{"id":16138,"date":"2026-06-27T02:56:11","date_gmt":"2026-06-27T02:56:11","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=16138"},"modified":"2026-06-27T02:56:11","modified_gmt":"2026-06-27T02:56:11","slug":"how-agentic-ai-menace-intelligence-aids-ngo-cyber-protection-case-research","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=16138","title":{"rendered":"How agentic AI menace intelligence aids NGO cyber protection: Case research"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div id=\"content-body\">&#13;<\/p>\n<p>Nonprofits serving susceptible populations sit on the uncomfortable intersection of delicate information, world publicity and restricted safety assets.<\/p>\n<p>Geneva-based Defend.ngo, previously the CyberPeace Institute, helps nonprofit and nongovernmental organizations (NGOs) navigate these challenges with free cybersecurity help. To satisfy its mission, Defend.ngo, itself a nonprofit, should regularly determine and analyze the threats that focus on its almost 700 member organizations &#8212; far simpler stated than performed.<\/p>\n<section class=\"section main-article-chapter\" data-menu-title=\"The problem: When manual monitoring isn't enough\">\n<h2 class=\"section-title\"><i class=\"icon\" data-icon=\"1\"\/>The issue: When handbook monitoring is not sufficient<\/h2>\n<p>When Defend.ngo began in 2018, its cybersecurity analysts relied on open supply intelligence expertise to trace publicly reported cyberattacks in opposition to the nonprofits in its community. The method concerned manually checking information retailers, <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.techtarget.com\/searchsecurity\/feature\/Data-after-the-breach-Economics-of-the-dark-web\">darkish net boards<\/a>, social media and different sources.<\/p>\n<p>&#8220;Many [NGOs] have a smaller digital footprint,&#8221; stated Miles Collins, a cyberthreat analyst at Defend.ngo. &#8220;This could make it harder to detect whether or not they have been focused and to collect sufficient proof for technical attribution.&#8221;<\/p>\n<p>With no unified view of the menace panorama dealing with NGOs and different civil society organizations, the work was time-consuming, inconsistent and unwieldy. The outcomes additionally failed to provide Defend.ngo analysts the real-time insights they wanted to correctly analyze and prioritize rising and ongoing <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.techtarget.com\/searchsecurity\/feature\/Top-10-types-of-information-security-threats-for-IT-teams\">safety threats<\/a>. The size of Defend.ngo&#8217;s monitoring actions compounded the problem, with a whole lot of member organizations spanning completely different areas, sectors and working environments.<\/p>\n<p>These challenges however, it was vital that analysts detect assaults rapidly and persistently, each for instantly affected organizations and their friends. A menace surfacing in a single nook of the Defend.ngo community might have implications for numerous different NGOs. Plus, any missed or delayed detections might create gaps within the public information upon which researchers and policymakers rely.<\/p>\n<p>By March 2025, Defend.ngo analysts had manually documented greater than 295,000 threats, 760 vulnerabilities and 1,100 distinct assaults on NGOs &#8212; and the menace panorama was solely worsening.<\/p>\n<\/section>\n<section class=\"section main-article-chapter\" data-menu-title=\"The fix: AI joins the cause\">\n<h2 class=\"section-title\"><i class=\"icon\" data-icon=\"1\"\/>The repair: AI joins the trigger<\/h2>\n<p>Across the identical time, Defend.ngo turned to AI to help the efforts of its human analysts. The group deployed Dataminr&#8217;s AI-powered menace intelligence platform, which has the next capabilities.<\/p>\n<ul class=\"default-list\">\n<li>Aggregates info from numerous sources throughout the general public, deep and darkish net, together with authorities advisories, social media, cyber menace boards, darkish net boards, information retailers, vulnerability disclosures, breach stories and <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.techtarget.com\/searchsecurity\/tip\/Top-open-source-and-commercial-threat-intelligence-feeds\">menace intelligence feeds<\/a>.<\/li>\n<li>Ingests and analyzes textual content, code, picture and video information.<\/li>\n<li>Makes use of agentic AI and enormous language fashions to autonomously analyze, enrich and contextualize information. The AI brokers summarize incidents; correlate adversarial exercise; determine patterns; and map relationships between cyber incidents, menace actors and focused organizations.<\/li>\n<li>Presents deduped, structured and contextualized intelligence alerts and briefs to human analysts in actual time. Alerts embrace detailed supply attribution, screenshots and background on menace actors concerned.<\/li>\n<\/ul>\n<p>In response to Collins, he and his fellow analysts at Defend.ngo evaluate and confirm all AI-driven alert and intelligence information, guaranteeing its accuracy and reliability earlier than figuring out subsequent steps.<\/p>\n<p>&#8220;Human analysts are nonetheless required with regards to judging whether or not these claims are credible or not,&#8221; Collins added. &#8220;As a part of our methodological course of, we all the time have an analyst reviewing AI output.&#8221;<\/p>\n<blockquote class=\"main-article-pullquote\">\n<p><figure>\n    Human analysts are nonetheless required with regards to judging whether or not these claims are credible or not.<br \/>\n   <\/figure><figcaption>\n    <strong>Miles Collins<\/strong>Cyber menace analyst, Defend.ngo<br \/>\n   <\/figcaption><i class=\"icon\" data-icon=\"z\"\/>\n  <\/p>\n<\/blockquote>\n<p>Along with supercharging cyberattack and menace monitoring for Defend.ngo&#8217;s consumer organizations, Dataminr&#8217;s AI menace intelligence expertise informs the nonprofit&#8217;s <a rel=\"nofollow\" target=\"_blank\" target=\"_blank\" href=\"https:\/\/tracer.protect.ngo\/\" rel=\"noopener\">Cyber Tracer<\/a>. The general public platform tracks vulnerabilities, threats and assaults related to civil society organizations and helps ongoing analysis on conflict-zone cyberactivity, together with the Russia-Ukraine struggle. NGOs, policymakers and researchers can use Cyber Tracer &#8212; which additionally consists of structured, domain-specific information from third-party companions Cloudflare, Bitsight and Kaduu &#8212; to higher mitigate danger and <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.techtarget.com\/searchsecurity\/tip\/CISOs-guide-to-demonstrating-cyber-resilience\">enhance cyber resilience<\/a>.