Skip to main content

Digital Security Toolkit for UK Journalists

Practical, proportionate digital security guidance for UK journalists. Protect your sources, harden your devices, communicate securely, and know what to do when things go wrong.

Last reviewed: Next review due:

General guidance, not professional security advice. This information is intended for educational purposes. For high-risk threat models involving state actors, organised crime, or serious physical danger to sources, consult a qualified digital security professional. The Access Now Digital Security Helpline provides free, confidential support to journalists and activists.

Start here

Digital security is not about paranoia — it is about proportionality. The right starting point is always your threat model: who might want your data, what they could do with it, and what it would cost them to get it. Everything else follows from that.

New to digital security? Read threat modelling first, then encrypted messaging. Covering a sensitive story right now? Go to the Crisis Response Playbook or Secure File Sharing.

On this page

15 Digital Security Guides

Every guide includes a plain-English explanation, a practical checklist, red flags, common mistakes, primary source links, and FAQs.

Threat Modelling for UK Journalists
Assess realistic threats proportionately — commercial, criminal, state-actor — before choosing your tools.
Encrypted Messaging
Signal, ProtonMail, Wire, and when WhatsApp is not enough for source communications.
Secure File Sharing
SecureDrop, OnionShare, Magic Wormhole, and encrypted USB sticks for sensitive material.
SecureDrop for Newsrooms
What SecureDrop is, the cost and complexity, and alternatives for smaller newsrooms.
Device Security
Full-disk encryption, strong passphrases, secure boot, and the case for a dedicated source phone.
Password Managers & 2FA
1Password, Bitwarden, KeePass, YubiKey, TOTP — and why SMS 2FA is not good enough.
VPNs & Tor
When each helps, UK-relevant audit-verified VPN providers, and combining VPN with Tor.
Metadata & Document Cleaning
EXIF data in photos, Word/PDF metadata, redaction failures, and a proper cleaning workflow.
Cloud Storage Risks
iCloud, Google Drive, OneDrive, production orders, and zero-knowledge alternatives.
Travel Security & UK Border
Schedule 7 powers, clean-device strategy, and NUJ advice for border crossings.
State-Actor Threats
Investigatory Powers Act 2016, RIPA, recognising surveillance indicators, CHIS authorisations.
Social Engineering & Phishing
Fake editor emails, spoofed sources, SIM-swap risks, and verifying unusual requests.
Harassment & Doxxing
Practical response when personal details are published, IPSO routes, and physical security.
Crisis Response Playbook
What to do if compromised: first 24 hours, evidence preservation, notifying sources, editor roles.
Newsroom Security Policies
Building team capacity, incident response plans, training resources, and budget allocation.

Useful Tools

These tools in our toolkit are directly relevant to digital security practice.

Frequently Asked Questions

Do UK journalists really face digital security threats?
Yes. UK journalists face a spectrum of threats depending on their work. Investigative reporters covering organised crime, corporate fraud, or government corruption face risks from commercial actors willing to use private investigators, malware, or social engineering. Those covering terrorism, intelligence, or foreign state actors face more sophisticated threats. Even reporters covering local government or sensitive social issues may have their phones or laptops examined at UK borders under Schedule 7 of the Terrorism Act 2000. Good digital security is proportionate to your threat model, not one-size-fits-all.
Is Signal really secure enough for sources?
Signal is the gold standard for encrypted messaging for journalists. It uses end-to-end encryption with open-source, independently audited code. Messages cannot be read in transit even by Signal itself. However, Signal is not magic: your device's physical security matters, disappearing messages should be enabled for sensitive conversations, and sources should understand that metadata (who you contacted, when) may still be visible to network observers in some threat models. For extremely high-risk sources, consider SecureDrop over Tor instead.
What is Schedule 7 of the Terrorism Act 2000?
Schedule 7 gives police and border officers at UK ports and airports the power to stop and examine any person to determine whether they are or have been involved in the commission, preparation, or instigation of acts of terrorism. Crucially, they do not need to have any suspicion. Journalists can and have been stopped under Schedule 7 and had their devices examined or seized. The NUJ has guidance on this. Travelling with a clean device and leaving sensitive material encrypted and off-device is prudent for journalists covering certain topics.
What is the difference between a VPN and Tor?
A VPN (Virtual Private Network) encrypts your traffic and hides your IP from the sites you visit, routing it through a server run by the VPN provider. The provider can see your traffic. Tor routes your traffic through three volunteer-operated nodes, with encryption at each hop — no single node can see both who you are and what you are doing. Tor is slower but provides stronger anonymity. A VPN is good for hiding your activity from your ISP or casual observers; Tor is better for high-anonymity browsing or accessing .onion sites like SecureDrop.
What should I do if I think my device has been compromised?
Do not use the device for any sensitive communications. Do not delete anything — preserve it as evidence. Disconnect from Wi-Fi and mobile data. Contact your editor and legal team immediately. For serious suspected compromises (e.g., state-actor spyware such as Pegasus), contact the Access Now Digital Security Helpline or a specialist security consultant. Do not attempt to 'clean' the device yourself — a forensic image should be taken first. Notify any sources who may have communicated with you via the device.
Do I need to use all of these tools?
No. Proportionality is the key principle. If you are a local reporter covering planning disputes, you probably do not need SecureDrop. If you are working on a story involving organised crime or intelligence agencies, basic tools are not enough. Start with your threat model — who might want your data, what they could do with it, and what it would cost them to get it. Then choose tools that match that risk level. The threat modelling guide on this hub is the right starting point.

Protect your sources. Secure your work.

Use our Source Protection Checklist to assess whether your current security setup is adequate for your next story.