The programme
EcoSecure is Dunicot’s dedicated programme for nature and climate-focused organisations: environmental NGOs, conservation trusts, climate research institutions, carbon registries, renewable energy operators, and the funders financing them.
It exists because this sector sits at an unusual intersection. The work produces findings with commercial and political consequence, which attracts adversaries far more capable than the organisation’s size would normally invite, while the security budget is whatever was left after the fieldwork. Standard commercial security scoping does not fit that shape, so this programme does not use it.
A research institute with twelve staff, holding data a state-linked actor wants, is not a small security problem. Programme rationale
Vision and goals
The aim is that an organisation working on climate or conservation can hold sensitive data, run a public platform and take on a well-resourced adversary without needing a security budget it will never have. Five goals carry that.
Programme goals
- Scoping built for the sector
- Testing scoped to the systems whose compromise would damage the mission, rather than to the full estate. A twelve-person research institute holding data a state-linked actor wants is not a small security problem, and is not priced as one.
- Sustainable practice
- Engagements run remotely by default, with travel only where terminal or on-site work requires it. The carbon cost of securing an organisation should not undercut what it is trying to protect.
- Education and awareness
- Training built around the lures this sector receives in practice, so staff and field teams recognise them. Delivered as part of the programme rather than sold separately.
- A working ecosystem
- Findings that affect shared platforms, coalition tooling or common suppliers are reported to everyone exposed, with consent, rather than stopping at the one client who paid.
- Research that stays current
- Time funded for tracking how adversaries target this sector, with what we learn published in the research section rather than kept as a sales advantage.
Where the programme is going: more organisations served each year, regional coverage from both offices so support sits in a workable timezone, and published sector research rather than private findings. We do not publish revenue targets, and none of the above is contingent on hitting one.
The threat model
This sector’s risks differ sharply from a bank’s or a SaaS platform’s, and the differences drive the scoping.
| Risk | What it looks like in practice |
|---|---|
| Research data integrity | Quiet alteration of measurements, models or historical series: the most damaging attack in this sector, because it discredits the work rather than stealing it |
| Pre-publication access | Unpublished findings read in advance by interests preparing to counter them, or to trade on them |
| Field-researcher safety | Location data, communications and device contents exposing staff working in contested or hostile areas |
| Funder and grant systems | Financial and reporting platforms holding grant flows, beneficiary data and disbursement authority |
| Carbon and credit registries | Registry integrity, double-counting, and manipulation of issuance or retirement records |
| Operational technology | Sensors, monitoring stations, buoys and remote installations, often deployed for years without updates |
| Reputational attack | Website and social account compromise used to publish retractions or fabricated positions |
| Supply chain | Shared platforms across a coalition, where the weakest member exposes the rest |
What the programme includes
Assessment, scoped to consequence
Rather than pricing the whole estate, we identify the two or three systems whose compromise would damage the mission: the data platform, the grant system, the publication pipeline, and test those properly.
Field operations security
Device hardening, communications, data handling in the field, and a documented plan for what happens when a device is seized, lost or searched at a border.
Training and awareness
Delivered for people who are field scientists first and computer users second. Built around the actual lures this sector receives, not generic examples.
Incident support
Access to forensics and incident response without a procurement cycle, because a small organisation in an incident does not have weeks to arrange help.
Funder assurance
Documentation that satisfies institutional funders’ increasing security requirements, so security work supports grant applications rather than competing with them for budget.
How it is funded
Programme terms
- Eligibility
- Registered non-profits, research institutions, and mission-driven organisations in the environmental and climate sector
- Rates
- Reduced rates for registered non-profits and academic institutions
- Scoping
- Consequence-first: the systems that would damage the mission, not the full estate
- Coalitions
- Shared engagements across coalition members, splitting cost where a platform is shared
- Confidentiality
- Standard mutual NDA; we never name an EcoSecure client without written consent
- Starting point
- A free scoping conversation, tell us the budget and we will say what it buys
If the honest answer is that your budget does not cover what you need, we will say so and point you at what to do first for nothing. That is a better outcome than an engagement shaped to a number rather than to a risk.
Questions
Who is EcoSecure for?
Environmental NGOs, conservation trusts, climate research institutions, carbon registries, renewable energy operators and the funders behind them. Any organisation whose work produces environmental data, holds field-researcher information, or moves climate finance.
Are environmental organisations actually targeted?
Yes, and by unusually capable adversaries for their size. Organisations publishing findings that carry commercial or political consequence attract attention from interests those findings affect: including surveillance of staff, attempts to alter or discredit data, and access to unpublished research. The mismatch between the sophistication of the adversary and the security budget of the target is the gap this programme exists to close.
We have almost no security budget. Is this realistic?
That is the assumption the programme is built on. Engagements are scoped to the highest-consequence surface rather than the whole estate, training is prioritised over tooling because it costs less and lasts longer, and we offer reduced rates for registered non-profits and research institutions. Tell us the budget you have and we will tell you honestly what it buys.
Does field-staff safety fall in scope?
Where you want it to. Operational security for staff working in sensitive locations is a distinct workstream, and often the one with the most direct human consequence: device hardening, communications, data handling in the field, and what happens if a device is seized or lost.