Digital Security Pack
Tools and guides for protecting your sources, data, and communications when reporting sensitive stories — from source protection checklists to legal guides on production orders and the Official Secrets Act.
Last reviewed: Next review due:
Who this pack is for
This pack is for any UK journalist who handles sensitive source material, works on investigations involving powerful individuals or institutions, reports on defence and security matters, or needs to protect confidential information from legal and technical exposure. Digital security is not just for war correspondents — any journalist with a confidential source has an obligation to protect them.
The pack combines three operational tools (source protection checklist, story risk register, and social media verification) with four guides covering the legal and practical dimensions of digital security in the UK: encrypted communications, UK surveillance law, production orders, and the Official Secrets Act. Together they give you the operational and legal framework to report sensitive stories safely.
What’s included
Three tools and four guides — click any card to open it directly.
Source Protection Checklist
A step-by-step operational checklist for protecting confidential sources from identification — communications, record-keeping, and meetings.
Story Risk Register
Log and assess the legal and editorial risks of a story in development with a structured pre-publication risk matrix.
Social Media Verification Checklist
Verify social media posts, images, and accounts before publication following the First Draft verification protocol.
Guide: Digital Security for Journalists
A practical guide to encrypted communications, secure file handling, device security, and operational security for UK journalists.
Guide: Source Protection Law
Your legal rights as a journalist when protecting confidential sources under PACE 1984 and the Terrorism Act 2000.
Guide: Production Orders
How production orders work, the grounds for resistance, and how to get emergency legal help when police seek your material.
Guide: Defence and Security Reporting
Reporting on defence, intelligence, and national security: the Official Secrets Act 1989, D-Notices, and managing legal risk.
How to use this pack
- 1
Read the Digital Security Guide first
Start with the Digital Security Guide to understand the threat landscape for UK journalists: surveillance law, device security, encrypted communications, and secure file handling. This gives you the context to use the operational tools in this pack effectively.
- 2
Run the Source Protection Checklist before any contact with a confidential source
Before making first contact with a potential confidential source, work through the Source Protection Checklist. It covers: which communication channel to use, how to handle metadata, how to receive documents securely, how to store information, and what records not to keep. Completing this before contact — not after — is essential.
- 3
Open a Story Risk Register for every sensitive investigation
For any story involving confidential sources or sensitive information, open a Story Risk Register entry. Log the risks, the evidence you have, the steps you have taken to protect sources, and the legal review steps required before publication. This protects you and your source if the story is challenged.
- 4
Verify all digital evidence before publication
Use the Social Media Verification Checklist for any social media content, images, or documents you intend to publish. Strip metadata from documents before sharing them with editors. Document your verification steps in your editorial file.
- 5
Know your legal rights before a police or court challenge arrives
Read the Source Protection Law and Production Orders guides before you need them. If police seek access to your material, contact the NUJ or a media law specialist immediately. Do not hand over material voluntarily — make the police or court go through the proper legal process, which gives you the opportunity to resist.
Red flags — digital security lapses to act on immediately
- You are communicating with a confidential source by SMS or standard phone call — switch to Signal immediately and assume all previous communications may be visible to law enforcement.
- You have received sensitive documents by unencrypted email — assume the metadata (sender, timestamps, IP address) is exposed; do not forward the documents via email.
- Your laptop or phone has left your physical control (lost, stolen, or border search) — change all passwords immediately and notify your source through a different, clean channel.
- You have not stripped EXIF metadata from images or documents before sharing — GPS, timestamp, and device serial data in image files can identify both you and your source.
- You have received a notice of a production order application or a letter from police requesting your material — do not comply voluntarily; contact the NUJ legal team immediately.
- You are storing source correspondence in a cloud account linked to your professional or personal identity — move sensitive material to an encrypted, air-gapped location.
- A source has contacted you from a work device or a device registered in their name — advise them to stop and use an unregistered device on a public Wi-Fi network instead.
Primary sources
- Investigatory Powers Act 2016 — the surveillance powers available to UK law enforcement and intelligence agencies
- PACE 1984, Schedule 1 — production orders for journalistic material; procedure and grounds for resistance
- EFF Surveillance Self-Defence — practical guides to encrypted communications, device security, and threat modelling
- SecureDrop.org — the open-source whistleblowing platform used by the Guardian, BBC, and other UK media organisations
- NUJ Source Protection Guidance — NUJ practical guidance on legal and operational source protection
- CPJ Digital Safety Kit — Committee to Protect Journalists' digital safety kit for journalists at risk
- RIPA 2000, s.49 — compelled decryption notices; the legal basis for demanding passwords from journalists
Common mistakes
- Assuming encrypted messaging protects the fact of contact. Signal encrypts content, not metadata. Law enforcement can see that you communicated with a number even if they cannot read the messages — use a secondary number or Signal usernames for highly sensitive contacts.
- Storing source notes in a shared cloud drive. Google Drive, Dropbox, and OneDrive are accessible to law enforcement under MLAT requests. Keep source notes on an encrypted, locally stored drive or encrypted note-taking tool such as Standard Notes.
- Not having a device protocol before crossing borders. Decide before you travel what is on your device and what happens if it is seized. Carrying a clean travel device for high-risk journeys is standard practice for investigative journalists.
- Reusing passwords across professional accounts. A single compromised password can expose your entire source network. Use a password manager (Bitwarden or 1Password) and enable hardware-key 2FA on all professional accounts.
- Forgetting that your editors and colleagues are an attack surface. Your source's identity can be exposed via the chain of communication within your newsroom, not just by your own security practices. Limit need-to-know access to source identities.