TL;DR: Stronger security is being extended to cyber defenders, including nonprofit teams, through Yubico’s Secure it Forward initiative, according to Yubico. The broader lesson is that identity and authentication programmes now influence not just enterprise control, but the security capacity of the ecosystems organisations depend on.
At a glance
What this is: This is a social impact and partnership update showing how Yubico is framing support for cyber defenders, nonprofit security, and stronger authentication practices across the sector.
Why it matters: It matters because IAM, PAM, and identity architects increasingly have to think beyond a single organisation and account for shared-security ecosystems, trust communities, and the authentication choices that help smaller defenders operate safely.
By the numbers:
- The session drew more than 70 nonprofit organisations to discuss digital resilience and stronger authentication approaches.
- Yubico donated 300 YubiKeys to support NGO-ISAC members and the wider security programme.
- 10 organisations from the NGO-ISAC community joined Secure, ned Secure it Forward this year.
👉 Read Yubico's Secure it Forward update on supporting cyber defenders
Context
Cyber defenders often act as shared-security infrastructure for entire sectors. They do not just protect one environment, they move intelligence, training, incident support, and resilience practices into communities that would otherwise have limited capacity to respond well to attacks. For identity teams, that expands the frame from internal access control to the security of the ecosystem that supports it.
This post sits in the nonprofit and community resilience space, where stronger authentication and access practices matter because these organisations are frequently targeted but rarely have enterprise-scale resources. The article uses Secure it Forward and NGO-ISAC to show how sector-wide support can change practical outcomes without changing the core identity problem: who can access what, under what assurance, and with what recovery path.
The starting point is typical for mission-driven security groups: high impact, limited resources, and disproportionate responsibility for others' protection.
Key questions
Q: How should organisations support external cyber defenders without increasing identity risk?
A: Support should flow through controlled authentication, scoped access, and clear recovery paths. External defenders, nonprofits, and community partners often need collaboration access without inheriting broad privileges. The safest approach is to define the minimum assurance required for each shared workflow and use phishing-resistant authentication wherever trust crosses organisational boundaries.
Q: Why do nonprofit and community security groups matter to IAM programmes?
A: They matter because they extend your trust ecosystem. When those groups share intelligence, support recovery, or advise on security practice, their identity controls affect the resilience of the broader sector. IAM teams should therefore treat external collaboration paths as governed trust relationships, not informal channels.
Q: What identity controls matter most for mission-driven security collaborations?
A: The most important controls are phishing-resistant authentication, tight privilege scoping, and reliable account recovery. Those three reduce the likelihood that a compromised partner account can disrupt shared operations or impersonate a trusted defender. The aim is to preserve collaboration without creating a wide-open access surface.
Q: Should security teams include external partners in their access governance model?
A: Yes. If a partner can share intelligence, assist recovery, or operate shared services, they are already part of the trust model. Access reviews, emergency access design, and authentication standards should reflect that reality so the organisation is not blind to the dependencies that support its resilience.
Technical breakdown
Why nonprofit defenders need stronger authentication than ever
Nonprofit security teams often operate with small staff, shared admin access, volunteer turnover, and remote collaboration. That combination makes password-only access brittle because the account boundary becomes the main control boundary. Passkeys and security keys reduce phishing exposure and make credential replay much harder, which is why modern authentication keeps appearing in sector resilience conversations. The technical point is not that nonprofits need a different identity model, but that their control gap is often broader than their budget allows them to close with legacy methods.
Practical implication: prioritise phishing-resistant authentication for the accounts that carry operational or sector-wide trust.
How trusted information sharing changes incident readiness
Information-sharing groups create value when threat intelligence, playbooks, and recovery guidance move quickly enough to alter defender behaviour. In practice, that means the value of an ISAC is not just the content, but the coordination layer that reduces delay between one organisation's lesson and another organisation's control change. For identity programmes, this matters because account compromise, access abuse, and recovery steps are all time-sensitive and often benefit from shared patterns rather than isolated response work.
Practical implication: treat sector intelligence feeds as operational inputs for access policy, recovery, and authentication decisions.
Why ecosystem resilience is an identity problem, not just a funding problem
Programmes like Secure it Forward show that the resilience of a community depends on the security practices available to the organisations serving that community. Identity controls are central because every helpdesk workflow, privileged admin path, and incident response collaboration depends on trustworthy authentication. If those controls are weak, the whole support chain becomes easier to phish, impersonate, or misuse. That is why ecosystem support belongs in the identity conversation, not beside it.
Practical implication: include external defenders, partners, and shared-service relationships in your identity trust model.
NHI Mgmt Group analysis
Cyber defenders are part of the identity perimeter, even when they sit outside the enterprise. The article makes a useful point that many security programmes still miss: the organisations that train, advise, and coordinate defenders can become force multipliers for resilience. That does not make them an abstraction. It makes their authentication, account recovery, and collaboration controls part of the wider trust surface.
Strong authentication is most valuable where trust is redistributed. Sector groups, nonprofit networks, and peer communities rely on shared access to information, tools, and support. In those environments, phishing-resistant authentication is not a convenience feature, it is a prerequisite for keeping shared trust from becoming shared exposure.
