Dunicot A cybersecurity consultancy and advisory firm.

Programme · EcoSecure

Security for the organisations protecting the planet.

Climate and conservation organisations hold data that powerful interests would prefer altered, discredited or read early, and they hold it on the budget of a charity. EcoSecure exists to close that gap.

The programme

EcoSecure is Dunicot’s dedicated programme for nature and climate-focused organisations: environmental NGOs, conservation trusts, climate research institutions, carbon registries, renewable energy operators, and the funders financing them.

It exists because this sector sits at an unusual intersection. The work produces findings with commercial and political consequence, which attracts adversaries far more capable than the organisation’s size would normally invite, while the security budget is whatever was left after the fieldwork. Standard commercial security scoping does not fit that shape, so this programme does not use it.

A research institute with twelve staff, holding data a state-linked actor wants, is not a small security problem. Programme rationale

Vision and goals

The aim is that an organisation working on climate or conservation can hold sensitive data, run a public platform and take on a well-resourced adversary without needing a security budget it will never have. Five goals carry that.

Programme goals

Scoping built for the sector
Testing scoped to the systems whose compromise would damage the mission, rather than to the full estate. A twelve-person research institute holding data a state-linked actor wants is not a small security problem, and is not priced as one.
Sustainable practice
Engagements run remotely by default, with travel only where terminal or on-site work requires it. The carbon cost of securing an organisation should not undercut what it is trying to protect.
Education and awareness
Training built around the lures this sector receives in practice, so staff and field teams recognise them. Delivered as part of the programme rather than sold separately.
A working ecosystem
Findings that affect shared platforms, coalition tooling or common suppliers are reported to everyone exposed, with consent, rather than stopping at the one client who paid.
Research that stays current
Time funded for tracking how adversaries target this sector, with what we learn published in the research section rather than kept as a sales advantage.

Where the programme is going: more organisations served each year, regional coverage from both offices so support sits in a workable timezone, and published sector research rather than private findings. We do not publish revenue targets, and none of the above is contingent on hitting one.

The threat model

This sector’s risks differ sharply from a bank’s or a SaaS platform’s, and the differences drive the scoping.

Sector-specific threats
RiskWhat it looks like in practice
Research data integrityQuiet alteration of measurements, models or historical series: the most damaging attack in this sector, because it discredits the work rather than stealing it
Pre-publication accessUnpublished findings read in advance by interests preparing to counter them, or to trade on them
Field-researcher safetyLocation data, communications and device contents exposing staff working in contested or hostile areas
Funder and grant systemsFinancial and reporting platforms holding grant flows, beneficiary data and disbursement authority
Carbon and credit registriesRegistry integrity, double-counting, and manipulation of issuance or retirement records
Operational technologySensors, monitoring stations, buoys and remote installations, often deployed for years without updates
Reputational attackWebsite and social account compromise used to publish retractions or fabricated positions
Supply chainShared platforms across a coalition, where the weakest member exposes the rest

What the programme includes

Assessment, scoped to consequence

Rather than pricing the whole estate, we identify the two or three systems whose compromise would damage the mission: the data platform, the grant system, the publication pipeline, and test those properly.

Field operations security

Device hardening, communications, data handling in the field, and a documented plan for what happens when a device is seized, lost or searched at a border.

Training and awareness

Delivered for people who are field scientists first and computer users second. Built around the actual lures this sector receives, not generic examples.

Incident support

Access to forensics and incident response without a procurement cycle, because a small organisation in an incident does not have weeks to arrange help.

Funder assurance

Documentation that satisfies institutional funders’ increasing security requirements, so security work supports grant applications rather than competing with them for budget.

How it is funded

Programme terms

Eligibility
Registered non-profits, research institutions, and mission-driven organisations in the environmental and climate sector
Rates
Reduced rates for registered non-profits and academic institutions
Scoping
Consequence-first: the systems that would damage the mission, not the full estate
Coalitions
Shared engagements across coalition members, splitting cost where a platform is shared
Confidentiality
Standard mutual NDA; we never name an EcoSecure client without written consent
Starting point
A free scoping conversation, tell us the budget and we will say what it buys

If the honest answer is that your budget does not cover what you need, we will say so and point you at what to do first for nothing. That is a better outcome than an engagement shaped to a number rather than to a risk.

Questions

Who is EcoSecure for?

Environmental NGOs, conservation trusts, climate research institutions, carbon registries, renewable energy operators and the funders behind them. Any organisation whose work produces environmental data, holds field-researcher information, or moves climate finance.

Are environmental organisations actually targeted?

Yes, and by unusually capable adversaries for their size. Organisations publishing findings that carry commercial or political consequence attract attention from interests those findings affect: including surveillance of staff, attempts to alter or discredit data, and access to unpublished research. The mismatch between the sophistication of the adversary and the security budget of the target is the gap this programme exists to close.

We have almost no security budget. Is this realistic?

That is the assumption the programme is built on. Engagements are scoped to the highest-consequence surface rather than the whole estate, training is prioritised over tooling because it costs less and lasts longer, and we offer reduced rates for registered non-profits and research institutions. Tell us the budget you have and we will tell you honestly what it buys.

Does field-staff safety fall in scope?

Where you want it to. Operational security for staff working in sensitive locations is a distinct workstream, and often the one with the most direct human consequence: device hardening, communications, data handling in the field, and what happens if a device is seized or lost.

Working in climate or conservation?

Start with a scoping conversation. Reduced rates apply for registered non-profits and research institutions.