TL;DR: Stronger security is being extended to cyber defenders, including nonprofit teams, through Yubico’s Secure it Forward initiative, according to Yubico. The broader lesson is that identity and authentication programmes now influence not just enterprise control, but the security capacity of the ecosystems organisations depend on.
NHIMG editorial — based on content published by Yubico: Secure it Forward and support for cyber defenders
By the numbers:
- The session drew more than 70 nonprofit organisations to discuss digital resilience and stronger authentication approaches.
- Yubico donated 300 YubiKeys to support NGO-ISAC members and the wider security programme.
- 10 organisations from the NGO-ISAC community joined Secure, ned Secure it Forward this year.
Questions worth separating out
Q: How should organisations support external cyber defenders without increasing identity risk?
A: Support should flow through controlled authentication, scoped access, and clear recovery paths.
Q: Why do nonprofit and community security groups matter to IAM programmes?
A: They matter because they extend your trust ecosystem.
Q: What identity controls matter most for mission-driven security collaborations?
A: The most important controls are phishing-resistant authentication, tight privilege scoping, and reliable account recovery.
Practitioner guidance
- Map your external trust ecosystem Identify nonprofit partners, ISACs, managed responders, and training collaborators that can influence your detection, response, or recovery posture.
- Prioritise phishing-resistant authentication for shared-service roles Use passkeys or security keys for accounts that coordinate incident response, partner collaboration, or administrative access across organisational boundaries.
- Build sector intelligence into access decisions Feed trusted threat intelligence and incident lessons into authentication policy, privileged access reviews, and recovery runbooks.
What's in the full article
Yubico's full article covers the operational detail this post intentionally leaves for the source:
- How Secure it Forward is structured as a social impact initiative for cyber defenders and mission-driven organisations.
- Specific examples of how NGO-ISAC supports nonprofit cybersecurity preparedness through trusted information sharing.
- Details of the 70-plus organisation briefing and the 300 YubiKey donation tied to the partnership.
- Context on how the programme is expanding through additional NGO-ISAC community participation.
👉 Read Yubico's Secure it Forward update on supporting cyber defenders →
Cyber defenders and nonprofit resilience: what IAM teams should notice?
Explore further
Cyber defenders are part of the identity perimeter, even when they sit outside the enterprise. The article makes a useful point that many security programmes still miss: the organisations that train, advise, and coordinate defenders can become force multipliers for resilience. That does not make them an abstraction. It makes their authentication, account recovery, and collaboration controls part of the wider trust surface.
A few things that frame the scale:
- Only 1.5 out of 10 organisations are highly confident in their ability to secure NHIs, compared to nearly 1 in 4 for securing human identities, according to The State of Non-Human Identity Security.
- The same research found that 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, which shows how quickly trust extends beyond the primary identity boundary.
A question worth separating out:
Q: Should security teams include external partners in their access governance model?
A: Yes. If a partner can share intelligence, assist recovery, or operate shared services, they are already part of the trust model. Access reviews, emergency access design, and authentication standards should reflect that reality so the organisation is not blind to the dependencies that support its resilience.
👉 Read our full editorial: Supporting cyber defenders is now part of security strategy