Last reviewed: Next review due:
Why institutional security matters
Individual journalists can adopt excellent personal security practices, but this is undermined if the newsroom around them has no security culture. A journalist’s secure Signal communications are compromised if their editor discusses the source on an unencrypted work email. A journalist’s encrypted device is less useful if their source documents are stored in a shared Google Drive with no access control. Security is a system, not a collection of individual choices.
Building newsroom security capacity is also a legal and ethical obligation. PACE and the IPA 2016 give law enforcement tools to compel information from newsrooms. A newsroom that has not thought about its security posture in advance is poorly placed to respond to a production order or an incident.
Core policy elements
A written policy covering how journalists handle confidential sources: approved communication channels, how source identities are recorded (or not), who has access to source information, and how sources are notified in an incident.
Minimum standards for staff devices: full-disk encryption required, approved password manager, 2FA mandatory on all work accounts, clear policy on using personal devices for work with sensitive sources.
A written plan that covers: who to contact when a journalist believes their device or accounts are compromised; who has authority to engage external specialist support; how sources are notified; the editor's role; and legal escalation procedures.
A documented procedure for how the newsroom responds to production orders, RIPA s.49 key disclosure demands, and court orders seeking source information. Must be agreed with legal counsel in advance.
A regular (at minimum annual) security training programme for all journalists covering their beat-appropriate tools and scenarios. New hires should receive security induction as part of onboarding.
Training resources
Red flags in newsroom security culture
- No written source protection policy — security decisions are made ad hoc under deadline.
- Sensitive source information discussed in newsroom-wide Slack channels or unencrypted email.
- No defined procedure for responding to a production order or legal demand.
- No training budget for digital security — tools are adopted without understanding.
- Security is treated as IT's job, not editorial leadership's responsibility.
- No one has responsibility for owning and updating the security policy.
Newsroom security policy checklist
- We have a written source protection policy that all journalists have read.
- We have minimum device security standards (encryption, 2FA, password manager) documented and enforced.
- We have a written incident response plan covering device compromise, account takeover, and legal demands.
- We have identified who journalists should contact in a security emergency — internal and external.
- We have a documented legal demand procedure agreed with legal counsel.
- We provide security training at onboarding and at least annually thereafter.
- We have a named owner for the security policy who is responsible for keeping it current.
- We have considered whether a SecureDrop or equivalent is appropriate for our newsroom.
Source protection tools
Use our source protection checklist to baseline your newsroom’s current posture.
Source Protection ChecklistCommon mistakes
- Treating security as a one-time project rather than an ongoing practice.
- Delegating security entirely to IT — security policy decisions are editorial decisions.
- Security policies that are too complex for journalists to follow under deadline — friction causes abandonment.
- No budget for security — treating free tools as sufficient for all scenarios.
- Not testing the incident response plan before an incident happens.
Related guides
Primary sources
Frequently asked questions
What is the minimum viable security policy for a small UK newsroom?
How much should a newsroom budget for digital security?
Does my newsroom need to appoint a dedicated security person?
How do I balance security training with newsroom workflow?
Related guides
Primary sources
- Cyber Security for Small Organisations— National Cyber Security Centre
- Security Training for Journalists— Freedom of the Press Foundation
- Surveillance Self-Defence: Journalist Playlist— Electronic Frontier Foundation
- Digital Security Helpline— Access Now
- Journalist Safety Resources— Reporters Without Borders
- Journalist Security Guide— Committee to Protect Journalists
- Guide to UK GDPR for Organisations— Information Commissioner's Office