Skip to content
Saturday, August 29, 2026
PUBLIC MEDIA REVIEWPUBLIC INTEREST MEDIA · INNOVATION
S&P 500−0.35%FTSE 100−0.17%Euro/Dollar+0.22%Brent Crude+1.25%10-Year US+1.40%
PUBLIC MEDIA REVIEWPUBLIC INTEREST MEDIA · INNOVATION
Home / Journalism
Journalism

A Digital-Security Baseline Every Reporter Can Run in a Week

Full anonymity is a specialist skill; the baseline is not — device updates, a password manager, two-factor hardware, encrypted source channels, and a threat model written on one page.

RM
Rosa Marchetti, · May 20, 2026 · 4 min read
ShareXFacebookLinkedInTelegramEmail
Close-up of a hand attaching a security key to a laptop USB port

A working digital-security baseline for a reporter is five things, achievable in a week: updated devices, unique passwords in a manager, two-factor authentication with a second factor that is not a text message, an encrypted channel for sensitive sources, and a one-page threat model naming what the reporter is actually protecting and from whom. The Committee to Protect Journalists' safety guides and thefreedom.press digital security training materials — the standard references in the field — organize everything around that last document, because security without a threat model is a collection of apps.

What is the threat model and why does it come first?

It is one page answering four questions: What am I protecting (source identities, unpublished material, my own location)? From whom (a lawsuit-seeking attorney, an aggressive official, a stalker, a state actor)? How likely is each? And what happens if I fail? A local court reporter covering the school board faces subpoenas and records seizures, not nation-state hacking — a locked-down phone matters less than a clean legal separation between notes and personal devices. An investigative reporter with sources inside an organization faces the reverse. Security choices that do not follow from this page are theater, and expensive theater wastes the attention a small newsroom cannot spare.

What does the week look like?

A practical schedule used in newsroom security trainings:

DayAction
1Update every device and operating system; enable automatic updates
2Adopt a password manager; migrate the accounts that matter first — email, primary social, banking
3Turn on two-factor everywhere, preferring an authenticator app or hardware key over SMS
4Full-disk encryption on laptop and phone (built into modern systems, often just a switch)
5Set up one encrypted source channel — a tips system with end-to-end encryption — and publish the address
6Backups: automatic, encrypted, tested by restoring one file
7Write the threat model; book a six-month review

What protects sources specifically?

Layered habits rather than any single tool. Metadata minimization: don't log what you don't need — turn off message-history settings that hoard years of conversation. Communication discipline: agree with each sensitive source how you will and will not communicate, in writing, before the first substantive contact. Data separation: unpublished notes live in one place with its own authentication, not scattered across email threads. And the legal layer, which no app replaces: know your jurisdiction's shield-law protections and their limits, and decide in advance — with the outlet's editor and, where possible, counsel — how the newsroom responds to a subpoena, because the response drafted in calm weather is the only one that will hold in a storm.

What should a small newsroom standardize?

Security that depends on individual enthusiasm decays with staffing changes. Standardize the cheap, universal layer: the access manager and two-factor for every work account, automatic updates, full-disk encryption, one approved encrypted tips channel published on the site's contact page, and a short written standard — a page — that new hires read on day one. Then invest individually only where the threat model says it matters: the reporter on the police accountability beat gets the specialist training; the society page does not.

What are the failure modes?

Two recur. Tools-first drift: adopting every recommended app until the reporter can no longer get into her own accounts — usability failures are the most common security failures at small outlets. And the perfection freeze: deciding that since total security is impossible, nothing will be done. The baseline exists precisely against that conclusion — it is not armor against every adversary, it closes the doors that are trivially open, and it does so in a week.

Frequently asked questions

Are mainstream messaging apps safe for sources?

Apps with end-to-end encryption by default protect message contents; they still hold metadata. For sources whose risk is identification, use a channel with minimized metadata — and, always, one the source is comfortable using, because security the source cannot operate fails.

Should reporters use a VPN?

For most local work, a reputable VPN is optional; device encryption and account security matter more. A VPN earns its keep on public networks and when hiding network origin from the sites visited is part of the threat model.

What if the newsroom has no IT staff?

The baseline was written for that case: every item is a consumer-grade setting or service. The six-month review can be a single afternoon with the free training materials from press-freedom organizations.

Frequently Asked Questions

Are mainstream messaging apps safe for sources?
Apps with end-to-end encryption by default protect message contents; they still hold metadata. For sources whose risk is identification, use a channel with minimized metadata — and always one the source can operate, because security they cannot use fails.
Should reporters use a VPN?
For most local work, a reputable VPN is optional; device encryption and account security matter more. A VPN earns its keep on public networks and when hiding network origin is part of the threat model.
What if the newsroom has no IT staff?
The baseline was written for that case: every item is a consumer-grade setting or service, and the six-month review is a single afternoon with free training materials from press-freedom organizations.