Security Resilience Starts Before an Incident

Sep 18, 2026

On May 21, grantmaking and social impact leaders gathered in New York City for the Resilience in Action Security Summit, a one-day, action-oriented convening co-produced by TAG, the Ford Foundation, and NGO-ISAC and hosted by ServiceNow

Two themes stood out for grantmakers: security is an organizational risk, and resilience depends on cross-functional coordination before a crisis begins. 

Digital Risk is Organizational Risk 

Lisa Kaplan, Founder and CEO of Alethea, opened the Summit by introducing three emerging threat vectors: AI-generated “slopaganda,” rogue citizen journalists, and coordinated and targeted campaigns against individual staff and leadership. These emerging threats open social impact organizations to unprecedented risks that require immediate, organization-wide action to address effectively and timely. 

To help illustrate the impacts of AI “slopaganda,” Kaplan outlined how its mechanics contribute to a category of risk that conventional monitoring tools are not designed to detect. When correctly executed, unchecked AI “slopaganda” can go viral overnight, resulting in a media frenzy that many civil society and philanthropic institutions were never prepared to handle. Once the message is out in the world, these organizations will have to invest in methods to counter the misinformation while also mitigating the reputational harm that could affect partner and collaborator relationships.

That theme continued in a panel moderated by Sarah Powazek, Program Director for Public Interest Cybersecurity at the Center for Long-Term Cybersecurity. Panelists Cathy Rought-Jacobson of Integritas Public AffairsMichael Razeeq of New America’s State Civilian Cyber Corps Initiative, and Tara Arthur, Founder and CEO of Collective Security Group, explored how online threats can translate into real-world risks for institutions, staff, partners, and communities. 

Two black women in professional dress talking over a table during a workshop.

According to Kaplan, the social sector needs to be prepared for the rise of citizen journalists operating outside editorial oversight and with a consistent harassment playbook. Some of these tactics include ambushing targets and exposing personal staff information. With these threats growing each passing day, decision-makers at grantmaking organizations and their nonprofit partners must develop the skills and resources to ensure their staff can respond to online attacks.

While Kaplan’s message was clear from her opening statement, it was her last threat example that helped make the connection between the convening and philanthropy’s risk future. Coordinated attacks on individual staff members and institutional leadership represent some of the most concerning disinformation and misinformation risks facing the social sector. Organizations can build the resilience to withstand these campaigns, but it requires a combination of preparation and an increased awareness of threat patterns before they escalate.  

For technical and operational leaders, the takeaway is straightforward: incident response planning needs to include governance, communications, legal, finance, programs, and executive leadership. Escalation paths should be known before they are needed. As Kaplan put it, organizations need to know, “Who are you calling and when are you going to call them?” 

Resilience in Action Panelists

That theme continued in a panel moderated by Sarah Powazek, Program Director for Public Interest Cybersecurity at the Center for Long-Term Cybersecurity. Panelists Cathy Rought-Jacobson of Integritas Public AffairsMichael Razeeq of New America’s State Civilian Cyber Corps Initiative, and Tara Arthur, Founder and CEO of Collective Security Group, explored how online threats can translate into real-world risks for institutions, staff, partners, and communities. 

The discussion reinforced that disinformation should not be treated as a temporary communications nuisance. For grantmakers and the nonprofit communities they serve, it can become a strategic threat that undermines the work and people their funding is intended to support. 

Resilience is a Team Sport 

In a hands-on workshop led by RipRap Security and featuring the day’s speakers, participants worked through real-world scenarios and surfaced the dependencies that organizations often discover only under pressure. 

The exercise made one thing clear: no single person, department, or tool can carry organizational resilience alone. Effective security requires shared ownership across functions and across institutions. 

That means IT and communications need a joint incident response workflow. Program staff need to recognize social engineering risks. HR needs to reinforce security expectations during onboarding and role changes. Finance and operations need continuity plans for payments, approvals, and access. Executive leaders need a decision-making structure for moments when reputational, operational, and safety concerns intersect. 

Group of professionals working at various round tables with papers and pens.

It also means philanthropy needs trusted relationships beyond the walls of any one organization. Because the sector is interconnected, a security failure in one place can ripple outward through networks of funders, nonprofits, vendors, and partners. Tara Arthur summarized one practical mitigation strategy simply: “Make friends. It’s the low-cost mitigation to cyber threats.” 

What Grantmakers Can Do Now 

■ Map incident roles across IT, communications, legal, HR, finance, programs, and executive leadership 

■ Clarify escalation paths for cyber incidents, disinformation events, physical security concerns, and reputational attacks 

■ Test crisis communications and decision-making with realistic tabletop exercises 

■ Train staff to recognize social engineering and reporting pathways 

■ Build peer relationships before an incident, including trusted contacts at partner organizations, vendors, and sector groups 

■ Bring security into strategy, governance, and budgeting conversations early, not only after an event occurs 

Moving Forward 

The Summit renewed a sense of urgency to build resilient organizations. The risks are real, but philanthropy has the relationships, expertise, and collective capacity to address them if we invest in readiness before a crisis. 

TAG will continue to develop resources, facilitate peer learning, and convene the sector around the security challenges that affect our ability to pursue mission. We are grateful to our partners at the Ford Foundation and NGO-ISAC, to the Summit speakers, to RipRap Security for leading the workshop, and to ServiceNow for hosting the convening. 

About the Technology Association of Grantmakers

TAG is a 501(c)(3) non-profit membership organization that promotes the strategic, innovative, and equitable use of technology in philanthropy to solve problems and improve lives. With over 2000 members in 300 foundations throughout North America and beyond, TAG is the voice of technology in the philanthropic sector, providing technology professionals, tech funders, and “accidental techies” with knowledge, networks, mentoring, and educational opportunities.

Since 2008, the Technology Association of Grantmakers (TAG) has built a global community, conducted groundbreaking research, and become an advocate for investment in tech infrastructure throughout the charitable sector. For more information, visit tagtech.org.