Support programmes reveal a governance gap between enterprise IAM and community security capacity. Many organisations can buy controls, but the wider ecosystem of smaller defenders still depends on donated capability, education, and practical access to better methods. The implication is that identity security maturity should be measured partly by how well it strengthens the organisations that protect others.
Named concept: ecosystem identity resilience. This is the idea that an organisation's security posture includes the trusted external groups that help it detect, advise, recover, and improve. For practitioners, the conclusion is that resilience planning should extend beyond internal users and into the identity trust relationships that support the sector.
From our research:
- Only 1.5 out of 10 organisations are highly confident in their ability to secure NHIs, compared to nearly 1 in 4 for securing human identities, according to The State of Non-Human Identity Security.
- The same research found that 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, which shows how quickly trust extends beyond the primary identity boundary.
- That visibility gap is a useful forward pivot into Ultimate Guide to NHIs and Key Challenges and Risks, where sprawl and over-privilege are treated as governance problems rather than isolated technical issues.
What this signals
Ecosystem identity resilience: as organisations rely more on shared defenders, the question is no longer only whether internal accounts are protected, but whether the external groups that advise and support them can be trusted operationally. Identity programmes should widen their trust model to include partner collaboration, emergency access, and shared recovery paths.
With 85% of organisations lacking full visibility into third-party vendors connected via OAuth apps, according to The State of Non-Human Identity Security, ecosystem support without identity governance becomes another blind spot. The practical response is to bring external communities into the same governance discipline used for internal privileged access.
The next maturity step for many programmes is not a new control class, but a better boundary model. If the organisations that protect others cannot authenticate safely, the broader security ecosystem inherits their weakest identity assumptions.
For practitioners
- Map your external trust ecosystem Identify nonprofit partners, ISACs, managed responders, and training collaborators that can influence your detection, response, or recovery posture. Treat their access paths, contact points, and privileged workflows as part of the identity threat model, not as informal relationships.
- Prioritise phishing-resistant authentication for shared-service roles Use passkeys or security keys for accounts that coordinate incident response, partner collaboration, or administrative access across organisational boundaries. Focus first on the roles that would create outsized blast radius if compromised.
- Build sector intelligence into access decisions Feed trusted threat intelligence and incident lessons into authentication policy, privileged access reviews, and recovery runbooks. The goal is to shorten the time between a sector warning and a concrete control change.
- Include mission-driven groups in resilience planning Where your organisation supports nonprofits or community defenders, define what secure collaboration looks like before a crisis. That includes recovery contacts, emergency access paths, and the minimum assurance level for shared accounts.
Key takeaways
- Security support for nonprofits and defenders is an identity issue because collaboration, recovery, and intelligence sharing all depend on trustworthy access.
- Sector resilience improves when phishing-resistant authentication and governed partner access replace informal trust in shared workflows.
- Identity teams should model the external organisations that protect their sector as part of the trust perimeter, not as peripheral relationships.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC-1 | The article centres on access assurance for partner and community workflows. |
| NIST SP 800-53 Rev 5 | IA-2 | Modern authentication is central to the nonprofit and defender collaboration model described here. |
| NIST Zero Trust (SP 800-207) | Trusted external collaboration fits zero trust assumptions about never trusting implicit network access. | |
| OWASP Non-Human Identity Top 10 | NHI-01 | Shared service and collaboration accounts still need governed non-human identity treatment. |
Define assurance levels for external collaboration paths and enforce them consistently across shared accounts.
Key terms
- Ecosystem Identity Resilience: The ability of a security ecosystem to stay trustworthy when organisations, partners, and community groups depend on one another for support, intelligence, or recovery. It extends identity governance beyond the perimeter and focuses on whether external relationships can be authenticated, scoped, and managed safely.
- Phishing-Resistant Authentication: Phishing-resistant authentication proves identity without relying on a user to approve a prompt or reveal a reusable secret. It typically binds access to a device, key, or cryptographic proof that an attacker cannot easily reuse or coerce. This approach reduces reliance on human judgment at login time.
- Local Trust Surface: The local trust surface is the set of browser, service, database, and credential interactions exposed during development. It matters because developers learn habits from the systems they use every day. If that surface is unsecured or inconsistent, the organisation trains people into unsafe patterns before code ever ships.
- Sector Information Sharing and Analysis Center: A collaboration body that helps organisations in the same sector exchange threat intelligence, incident lessons, and resilience practices. For identity programmes, an ISAC matters because it can accelerate control changes across many organisations at once when a shared threat pattern emerges.
What's in the full article
Yubico's full article covers the operational detail this post intentionally leaves for the source:
- How Secure it Forward is structured as a social impact initiative for cyber defenders and mission-driven organisations.
- Specific examples of how NGO-ISAC supports nonprofit cybersecurity preparedness through trusted information sharing.
- Details of the 70-plus organisation briefing and the 300 YubiKey donation tied to the partnership.
- Context on how the programme is expanding through additional NGO-ISAC community participation.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an identity security programme, it is worth exploring.
Published by the NHIMG editorial team on August 26, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org