Digital safety

Digital safety

Natalie Moore
April 24, 2026· Updated August 9, 2026· 6 min read

Digital safety in a crisis is not about installing every security tool. It is about reducing exposure across accounts, devices, communications, and evidence under pressure. Journalists, activists, human rights workers, and nonprofits face concentrated risks: phishing, device seizure, internet shutdowns, social account takeover, and exposed contacts can become one connected chain. CPJ and Access Now both list safety planning, account protection, device hardening, and emergency help as basic steps for high-risk groups.[1][2]

CISA likewise identifies journalists, activists, human rights defenders, academics, and civil-society staff as high-risk communities targeted because of their identity or work.[4]

Key Takeaways

  • Start with risk tiers: are you protecting people, identities, contacts, material, or communication channels?
  • High-risk accounts need strong unique passwords, a password manager, and multifactor authentication.
  • Carry less data in the field, and encrypt backups of essential material quickly.
  • If you suspect intrusion, device seizure, or an urgent shutdown, do not handle it alone. Contact trusted digital security support.

Use the online security guide as the baseline: it connects this risk to account, device, browser, and network hardening.

What should digital safety protect first in a crisis?

Protect people first, accounts second, and data integrity after that. Many security checklists start with tools, but in high-risk situations the better first question is: who could be harmed by this exposure?

What to protectCommon riskFirst action
Your identityOffline tracking, account identity linksReduce public location and identity clues
ContactsExposed address books, chat historySeparate work and personal accounts
EvidenceLost phone, seized deviceEncrypt, back up, and carry less data
Publishing channelsStolen social accounts, email takeoverStrong MFA, backup admins, recovery codes
Communication pathBlocking, monitoring, malicious hotspotsEncrypted messaging and a trusted VPN

This is different from everyday digital privacy protection. Most users worry about ad tracking and scams; people in a crisis worry about identities, contacts, and evidence being connected.

How can accounts avoid takeover?

Use a password manager to create unique passwords

Do not reuse one password across email, social media, cloud storage, and messaging tools. After one platform leaks, attackers automatically try the same password elsewhere. The FTC also recommends different strong passwords for different accounts, plus extra verification.[3]

Prefer security keys or authenticator apps for MFA

SMS codes are better than nothing, but they are not ideal in high-risk settings. Use a hardware security key or authenticator app when possible, and keep recovery codes offline.

Add backup administrators for critical accounts

Newsrooms, nonprofits, and action groups should not put publishing power in one person’s hands. Prepare at least one trusted backup administrator and define who can remove posts, change passwords, or revoke access.

Review signed-in devices and third-party permissions

Many takeovers do not begin with an immediate password change. Attackers may quietly add a third-party authorization. Check signed-in devices, OAuth permissions, and email forwarding rules weekly, especially for email accounts.

How should you handle devices and material?

Carry less data in the field. The more phones, laptops, cameras, chat logs, and files you carry, the larger the exposure if a device is stolen, seized, or searched.

  1. Update your operating system and common apps before leaving;
  2. Remove unnecessary chat history, contact copies, and old material;
  3. Enable full-disk encryption and automatic screen lock;
  4. Use a short auto-lock timer, and avoid simple pattern locks in the field;
  5. Upload essential material quickly to a trusted encrypted cloud or newsroom workflow;
  6. Keep real-identity accounts and high-risk reporting accounts off the same device when possible.

CPJ’s digital safety guide also stresses that journalists should assess devices, accounts, location exposure, and communications before reporting.[1]

How should you choose communications and network connections?

End-to-end encrypted messaging is best for sensitive conversations, but it assumes the other person’s account is safe too. A VPN protects the network path on public networks, especially in hotels, airports, temporary offices, and unfamiliar hotspots.

These are not substitutes. Signal-style encrypted messaging protects message content; a VPN protects the connection between your device and the VPN server; cloud permissions, device locks, and account MFA protect other layers.

If you are facing network blocking or platform restrictions, the risk boundaries in what is an internet shutdown apply: do not treat one tool as a universal access point. Prepare backup communication channels before you need them.


What should you do if you suspect an attack?

Preserve evidence first, then reduce the risk. Do not rush to delete everything, because a security responder may need email headers, suspicious links, login alerts, and screenshots to understand the attack path.

SituationFirst action
You clicked a suspicious linkEnd sessions, change passwords, check MFA and forwarding rules
A phone is lostRemote-lock it, revoke account sessions, notify contacts
Social media is stolenUse a backup admin to freeze permissions and recover the account
You receive threatsScreenshot, save the original email, contact your organization’s security lead
A device is seizedAssume data is exposed and start contact and account protection procedures

If the risk involves physical safety, spyware, or persistent tracking, contact a trusted digital security organization. Access Now’s Digital Security Helpline provides 24/7 support for civil society members.[2]

What should teams prepare in advance?

Personal safety matters, but crisis work needs team processes. At minimum, prepare a contact priority list, an account permission table, and an incident response table.

Summary

  • Digital safety in a crisis should protect people and contacts first, then accounts and material.
  • Password managers, MFA, full-disk encryption, and carrying less data are baseline steps for high-risk groups.
  • A VPN protects connections on untrusted networks, but it does not replace account security, device hardening, or response planning.
  • After an incident, preserve evidence, revoke sessions, and contact trusted support instead of relying on deleting records.

FAQ

Do journalists always need a VPN?

Not always, but on public Wi-Fi, temporary office networks, travel networks, and in censorship environments, a VPN is a useful layer of connection protection.

Can a VPN protect message content?

It protects the network path, not the message content itself. Sensitive messages should still use trusted end-to-end encrypted messaging tools.

What is the first security feature for high-risk accounts?

Turn on multifactor authentication, ideally with a hardware security key or authenticator app. Then use a password manager to replace every reused password.

Should you bring your primary phone into a crisis site?

Avoid it when possible. A safer approach is to use a work device with minimal data, encryption, backups, and remote locking already configured.

What is the first step after phishing?

Change the relevant account password immediately, revoke unfamiliar sessions, and check email forwarding rules and third-party permissions. Do not just delete the email.


Disclaimer: This article is for general cybersecurity education only and does not constitute legal, newsroom safety, or personal safety advice. High-risk work should be planned with local law, organizational safety procedures, and professional support in mind.

AethoVPN does not replace the non-network steps in “Digital safety”.

Sources:

  1. Committee to Protect Journalists - Digital safety: https://cpj.org/reports/2019/07/digital-safety/
  2. Access Now - Digital Security Helpline: https://www.accessnow.org/help/
  3. FTC Consumer Advice - Password checklist: https://consumer.ftc.gov/articles/password-checklist
  4. CISA - High-Risk Communities: https://www.cisa.gov/audiences/high-risk-communities

Sources checked 8 May 2026.


Related Articles:

Start your 3-day free trial

Sign up to experience all premium features at no cost.

*Available only to new users. Each user is limited to one trial.

Digital safety | AethoVPN