Why Democratizing Cybersecurity Is Good for Business

Jochai Ben-Avie (Non-Resident Fellow · Atlantic Council), Kayle Giroud (Director, Common Good Initiatives · Global Cyber Alliance), Chris Painter (Former President · The Global Forum on Cyber Expertise Foundation), Rob Sheldon (Sr. Director, Public Policy & Strategy · CrowdStrike), Erin Ceynar (Senior Advisor, Corporate Social Impact · Tides Foundation)

RSA Conference 2025 · Day 1 · Policy · Policy & Government

Overview

A panel from the Global Cyber Alliance's Common Good Cyber initiative made the case that uneven access to cybersecurity tools and expertise is not just a fairness problem — it is a systemic risk problem. With nonprofits representing ten percent of the U.S. workforce and more than half of healthcare delivery on the African continent, leaving mission-driven organizations unprotected creates exploitable gaps for every sector. The session argued that corporations, philanthropic funders, vendors, and policymakers each have concrete roles to play, and offered an unusually practical set of actions for attendees to take home. ---

Watch on YouTube

Visual summary for Why Democratizing Cybersecurity Is Good for Business by Jochai Ben-Avie, Kayle Giroud, Chris Painter, Rob Sheldon, Erin Ceynar
Visual summary for Why Democratizing Cybersecurity Is Good for Business by Jochai Ben-Avie, Kayle Giroud, Chris Painter, Rob Sheldon, Erin Ceynar

Key moments

  1. 4:07 4 million global cybersecurity workforce shortfall — who fills the gap?
  2. 8:32 Over 50% of African healthcare delivered by nonprofits lacking basic cyber tools
  3. 10:00 Access Now's 24/7 digital security helpline — only service of its kind globally
  4. 16:28 Secure by design shifts security burden from end users to platform developers
  5. 18:49 Painter: critical shared security infrastructure is 'critically unfunded'
  6. 20:01 State Department funding for civil society cyber protection being eliminated
  7. 32:03 Call to action: businesses should fund MITRE ATT&CK and Shadowserver directly
  8. 40:03 Common Good Cyber fund launch — baseline funding mechanism for cyber commons

Why Democratizing Cybersecurity Is Good for Business

Talk ID: RSA25-019

Speakers: Jochai Ben-Avie (Atlantic Council), Kayle Giroud (Global Cyber Alliance), Chris Painter (Global Forum on Cyber Expertise Foundation), Rob Sheldon (CrowdStrike), Erin Ceynar (Tides Foundation)

Conference: RSA Conference 2025 — April 28–May 1, 2025, Moscone Center, San Francisco

Stage: Policy Stage | Track: Policy & Government

YouTube: Watch on YouTube

Reading Time: ~7 minutes

TL;DR

A panel from the Global Cyber Alliance's Common Good Cyber initiative made the case that uneven access to cybersecurity tools and expertise is not just a fairness problem — it is a systemic risk problem. With nonprofits representing ten percent of the U.S. workforce and more than half of healthcare delivery on the African continent, leaving mission-driven organizations unprotected creates exploitable gaps for every sector. The session argued that corporations, philanthropic funders, vendors, and policymakers each have concrete roles to play, and offered an unusually practical set of actions for attendees to take home.

Introduction

On the last morning of RSA Conference 2025, a panel convened by the Global Cyber Alliance's Common Good Cyber initiative posed a question that rarely gets serious airtime in the main expo hall: what happens to the organizations that cannot afford what everyone else in the building is selling?

The panel brought together Chris Painter, the first U.S. Cyber Diplomat and now president of the Global Forum on Cyber Expertise Foundation; Jochai Ben-Avie of the Atlantic Council, formerly head of international public policy at Mozilla and co-founder of RightsCon; Rob Sheldon, Senior Director of Public Policy and Strategy at CrowdStrike; and Erin Ceynar, Managing Advisor at Tides Foundation. Kayle Giroud, Director of Common Good Initiatives at the Global Cyber Alliance, moderated.

