Home > Insights and updates > Reflections on a changing digital risk landscape in the US

Reflections on a changing digital risk landscape in the US

Lena Weber, associate director for digital risk and resilience US programming at Open Briefing, reflects on some of the trends our digital risk and resilience team is seeing in the US – and what they mean for civil society organisations navigating a rapidly changing environment.

Digital spaces – from how we communicate with one another to the tools and technologies we use to collect, store, and share information – are often also essential to how organisations, collectives and movements find community, joy, organise for change, and navigate finding and offering urgent services and support. 

But as the legal and political landscape for civil society in the United States is shifting quickly, so too is the digital risk landscape.

Phishing, account compromise, data breaches and information being lost or mishandled are not new problems. Many communities have also already faced long-standing targeted surveillance and repression. What is changing – sometimes incredibly quickly – is the technology and environment around these risks, and what the consequences might be when something goes wrong.

For me, that is one of the most important things to understand about this moment.

At the same time, AI is rapidly changing what is possible, organisations are thinking differently about how governments, companies and non-state actors might access or use digital information, and people are questioning technologies and platforms they may have relied on for years.

That is a lot to navigate – particularly for activists and organisations already working under pressure.

When the context changes, information can change too

We can see this particularly clearly in the changing environment around immigration.

If the legal status or protections afforded to a particular community change, information held by an organisation supporting that community can suddenly become much more sensitive. Details about the people an organisation works alongside, for example, could take on very different significance if exposure might contribute to someone being identified, detained or deported.

Similar questions are arising for organisations working with LGBTQIA+ communities, reproductive rights and justice groups, environmental activists, Palestinian solidarity movements and others navigating changing levels of scrutiny or legal risk.

And risk does not always build gradually. One thing we’re seeing is how sudden visibility can create a sudden spike in digital risk.

An organisation or activist can move very quickly from operating relatively quietly to receiving significant public or political attention. That can bring increased online monitoring, doxxing and harassment, attempts to access information, and other forms of scrutiny with it.

What begins as a digital risk can therefore quickly have wider consequences, affecting people’s physical safety, legal exposure and wellbeing.

So digital resilience isn’t simply about asking, ‘Is this information secure?’ We also have to think about what that information could mean in a particular context, and what could happen to the people represented in it if that context changes.

The chilling effect of uncertainty

There is a broader chilling effect to all of this, too.

We’re hearing concerns about surveillance and online monitoring, doxxing and harassment, infiltration of physical and virtual spaces, and scrutiny connected to organisations’ activities, networks, funding or information.

Changes in federal priorities are part of that context. National Security Presidential Memorandum 7, as just one example, has raised questions about the potential scrutiny of organisations, networks and funding sources in connection with investigations into political violence and domestic terrorism. 

But for me, the impact of this environment isn’t only about whether an organisation ultimately faces legal action. Uncertainty itself has an effect.

Organisations are asking: What can we use? What should we not be using? What information should we be holding? How can we most safely communicate with one another? Could continuing to use this platform put somebody at risk?

Those are difficult questions when digital tools are also fundamental to how people build movements and simply come together. As certain forms of health care, community support, and expression are increasingly surveilled and criminalised, digital tools can become even more important to find community, resilience and joy. We don’t want fear around digital risk to make those things impossible.

Moving beyond lists of digital security tips

Lists of digital security tips and tricks may be helpful, but it can be hard to know which pieces are actually relevant, feasible and useful to your specific context. There is no one-size-fits-all digital security magic wand. Maybe a tip list says “don’t use this platform”, but that platform has been key to how an organisation creates impactful change alongside coalition partners, so it doesn’t feel like a quick or easy decision to make.

Every organisation is different. The information it holds and the people it works alongside are different, as are its infrastructure, capacity, relationships and risk environment.

For me, that’s where prioritisation becomes really important. When everything feels like it could be a threat, it can be difficult to know where to begin.

What is actually posing a threat right now? What might be a lesser concern? What are we worried about because it could become more significant later? And, realistically, what can we do about it?

The basics still matter. A convincing phishing email or compromised account may be a much more immediate threat than some of the larger political or legal scenarios an organisation is worried about.Analysing the specific details of an organisation’s situation can help identify where the priorities lie.

But those things aren’t necessarily separate, anyway. If someone falls for a phishing attempt and an account is compromised, the consequences depend on what information is there, who might gain access to it, and what that information could mean for the people involved.

Digital resilience isn’t just about technology

I also think we need to get away from the idea that digital security is primarily a technical problem.

You can have all the technical protections and tools in the world, but they will only get you so far if people within your team don’t feel comfortable using them, or if the policies and culture around them don’t work in practice.