<\/p>\n<\/section>\n<section class=\"section main-article-chapter\" data-menu-title=\"The results: Consolidated and contextualized threat intelligence data\">\n<h2 class=\"section-title\"><i class=\"icon\" data-icon=\"1\"\/>The outcomes: Consolidated and contextualized menace intelligence information<\/h2>\n<p>At Defend.ngo, Collins stated the core operational advantage of agentic AI menace intelligence has been the consolidation of numerous and far-flung occasion, menace and danger information. A single, deduped and contextualized feed means analysts spend much less time gathering and organizing info and extra time analyzing and prioritizing it.<\/p>\n<p>AI-driven monitoring additionally extends protection into channels that analysts at resource-constrained organizations hardly ever have the capability to look at persistently, reminiscent of darkish net boards the place <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.techtarget.com\/searchsecurity\/definition\/ransomware\">ransomware<\/a> teams publish claims in opposition to victims which may not seem in typical information sources.<\/p>\n<h3>The primary alert on an exfiltrated database<\/h3>\n<p>The agentic menace intelligence workflow was initially examined throughout an incident involving a nonprofit in Defend.ngo&#8217;s <a rel=\"nofollow\" target=\"_blank\" target=\"_blank\" href=\"https:\/\/protect.ngo\/the-builders\" rel=\"noopener\">The Builders<\/a> program, a matchmaking initiative that connects company cybersecurity volunteers with NGOs that want help.<\/p>\n<p>On this occasion, a menace actor claimed to have exfiltrated information from the group&#8217;s surroundings and revealed a pattern of the database on-line. Dataminr surfaced the alert earlier than Defend.ngo volunteer analysts recognized it by every other channel, Collins stated, enabling them to rapidly contact the group with remediation help.<\/p>\n<p>To this point, Defend.ngo has recorded greater than 878,000 threats, detected 1,084 vulnerabilities throughout NGOs, recognized greater than 2,000 assaults, quarantined greater than 560,000 phishing emails and detected greater than 315,000 uncovered credentials.<\/p>\n<\/section>\n<section class=\"section main-article-chapter\" data-menu-title=\"A caveat: AI won't make up for poor cybersecurity hygiene\">\n<h2 class=\"section-title\"><i class=\"icon\" data-icon=\"1\"\/>A caveat: AI will not make up for poor cybersecurity hygiene<\/h2>\n<p>Regardless of Defend.ngo&#8217;s optimistic expertise with the AI menace intelligence platform, Collins warned that smaller organizations with out devoted safety features typically lack the baseline controls that make such monitoring instruments helpful within the first place.<\/p>\n<p>Organizations with out in-house safety workers ought to focus first on the fundamentals &#8212; <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.techtarget.com\/searchsecurity\/tip\/Multifactor-authentication-Examples-and-strategic-use-cases\">MFA<\/a>, <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.techtarget.com\/searchnetworking\/definition\/virtual-private-network\">VPNs<\/a>, <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.techtarget.com\/searchsecurity\/tip\/Top-5-password-hygiene-tips-and-best-practices\">robust password administration<\/a> and software program updates. &#8220;Keep away from getting any complicated instruments earlier than the foundational operational safety is in place,&#8221; he stated.<\/p>\n<p>As soon as that basis exists, <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.techtarget.com\/searchsecurity\/video\/AI-security-Top-experts-weigh-in-on-the-why-and-how\">AI instruments<\/a> turn out to be a sensible possibility. For resource-constrained groups, nevertheless, the danger then turns into treating AI as an alternative choice to human reasoning, perception and judgment, and the self-discipline that makes such instruments significant.<\/p>\n<p>&#8220;It&#8217;s all the time vital to needless to say AI could make errors and once more, primary safety practices stay a very powerful to implement,&#8221; Collins stated.<\/p>\n<p><i>Sean Michael Kerner is an IT guide, expertise fanatic and tinkerer. He has pulled Token Ring, configured NetWare and been identified to compile his personal Linux kernel. He consults with trade and media organizations on expertise points.<\/i><\/p>\n<\/section>\n<\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>&#13; Nonprofits serving susceptible populations sit on the uncomfortable intersection of delicate information, world publicity and restricted safety assets. Geneva-based Defend.ngo, previously the CyberPeace Institute, helps nonprofit and nongovernmental organizations (NGOs) navigate these challenges with free cybersecurity help. To satisfy its mission, Defend.ngo, itself a nonprofit, should regularly determine and analyze the threats that focus [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":16140,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[2105,1628,690,959,397,312,9566,1776,461],"class_list":["post-16138","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-agentic","tag-aids","tag-case","tag-cyber","tag-defense","tag-intelligence","tag-ngo","tag-study","tag-threat"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/16138","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=16138"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/16138\/revisions"}],"predecessor-version":[{"id":16139,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/16138\/revisions\/16139"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/16140"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=16138"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=16138"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=16138"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-06-27 05:34:06 UTC -->