Skip to content
All guides and resources
Free guide

Security guide for independent journalists

Protect your reporting, your sources and the publication you depend on. A practical starting point for solo journalists and small newsrooms, with steps you can take today and a plan for when something goes wrong.

By OpsHelpUpdated 10 min readNo email wall

Start here

Your first hour: protect the keys to your publication

  • Secure your main email and domain account with unique passwords and the strongest sign-in protection they support.
  • Save recovery codes somewhere you can reach if your phone or laptop is lost.
  • Install pending device updates and check that disk encryption is enabled.
  • Restore one file from a backup, and write down who you would contact during an incident.

01

Start with your reporting and your risks

A local reporter facing account harassment needs a different plan from someone receiving documents from a source under surveillance. Start with the next assignment, not a shopping list of security products.

Write down the information that could hurt someone if exposed: source identities, unpublished notes, location history, reader records and access to your publishing accounts. Record where it lives and who can reach it. Keep that assessment private.

For each item, choose a realistic problem to prepare for. Could a stolen phone expose a conversation? Could an ex-contributor still publish? Could somebody reset your website password through your email? Pick an action, an owner and a date for the highest-impact gaps.

The Electronic Frontier Foundation’s security-planning guide is a useful framework. Revisit your plan before a sensitive investigation, travel or a change of staff. If a source could face detention, violence or serious retaliation, arrange specialist advice before collecting their material. This guide is a baseline, not a complete plan for targeted surveillance.

02

Secure accounts and recovery routes

Start with the accounts that control everything else: your main email, password manager, domain registrar and hosting account. Then work through publishing, newsletter, payment and social accounts.

  1. Use a different, generated password for each account. Store passwords in a maintained password manager. Protect the manager with a strong master passphrase and its available sign-in protections.
  2. Use passkeys or hardware security keys where supported. They resist fake login pages better than codes you type into a website. Register a spare security key where possible and store it separately. If those options are unavailable, an authenticator app is a useful fallback; SMS is better than leaving a supported second factor off.
  3. Check recovery before signing out. Remove obsolete phone numbers and recovery addresses. Store backup codes securely outside the device you could lose. A recovery account needs protection too.
  4. Review active sessions and connected apps. Remove access you no longer recognise or need. Check email forwarding rules, delegated mailbox access and app passwords.

Give contributors individual accounts with only the permissions they need. Remove access when an assignment ends. Keep the domain registered to the publication or its owner, with renewal reminders and an up-to-date payment method.

For the wider account-security checklist, see the Committee to Protect Journalists’ digital safety kit. Practise recovering an account before you depend on that process during an incident.

03

Handle links, files and devices carefully

Journalists routinely receive documents from strangers. Treat a convincing invitation, legal threat or “new evidence” message as something to verify before signing in or opening an attachment.

Open a service through your saved bookmark or its app rather than a message’s login link. Verify an unexpected request through a contact route you already trust. A familiar display name, logo or polished writing does not establish who sent it. Do not approve an unexpected sign-in prompt or share a recovery code.

Never enable document macros, install a viewer or paste a terminal command just because a sender says it is needed to read a file. For sensitive suspicious attachments, get help with a separate analysis environment. Do not upload source material to a public malware scanner or online converter: that can disclose the document. EFF’s phishing guide explains the common traps.

Make a lost device less damaging

  • Keep the operating system, browser and applications supported and updated. Remove extensions and apps you no longer need.
  • Enable full-disk encryption and a strong device passcode. Check where the recovery key is stored. Encryption helps protect data on a locked or powered-off device; it does not protect files from malware while you are using them.
  • Use a short automatic screen lock and hide message previews on the lock screen.
  • Carry only the reporting material you need. Check whether cloud sync, downloads or offline folders have copied sensitive files onto a travel device.

Back up before changing encryption settings. EFF’s data-protection guidance covers encryption and the limits of relying on deletion alone.

04

Choose a safe way to speak to sources

Agree how to communicate before discussing the sensitive part of a story. Ask whether a source’s device, account or network is managed by an employer or shared with someone else. An encrypted conversation can still be exposed at either end.

Signal can be useful for conversations, but set it up deliberately. Review Settings → Privacy → Phone Number, use a username when you do not want to give a new contact your number, and check what your profile reveals. Usernames do not make a person anonymous, and people who already know your number may still connect it to you. See Signal’s phone-number privacy guidance.

For sensitive conversations, verify the contact through an independent trusted route and compare safety numbers. Review linked devices. Agree whether disappearing messages are appropriate for your reporting and record-keeping obligations; they do not stop screenshots, copying or a compromised device.

A tip line needs an operating process

An ordinary web form, email address or customer-support chat is not an anonymous submission system. It may retain IP addresses, message contents, notifications and backups. Do not promise anonymity on a contact page unless the whole process has been designed and assessed for it.

SecureDrop is built for newsrooms receiving sensitive submissions. Running it involves dedicated infrastructure, maintenance, trained staff and a safe document-handling workflow. A small newsroom may be better served by working with an established organisation that already runs a suitable intake system.

Publish clear contact instructions, including what the channel can and cannot protect. Keep source intake separate from newsletter sign-ups, public comments and business enquiries.

