Start your 3-day free trial
Sign up to experience all premium features at no cost.
*Available only to new users. Each user is limited to one trial.


Digital safety in a crisis is not about installing every security tool. It is about reducing exposure across accounts, devices, communications, and evidence under pressure. Journalists, activists, human rights workers, and nonprofits face concentrated risks: phishing, device seizure, internet shutdowns, social account takeover, and exposed contacts can become one connected chain. CPJ and Access Now both list safety planning, account protection, device hardening, and emergency help as basic steps for high-risk groups.[1][2]
CISA likewise identifies journalists, activists, human rights defenders, academics, and civil-society staff as high-risk communities targeted because of their identity or work.[4]
Key Takeaways
- Start with risk tiers: are you protecting people, identities, contacts, material, or communication channels?
- High-risk accounts need strong unique passwords, a password manager, and multifactor authentication.
- Carry less data in the field, and encrypt backups of essential material quickly.
- If you suspect intrusion, device seizure, or an urgent shutdown, do not handle it alone. Contact trusted digital security support.
Use the online security guide as the baseline: it connects this risk to account, device, browser, and network hardening.
Protect people first, accounts second, and data integrity after that. Many security checklists start with tools, but in high-risk situations the better first question is: who could be harmed by this exposure?
| What to protect | Common risk | First action |
|---|---|---|
| Your identity | Offline tracking, account identity links | Reduce public location and identity clues |
| Contacts | Exposed address books, chat history | Separate work and personal accounts |
| Evidence | Lost phone, seized device | Encrypt, back up, and carry less data |
| Publishing channels | Stolen social accounts, email takeover | Strong MFA, backup admins, recovery codes |
| Communication path | Blocking, monitoring, malicious hotspots | Encrypted messaging and a trusted VPN |
This is different from everyday digital privacy protection. Most users worry about ad tracking and scams; people in a crisis worry about identities, contacts, and evidence being connected.
Do not reuse one password across email, social media, cloud storage, and messaging tools. After one platform leaks, attackers automatically try the same password elsewhere. The FTC also recommends different strong passwords for different accounts, plus extra verification.[3]
SMS codes are better than nothing, but they are not ideal in high-risk settings. Use a hardware security key or authenticator app when possible, and keep recovery codes offline.
Newsrooms, nonprofits, and action groups should not put publishing power in one person’s hands. Prepare at least one trusted backup administrator and define who can remove posts, change passwords, or revoke access.
Many takeovers do not begin with an immediate password change. Attackers may quietly add a third-party authorization. Check signed-in devices, OAuth permissions, and email forwarding rules weekly, especially for email accounts.
Carry less data in the field. The more phones, laptops, cameras, chat logs, and files you carry, the larger the exposure if a device is stolen, seized, or searched.
CPJ’s digital safety guide also stresses that journalists should assess devices, accounts, location exposure, and communications before reporting.[1]
End-to-end encrypted messaging is best for sensitive conversations, but it assumes the other person’s account is safe too. A VPN protects the network path on public networks, especially in hotels, airports, temporary offices, and unfamiliar hotspots.
These are not substitutes. Signal-style encrypted messaging protects message content; a VPN protects the connection between your device and the VPN server; cloud permissions, device locks, and account MFA protect other layers.
If you are facing network blocking or platform restrictions, the risk boundaries in what is an internet shutdown apply: do not treat one tool as a universal access point. Prepare backup communication channels before you need them.
Preserve evidence first, then reduce the risk. Do not rush to delete everything, because a security responder may need email headers, suspicious links, login alerts, and screenshots to understand the attack path.
| Situation | First action |
|---|---|
| You clicked a suspicious link | End sessions, change passwords, check MFA and forwarding rules |
| A phone is lost | Remote-lock it, revoke account sessions, notify contacts |
| Social media is stolen | Use a backup admin to freeze permissions and recover the account |
| You receive threats | Screenshot, save the original email, contact your organization’s security lead |
| A device is seized | Assume data is exposed and start contact and account protection procedures |
If the risk involves physical safety, spyware, or persistent tracking, contact a trusted digital security organization. Access Now’s Digital Security Helpline provides 24/7 support for civil society members.[2]
Personal safety matters, but crisis work needs team processes. At minimum, prepare a contact priority list, an account permission table, and an incident response table.
Not always, but on public Wi-Fi, temporary office networks, travel networks, and in censorship environments, a VPN is a useful layer of connection protection.
It protects the network path, not the message content itself. Sensitive messages should still use trusted end-to-end encrypted messaging tools.
Turn on multifactor authentication, ideally with a hardware security key or authenticator app. Then use a password manager to replace every reused password.
Avoid it when possible. A safer approach is to use a work device with minimal data, encryption, backups, and remote locking already configured.
Change the relevant account password immediately, revoke unfamiliar sessions, and check email forwarding rules and third-party permissions. Do not just delete the email.
Disclaimer: This article is for general cybersecurity education only and does not constitute legal, newsroom safety, or personal safety advice. High-risk work should be planned with local law, organizational safety procedures, and professional support in mind.
AethoVPN does not replace the non-network steps in “Digital safety”.
Sources:
Sources checked 8 May 2026.
Related Articles:
Sign up to experience all premium features at no cost.
*Available only to new users. Each user is limited to one trial.