CyberCAN: A Roadmap for Municipal Support of Cybersecurity
Sarah Powazek, Shannon Pierson
BSidesSF 2025 — Here Be Dragons · Day 2 · Main
Overview
Researchers Sarah Powazek and Shannon Pierson from UC Berkeley's Center for Long-Term Cybersecurity surveyed 68 San Francisco nonprofits and found that 85% had suffered at least one cyberattack, over half had no full-time IT staff, 75% collect social security numbers, and the ratio of IT staff to total employees is 1:96 — nearly three times worse than the nonprofit sector average. Their research, conducted with San Francisco's Department of Technology, produced six concrete recommendations for how cities can use their unique position as conveners, grantmakers, and technical resources to dramatically improve cybersecurity outcomes for the nonprofits that provide critical public services. ---

Key moments
- 0:00 Public interest cybersecurity: community security equals national security
- 2:00 Case study: Philadelphia hunger org lost $1M to cyberattack in 2020
- 3:59 Red Cross breach: 500k+ vulnerable people's data stolen in 2022
- 5:59 Key insight: cities already fund nonprofits, making them natural cyber hubs
- 8:00 SF Dept of Technology treats nonprofits as city infrastructure extensions
- 8:30 Survey design: 220 SF nonprofits queried on cyber needs and resources
- 9:59 CyberCAN framework: city as centralized cyber defense hub for nonprofits
CyberCAN: A Roadmap for Municipal Support of Cybersecurity
Speakers: Sarah Powazek, Shannon Pierson
Conference: BSidesSF 2025 — April 26-27, 2025, San Francisco
YouTube: Watch the full talk
Reading time: ~8 minutes
TL;DR
Researchers Sarah Powazek and Shannon Pierson from UC Berkeley's Center for Long-Term Cybersecurity surveyed 68 San Francisco nonprofits and found that 85% had suffered at least one cyberattack, over half had no full-time IT staff, 75% collect social security numbers, and the ratio of IT staff to total employees is 1:96 — nearly three times worse than the nonprofit sector average. Their research, conducted with San Francisco's Department of Technology, produced six concrete recommendations for how cities can use their unique position as conveners, grantmakers, and technical resources to dramatically improve cybersecurity outcomes for the nonprofits that provide critical public services.
Introduction
The framing that opens the CyberCAN presentation is deceptively simple: "community security is the same thing as national security." Powazek, the program director of public interest cybersecurity at UC Berkeley's Center for Long-Term Cybersecurity, and Pierson, a senior fellow in the same program, argue that individual nonprofits — food banks, homeless shelters, addiction services, legal aid organizations — rarely reach the threshold of a national security threat on their own. But as a class, the organizations that uphold public life do meet that threshold, and they are almost universally under-resourced when it comes to cybersecurity.
The CyberCAN project started from a practical question posed by San Francisco's Department of Technology: we hear anecdotally that the nonprofits we fund are struggling with cybersecurity, particularly business email compromise and phishing scams, but we don't have hard data. What do they actually need, and what could the city actually do about it? Powazek and Pierson spent the next several months generating that data.
The Survey: Methodology and Scope
▶ Watch: Survey design and methodology (11:45)
The research team began with a workshop hosted in downtown San Francisco alongside the Department of Technology, inviting nonprofits to a small event that combined introductory cybersecurity guidance — pointing to pro bono resources, outlining first steps — with direct conversation about what organizations were struggling with. The workshops were candid: one nonprofit shared that it had fallen victim to a gift card scam, describing the downstream grant impact; another raised the issue of staff turnover and the credential and knowledge management problems that come with it.
These conversations shaped the survey, which was subsequently sent to approximately 220 San Francisco nonprofits. The final instrument ran 20 questions: 15 covering cybersecurity resources they have and resources they want, and a voluntary five-question addendum on actual cyber hygiene practices. The hygiene addendum was kept optional because it asked for sensitive information about MFA implementation, software update cadence, and related controls — and it came with an incentive: organizations that completed it received customized first-step guidance, toolkits, and resource recommendations in return.
