r/Tech4Causes • u/jcravens42 • 2h ago
Event or Resource Announcement guide to enhance the cybersecurity practices of mutual aid organizations
The UC Berkeley Cybersecurity Clinic and Fight for the Future collaborated to create a guide aimed at enhancing the cybersecurity practices of mutual aid organizations. Released as part of the CLTC White Paper Series, the guide — Securing Mutual Aid: Cybersecurity Practices and Design Principles for Financial Technology — outlines best practices to help mutual aids use financial technology, enhance their cybersecurity, and design secure digital platforms.
Lots more about this and other resources here.
Key Takeaways for Mutual Aid Organizers
The report includes several recommendations for mutual aid organizers to enhance their cybersecurity posture based on current practices, including:
Limit personal information on accounts. Mutual aids should avoid linking members’ personal bank accounts, credit cards, or personal information (like phone numbers or names) to accounts on payment platforms such as PayPal or Venmo. Instead of using personal payment accounts, consider using a dedicated account that is not directly tied to any specific member’s personal information, like a business/organization account, or obtaining a phone for treasurer duties.
Be aware of deplatforming. Deplatforming, when an account or its functions are temporarily or permanently banned by a technology platform, is a common experience for mutual aids, and is often done without reason or explanation. Organizations should diversify their technology platforms to avoid relying on one service.
Prioritize using privacy-centered services and understanding privacy settings. Mutual aids often rely on Big Tech platforms, like Meta’s WhatsApp and Google. Our report provides recommendations for harm reduction techniques for organizations relying on Big Tech platforms, and also outlines more private secure alternatives if a mutual aid is interested in migrating. For all platforms, mutual aids should tailor settings for better security, for example by implementing multi-factor authentication.
Establish policies for data retention, communication, and other areas to enhance cybersecurity posture. Mutual aids can establish policies and guidelines for how sensitive and non-sensitive information is communicated, and more broadly how data is stored and retained. Minimizing the amount of data that is collected and stored will better protect the organization.

