Skip to main content

Crisis Response Playbook

When you believe your device or accounts have been compromised, the decisions you make in the first few hours matter enormously. This playbook provides a structured response process.

General guidance, not professional security advice. For high-risk threat models involving state actors or organised crime targeting, consult a qualified security professional or the Access Now Digital Security Helpline immediately.

Last reviewed: Next review due:

The first 24 hours

Hour 1: Stop & isolate

  • Stop using the suspected compromised device for any sensitive communications immediately.
  • Disconnect it from Wi-Fi and mobile data to prevent ongoing exfiltration.
  • Do not delete anything — preserve the device as evidence.
  • Do not attempt to "clean" the device yourself.

Hours 1–3: Notify

  • Contact your editor and senior management — do not handle this alone.
  • Contact the NUJ legal team if you are a member.
  • Contact the Access Now Digital Security Helpline for specialist triage.
  • Identify which sources may have communicated with you via the compromised device or account.

Hours 3–8: Source notification

  • Notify sources who communicated via the compromised channel — they need to know their identity may have been exposed.
  • Use a clean device and a secure channel (Signal from a different device) for these notifications.
  • Do not tell sources more than they need to know — keep notifications brief and factual.

Hours 8–24: Evidence and containment

  • Work with a specialist to forensically image the compromised device before any wipe.
  • Change passwords on all accounts from a clean device, prioritising email, cloud storage, and social media.
  • Revoke all active sessions on compromised accounts.
  • Enable the strongest available 2FA on all accounts from the clean device.

When this matters most

  • 1You have received an unexpected password reset email or login alert for an account you did not access.
  • 2A source tells you that something they only shared with you has become known to the story subject.
  • 3You have clicked a link or opened an attachment you now believe may have been malicious.
  • 4Your device has been seized at a border or by police.
  • 5You have received a legal demand for source information (production order, RIPA s.49 notice).

Red flags suggesting serious compromise

  • Information shared privately has appeared in the hands of story subjects or third parties.
  • Multiple accounts are showing unusual login activity simultaneously.
  • A source has been approached by people who knew details of their confidential contact with you.
  • You have received a legal demand that references information that was not publicly available.
  • A known malicious actor (linked to a story subject) has unusual insight into your unpublished work.

Crisis response checklist

  • I have stopped using the compromised device and disconnected it from networks.
  • I have not deleted anything from the compromised device.
  • I have notified my editor and senior management.
  • I have contacted the NUJ legal team (if a member) or a media lawyer.
  • I have contacted the Access Now Digital Security Helpline for specialist triage.
  • I have identified and notified sources who communicated via the compromised channel.
  • I am using a clean device for all post-incident communications.
  • I have changed passwords and revoked sessions on all accounts from the clean device.
  • I have a forensic image or specialist involvement before wiping the compromised device.

Story risk register

Log security incidents alongside editorial risks using our story risk register.

Story Risk Register

Common mistakes

  • Wiping the device immediately — destroying forensic evidence of the compromise.
  • Continuing to use the compromised device while investigating — allowing ongoing exfiltration.
  • Not notifying sources — their safety may depend on knowing promptly.
  • Trying to resolve the incident alone without specialist help.
  • Complying with a legal demand for source information without taking legal advice first.

Related guides

Primary sources

Frequently asked questions

How do I know if my device has been compromised?
There is often no clear indicator. Some warning signs: unexpected battery drain; elevated data usage you cannot account for; apps crashing more than usual; the device becoming hot when idle; unusual account activity (logins from unexpected locations, password reset emails you did not request); or being told by a source or colleague that information you shared privately has leaked. None of these is definitive — contact a specialist if you have serious concerns.
Should I wipe a compromised device immediately?
No. Wiping a device destroys forensic evidence that could help identify what happened, who did it, and the extent of the compromise. Before any wipe, the device should be forensically imaged by a specialist if possible. If that is not feasible, at minimum document what was on the device and what you know about recent activity. Only after this should you consider wiping.
When should I involve legal counsel in a digital security crisis?
Immediately if: you have received a legal demand (production order, RIPA s.49 key disclosure notice, court order); you believe the compromise may be connected to a story subject who could use the information against you legally; or you intend to pursue civil or criminal remedies. Do not comply with any legal demand without taking legal advice first. Contact the NUJ legal team if you are a member.
What is the editor's role when a journalist is compromised?
The editor's role includes: ensuring the journalist gets specialist support (legal and technical); assessing which sources and stories may be affected and taking steps to protect them; deciding whether and how to report the compromise publicly; liaising with legal counsel; and managing the editorial and reputational implications. Editors should not attempt to resolve a serious digital security crisis without specialist help.