Creating a no-blame culture around digital incidents is a good example. Someone might think they’ve fallen for a phishing attempt but feel embarrassed or worried about reporting it. Or people might be using AI tools when their organisation hasn’t yet developed an AI policy – or simply because it isn’t clear which tools they can use, or how to use them safely within their work. They use them anyway, but don’t talk about it: what is sometimes called ‘shadow AI’.

That’s why creating a culture where people feel safe talking about these things matters so much. If people are worried about being blamed or shamed, it becomes much harder to understand what the actual risks are or what people need to be able to do their work safely and effectively.

And without that understanding, it’s difficult to develop policies and processes that work in practice, prevent incidents where possible, and make sure people know what to do when something does go wrong.

Digital resilience isn’t only about having the right technology in place. It also has a wellbeing dimension. It’s about creating an environment where people can say, ‘I’m not sure about this’, ‘I’ve been using this tool’, or ‘I think something has gone wrong. Can we look at it together?’ This kind of supportive, no-blame culture can help people raise their concerns earlier and navigate incidents together, rather than carrying that pressure alone.

We are stronger when we navigate this together 

One thing I find encouraging is how much knowledge already exists within communities and movements.

When things change quickly, we tend to turn to the people we trust. We’re seeing organisations talking to coalition partners, funders, members and communities and asking each other: ‘What have you heard? What are you seeing? How are you approaching this?’

I think there is real strength in that.

There is also a lot of existing knowledge and experience to draw on. Communities in the US have been navigating these kinds of threats for a long time – from Indigenous organising, to labour movements, to Muslim communities in the years following 9/11, to Black communities that have long experienced surveillance and targeting.

There are already tools, resources and strategies that have grown out of those experiences, and a lot that can be learned from one another. The same is true internationally. Through Open Briefing’s work in different parts of the world, we see similar patterns of repression and threats – both long-standing and emergent – playing out in different ways, at different scales, and in very different contexts.

That doesn’t mean the contexts or human impacts are the same. But it does mean there are opportunities to learn from how people and movements have navigated similar challenges – both within the US and internationally.

None of us needs to approach this as though we’re starting from zero.

Making space to work through the uncertainty

Of course, recognising that something needs attention and having the time, resources or specialist expertise to address it are very different things.

Many of the organisations we’re speaking to are already stretched. They may not have dedicated IT or digital security capacity, while decisions about something seemingly technical – changing a platform, moving where information is stored, or introducing a new policy – can affect an entire team, coalition or community.

Sometimes having someone outside the organisation to work through the options and priorities with can help make the situation feel much more manageable.

For us, that starts with recognising that the people and organisations we work with are the experts in their own context. Our role isn’t to arrive with a prescribed set of answers. It’s to be a thought partner: bringing specialist expertise, asking questions, working through the risks together and helping identify what makes sense for that particular organisation, its people and its context.

That might mean developing a roadmap and taking things bit by bit. It might mean preparing for a particular scenario or strengthening a policy or process. Sometimes it is simply about having the space and support to understand the choices available and decide what to prioritise.

Accessing support

I also think it’s important to acknowledge that not every organisation has the resources to bring in specialist support, even when it could make a significant difference.

The digital risks explored here also don’t exist in isolation. Online harassment, doxxing, surveillance or other digital threats can affect people’s sense of safety and wellbeing, while sustained uncertainty and pressure can contribute to stress, exhaustion and burnout. These impacts can also ripple through teams and movements. This is why we take a holistic approach to security, recognising that digital resilience, physical safety, and wellbeing and collective care are interconnected.

This has also been reflected in our wellbeing work with US defenders and organisations. Earlier this year, our wellbeing and resilience team ran a four-part ‘Hope for Resistance’ webinar series for US activists, journalists, organisers and civil society groups focused on sustaining movements under pressure. The sessions created space to explore some of the pressures people are carrying – including grief, stress and over-responsibility – alongside practices for grounding, collective care, connection and sustaining hope over time.

In practice, Open Briefing works with activists and organisations across digital resilience, physical safety, and wellbeing and collective care, with support shaped around their particular risks, needs and context. This can include digital risk analysis and prioritisation, secure communications guidance, policies and protocols, incident and crisis preparedness and response, and training and scenario exercises, alongside physical protection support and tailored wellbeing and collective care.

Open Briefing provides fully-funded assistance to activists and organisations facing threats related to their work. You can request support through our responsive assistance mechanism. 

Ultimately, digital resilience isn’t about achieving perfect security. It’s about being able to understand the risks that matter in your context, make informed choices and continue doing the work that matters to you.

The landscape may be changing quickly, but we don’t have to understand everything at once. There is always somewhere to start – and we don’t have to navigate it alone.