The survey received 68 responses, with about 66% completing the optional addendum. Respondents ranged from organizations with two full-time staff to those with 700, spanning workforce development, arts and culture, and housing support services.
Five Key Findings
▶ Watch: Research findings overview (22:30)
Finding 1: Nonprofits are frequent and attractive targets.
85% of surveyed nonprofits had suffered at least one type of cyberattack. Phishing was the dominant attack type at 85%; business email compromise accounted for 32%; credit card or bank account fraud 29%. The financial skew makes sense — most nonprofits are not political targets, so attackers are oriented toward their money.
The sensitivity of the data they hold compounds the risk: 75% of nonprofits collect social security numbers. Contact information and names were nearly universal. Financial information was collected by 61% of respondents and health information by 32%. These organizations hold data that is worth stealing, but they are not resourced to protect it.
Finding 2: Nonprofits lack the staff to protect themselves.
Over half of surveyed organizations had zero full-time IT staff. 21% had exactly one. More than 70% had one or fewer. The aggregate ratio: for those that had any IT staff at all, one IT employee was responsible for approximately 96 people — nearly three times the 1:33 ratio found in comparable nonprofit sector benchmarks.
Counterintuitively, organizations without IT staff were also less likely to use managed service providers (MSPs) or managed security service providers (MSSPs). The researchers had assumed that the absence of internal staff would correlate with outsourcing; instead, they found that organizations that already had IT staff were more likely to engage MSPs. Powazek described the pattern as a cyber poverty line: "those that have and those that have not — and the have-nots really don't have anything."
Finding 3: Basic controls have moderate but incomplete adoption.
16% of nonprofits used no MFA on any platform. 61% had MFA on email and collaboration tools — driven in part by Google Workspace and Microsoft Teams prompting users to enable it at setup. But the gap between 61% and full coverage across all platforms used by the organization is large, and the researchers suspect this gap is a contributing factor to the phishing and BEC rates.
Software update cadence split roughly 50/50 between organizations with regular update practices (34% with auto-updates, 16% updating monthly) and those with effectively no coherent policy — updating "whenever there's time," on undefined alternate timelines, or on six-to-twelve-month cycles.
Finding 4: The primary barrier is funding — but nonprofits want human solutions, not money.
When asked to rank barriers to cybersecurity, 89% of respondents ranked "prioritization" in their top three. The number one ranked barrier overall was funding — a finding that initially seemed straightforward. But when asked what resources they most wanted from the city, funding ranked near the bottom of the list. What nonprofits actually wanted were human solutions: a city helpline staffed by someone with cybersecurity expertise, proactive consulting, and help navigating the landscape.
The workshops had surfaced a recurring theme: nonprofits don't have the cybersecurity literacy to know where to start, and even when they do identify a need, they face a structural problem. Many city, state, and federal grants cap overhead (including technology) at 10%. Cybersecurity — already at the bottom of a long list of needs competing for that 10% — consistently loses out. Organizations cannot spend grant funding on security even when they want to.
Finding 5: Nonprofits have cyber literacy, not cyber inertia.
Powazek was emphatic about a misconception: "Something that I hear a lot is that organizations don't care about cybersecurity, they don't know anything about it. That was not what we heard. What we heard was: they know it's a problem and they just don't know what to do about it."
Six Recommendations for the City of San Francisco
▶ Watch: Policy recommendations (35:00)
The research team's recommendations were explicitly scoped to what San Francisco's Department of Technology could feasibly implement with its existing resources and relationships:
Education:
- Provide regular cybersecurity advice and assistance. San Francisco's CISO volunteered to serve as a virtual CISO for nonprofits — taking calls, offering guidance, and filling the "where do I start" gap without requiring nonprofits to hire a full-time expert.
