Five moves that protect the story and the source.
Cybersecurity for reporters, in plain language. You are not the target; you are the route to the target. Your security protects the person who trusted you, not just your own inbox. Do these five today; the full field guide handles the rest.
Five moves, matched to your risk.
- 01
Name your adversary before you buy anything
Start hereThreat-model in four questions: what are you protecting, who wants it, how bad if they get it, and what will you actually do. A protocol you abandon in week two protects nobody.
- 02
Order two security keys
CriticalPhishing-proof, hardware two-factor. When Google issued keys to 85,000 staff, successful account phishing dropped to zero. Buy two: one on your keyring, one in a drawer.
- 03
Guard your email like the master key
CriticalA password manager for unique logins, and get email off SMS codes. Whoever holds your inbox can reset almost everything else you own.
- 04
Treat metadata as the evidence
CriticalEncryption hides what you said, not that you said it. Use Signal, configured; and for the things that would end someone, meet in person. The pattern of contact is the case.
- 05
Sanitize documents before you publish
HighStrip metadata from files, and redact by deleting text, not drawing a black box over it. Assume the leaked file is watermarked: publish the information, not the artefact.
From five moves to the whole playbook.
- 27 chapters written for reporters and their sources.
- 10 step-by-step how-tos: security keys, encrypted containers, redaction, and a self-dox audit.
- 3 risk-tier checklists, from General Reporter to High-Risk Investigation.
- A 24/7 help directory for when something is already going wrong.
Buy once, download instantly, keep it for good. Read on any device, or print it.
Full Guide Coming Soon Or take the free one-pager Coming SoonThis isn't hypothetical.
The Pegasus Project: reporters' iPhones were infected by zero-click spyware. The sources were the real objective.
Reality Winner was charged within days. Investigators used printing records and email trails; nothing was decrypted.
Google issued hardware keys to 85,000 staff - successful phishing dropped to zero.
Quick questions.
Is the one-pager really free?
Yes. The one-page PDF downloads instantly - no card, no signup.
What format is the guide?
A designed PDF you can read on any device, print, or store in an encrypted container. Yours to download the moment you buy.
I'm not high-risk. Is this overkill?
No. It starts by helping you right-size your effort, so a general reporter isn't running a war-correspondent setup.
Does encryption alone keep a source safe?
No - and the guide is blunt about it. Metadata and contact patterns often matter more, which is why they get their own chapters.