An operations director at a Paris-based humanitarian NGO receives an alert at 6am. The server at the Central African Republic field office is unreachable. The field team has lost access to the medical data they need for the day’s vaccination programme.
The volunteer IT manager, contacted urgently, cannot work out the fault from a distance. The satellite connection is unreliable. Meanwhile, institutional donors are waiting for activity reports.
This kind of situation is not exceptional for NGOs operating across multiple countries. It is structural, and the responses need to be too.
What makes multi-country IT so difficult
Humanitarian organisations do not have the luxury of multinationals deploying standardised infrastructure in well-connected offices. Field offices are often in areas where connectivity depends on an unstable satellite link or a mobile connection. Teams change regularly (international volunteers, local staff, rotating expatriates), creating a constant turnover of users and access rights.
Synchronising data between headquarters and field offices raises real technical challenges. Databases must stay consistent despite frequent disconnections. Version conflicts must resolve automatically. And all of this must happen while keeping data secure, including over public networks.
When a field office goes down, the whole mission can stall. That is why NGO business continuity is something you prepare in advance, not on the day of the outage.
The right architecture for humanitarian constraints
Tools designed for stable, high-speed connections perform poorly when bandwidth falls below 1 Mbps and interruptions are unpredictable. The solutions need to be designed with this in mind.
Hybrid local/cloud. Each field office has local infrastructure capable of operating independently for extended periods, synchronising with central systems as soon as connectivity allows. This is the base architecture, not a fallback arrangement.
Centralised monitoring. A single dashboard shows the status of every site from headquarters: equipment availability, connection status, active alerts. This enables teams to anticipate failures rather than react to them.
Remote access optimised for low bandwidth. Technical interventions from a distance must work even on degraded connections. Standard remote desktop tools are not built for this.
Identity and access management
Team rotation creates a persistent risk: access credentials that are not revoked when someone leaves, accounts shared between multiple people, passwords written on paper. These practices are rarely malicious; they are the result of working methods that have not kept pace with how the organisation actually runs.
Centralised identity management solves this: every new arrival gets access configured for their role, every departure triggers an immediate and automatic revocation. This process must be documented and managed systematically, not handled case by case.
Beneficiary data in sensitive contexts
For NGOs working in conflict zones or under authoritarian regimes, beneficiary data is a direct physical risk to the people it describes.
A few plain rules then apply: keep only what is strictly necessary on local devices, pseudonymise sensitive records, encrypt databases, and never leave full identity details on a device that could be seized. In this setting, these security rules carry immediate human consequences.
To find out more about IT support tailored to NGOs, visit /en/nonprofits/.
