From Participant to Champion: Empowering Youths to Lead Their Organization’s Digital Resilience

Workshop Session at the Young Tech Collective On-site Training
Picture of Arie Mega

Arie Mega

Project Research and Learning Specialist for the Digital Democracy Initiative at Tifa Foundation

From Participant to Champion: Empowering Youths to Lead Their Organization’s Digital Resilience

Midway through the training in Kuala Lumpur,  LJ, a focal point from a labour and human rights institution in the Philippines, messaged his executive director with a simple question. Did the organisation have a digital security plan, and if so, could he see it? The document arrived. He opened it, and then fell quiet. 

“Upon reviewing it, we only have just like one paragraph,” he said. Elsewhere in the same document, the assessment of their digital security situation ran on at length. There was awareness of the problem, but almost nothing in the way of a plan to address it. 

Moments like that repeated across many organisations during the five days of the Young Tech Collective (YTC) onsite training in late May 2026. And it is precisely from that kind of honest starting point that the focal point model does its work. 

“Prevention is actually better than cure.”

An Honest Starting Point 

Almost every participant arrived in a similar condition. Not without security, but with security that had grown reactively, always one step behind the incident. 

GL, a focal point from a youth organisation working on sustainable development issues in the Philippines, described it candidly. Her organisation began backing up documents digitally only after their paper archives were damaged by a leak in their old office. They began enforcing two-factor authentication only after an officer’s social media account was hacked and the organisation’s page was taken down. 

“Everything we have done so far with security has been reactive. Danger usually happens before we did something,” she said. “Prevention is actually better than cure.” 

At the organisation where AC works, a Yogyakarta-based institution accompanying networks of young activists, the assessment was equally blunt. “The state of our digital security was, in my view, quite low,” he said, largely because they had no digital security policy at all, while managing a website, social media accounts, and shared document storage. 

What LJ faced was more structural still. The security knowledge his institution once held had never been passed on, because a colleague died and the staff member responsible for security was retiring. “The transfer of knowledge has not been done,” he said.

Why It Has to Be an Insider 

This is where YTC’s design choice sits. Rather than sending in an external consultant to train an entire team over a day or two, the programme selects one person from inside each organisation, equips them, and then accompanies them for four months. 

RS, one of the facilitators from the Digital Defenders Partnership (DDP), explained the reasoning. “With a one-off training, the awareness only lasts a moment. During the session they are aware, and once they walk out, they forget again,” he said. “That is why we use a long accompaniment model, because building awareness and capacity is a slow process.” 

Some of the work can only be done by an insider, and it is not technical work. One focal point from Myanmar faces colleagues who consider digital security an overreaction. Many of them are senior activists and politicians who feel experienced enough already. “They feel they do not need to use a VPN, digital security is not important for them,” she said. “I always try to change their mindset.” 

A consultant who arrives one day and leaves the next will never win against that kind of resistance. The person who can is the one sitting in the same room every day, who knows who needs to be approached and how, and who has the time to repeat the same conversation until it turns into a habit. 

From Participant to Facilitator 

The clearest shift over those five days came when participants began speaking not as people learning something, but as people preparing to teach it. 

GL recognised that the knowledge gap between herself and her colleagues was wide. Most staff were familiar only with ordinary email and common messaging apps, and had never received a basic introduction to digital security. Asked whether she felt ready to facilitate an internal session, she did not hesitate. “Yes, I think I am about ready, because I already have the situation down,” she said. 

Her plans are specific. Beyond introducing more secure communication channels, she wants to close a gap that had been overlooked: two-factor authentication was required only of those holding the main accounts, and had never extended to interns and volunteers. “We really have to include it in our onboarding next time,” she said. 

The focal point from Myanmar plans to run tutorial sessions for her colleagues and volunteers, including the password management she learned at this training and set up for herself that same night. LJ is planning internal training for his entire staff, and deliberately wants to invite representatives from other organisations to sit in. AC is starting from mapping. “We want to do a more comprehensive risk assessment first, look at what they actually need, and only then build a more concrete action plan,” he said. 

“The commitment of each individual will become an obstacle, because we have everyday tasks,”

The Obstacles They Name Themselves 

What makes these plans credible is that the focal points are equally clear-eyed about what stands in the way. 

For LJ, the first obstacle is funding, because his institution is small and improving digital infrastructure carries recurring costs. But she named a second obstacle that is harder to measure. “The commitment of each individual will become an obstacle, because we have everyday tasks,” he said. When there is a picket to document that same day, the internal training schedule is the first thing to move. 

For GL, the obstacle is more basic still: the quality of internet connections across their regional offices, which makes some of the more secure applications impractical for daily use. For AC, the challenge is scale, with only around 20 office staff but hundreds of beneficiaries outside. 

None of these obstacles is solved by a five-day training. But naming them openly is part of the work itself, and it is exactly where four months of accompaniment finds its purpose.

Protecting Those Who Protect 

DF, a focal point from a regional youth network organisation, closed her reflection with the line she intends to bring home to her colleagues. “Do you realise we are not as safe as we think? Our information is highly accessible to anyone with bad intentions towards us.” 

For LJ, the reason returns to the most basic premise of their work. “While we are securing the rights of other people, we also need to secure ourselves against those threats,” he said. “We need collective care and security in order to persist, in order to become resilient, in order to do our daily jobs without worrying so much.” 

This is what it actually means for a focal point to stand at the front line. Not because they are the most technically skilled person in the organisation, but because they are willing to be the first to raise the issue, and to keep tending to it long after the training ends. 

 

About the Young Tech Collective (YTC) 

As DDI’s non-financial support mechanism, Tifa implements YTC together with DDP to address the pressing needs of civil society organisations (CSOs), which often face limited resources and technical capacity in digital protection. Field experience shows that one-off training is frequently not enough: knowledge gained in the classroom rarely survives the return to daily work routines, and the security practices introduced are easily abandoned when no further accompaniment follows. Adopting a holistic, community-based and intersectional approach, YTC therefore provides four months of accompaniment designed around each partner organisation’s contextual risk profile, facilitating them to strengthen their holistic security capacity through a series of trainings, the strengthening of technological infrastructure and internal policy, and mentoring. The programme currently works with 13 organisation CSOs across Southeast Asia. Through this process, focal points connect with a network of young tech activists in the region and become part of the digital protection infrastructure for civil society. 

Written as part of the learning documentation for the Young Tech Collective (YTC), a non-financial support mechanism under the framework of the Tifa Foundation’s Digital Democracy Initiative (DDI). 

Scroll to the top