle sensitive information about sources, staff and beneficiaries. The attack types in the report hit availability and publishing above all, which for these organisations is the work itself.

Berigo recommends

  • Put the website behind a service that absorbs denial-of-service attacks, using free or subsidised offerings where they exist.
  • Keep the publishing platform updated and remove plugins that are not in active use.
  • Introduce two-factor authentication for everyone with editorial or administrative access.
  • Keep a simple written plan for what happens if the site goes down or source data may be exposed.

Source

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch