Surveying Vulnerable Populations: A Case Study of Civil Society Organizations
Nikita Samarin, Alisa Frik, Sean Brooks, Coye Cheshire, Serge Egelman

TL;DR
This paper surveys the security and privacy challenges faced by civil society organizations (CSOs), highlighting their vulnerabilities, the unique needs of their employees, and methodological issues in studying this population.
Contribution
It provides a case study of surveying CSO employees, discusses methodological challenges, and offers insights to improve future research on CSO security and privacy.
Findings
Identified specific security threats perceived by CSO employees
Highlighted methodological issues in survey design for vulnerable populations
Provided recommendations for future research approaches
Abstract
Compared to organizations in other sectors, civil society organizations (CSOs) are particularly vulnerable to security and privacy threats, as they lack adequate resources and expertise to defend themselves. At the same time, their security needs and practices have not gained much attention among researchers, and existing solutions designed for the average users do not consider the contexts in which CSO employees operate. As part of our preliminary work, we conducted an anonymous online survey with 102 CSO employees to collect information about their perceived risks of different security and privacy threats, and their self-reported mitigation strategies. The design of our preliminary survey accounted for the unique requirements of our target population by establishing trust with respondents, using anonymity-preserving incentive strategies, and distributing the survey with the help of a…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsInformation and Cyber Security · Privacy, Security, and Data Protection · Spam and Phishing Detection
