Skip to main content

Digital Security Pack

Tools and guides for protecting your sources, data, and communications when reporting sensitive stories — from source protection checklists to legal guides on production orders and the Official Secrets Act.

Last reviewed: Next review due:

Who this pack is for

This pack is for any UK journalist who handles sensitive source material, works on investigations involving powerful individuals or institutions, reports on defence and security matters, or needs to protect confidential information from legal and technical exposure. Digital security is not just for war correspondents — any journalist with a confidential source has an obligation to protect them.

The pack combines three operational tools (source protection checklist, story risk register, and social media verification) with four guides covering the legal and practical dimensions of digital security in the UK: encrypted communications, UK surveillance law, production orders, and the Official Secrets Act. Together they give you the operational and legal framework to report sensitive stories safely.

What’s included

Three tools and four guides — click any card to open it directly.

How to use this pack

  1. 1

    Read the Digital Security Guide first

    Start with the Digital Security Guide to understand the threat landscape for UK journalists: surveillance law, device security, encrypted communications, and secure file handling. This gives you the context to use the operational tools in this pack effectively.

  2. 2

    Run the Source Protection Checklist before any contact with a confidential source

    Before making first contact with a potential confidential source, work through the Source Protection Checklist. It covers: which communication channel to use, how to handle metadata, how to receive documents securely, how to store information, and what records not to keep. Completing this before contact — not after — is essential.

  3. 3

    Open a Story Risk Register for every sensitive investigation

    For any story involving confidential sources or sensitive information, open a Story Risk Register entry. Log the risks, the evidence you have, the steps you have taken to protect sources, and the legal review steps required before publication. This protects you and your source if the story is challenged.

  4. 4

    Verify all digital evidence before publication

    Use the Social Media Verification Checklist for any social media content, images, or documents you intend to publish. Strip metadata from documents before sharing them with editors. Document your verification steps in your editorial file.

  5. 5

    Know your legal rights before a police or court challenge arrives

    Read the Source Protection Law and Production Orders guides before you need them. If police seek access to your material, contact the NUJ or a media law specialist immediately. Do not hand over material voluntarily — make the police or court go through the proper legal process, which gives you the opportunity to resist.

Red flags — digital security lapses to act on immediately

  • You are communicating with a confidential source by SMS or standard phone call — switch to Signal immediately and assume all previous communications may be visible to law enforcement.
  • You have received sensitive documents by unencrypted email — assume the metadata (sender, timestamps, IP address) is exposed; do not forward the documents via email.
  • Your laptop or phone has left your physical control (lost, stolen, or border search) — change all passwords immediately and notify your source through a different, clean channel.
  • You have not stripped EXIF metadata from images or documents before sharing — GPS, timestamp, and device serial data in image files can identify both you and your source.
  • You have received a notice of a production order application or a letter from police requesting your material — do not comply voluntarily; contact the NUJ legal team immediately.
  • You are storing source correspondence in a cloud account linked to your professional or personal identity — move sensitive material to an encrypted, air-gapped location.
  • A source has contacted you from a work device or a device registered in their name — advise them to stop and use an unregistered device on a public Wi-Fi network instead.

Primary sources

Common mistakes

  • Assuming encrypted messaging protects the fact of contact. Signal encrypts content, not metadata. Law enforcement can see that you communicated with a number even if they cannot read the messages — use a secondary number or Signal usernames for highly sensitive contacts.
  • Storing source notes in a shared cloud drive. Google Drive, Dropbox, and OneDrive are accessible to law enforcement under MLAT requests. Keep source notes on an encrypted, locally stored drive or encrypted note-taking tool such as Standard Notes.
  • Not having a device protocol before crossing borders. Decide before you travel what is on your device and what happens if it is seized. Carrying a clean travel device for high-risk journeys is standard practice for investigative journalists.
  • Reusing passwords across professional accounts. A single compromised password can expose your entire source network. Use a password manager (Bitwarden or 1Password) and enable hardware-key 2FA on all professional accounts.
  • Forgetting that your editors and colleagues are an attack surface. Your source's identity can be exposed via the chain of communication within your newsroom, not just by your own security practices. Limit need-to-know access to source identities.

Frequently asked questions

What encrypted messaging app should journalists use?
Signal is the gold standard for journalist-to-source communications: it uses end-to-end encryption by default, supports disappearing messages, and does not retain metadata on its servers. WhatsApp also uses Signal's encryption protocol but is owned by Meta and retains more metadata. Avoid SMS and standard phone calls for sensitive communications — metadata (who you called, when, for how long) can be legally accessed by law enforcement in the UK under the Investigatory Powers Act 2016 without individual warrants. The Digital Security Guide in this pack covers specific tool recommendations and operational hygiene.
Can UK police access my phone and communications without a warrant?
UK police can access communications data (metadata: who you communicated with, when, and from where) under the Investigatory Powers Act 2016 without a warrant in many circumstances. They require a warrant to access the content of communications. If you are arrested, police can require you to provide a PIN or password to a device under section 49 of the Regulation of Investigatory Powers Act 2000 — refusing is a criminal offence carrying up to two years in prison. The Source Protection Law guide explains these powers and how to mitigate them.
How do I receive documents securely from a whistleblower?
Use SecureDrop — an open-source whistleblowing platform — if your organisation has it. SecureDrop routes documents through the Tor network, stripping metadata and preventing your organisation from knowing the source's IP address. If SecureDrop is not available, use Signal's "Note to Self" function to receive documents, and instruct the source to use a device not connected to their identity. Strip document metadata using tools like MAT2 before storing or sharing files. Do not receive sensitive documents via email unless using PGP encryption — and even then, email metadata is not encrypted.
What is a production order and can I resist one?
A production order under the Police and Criminal Evidence Act 1984 (Schedule 1) compels a journalist to hand over journalistic material. Police must satisfy a circuit judge that the material is likely to be relevant to a serious arrestable offence and cannot reasonably be obtained elsewhere. Journalists can and should contest these applications — contact the NUJ legal team or a media law specialist immediately if you receive notice of an application. The Production Orders guide in this pack explains the procedure and grounds for resistance.
Are journalists reporting on defence and security subject to the Official Secrets Act?
Yes. The Official Secrets Act 1989 criminalises the unauthorised disclosure of information in six protected categories: security and intelligence, defence, international relations, crime, special investigation powers, and information entrusted in confidence to other states. A journalist who knowingly publishes material falling within these categories could face prosecution. However, the Act does not contain an explicit public interest defence. The Defence and Security Reporting guide in this pack explains which categories carry the highest risk and how other journalists have navigated them.
What should I do if my phone or laptop is seized by police at a border or checkpoint?
Do not enter passwords or decrypt devices voluntarily — stop, stay calm, and ask for the legal basis for the seizure. Under Schedule 7 of the Terrorism Act 2000, officers can examine, retain, and search devices at ports and airports without suspicion. Under PACE 1984, they may examine devices held on arrest. In both cases, contact the NUJ or a media law solicitor immediately. Before travelling to any high-risk jurisdiction, consider carrying a clean device with no source material, and keep working files in an encrypted cloud store rather than on the device itself.
How do I protect my source if I am photographing or filming them?
Strip EXIF metadata from all images before transmitting them — GPS coordinates, camera serial numbers, and timestamp data embedded in JPEG files can identify both you and your source. Use tools such as ExifTool or the built-in metadata-stripping function in Signal when sending images. If filming, be aware that background details — distinctive wallpaper, views from windows, and overheard sounds — can be used to identify a location. Consider using artificial background blur or changing meeting venues. Never store original, unstripped files in a cloud account linked to your work identity.

Related packs

Related guides