Security Resources
A living hub for security resources, training, and community
We’ve been hearing more and more from Lab members that you’re concerned about threats to our personal and organizational security, from doxxing attacks to phishing to physical intimidation and harassment. This page is a living hub for resources, training, and community as we navigate this world together. We will be uploading this page regularly and adding content, so keep checking back.
If you are feeling overwhelmed, let’s start with 5 things you can do immediately:
Turn on two-factor authentication
Turn on two-factor authentication
For ALL of your accounts! That includes personal and professional Apple, Google, and Microsoft accounts; CRMs like Salesforce; email accounts; social media logins (Instagram, Facebook, X), and all other apps where it is possible. This provides an additional protection against hacks and other attacks.
Use a secure messenger
Use a secure messenger
Signal is the standard for secure, encrypted communications and it doesn’t leak your contact list. WhatsApp uses the same protocol as Signal but you can be linked to your contacts. Apple Messages uses a secure protocol, but is connected to your Apple profile. Use your best judgment for what level of security you need.
Use a password manager
Use a password manager
Long, unique passwords are the building blocks of online security. Use an app like 1Password to help you generate and store them, so you never have to remember a password again.
Update your devices
Update your devices
Those annoying popups on your phone, in your browser, or on your computer asking you to update are super important! Those updates usually contain important fixes for security vulnerabilities that, if exploited, offer attackers a way into your digital world.
Review your personally-identifiable information (PII)
Review your personally-identifiable information (PII)
Doxxing attacks are often possible because personal info is available online. Do a scan of your organization’s website and your personal web presence. Is there info about you (email addresses, home addresses, lists of friends and family) that could be used in an attack against you? Do your social media profiles restrict personal info to friends?
Digital Security 101
Doxxing attacks and increased surveillance are threatening to undo years of progress in the climate movement. Online harassment makes social media increasingly dangerous and toxic. Attacks on free speech are making it harder to advocate for change.
In this environment, it’s important for you and your organization to understand your individual “threat model,” and to have the tools and support you need to continue operating.
This page offers resources to help you and your organization stay safe online. It includes primers to basic digital security concepts, suggested providers to help with specific needs, and online guides for when you’re ready to dig deeper.*
*These resources do not constitute legal advice. Please consult your legal team for all legal matters
What it is: “Threat modeling is a structured approach that aims to identify and prioritize potential threats and vulnerabilities in software applications. It involves identifying potential attackers, their motivations, and the methods they might use to exploit vulnerabilities in a system.”
What you can do: Check out this list of threat modeling best practices, which outlines practical steps you can take to gain insight into you and your organization’s threat landscape, and what you can do to stay safe.
What it is: Doxxing is the act of publishing private information about an individual online, without their consent, typically with malicious intent. This includes information like:
- Name
- Address
- Workplace or school
- Family members’ names
- Phone numbers and/or email addresses
- Private photos
What can you do: Use a service that specializes in removing personal or professional online data to minimize the potential harm of a doxxing attack.
What it is: When traveling internationally, especially to the U.S., be aware that border agents can legally search electronic devices without a warrant.
What you can do:
- Bring minimal devices when traveling (if you don’t need your laptop, consider leaving it at home).
- Make your device use a passcode, rather than a fingerprint or Face ID, to unlock. This makes it harder for an agent to access your device.
- Consider bringing a “burner” phone that is completely free of any data or accounts.
- Be mindful of content on your phones and public social media profiles and log out of any account that may raise suspicion
- Permanently delete sensitive content (not just move to trash)
- Remember that while you can verbally state your non-consent to searches, border agents can still proceed with them, particularly for non-citizens.
What it is: Every email, document, user profile, and social media post is stored on a server somewhere, with a long and complicated set of terms of service and often, unclear policies on who owns the data and when and how it can be shared. Add to this collaborative work documents sharing using Google Drive or Microsoft OneDrive, and it’s clear we’re all swimming in a sea of data – our own and other people’s. Dozens of companies claim access to that information about ourselves, our work, and our collaborators. It can feel like we have little to no control over any of it.