05

Control documents, sharing and backups

Keep a protected original of reporting material and make a separate working copy for editing or publication. Restrict source identities to the people who need them; avoid putting a name in every filename, calendar event or shared task.

Before publishing a document or image, check for names in metadata, tracked changes, comments, hidden spreadsheet tabs, location information and identifying details in the content itself. Drawing a black rectangle over text may leave the text underneath selectable. Use a proper redaction process, then check the exported result by searching and copying text as well as looking at it.

Ask a second person to review sensitive releases. Removing metadata cannot remove clues in writing style, document numbering or facts known to only one person.

Make recovery real

Keep an encrypted backup separate from your working account, with credentials an attacker cannot use just by taking over your laptop. Cloud sync alone is not a backup: deletion or unwanted changes may sync too.

For a publication, include the database, uploads, configuration and the instructions needed to restore them. Agree how much work you can afford to lose and how quickly you need to recover. Restore a sample regularly and record the result. A successful backup notification is not proof that a site can be rebuilt.

Set a retention schedule for source documents and reader exports. Include shared drives, old devices and backups in that policy. Do not improvise deletion during an incident or after a legal preservation request; get advice on what must be retained.

06

Keep your site and newsroom working

A publication depends on more than its web server. Make an inventory of the domain, DNS, hosting, content system, newsletter sender and payment provider. Record the owner, renewal route and support contact for each. Keep a copy reachable if the website or main email is unavailable.

For WordPress, keep core, themes and plugins updated and remove unused ones. Test significant changes on a private staging copy with outgoing email disabled. Give editors editorial permissions rather than administrator access. Restrict administrative access and use additional sign-in protection where your setup supports it.

Ask your host what happens during a traffic flood, a compromised administrator account and a failed update. Useful controls include caching, rate limits, access logs, monitoring and tested restoration. A firewall does not replace account security, and an uptime alert does not mean somebody is responding around the clock. Agree response hours and escalation separately.

For custom sites, make sure someone owns dependency updates, deployment access, secrets and recovery. A system that only its original developer can restore creates another point of failure.

Prepare a short status message and an alternative place readers can find it. Before publishing a contentious story, check backups and the support route, and agree who will watch comments and incoming reports. Avoid making infrastructure changes during the same window unless they are necessary.

07

What to do when an attack starts

Start with people. If there is an immediate physical threat, prioritise getting to safety and appropriate local help. For digital incidents, choose a response lead and move coordination to a device and account you believe are safe.

  1. Write down what you know. Record times, affected accounts, unexpected actions and any threats. Preserve relevant alerts, message headers and logs securely. Separate observations from guesses.
  2. Contain the affected access. For an account takeover, use a clean device to recover the account, change the password, revoke sessions and connected apps, and check recovery details and forwarding rules. A password change alone may not remove every access route.
  3. Treat a suspected infected device differently. Stop using it for reporting and recovery. Seek specialist guidance before resetting, wiping or powering it down; those actions can destroy evidence. If it is actively exposing data, isolate it from networks while arranging help.
  4. Bring in the right support. Contact your host for a site attack and the relevant provider for account recovery. Explain symptoms, timing and actions already taken. Ask for logs to be preserved before they expire.
  5. Assess who may be affected. Consider sources, colleagues and readers. Agree safe notification routes; avoid sending sensitive warnings through an account the attacker may control.
  6. Recover and verify. Close the entry point, restore from a checked backup if needed, rotate exposed credentials and test publishing, email and payments. Monitor for repeat access. Record what will change before normal work resumes.

For targeted digital attacks, Access Now’s Digital Security Helpline supports eligible civil-society users, including journalists. Use its current contact and eligibility instructions from a safe device.

If personal data may have been exposed

Assess the risk promptly and document the decision. Where UK GDPR reporting is required, notify the ICO without undue delay and, where feasible, within 72 hours of becoming aware of the breach. High risk to individuals may also require notifying them without undue delay. Use the ICO’s breach assessment and reporting guidance and get advice for your circumstances; do not wait for every fact before assessing your obligations.

08

Make security a routine

Put a short review into the publishing calendar. Assign it to a named person, even if that person is you.

Every week: install pending updates, check backup results and review important account alerts. Follow up on failures rather than letting them become background noise.

Every month: restore a sample, review staff access and connected apps, check domain renewals and confirm your emergency contacts still work.

Before a sensitive assignment: revisit the risk assessment, agree the source-contact route, minimise what is on your devices and plan who will help if something goes wrong.

Use this final checklist at your next editorial meeting:

  • The main email, domain and publishing accounts have strong sign-in protection and a usable recovery route.
  • Each contributor has their own account, and departing contributors have been removed.
  • Device encryption, updates and screen locks are in place.
  • Sources have clear contact instructions without an unsupported promise of anonymity.
  • Sensitive documents have an agreed storage, review and retention process.
  • Backups have been restored successfully, not merely created.
  • The response lead, support hours and escalation route are written down.

Save or print this guide using your browser if you need an offline reference. Keep passwords, recovery codes and source details in your secure records, not on a shared checklist.

Keep reading

Leaving Substack: a migration guide