Skip to main content

Newsroom Security Policies

Individual journalist security only goes so far. This guide covers how to build institutional capacity: training, incident response plans, budget allocation, and security governance for UK newsrooms.

General guidance, not professional security advice. For high-risk newsrooms dealing with state-actor or organised crime threats, consult a qualified security professional or the Access Now Digital Security Helpline.

Last reviewed: Next review due:

Why institutional security matters

Individual journalists can adopt excellent personal security practices, but this is undermined if the newsroom around them has no security culture. A journalist’s secure Signal communications are compromised if their editor discusses the source on an unencrypted work email. A journalist’s encrypted device is less useful if their source documents are stored in a shared Google Drive with no access control. Security is a system, not a collection of individual choices.

Building newsroom security capacity is also a legal and ethical obligation. PACE and the IPA 2016 give law enforcement tools to compel information from newsrooms. A newsroom that has not thought about its security posture in advance is poorly placed to respond to a production order or an incident.

Core policy elements

Source protection policy

A written policy covering how journalists handle confidential sources: approved communication channels, how source identities are recorded (or not), who has access to source information, and how sources are notified in an incident.

Device and account security standards

Minimum standards for staff devices: full-disk encryption required, approved password manager, 2FA mandatory on all work accounts, clear policy on using personal devices for work with sensitive sources.

Incident response plan

A written plan that covers: who to contact when a journalist believes their device or accounts are compromised; who has authority to engage external specialist support; how sources are notified; the editor's role; and legal escalation procedures.

Legal demand procedure

A documented procedure for how the newsroom responds to production orders, RIPA s.49 key disclosure demands, and court orders seeking source information. Must be agreed with legal counsel in advance.

Training programme

A regular (at minimum annual) security training programme for all journalists covering their beat-appropriate tools and scenarios. New hires should receive security induction as part of onboarding.

Training resources

Freedom of the Press Foundation
Free online courses and guides for journalists, covering device security, encrypted messaging, SecureDrop, and more.
Visit ↑
EFF Surveillance Self-Defence
Free, regularly updated guides tailored to journalists, activists, and at-risk individuals.
Visit ↑
Access Now Digital Security Helpline
Free, confidential support for journalists and news organisations — including remote security training.
Visit ↑
NUJ Digital Security Resources
Union-specific guidance and legal support for UK-based journalists.
Visit ↑
Reporters Without Borders Safety Guide
Comprehensive journalist safety and digital security resources, available in multiple languages.
Visit ↑

Red flags in newsroom security culture

  • No written source protection policy — security decisions are made ad hoc under deadline.
  • Sensitive source information discussed in newsroom-wide Slack channels or unencrypted email.
  • No defined procedure for responding to a production order or legal demand.
  • No training budget for digital security — tools are adopted without understanding.
  • Security is treated as IT's job, not editorial leadership's responsibility.
  • No one has responsibility for owning and updating the security policy.

Newsroom security policy checklist

  • We have a written source protection policy that all journalists have read.
  • We have minimum device security standards (encryption, 2FA, password manager) documented and enforced.
  • We have a written incident response plan covering device compromise, account takeover, and legal demands.
  • We have identified who journalists should contact in a security emergency — internal and external.
  • We have a documented legal demand procedure agreed with legal counsel.
  • We provide security training at onboarding and at least annually thereafter.
  • We have a named owner for the security policy who is responsible for keeping it current.
  • We have considered whether a SecureDrop or equivalent is appropriate for our newsroom.

Source protection tools

Use our source protection checklist to baseline your newsroom’s current posture.

Source Protection Checklist

Common mistakes

  • Treating security as a one-time project rather than an ongoing practice.
  • Delegating security entirely to IT — security policy decisions are editorial decisions.
  • Security policies that are too complex for journalists to follow under deadline — friction causes abandonment.
  • No budget for security — treating free tools as sufficient for all scenarios.
  • Not testing the incident response plan before an incident happens.

Related guides

Primary sources

Frequently asked questions

What is the minimum viable security policy for a small UK newsroom?
At minimum: (1) all staff use a password manager with unique passwords per service; (2) all staff use TOTP or hardware-key 2FA on email, cloud storage, and social media; (3) all devices have full-disk encryption enabled; (4) there is a clear, written policy on how journalists handle communications with confidential sources; and (5) there is a named person (or external resource) journalists can call when they have a security concern.
How much should a newsroom budget for digital security?
This varies significantly by size and risk profile. Indicative figures: password manager licences (1Password Teams, ~£4/user/month); Signal and ProtonMail (free); security awareness training (~£100–500/person annually for a dedicated course, or free via FPF resources); a hardware security key per journalist covering high-risk beats (~£40–80 per key); specialist incident response retainer (£500–£2,000/year for a small newsroom). The cost of not investing is significantly higher when an incident occurs.
Does my newsroom need to appoint a dedicated security person?
Larger newsrooms benefit from a dedicated Digital Security Officer or equivalent role. Smaller newsrooms typically cannot justify this and should instead: nominate an interested staff member to own security policy; use external resources (FPF, NUJ, Access Now) for training and incident support; and ensure that the editor understands their role in an incident. The most important thing is that someone owns the function — security policy with no owner is security theatre.
How do I balance security training with newsroom workflow?
Security training that is too complex creates friction and gets abandoned. Focus on high-impact, low-friction changes first: password managers (one session to set up, then largely invisible); device encryption (a setting, not a daily workflow change); Signal for source communications (familiar interface for most journalists). Reserve more complex measures (SecureDrop, Tor, clean devices) for journalists who actually need them based on their beat and current stories.