What you can do: Conduct an organizational assessment of all file-storing procedures, as well as a sweep of all shared files. Are your old spreadsheets on Google Drive shared with volunteers who haven’t worked with you in years? Can unauthorized people view sensitive documents? Is your CRM, which is likely full of sensitive user data, properly protected? Did you import data into an app like Notion or Airtable before deciding it wasn’t for you? Take time to assess where all of your organization’s data is stored and what is shared.
What it is: So much of our work, communication, and daily life takes place on a chat app: Apple Messages, Slack, Facebook Messenger, WhatsApp, Signal, even DMs on Instagram. All of these platforms offer differing levels of security from third-party snoopers, hackers, and government surveillance.
What you can do: Conduct an overview of the chat apps you use. Are you worried about third parties being able to intercept your communications? Are you sharing organizational secrets on a platform that is subject to a law enforcement request? Is your team utilizing the appropriate archive controls on Slack?
All apps have strengths and weaknesses. For example, Signal uses a strong form of encryption and keeps your contacts secret, but it’s not used by everyone. WhatsApp is the most-used chat app in the world and is often the best way to be in touch with people, and it uses a strong form of encryption (the same as Signal), but it leaks your “social graph” (the people who you contact, who they contact, etc) to Meta.
What it is: The data shared on your chat apps, in your documents, and in your email is only as secure as the devices you use to access it. A law enforcement request or subpoena can give others access to your computer and phone, which could reveal sensitive data even if that data is encrypted.
What you can do: Use strong passwords on your laptop and desktop computers and ensure your hard drives are encrypted and put proper security measures in place on mobile devices.
What it is: Strong, unique passwords are the highest priority of online security, with two-factor authentication coming in second. Login information, including passwords, is routinely compromised on large and small websites, and attackers will use combinations of these to try to access email accounts, organization websites, file storage sites, health care platforms, and much more. In addition, successful phishing attempts gain access to users’ passwords. A second form of authentication in the form of an app-generated code or passkey can protect against this kind of intrusion.
What you can do: Use a password manager (we like 1Password) to generate and store long, unique passwords for EVERY account you have. Also turn on two-factor authentication (also known as multi-factor authentication) for every account possible, using Google Authenticator or a similar app. You can also explore using passkeys, a secure method for adding two-factor authentication to your accounts.
What it is: Given how much sensitive data users’ mobile devices hold, bad actors are constantly attempting to gain access by any means they can – including by tricking people into downloading malicious apps. These apps can steal private data and silently surveil users without anyone noticing. While targeted malware attacks are relatively rare (though brutally effective), broader, random attacks are common especially in regions where users rely on older Android phones that are prone to fall behind in security updates.
What you can do: Keep all of our devices up to date. Whenever you’re prompted to install an update on your phone, web browser, tablet, or computer, do it right away. These updates are usually meant to patch security vulnerabilities on your device or in your software. If you are using an Android phone, only install apps from the official Google Play app store.
Social impact, social justice policy, and advocacy groups are all under attack. The flurry of Executive Orders attempting to freeze trillions in federal funding, dismantle diversity, equity and inclusion (DEI) programming, withdraw from the Paris Agreement, and more, have significant impacts on a wide range of environmental causes. Environmental justice—a field that applies a racial and social equity lens to efforts addressing legacy pollution and historic underfunding in low-income and disadvantaged communities—is a target for its ties to DEI and climate action. In this new federal landscape, a range of environmental justice advocates, organizations and supporters could be impacted by executive action, Congressional oversight, reputational harm, or legal hurdles.
Below are some resources put together by our partners SKDK to help you navigate this landscape:
Crisis Communications & Reputational Risk
Threat Modeling
Incident Response
Mobile Security
Organizational Security
Physical Security
Removing Online Data
Crisis Communications and Reputational Risk
General Guides
Need help?
If you need immediate support, please email us or send a DM to @Kate at the Lab on our community Slack
We are here to listen and to help point you in the right direction if you have security questions or concerns.
-
-
Activist Tech Security
-
Can’t Find a Specific Resource?
We have hundreds of exclusive resources available only to our free member community.
Disclaimer
This page was set up to inform our community about resources and tools to help enhance digital security and risk management. They are not a guarantee of absolute protection, and users are responsible for their own security practices and potential risks.