The alert comes on a Saturday evening. A medical NGO’s central server has been hit by ransomware. Patient records, mission schedules, volunteer contact details: all encrypted and unreachable. In less than 48 hours, a surgical team needs to leave for an emergency deployment. The departure procedures are locked inside unreadable files.
For an NGO, this kind of scenario is not just an IT problem. It is an operational crisis with direct consequences for the people you are there to help.
What makes an NGO different from a business
A business facing an IT outage suffers financial losses and delays. For a humanitarian or emergency NGO, the stakes are different: some activities simply cannot wait.
Coordinating relief efforts, moving vital resources, maintaining secure communications with dispersed teams: all of this depends on IT systems that can fail at any moment. A 48-hour recovery time, acceptable for many businesses, may be completely unacceptable for an NGO operating in a crisis context.
The scenarios to plan for
Ransomware is the most immediate threat. NGOs are known targets: they depend heavily on their data and often have limited resources to respond. A full system encryption can paralyse field coordination within minutes.
Physical disasters at field sites (floods, earthquakes, conflicts) can destroy equipment and cut network access simultaneously across multiple locations.
Human error remains a frequent and underestimated cause of disruption: an accidental database deletion, a misconfigured piece of equipment, a device containing critical data going missing.
The pillars of a continuity plan
Reliable, tested backups. Three copies of data, on two different media, with at least one offsite. For sites with limited connectivity, a fast local backup is complemented by encrypted cloud replication when connection allows. The most commonly neglected step: actually testing that restoration works.
Written procedures that teams know. Who calls whom in a crisis? What are the backup access methods? Which alternative tools can be used if the primary systems are unavailable? These answers need to exist on paper and be accessible without needing the IT system itself.
A designated crisis team. It needs technical, decision-making, and communications capabilities. Members must be reachable outside normal hours, with clear procedures on who decides what.
Redundancy in critical infrastructure. Multiple internet connections at sensitive sites, backup equipment stored in separate locations. This is not a luxury; it can be the difference between a two-hour interruption and a paralysis lasting days.
Start with an impact analysis
Before trying to protect everything, identify what is truly critical. Which processes cannot wait? For a medical NGO: stock tracking and surgical team coordination. For a child protection NGO: beneficiary records and secure field communications.
Protect what cannot stop first, and build your plan around those priorities.
To find out more about IT support tailored to NGOs and nonprofits, visit /en/nonprofits/.
