Last reviewed: Next review due:
What is threat modelling?
Threat modelling is the practice of systematically identifying what you need to protect, who you need to protect it from, and how much effort you are willing to invest in doing so. It is the foundation of all good digital security practice. Without it, journalists either adopt security tools they do not need (wasting time and introducing friction into their work) or skip tools they do need (putting sources and stories at risk).
For journalists, the core assets to protect are typically: the identity of confidential sources; unpublished story materials and notes; communications with sources; login credentials for accounts; and personal safety information. The adversaries trying to access these assets range from opportunistic hackers and corporate private investigators through to organised crime groups and, in a small number of cases, state intelligence agencies.
The key test: Would my source be safe if my phone was seized at the UK border under Schedule 7? Run every security decision through that question before you start.
When this matters most
- 1When you are working with a confidential source whose identity, if revealed, could lead to dismissal, prosecution, or physical harm.
- 2When your investigation involves organised crime, public corruption, corporate fraud, or intelligence agencies.
- 3When you are travelling internationally — especially through countries with adversarial intelligence services.
- 4When you are covering stories that have attracted legal threats or private investigator activity.
- 5When you are sharing sensitive unpublished material with colleagues, editors, or freelancers.
- 6Before every major investigation — your threat model is story-specific, not career-wide.
UK threat landscape at a glance
Private investigators, social engineering, account hacking. Targets: business reporters, those with litigation-adjacent stories.
Organised crime groups with technical capability. Targets: crime reporters, those with court stories, journalists with hostile sources.
UK intelligence agencies (RIPA/IPA warrants), foreign states (Pegasus-type spyware). Targets: national security, intelligence, foreign policy beats.
Red flags in your threat environment
- You have received legal threats from well-resourced organisations connected to your story subject.
- A source has told you they are being watched, or has changed behaviour suddenly.
- You are covering a beat where private investigator use is documented (financial crime, celebrity, organised crime).
- A story subject has links to foreign state actors or intelligence services.
- You have received unexpected password reset emails or login alerts on accounts related to your work.
- Colleagues covering similar stories have experienced device compromise or account takeovers.
Threat modelling checklist
- I have identified the assets I need to protect for this story (source identity, notes, communications, drafts).
- I have identified the realistic adversaries for this story and their likely capabilities.
- I have assessed how likely each adversary is to actually target me on this story.
- I have considered what would happen if each asset was compromised — and how bad that would be.
- I have chosen security tools proportionate to my threat level, not the maximum possible.
- I have confirmed my source's own security situation — do they use Signal? Are they on a work device?
- I have applied the border test: if my phone was seized today, would my source be identifiable?
- I will reassess this threat model if the story changes, new sources come forward, or I receive threats.
Source protection tools
Use our source protection checklist to assess whether your current setup is adequate for your next story.
Common mistakes
- Applying maximum security to every story — creates friction and leads to security fatigue.
- Never updating your threat model — a story can escalate significantly mid-investigation.
- Assuming Signal is enough regardless of threat level — it is not designed for state-actor adversaries.
- Ignoring the source's threat model — your security is only as good as your source's security.
- Treating threat modelling as a one-off exercise rather than an ongoing practice.
- Confusing inconvenience with security — using a VPN for non-sensitive work while skipping encryption for sensitive notes.
Related guides
Primary sources
Frequently asked questions
What is a threat model and why do I need one as a journalist?
What are the five questions in a basic threat model?
Are UK journalists regularly targeted by state actors?
Does my threat model change story by story?
Related guides
Primary sources
- NCSC: Phishing Guidance— National Cyber Security Centre
- Investigatory Powers Act 2016— legislation.gov.uk
- Surveillance Self-Defence: Your Security Plan— Electronic Frontier Foundation
- Security Training for Journalists— Freedom of the Press Foundation
- Digital Security Helpline— Access Now
- Journalist Security Guide— Committee to Protect Journalists
- Journalist Safety Resources— Reporters Without Borders