Their combined framing: the first being attacked are often the last being served.

Section 1: What "Democratizing Cybersecurity" Actually Means

The panel opened with a definitional exercise that turned substantive quickly. Ceynar set the tone from Tides Foundation's vantage point: "Problems and solutions are found in the same place." Democratizing cybersecurity means more than making tools cheaper — it means including affected communities in the governance and decision-making about those tools.

▶ Watch: Defining democratizing cybersecurity — who's at the table? (02:00)

Ben-Avie extended the definition to breadth and depth: who has access to tools, techniques, knowledge, and partnerships. Walking through the RSA expo hall, he noted, reveals sophisticated defenses developed primarily for corporate customers. "Too often we see that nonprofits, but also small businesses, we see any number of organizations that are doing really important work — whether you care about it from a political perspective, a human rights perspective, or an economic perspective — that are not benefiting from the latest and greatest tools."

Sheldon added a vendor-side perspective: specificity in threat intelligence moves the needle for underserved organizations. When CrowdStrike can tell a nonprofit advocacy group that a specific Chinese military unit or Russian criminal group is targeting their specific sector, that information changes behavior in a way that generic "there are threats" messaging never does.

Section 2: The Structural Gap — Nonprofits, Small Businesses, and Critical Infrastructure

▶ Watch: 50% of African healthcare delivered by nonprofits — the protection gap (08:01)

Ben-Avie offered a figure that reframed the entire discussion: nonprofits make up ten percent of the workforce in the United States. More than fifty percent of healthcare delivery on the African continent is done by nonprofits. Yet these organizations have almost no dedicated cybersecurity budgets and virtually no access to the enterprise-grade tools discussed elsewhere at RSA.

Access Now's twenty-four-hour digital security helpline for activists at risk worldwide exists precisely because of this gap — and it survives on a combination of philanthropic funding and corporate partnerships that provide escalated response pathways. Ben-Avie acknowledged that almost no organization he could think of had a genuine budget line item for cybersecurity.

Ceynar added that organizations under the most severe attack are often delivering the most critical services — humanitarian organizations, civil society groups, and mission-driven nonprofits whose compromise has downstream effects on populations that cannot absorb disruption. "All of our fates are tied."

Section 3: The Vendor Responsibility — Managed Services and Secure by Design

Sheldon argued that the vendor community has a specific and under-fulfilled obligation in this space. Making tools accessible is not only a charitable gesture; it is a business risk issue.

▶ Watch: CrowdStrike on managed services for mission-driven orgs (14:02)

For a ten- or twenty-person nonprofit, maintaining a full security program is unrealistic. Sheldon pointed to managed security services as the practical solution — twenty-four-by-seven-by-three-sixty-five coverage that allows organizations to focus on their actual mission rather than on security operations they are not equipped to run. "In the past couple of years the extent to which managed security services are much more easy to use from the user's perspective, and also much more effective than trying to build, maintain, and sustain a full security program" marks genuine progress.

He also called out the "secure by design" movement as critically important for the underserved sector. Many nonprofit workers and volunteers are operating on consumer devices, using consumer applications, and not sitting inside a traditional enterprise network. If consumer services are not secured at the platform level, those users cannot protect themselves regardless of their awareness. The burden must sit upstream.

▶ Watch: Secure by design — moving the burden from users to platforms (16:02)

Section 4: The Funding Crisis for the Cyber Commons

Chris Painter delivered the sharpest diagnosis. The adage that "cybersecurity is everyone's responsibility" is true in principle — but not everyone has the capability to exercise that responsibility, and not everyone with the capability is actually doing so.

▶ Watch: Chris Painter on critically underfunded cyber commons infrastructure (18:02)

He enumerated organizations that form the backbone of the shared security infrastructure — the Shadowserver Foundation, the Center for Internet Security, Sightline Security, the Global Forum on Cyber Expertise — and named a common characteristic: "They are critically unfunded."

