Protecting civil society: inside the fight to keep vulnerable voices online
Internet security is a deeply personal matter, particularly for the vulnerable communities, political dissidents, journalists in authoritarian nations, and human rights advocates who face rising threats both online and offline. Democratizing access to powerful security tools requires more than a single vendor's effort. Collaboration and sharing of best practices among multiple stakeholders is essential to getting the right protection into the hands of those who need it most.
Civil society has historically served as the voice for sharing information about attacks targeting vulnerable communities. Now, governments are increasingly recognizing how cyber attacks affect these groups. In March 2023, the US government launched the Summit for Democracy co-hosted by Costa Rica, Zambia, the Netherlands, and South Korea. Following that event, Cloudflare was included in USAID's announcement as a potential technology partner for the Advancing Digital Democracy Academy, an initiative offering skills training in cybersecurity, cloud computing, and responsible AI.
What threats do civil society organizations face?
Civil society organizations—including non-governmental organizations, community-based organizations, and advocacy groups—face a broad range of threats that vary based on their location, focus, and activities. These threats come from governments, non-state actors, and external influences, both online and offline.
Cloudflare has provided free services since its founding on the principle that democratizing access to cybersecurity products makes the Internet safer for everyone. Project Galileo, launched in 2014, now protects more than 2,600 organizations across 111 countries. In June 2023, Cloudflare published a report showing that between July 1, 2022, and May 5, 2023, the project mitigated 20 billion attacks against those organizations—an average of nearly 67.7 million cyber attacks per day over a 10-month span.
The Q2 2023 DDoS report noted that 17.6% of all traffic to nonprofits was DDoS traffic, making nonprofits the second most targeted sector for DDoS attacks. The International Press Institute, a Cloudflare partner, also fell victim to an attack after releasing a report identifying multiple DDoS attacks against independent Hungarian media outlets.
What an attack looks like in practice
Aggregate statistics only tell part of the story about how attacks unfold in real time. During development of the Radar dashboard for Project Galileo's 9th anniversary, Cloudflare came across a notable incident involving an organization reporting on international legal issues. The event occurred between March 17 and March 18, 2023, when an international arrest warrant was issued for Russian President Vladimir Putin and Russian official Maria Lvova-Belova.

Before the incident, the organization's website experienced low levels of traffic. On March 17, request traffic escalated dramatically, rising from under 1,000 requests per second to approximately 100,000 requests per second within four hours, peaking at 19:00 UTC. Most of this traffic was managed by the Web Application Firewall. A second spike occurred on March 18, peaking at 09:45 UTC with over 667,000 requests per second—almost all identified as DDoS attacks. Throughout March 18, Cloudflare successfully thwarted 844.4 million requests categorized as application-layer DDoS attacks.
This incident shows a recurring theme in Project Galileo: organizations often remain unaware of their vulnerability until they are targeted by disruptive attacks. In this case, the organization maintained its online presence throughout the entire attack and likely only discovered the unusual traffic surge afterward.
Extending protections through partnership with CISA
Partnerships are a key way Cloudflare expands Project Galileo protections. Cloudflare now works with more than 50 civil society organizations who approve organizations for protection under the project. Among them is an initiative with CISA through the Joint Cyber Defense Collaborative (JCDC), a multistakeholder group focused on protecting vulnerable communities online.
Through JCDC, three working groups cover a range of topics: crowdsourcing resources available for at-risk communities, developing new resources for these groups, cyber volunteer programs from companies and civil society, information sharing, and threat report development. With stakeholders including civil society, tech companies, and CISA, the effort targets capacity building and transparency in extending products to these communities.
Steps organizations can take now
The JCDC working groups focused on enhancing baseline cyber hygiene for civil society organizations and improving resilience and response capabilities. Available tools and resources for these groups include:
- Cloudflare's Social Impact portal helps organizations navigate how to keep their website secure on Cloudflare.
- Zero Trust Security for vulnerable communities: a roadmap created by Cloudflare for civil society and at-risk organizations. It demystifies Zero Trust security, offering easy-to-follow steps that include case studies, effort levels, and team roles to make complex security more accessible.
- Cloudflare Radar and the Outage Center track Internet shutdowns and offer route leak and route hijack insights. Radar notifications allow organizations to subscribe to alerts about traffic anomalies, confirmed outages, and routing incidents.
- CISA's Awareness site: compiled through JCDC, this lists cybersecurity resources intended to help high-risk communities who face heightened targeting risk due to their identity or work.
Protecting vulnerable voices requires ongoing effort. By collaborating with government, civil society, and industry stakeholders, organizations can better share tools and expertise to help at-risk communities navigate complex digital environments.



