The Hague releases free cybersecurity blueprint for cities worldwide

The Hague and Protect.ngo have published a free, open framework to help municipalities build cybersecurity support networks for civil society organisations.

A bright modern control room features a large video wall displaying blue and green code, rows of white desks with multiple computer monitors, black office chairs, and file cabinets, illuminated by overhead linear lights.

The City of The Hague and international non-profit Protect.ngo have jointly released a free Cybersecurity Blueprint for Civil Society, a practical guide designed to help municipalities worldwide replicate The Hague's model of community-level digital resilience support. The launch was timed to coincide with the opening of Cybersecurity Week on 2 October 2026.

The blueprint draws on a programme that The Hague has operated since 2023, which began by supporting humanitarian NGOs and has since expanded to cover charities, sports clubs, neighbourhood organisations and volunteer-led foundations. The guide is intended as an adaptable open resource rather than a fixed model, encouraging cities to tailor the framework to local partnerships, volunteer networks and community structures.

What the blueprint covers

At its core, the framework provides guidance on three areas: forming partnerships between local government and cybersecurity professionals, recruiting and organising volunteers, and building sustainable support structures for smaller civil society bodies that typically lack dedicated IT staff or security budgets. The blueprint does not mandate a single implementation path, which is both its strength and its principal limitation; outcomes will vary considerably depending on how much local capacity municipalities can mobilise.

The Hague Humanity Hub, a coalition of nonprofits focused on peace and sustainability, is cited as a concrete example of the programme's impact. The Hub is reported to have nearly quadrupled its cybersecurity assessment score since joining the scheme, reflecting measurable improvement in its digital resilience posture. The release does not specify which assessment framework was used, nor the absolute starting or finishing scores, so independent benchmarking is not possible from the available information.

Richard de Mos, Alderman for Economic Affairs and Cybersecurity at the City of The Hague, said: "Local businesses, charities, sports clubs and community organisations are the backbone of every city. They should be able to focus on what they do best, not on defending themselves against increasingly sophisticated cyber threats."

Market and regulatory context

Civil society organisations sit in a difficult position in the cybersecurity landscape. They are frequently targeted by state-aligned threat actors and ransomware groups precisely because they hold sensitive beneficiary data, operate internationally and historically under-invest in security controls. Yet they fall outside most mandatory frameworks: the EU's NIS2 Directive, which entered force across member states from October 2024, covers essential and important entities in sectors such as energy, health and digital infrastructure, but does not extend obligations to the voluntary sector.

Protect.ngo, formerly known as the CyberPeace Institute, has built a model that bridges this gap by aggregating pro-bono expertise from the private sector and channelling it into structured capacity-building programmes. A number of other initiatives pursue similar goals, including the Global Cyber Alliance's free toolkits for civil society and the Cybersecurity Tech Accord's work with smaller organisations, but municipal-level coordination at the scale The Hague is now advocating remains relatively rare.

From a policy standpoint, the blueprint aligns with the European Commission's broader push to extend cybersecurity awareness beyond regulated industries, and with ENISA's ongoing guidance on digital resilience for public-interest bodies. Cities looking to adopt the framework will need to navigate local data-protection rules when volunteers handle assessments of third-party organisations, a compliance consideration the blueprint should address in subsequent iterations.

The Hague is positioning this release as the start of an international movement rather than a one-off publication. Whether other city governments commit resources to replicate the model will be the key measure of its reach over the next twelve months.