The problem is not lack of awareness. Companies know these organizations exist. "What happens is a lot of times there's the thought, 'Oh, this stuff is just gonna happen.'" The assumption that critical shared infrastructure will self-sustain without intentional investment is a collective action failure. The pool of funders willing to support operational security infrastructure for the commons is "very small" and falls far short of demand.

Compounding this: State Department funding that once supported digital security capacity building for dissidents and civil society organizations globally has contracted significantly. "When your funding is low already, and it gets even lower, that's a real challenge."

Section 5: Practical Actions — From the Conference Back to the Office

The panel closed with an unusually action-oriented set of recommendations, framed in one-week, three-month, and six-month horizons.

▶ Watch: Action framework — one week, three months, six months (32:03)

Within a week: businesses should audit their dependency on nonprofit-led open-source efforts — MITRE ATT&CK, Shadowserver threat intelligence — and reach out directly to ask if those organizations need funding support. As Giroud noted dryly, "They do, so they're already ready for it."

Within three months: broaden corporate social responsibility thinking to include security by design practices and support for the broader nonprofit ecosystem. Ceynar's Tides Foundation model — general operating support grants that give nonprofits flexibility to address immediate crises including security — was offered as a template.

Within six months: incorporate democratized security into core business practices. Common Good Cyber is developing a fund specifically designed to provide baseline funding for the critical shared infrastructure that the whole ecosystem depends on.

▶ Watch: Common Good Cyber fund launch plans and final ask (40:03)

Painter closed with a storytelling imperative: the sector needs to get better at quantifying not just dollar harm but societal harm, human impact, and long-term consequences — "to get more people to say, 'Okay, I need to do something about this. This is valuable to me as a business.'"

Notable Quotes

"The first being attacked are often the last being served." — Kayle Giroud

"More than fifty percent of healthcare delivery on the African continent is done by nonprofits. How many of them do you think are actually benefiting from the latest and greatest tools?" — Jochai Ben-Avie

"Cybersecurity is everyone's responsibility — while that may be true, not everyone has the capability to have that responsibility, and not everyone with the capability is taking responsibility." — Chris Painter

"All of our fates are tied. To mitigate risk, we need to make sure that problems and solutions are found in the same place." — Erin Ceynar

"We in the vendor community need to think about how we make tools exceptionally easy for people to use so they can focus on their actual core mission." — Rob Sheldon

Key Takeaways

  1. Uneven cybersecurity access is a systemic risk problem, not only an equity issue — gaps in nonprofit and civil society protection create exploitable pathways affecting the entire ecosystem.
  1. Nonprofits are the second most cyber-attacked organizational type, yet they are among the most resource-constrained; the mismatch between their criticality and their protection level is acute.
  1. Managed security services represent the most practical path for under-resourced organizations — twenty-four-by-seven coverage that allows organizations to focus on mission rather than security operations they cannot staff.
  1. Shared security infrastructure is critically underfunded — organizations like Shadowserver, CIS, and the GFCE operate on thin margins despite their role in maintaining the commons of threat intelligence and capacity building.
  1. The corporate sector has concrete, near-term actions — auditing dependencies on open-source security infrastructure, providing general operating support grants, and funding the Common Good Cyber fund are among them.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

An earnest and well-intentioned panel on cybersecurity equity that makes the systemic risk argument better than expected. The 50% of African healthcare delivered by nonprofits statistic is genuinely arresting. Chris Painter's diagnosis of structural underfunding of shared security infrastructure is the sharpest moment. Loses points for being a project pitch dressed as a policy panel and for lacking any empirical teeth — no data on whether democratization interventions actually work.

Heather Calloway (CISO) — STRONG ACCEPT

Common Good Cyber presents a framework for treating cybersecurity as a public good — arguing that the current market structure produces systematically under-resourced defense for the organizations that cannot afford enterprise security programs but are deeply embedded in critical infrastructure supply chains.

→ Top-rated talks at RSA Conference 2025

All talks from RSA Conference 2025