All articles
Press freedom · Case study

Building a managed security workspace for The Southlander

5 min read

The organization

The Southlander is a small local news team doing public-interest reporting. Like many independent newsrooms, the team has to protect drafts, assignments, internal planning, account access, and source-adjacent materials without the budget or staffing of a large media organization.

This case study is based on work done for a real newsroom environment. Sensitive implementation details have been deliberately removed: no internal hostnames, network ranges, recovery paths, credentials, or private screenshots are included. The goal is to show the operating model, not expose the system.

The problems

Small news teams often inherit the same security problems as larger organizations, but without the same support structure.

What we built

The first goal was to create a private workspace that the team could actually use. The second was to make it the foundation for ongoing managed security.

The workspace uses identity-based access instead of relying on public application exposure. Team members authenticate through a public identity endpoint, join a private network, and then reach internal tools through normal team-friendly hostnames. The apps themselves stay private.

That distinction matters. The login path has to be reachable from a fresh device, but the collaboration apps do not need to be open to the world.

The current workspace model includes:

For the first rollout, users can log in with password-based identity while accounts are being created and devices are being joined. Passkeys and YubiKeys remain part of the plan, but they will be introduced during an in-person enrollment session so users understand what they are setting up and how recovery works.

The managed security layer

The workspace is only one part of the work. The more important service is the managed security layer around it.

For The Southlander, that means treating security as an ongoing operating function:

This is the part most small teams need but do not have. A private workspace is useful. A private workspace with someone responsible for operating the access model, recovery process, and security review cadence is much more useful.

How the user journey works

A new team member should not need to understand the infrastructure.

They receive an account, sign in through the identity provider, join the private network, and open the workspace tools they need for their role. Later, during an in-person security session, they enroll a passkey or hardware key and learn what to do if a device is lost or replaced.

For the user, the experience should feel like:

  1. Sign in.
  2. Join the private workspace.
  3. Open the tools.
  4. Ask for help when access or device security changes.

For the operator, the important pieces are different:

  1. Confirm the user is active and entitled.
  2. Keep apps private by default.
  3. Make onboarding repeatable.
  4. Preserve recovery access.
  5. Add stronger authentication without creating avoidable lockout risk.

Why this matters for other news teams

The same pattern applies to many independent newsrooms and journalism nonprofits.

They may not need a large enterprise security program. They usually do need:

This is where managed security and managed workspaces overlap. The goal is not to sell a pile of tools. The goal is to give a small team a security operating model it can live with.

The outcome

The Southlander now has the foundation for a private newsroom workspace and a managed security program that can grow with the team.

The most important outcomes are:

The work is still evolving. That is part of the point. Security for small organizations should not be treated as a one-time project that produces a binder and disappears. It should become a manageable rhythm: onboard, review, improve, test, document, and repeat.

Services used

Security services

Workspaces

Need a secure workspace for your newsroom?

Start with a practical review of your accounts, devices, collaboration tools, and source-sensitive workflows.

Request newsroom security review Use the source protection checklist
Request review Book call