2026 NGO-ISAC Annual Conference
Building Operational Resilience November 17, 2026 | Downtown NW Washington, DC
Registration is NOW OPEN!

The NGO-ISAC Annual Conference is the only national gathering dedicated exclusively to nonprofit cybersecurity: a full day of peer learning, practical sessions, and community connection for the people protecting mission-driven organizations. Join us this November for a program built by and for the nonprofit cybersecurity community.
This year's agenda is built around resilience -- with sessions spanning Personal Protection, Incident Response, and Organizational Security. This gathering is a unique opportunity to explore these topics together, with your peers. Bring your questions, bring what you've learned the hard way, and help build the kind of collective wisdom that makes all of us more resilient.
Deadline to register is Friday, October 30, 2026 or when we reach capacity at 150 attendees, whichever comes first.
Note: Attendance is free for current NGO-ISAC members. Please review the Eligibility Checklist before registering. Questions? Contact [email protected].

Why Attend
- Relevant, practical content. Every session is designed for the realities of nonprofit and NGO security work, from resource-constrained IT teams to enterprise-scale operations.
- A community that gets it. Connect with peers who understand the unique challenges of protecting mission-driven organizations.
- Sessions for every level. Whether you're building your first security program or leading a mature one, you'll find content that meets you where you are.
- Proven impact. 96% of past attendees said they were likely or very likely to apply what they learned directly to their work. 4.6 out of 5 overall satisfaction.
Sponsorship Opportunities
NGO-ISAC's Annual Conference is the only gathering in the US dedicated exclusively to nonprofit cybersecurity, and sponsorship is the only way for vendors and companies to take part this year. With four tiers ranging from Ally to Community Champion, there's an entry point for organizations of every size, and each tier includes attendance access for your team along with visibility in front of 200 nonprofit security practitioners, IT staff, and operational leaders.

Agenda & Speakers
We’re excited to share our preliminary list of our nine conference breakout sessions! Please keep in mind that this list is subject to change. Full session details and speaker bios will be published soon. The 2026 conference program is built through an open community proposal process.
- Don't Panic, Prioritize: A Threat Modeling Workshop - Prioritize your security to-do list with a hands-on card game. Build and customize your own threat model to protect what matters most.
- Prepare, Respond, Recover: Lessons from Real NGO Incidents - Build your incident "go-bag" before crisis hits, then learn from real NGO breaches, detection through recovery, what actually worked and what didn't.
- From Shadow AI to Sanctioned Use: Build Your Org's AI Policy - Build a lightweight AI policy your under-resourced nonprofit can actually use. Leave this hands-on workshop with a starter template, key questions, and practical language.
- Locked, Seized, Tracked: Mobile Device Security for High-Risk Moments - Learn how spyware and targeted surveillance actually get detected on mobile devices, and rethink your organization's approach to phone security, location tracking, and legal preparedness for high-risk moments.
- Data Retention in Practice: A Working Session - Hear how a half-day "Data Detox" turned data retention policy into practice, cleaned up accounts and access, and brought a virtual team together.
- Who’s got your back? An exercise in building community support networks - Build a personal support network before crisis hits. Walk away with a plan for who to call and lean on after harassment or doxxing.
- Build a Security Program: Right-Sized for Where You Are - Real stories and practical frameworks for building a security program from scratch, no dedicated staff or big budget required, tailored to your organization's size.
- Culture Eats Policy: Building Security People Actually Want - Exploring how organizations build a genuine culture of security through equity, joy, and practical buy-in strategies that people actually embrace.
- A Resilience Roadmap for Lean Security Teams - A panel walking through the full arc of resilience for lean security teams, from a maturity model for self-assessment to incident command, regulatory response, and the newest front in incident response, AI-specific threats.
Community Awards
This year we're recognizing folks across three categories: Emerging Expert, Knowledge Builder, and the Nick Levay Lifetime Achievement Award. Awards will be announced at the conference. If someone in this community has taught you something, shared a resource at just the right moment, or quietly made the sector safer through their work, this is your chance to say so. Self-nominations welcome and encouraged, don't be shy. Nominate here >>
Nominations close midnight, Oct 9.
Pre-Conference Workshop
We are hosting a special workshop on Monday November 16 Workshop titled “Evolving Threats: Doxxing and Swatting Incident Response Tabletop”. It will be facilitated by Tara Arthur (Collective Security Group), Shauna Dillavou (Brightlines), and Rachel Vrabec (Kanary). We encourage you to register as soon as possible since we have limited space.
When: Monday, November 16th from 12:30pm-4:30pm EST, in-person only Location: Washington D.C. (exact location to be disclosed to participants) Eligibility: Must be an NGO-ISAC member to attend Cost: Free
For general event inquiries, please contact [email protected].
Thank you to our sponsors!

|