Civil Society Activities Strengthened with Information and Data Security
Overview
Artificial intelligence has become an everyday tool for civil society organizations as well; the same technology strengthens defense on one side while making phishing cheaper and more convincing on the other. Prepared under the SECURE-CS project by expert researcher Gülşen Nişli on behalf of ANKA Gelecek ve Yenilik Derneği, this field dossier offers a calm, practical framework for organizations that have to live with both realities at once. Across five chapters it examines the spread of AI, its dual role in security, why civil society is a target, and how data protection can be read as a promise made to beneficiaries, grounding every point in verifiable data from Stanford, IBM, Verizon, Microsoft and the World Economic Forum. The dossier closes with ten concrete steps that require habits rather than budgets, and a pointer to the online self-assessment platform (civilsocietysecurity.net) where organizations can take their own digital security snapshot. It is written in plain language for NGO managers, youth workers and volunteers, with no technical background required.
Key Findings
- Artificial intelligence is no longer the exception: 78% of organizations used AI in at least one business function in 2024, up from 55% a year earlier (Stanford HAI, 2025).
- Organizations that use security AI and automation extensively lost on average $2.2 million less per breach (IBM, 2024).
- Phishing emails generated entirely by AI deceived around 60% of participants while cutting campaign costs by more than 95% (Heiding et al., 2024).
- 68% of breaches involve a non-malicious human element, and the median time to fall for a phishing email is under one minute (Verizon, 2024).
- Audio and video are no longer proof of identity on their own; requests for money or data should be verified through a second channel, whatever the amount or urgency.
- Being small does not mean being invisible: most attacks are automated scans looking for an open door, and civil society organizations rank among the most targeted sectors (Microsoft, 2024).
- While 66% of executives expect AI to have the biggest impact on cybersecurity, only 37% of organizations assess the security of AI tools before deployment (WEF, 2025).
- Digital security is a habit built by teams, not a product; the soundest data protection principle is that data you never collect cannot leak.
Access the Document
Available in English and Turkish. Open access for all youth organizations.