One day a month

One day a month

Berigo sets aside one full working day each month for organisations that need security advice but lack the means to pay for it. Applications are open throughout the year.

What this is

Berigo sets aside one full working day each month, twelve days a year, for advisory work at no charge. It is done in the same way as any paid engagement. Nothing is expected in return: no publicity, no reciprocal favour, no later paid work.

Obligations under the GDPR apply regardless of budget, and the threat landscape takes no account of whether an organisation can afford to meet it. Security should not depend on being able to pay for the expertise.

Who it is for

The scheme is aimed at organisations where the consequences of a breach fall mainly on people other than the organisation itself. Humanitarian organisations, nature and climate organisations, and those working on human rights, vulnerable groups, press freedom or democracy often hold information about people who could come to real harm were it exposed: sources, whistleblowers, displaced people, local partners. Many are also of interest to well-resourced adversaries precisely because of the work they do, and few have access to security expertise at board or senior management level.

Who may apply

  • A non-profit organisation, foundation or association. Please give a registration number where one exists.
  • Based in Norway or elsewhere in Europe.
  • Work in humanitarian assistance, human rights, nature and climate, vulnerable groups, press freedom or democracy.
  • Buying comparable advice at market rates is beyond the organisation's means. We do not ask for accounts, and take your own assessment as given.

The scheme is not intended for political parties or commercial businesses, nor for organisations that already have a security function of their own. The criteria are applied with judgement. If you are unsure whether they cover you, it is better to ask.

What one day can cover

A single day is limited, and it is better to be plain about what it can offer. It might be used for:

  • a review of the risk picture: what information you hold, and who might want it
  • a prioritised list of measures, the most important first and costed realistically
  • a start on GDPR compliance: records of processing, roles and responsibilities, processor agreements
  • a briefing for the board on accountability, risk and the questions it ought to be asking
  • a working session with staff on practical security in day-to-day work

A day gives a basis for decisions and a sense of direction, not a complete picture, and it is no guarantee that everything of consequence will be found. It carries no ongoing operational responsibility, and it is neither an audit, a certification, nor an incident response arrangement. What we go through is summarised in writing, so that you can take it further yourselves.

How to apply

Please get in touch through the contact page. We need to know who you are, what you work on, what kinds of information you handle and roughly how large the organisation is. Say briefly what you regard as the most pressing question, and whether a deadline makes the timing matter. A single page is enough. Enquiries are treated in confidence, and we do not name the organisations we help.

How we prioritise

When more organisations apply than we have days for, we consider how serious the consequences would be for the people whose information is held, how limited other routes to this expertise are, and what one day can realistically achieve. Where an organisation has been allocated a day before, other applicants come first. Everyone receives a reply, including when we have no capacity.

Apply for a day

Days are allocated through the year. Tell us briefly who you are and what you need help with, and we will say whether we have capacity.

Send an enquiry