Digital security for humans
We help nonprofits and small to mid-sized businesses build security systems, policies, and habits that actually stick—without the jargon and needless complexity.
Come to us when…
…or any other reason you're not confident your organization is ready.
It usually starts with a weak password, a click on the wrong link, or a document pasted into the wrong AI tool
Security incidents are rarely a technical failure. Far more often, they involve someone doing their job.
of breaches involve a person: someone clicked, was tricked, or sent the wrong thing to the wrong address1
of reported breaches happen to organizations with fewer than 1,000 staff, not to big companies1
of successful scams start somewhere other than email: a text, a phone call, a message1
of staff put work information into AI tools their organization never approved, three times more than last year1
What these numbers describe is people making mistakes in their day to day work — which policies, processes, and training can prevent.
- Verizon, Data Breach Investigations Report 2026. 22,000+ confirmed breaches across 145 countries.
What we do and what changes for you
Every engagement is different, but most are built from one or more of these.
Risk assessments
You know something needs attention but not what comes first. We look at your programs, tools, and habits, then hand you an action plan: where you're strong, where you're exposed, and what to do about it, in order of priority.
- You stop guessing: you know what to fix first, and what can wait
- You have an expert report to put in front of your board or funder
Policy development & compliance
Whether you have no policies or policies nobody follows, we write them with you, matched to how your team actually works and to the capacity you actually have, not to an idealized standard nobody could reach.
- Policies that fit your team, and that people actually use
- Written answers ready when a client, insurer, or funder asks
Implementation support
We train your staff, help you find secure alternatives to the tools you're using, and stay available for the questions that come up once people start working differently.
- Your team knows what to do without asking
- New staff arrive into a system rather than into folklore
Two ways to start
Most of our work runs over months rather than weeks, but you don't have to commit to that on day one.
A short assessment
We look at your programs, tools, and habits, then hand you a report and an action plan you can act on immediately—with or without us.
It's the simplest way to find out what you're dealing with, and to see how we work before committing to anything longer.
- Two to six weeks
- A focused piece of work, not a months-long project
- You keep the report and the plan either way
Ongoing support
Assessment, policy work, training, and hands-on help, in whatever mix your organization needs.
Habits take time to change. This is where policies get tested against real situations, staff build confidence, and new practices actually stick.
- Three months to start, then as long as you want
- Your team gets more capable — and less dependent on us — each month
- Hourly or retainer, whichever suits you
Most organizations start with the assessment, though it isn't required;if you've had one done recently elsewhere, we can pick up from there. We scope every engagement to what you actually need.
Free half hour consultation. No prep needed, and no sales pitch from us.
Security that people actually understand
The best security solutions are the ones people actually understand, trust, and keep using.
We're a small, focused team that believes digital security should be simple to follow and realistic to implement.
We are experts in digital security, but also in translating complex technical ideas into simple language and delivering training programs that achieve real behavioral change.
Our approach is shaped by years of delivering security programs in some of the world's most challenging environments, where getting security wrong isn't just an inconvenience: it carries life-or-death consequences. That work taught us to aim for security that just works, not security that looks perfect on paper.
How we think about security
Three principles behind every engagement.
Developing a security culture
We don't just recommend "secure" apps: those can become outdated or inadequate to address new threats. We build resilience at the organizational level: staff knowledge, skills, and adaptable processes and policies.
Security as a process
Rather than a checkbox to check once and for all, security is an ongoing journey. It requires building safe habits online, and real knowledge of what "secure" means for your specific needs and threats.
A collective effort
Our digital lives are so deeply intertwined that one person's decisions inevitably affect the digital security of their coworkers, friends, and relatives. Improving it requires working together.
Who you'll be working with
Meet the people who make up DigiSafe.
Free resources to get you started right now
Yours to use whether or not you ever hire us.
Find out where you stand, in five minutes
Answer sixteen questions and get your Digital Preparedness Level.
- Free
- No email required
- We never see your answers
Build safer habits, a little at a time
A free newsletter and library of guides in the same plain language we use in our work. Sign your team up, or start reading today.
Or browse the Privacy HubLet's talk
Book a free consultation
Grab half an hour in our calendar. Come as you are, no prep needed, and no sales pitch from us.
Find a timeDrop us a line
Tell us a bit about your organization and we'll get back to you within two working days.
hello@digisafeconsulting.comNeed to share something confidential? Keep the first message brief and we'll set up an encrypted channel before you share anything that matters. And we use Proton, so emailing us from a Proton account means your message is end-to-end encrypted.