Civil society groups get a shared window into targeted cyber threats
Civil society organizations are frequent targets of cyber attacks, often because of their advocacy work and their typically limited security resources. Cloudflare says that organizations protected under Project Galileo experience an average of 95 million attacks per day in aggregate. Many of these incidents go unnoticed until after significant damage is done.
To help address this, Cloudflare has been working with the CyberPeace Institute, an independent Swiss non-profit that focuses on making cyberspace safer. Their collaboration has produced the CyberPeace Tracer, a public resource designed to give researchers, governments, and civil society organizations data-driven visibility into the threats facing NGOs, non-profits, and charities.
How the partnership works
The CyberPeace Institute joined Project Galileo in 2022. Through that program, Cloudflare has protected the Institute's website and provided Zero Trust tools to secure access to internal applications for its global workforce. The Institute also became an official Project Galileo partner, joining more than 53 other civil society organizations that help identify groups in need of protection.
During this collaboration, the CyberPeace Institute tested Cloudflare Email Security, which is designed to block phishing and ransomware. The Institute found the product's proactive detection and simple deployment useful, but saw a bigger opportunity: extending those protections to smaller NGOs that lack dedicated technical staff or budget.
Under the resulting arrangement, the CyberPeace Institute acts as a central hub, onboarding its network of NGOs with Cloudflare Email Security. This gives the Institute access to real-time data on email threats across the organizations it serves. The aggregated information powers a live dashboard, giving other organizations visibility into phishing campaigns that might affect them. This centralized model addresses a key problem in tracking targeted phishing: many incidents are never reported or are discovered only after a compromise has already occurred. Insights from one NGO can therefore help protect others before an attack spreads.
What the CyberPeace Tracer shows
The CyberPeace Tracer collects and analyzes data on cyber attacks and disinformation campaigns targeting NGOs, non-profits, and charities working on global societal challenges, from health and development to human rights and women's rights. The goal is to inform the public about the scale and impact of these threats so organizations can recognize emerging risks and strengthen their defenses.
Data for the Tracer comes directly from partners who monitor a predefined set of NGO domains. The dashboards cover several areas:
- Publicly disclosed software and hardware vulnerabilities that could be exploited against monitored NGOs
- Detected malware infections
- Analysis of phishing attacks, showing trends and attacker tactics
On the phishing dashboard, users can filter by country, see the top phishing subject lines received by NGOs, and review the top five threats blocked by Cloudflare Email Security. The collaboration also allows the CyberPeace Institute to analyze flagged emails, helping identify and disrupt malicious domains and ongoing campaigns. By studying past incidents, organizations can adopt best practices from others' experiences to reduce the likelihood of future attacks, a valuable capability in a sector where incidents often go unreported.
Getting involved
NGOs interested in Cloudflare Email Security through the CyberPeace Institute can visit cyberpeaceinstitute.org/cloudflare-area-1/. Organizations seeking protection under Project Galileo can apply at cloudflare.com/galileo/.



