Skip to main content

Threat Modelling for UK Journalists

Proportionate security starts with one question: who wants your data, and what would they do to get it? This guide walks you through a practical threat modelling process designed for UK journalists.

General guidance, not professional security advice. This information is educational. For high-risk threat models involving state actors or organised crime targeting, consult a qualified digital security professional such as the Access Now Digital Security Helpline.

Last reviewed: Next review due:

What is threat modelling?

Threat modelling is the practice of systematically identifying what you need to protect, who you need to protect it from, and how much effort you are willing to invest in doing so. It is the foundation of all good digital security practice. Without it, journalists either adopt security tools they do not need (wasting time and introducing friction into their work) or skip tools they do need (putting sources and stories at risk).

For journalists, the core assets to protect are typically: the identity of confidential sources; unpublished story materials and notes; communications with sources; login credentials for accounts; and personal safety information. The adversaries trying to access these assets range from opportunistic hackers and corporate private investigators through to organised crime groups and, in a small number of cases, state intelligence agencies.

The key test: Would my source be safe if my phone was seized at the UK border under Schedule 7? Run every security decision through that question before you start.

When this matters most

  • 1When you are working with a confidential source whose identity, if revealed, could lead to dismissal, prosecution, or physical harm.
  • 2When your investigation involves organised crime, public corruption, corporate fraud, or intelligence agencies.
  • 3When you are travelling internationally — especially through countries with adversarial intelligence services.
  • 4When you are covering stories that have attracted legal threats or private investigator activity.
  • 5When you are sharing sensitive unpublished material with colleagues, editors, or freelancers.
  • 6Before every major investigation — your threat model is story-specific, not career-wide.

UK threat landscape at a glance

Commercial threat

Private investigators, social engineering, account hacking. Targets: business reporters, those with litigation-adjacent stories.

Criminal threat

Organised crime groups with technical capability. Targets: crime reporters, those with court stories, journalists with hostile sources.

State Actor threat

UK intelligence agencies (RIPA/IPA warrants), foreign states (Pegasus-type spyware). Targets: national security, intelligence, foreign policy beats.

Red flags in your threat environment

  • You have received legal threats from well-resourced organisations connected to your story subject.
  • A source has told you they are being watched, or has changed behaviour suddenly.
  • You are covering a beat where private investigator use is documented (financial crime, celebrity, organised crime).
  • A story subject has links to foreign state actors or intelligence services.
  • You have received unexpected password reset emails or login alerts on accounts related to your work.
  • Colleagues covering similar stories have experienced device compromise or account takeovers.

Threat modelling checklist

  • I have identified the assets I need to protect for this story (source identity, notes, communications, drafts).
  • I have identified the realistic adversaries for this story and their likely capabilities.
  • I have assessed how likely each adversary is to actually target me on this story.
  • I have considered what would happen if each asset was compromised — and how bad that would be.
  • I have chosen security tools proportionate to my threat level, not the maximum possible.
  • I have confirmed my source's own security situation — do they use Signal? Are they on a work device?
  • I have applied the border test: if my phone was seized today, would my source be identifiable?
  • I will reassess this threat model if the story changes, new sources come forward, or I receive threats.

Source protection tools

Use our source protection checklist to assess whether your current setup is adequate for your next story.

Common mistakes

  • Applying maximum security to every story — creates friction and leads to security fatigue.
  • Never updating your threat model — a story can escalate significantly mid-investigation.
  • Assuming Signal is enough regardless of threat level — it is not designed for state-actor adversaries.
  • Ignoring the source's threat model — your security is only as good as your source's security.
  • Treating threat modelling as a one-off exercise rather than an ongoing practice.
  • Confusing inconvenience with security — using a VPN for non-sensitive work while skipping encryption for sensitive notes.

Related guides

Primary sources

Frequently asked questions

What is a threat model and why do I need one as a journalist?
A threat model is a structured way of thinking about who might want to access your information, what they could do with it, and how much effort they are likely to expend. Without one, you either under-protect (and put sources at risk) or over-protect (and waste time on tools your adversary could not realistically deploy). Every journalist has a different threat model depending on what they cover.
What are the five questions in a basic threat model?
(1) What do I want to protect? (2) Who do I want to protect it from? (3) How likely is it that I will need to protect it? (4) How bad are the consequences if I fail? (5) How much trouble am I willing to go to in order to protect it? The Electronic Frontier Foundation's Security Planner is a good starting point for working through these.
Are UK journalists regularly targeted by state actors?
Some are. Journalists covering intelligence services, terrorism, foreign governments, and UK government misconduct have been subjected to surveillance under the Investigatory Powers Act 2016, RIPA warrants, and in some documented cases, foreign state spyware (NSO Group's Pegasus has been found on devices in the UK). Most journalists do not face state-actor threats in their day-to-day work, but the threat is not hypothetical for those covering certain beats.
Does my threat model change story by story?
Yes. A journalist covering local sport has a very different threat model when working on an investigation into organised crime. It is good practice to re-assess your threat model at the start of each new investigation, particularly if it involves sensitive sources, corporate wrongdoing, or government misconduct.