- Host an annual cybersecurity convening. The pre-survey workshop demonstrated how valuable nonprofits found direct access to CISA Region 9 advisers, FBI field office representatives, and local cybersecurity expertise. A regular event that convenes the city, federal agencies, and industry partners providing free or low-cost tools could be transformative for organizations that otherwise have no face to put to cybersecurity.
Resource Coordination:
- Create a city cybersecurity resource web page. Hundreds of free and low-cost cybersecurity tools and toolkits exist. A city-curated, city-endorsed resource hub would address the "I Googled 'cybersecurity help' and didn't find what I needed" problem that multiple nonprofits described.
- Expand funding opportunities. Two paths: carve out one to three percent of existing grants specifically for technology, protecting that funding from the general overhead cap; alternatively, create a standalone cybersecurity grant program for nonprofits.
Implementation:
- Deliver a baseline cybersecurity assessment. Partner with the UC Berkeley Cybersecurity Clinic — which deploys graduate and undergraduate students across all disciplines to conduct pro bono risk assessments — to give nonprofits a structured starting point and clear prioritization.
- Host a launch event as an expo. Connect nonprofits face-to-face with cybersecurity volunteering organizations, industry partners offering tabletop exercises or donated software licenses, university programs seeking internship placements, and federal agency contacts — compressing the relationship-building that currently doesn't happen because nonprofits don't know where to look.
For security professionals in the audience who want to contribute directly, Pierson highlighted the Cyber Resilience Corps — a coalition of cyber volunteering organizations that includes Cyberpace Institute's Builders Program, which has a matching platform connecting individual volunteers with nonprofits for specific, bounded tasks.
Notable Quotes
"Community security is the same thing as national security — these organizations, taken as a whole, really do meet the threshold of a national security concern."
— Shannon Pierson, ▶ 3:30
"What we heard was: they know it's a problem and they just don't know what to do about it. They don't know where to start and they're overwhelmed."
— Sarah Powazek, ▶ 32:00
"Those that have and those that have not — the have-nots really don't have anything. We found many nonprofit organizations with no staff and no vendors, really on their own."
— Sarah Powazek, ▶ 27:45
Key Takeaways
- 85% of surveyed San Francisco nonprofits have been hit by at least one cyberattack; phishing (85%), BEC (32%), and financial fraud (29%) dominate, targeting organizations that collectively hold social security numbers for 75% of respondents.
- The staffing crisis is severe: more than 70% of nonprofits have one or fewer full-time IT staff, the IT-to-employee ratio is 1:96 (three times worse than sector benchmarks), and organizations without IT staff are statistically less likely — not more — to use managed service providers.
- The primary barrier nonprofits report is funding, but what they actually want is human support — a helpline, a consultant, someone to call when they are hit with ransomware — reflecting a cybersecurity literacy gap rather than a motivation gap.
- Structural grant constraints (overhead caps of 10% that must cover all technology) prevent nonprofits from spending even available funds on cybersecurity, making grant carve-outs a higher-leverage intervention than general overhead increases.
- Cities are uniquely positioned to solve this problem: they have established trust relationships with nonprofits, can convene federal agencies and industry partners, and can use their grantmaking authority to protect cybersecurity funding — making them natural hubs for regional cyber defense.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
Legitimate research with real survey data — 68 San Francisco nonprofits, 85% attack rate, 1:96 IT-to-staff ratio — and six specific policy recommendations directed at a city government with the actual authority to implement them. The finding that nonprofits without IT staff are statistically less likely to use MSPs, not more, is the most counterintuitive and important data point. The impact ceiling is bounded by the policy audience.
Heather Calloway (CISO) — MUST SEE
Eighty-five percent of San Francisco nonprofits have been attacked, 75% hold social security numbers, more than half have zero full-time IT staff, and the primary barrier they report is not motivation or literacy but funding structures that structurally prevent them from spending on security. The CyberCAN research is the rare talk that names the governance mechanism — grant overhead caps — and provides specific policy recommendations that cities can actually implement.