You Can’t Download Resilience: Building Digital Resilience Has to Be Grown, Not Installed

Maps of some region in Southeast Asia, showing about digital civic space's threats in each region. This is part of the workshop at the Young Tech Collective On-site Training.
Workshop Session at the Young Tech Collective On-site Training

You Can’t Download Resilience: Building Digital Resilience Has to Be Grown, Not Installed

Every time a digital security training is held, a classic question almost always arises in the minds of the participants: “Is the gadget I am using safe? Which app is the safest to use?” 

This question is entirely understandable. As digital platforms now serve as the lifeblood of advocacy for activists, journalists, and community organisers, the same cyberspace has also become a hunting ground for surveillance and repression. It is only natural to crave a quick fix, a supposedly foolproof solution. Advice often sounds the same: get the best VPN, switch to encrypted chats, or lock down your account settings. 

Yet, can digital security truly be reduced to just swapping one app for another? 

This mindset was thoroughly challenged at the Young Tech Collective (YTC) onsite training in late May 2026 in Kuala Lumpur, where 20 Focal Points from across Southeast Asia gathered. YTC, as part of the Digital Democracy Initiative (DDI) led by the Tifa Foundation and Digital Defenders Partnership (DDP), set out to show that digital resilience is not something you can download. Instead, it must be cultivated from within the very heart of an organisation.

"It is like wanting a single silver bullet for everything."

The Trap of “Instant Solutions” 

The myth of instant digital security was stripped away from day one. RS, one of the facilitators from the Digital Defenders Partnership (DDP), explained that the expectation of a “magic solution” is the biggest challenge frequently encountered in the training room. 

“Usually, the common assumption among participants when they come to a training is that they want to be able to apply something immediately, they want tools right away,” RS said. “It is like wanting a single silver bullet for everything. In reality, the approach should be based on measuring their own capacities and understanding their specific risks. Security must be grounded in the needs and contextual conditions of each organisation.”

When digital security is mistaken for a single “safe zone” reached by simply switching apps, disappointment is almost inevitable. Participants may light up with excitement in the classroom when they discover a shiny new tool, but back in the real world, that app often gathers dust, too complex, too demanding for their devices, or simply out of reach for the communities they serve. 

That is why YTC chooses a four-month intensive mentoring journey instead of a one-off workshop. The aim is to nurture awareness and skills slowly, allowing them to take root and flourish over time. 

How the Method Works 

In concrete terms, the YTC method runs as a single connected cycle rather than a series of standalone sessions. Each partner organisation first completes a risk assessment that maps the threat profile specific to its own context, and it is that assessment which determines the content of the accompaniment, not the other way around. From there, every focal point develops an action plan that is deliberately pushed to be broken down to a level that can actually be implemented, ranging from securing social media accounts and managing access rights to shared documents, to onboarding and offboarding protocols for staff, volunteers and interns, and the drafting of internal security policy. That plan is then accompanied over the following four months through mentoring sessions, regular check-ins, and support to strengthen technological infrastructure. In this way, the five days in Kuala Lumpur serve as a measurable starting point rather than the end of the process.

The Foundations of Holistic Security 

DDP’s approach within YTC weaves security into an interconnected ecosystem, where three dimensions fit together like puzzle pieces, rather than existing as isolated training modules: 

  • Physical Security: Protecting the body, workspace, and physical documents from risks such as raids or detention. 
  • Digital Security: Protecting information and communication by identifying what data is most sensitive, where it is stored, and who holds access. 
  • Psychosocial Security: Protecting mental health and emotional capacity so that human rights defenders can sustain their work over the long term without burning out. 

These three dimensions are inseparable. Even the most advanced password manager or layers of encryption are powerless if an organisation’s staff is worn down by exhaustion and unable to think clearly. On the other hand, the strongest physical safety measures will spring leaks if trust does not bind the team together.

“When they realise their password is not secure ... we do not need to blame them or amplify the mistake,”

Restoring Control Without Judgment 

A standout feature of this training is how it gently eases the panic that can set in when participants discover just how many vulnerabilities lurk in their devices. RS explains that facilitators must strike a careful balance when discussing threats, steering clear of fear-mongering and empowering participants instead. 

“When they realise their password is not secure because it is recycled across multiple platforms, we do not need to blame them or amplify the mistake,” RS noted. “Let them know that this is a common practice that many people do. Only then do we help them see that they have full control to fix it using features that are already available, such as enabling two-factor authentication (2FA).” 

Ultimately, digital security is not defined by the latest or most advanced app on our devices. True security is a living process of becoming safer, starting with the resources at hand, the capacities we nurture, and the shared habits we intentionally grow within our organisations.

About the Young Tech Collective (YTC) 

As DDI’s non-financial support mechanism, Tifa implements YTC together with DDP to address the pressing needs of civil society organisations (CSOs), which often face limited resources and technical capacity in digital protection. Field experience shows that one-off training is frequently not enough: knowledge gained in the classroom rarely survives the return to daily work routines, and the security practices introduced are easily abandoned when no further accompaniment follows. Adopting a holistic, community-based and intersectional approach, YTC therefore provides four months of accompaniment designed around each partner organisation’s contextual risk profile, facilitating them to strengthen their holistic security capacity through a series of trainings, the strengthening of technological infrastructure and internal policy, and mentoring. The programme currently works with 13 organisation CSOs across Southeast Asia. Through this process, focal points connect with a network of young tech activists in the region and become part of the digital protection infrastructure for civil society. 

Written as part of the learning documentation for the Young Tech Collective (YTC), a non-financial support mechanism under the framework of the Tifa Foundation’s Digital Democracy Initiative (DDI). 

Scroll to the top