The Unspoken Guardians of the Internet Why Non-profit Cybersecurity Matters for Public Safety and Global Resilience
Non-profit cybersecurity organisations are a foundational part of the global cyber ecosystem, yet their role remains systematically under-recognised and underfunded. This new HCSS report argues that these organisations provide essential public-interest security functions that governments and commercial providers cannot fully deliver on their own.
The report by Hans Horan, Ron Stoop and Jan Feldhusen finds that non-profit cybersecurity actors play a critical role in threat intelligence sharing, incident response coordination, standards development, capacity-building, and support for vulnerable communities. Their work helps reduce harm, strengthen cyber resilience, and sustain the shared infrastructure and protocols underpinning the global digital economy. The report warns that continued underfunding risks weakening critical cyber resilience functions worldwide. It recommends that governments establish dedicated multi-year funding streams, formally integrate non-profit actors into national cybersecurity strategies, and create rapid-response funding mechanisms for major cyber crises. It also calls on industry to adopt standing norms for financially supporting the sector.
Threat intelligence services can also generate substantial value. The most notable example would be Shadowserver, a non-profit that scans the global internet for vulnerabilities, malware, and active threats, and alerts affected organisations and governments. Single organisations such as ShadowServer and CIS account for market-equivalent values of USD 830M–980M and USD 354M, respectively. Shadowserver delivers this at an operating cost of USD 5.5 to 6 million per year: a leverage ratio of approximately 170 to 200 USD of economic value per dollar spent.









