Guided checklist

Review source protection across the reporting workflow.

Answer plain-language prompts about source contact, accounts, devices, pre-publication files, and escalation paths, then download a filled PDF for newsroom discussion.

Start guided checklist Get newsroom security help
Guided checklist

Walk through source protection from first contact to publication.

Use this guided checklist before a sensitive investigation, after a staffing change, or when deciding whether you need a tip line, private workspace, or deeper security review.

Source communication channels

Start by deciding how sources should contact reporters at different risk levels.

Which source communication channels are approved?

List the channels your newsroom expects reporters to use: email, phone, Signal, in-person, legal channel, anonymous tip line, or something else.

Example: Routine tips use email; sensitive sources use Signal or in-person; anonymous document submissions are not yet supported.

Do reporters know what each channel is and is not safe for?

Every channel has limits. Email has metadata. Phone numbers can identify people. Personal devices may not be controlled by the newsroom.

Example: Reporters know Signal is better for sensitive conversations, but we have not documented when email is acceptable.

Are source-facing shared inboxes secured?

Shared inboxes should have MFA, named owners, limited access, and recent review.

Example: Needs work: the tips inbox has MFA, but access has not been reviewed since last year.

What is the plan for high-risk source intake?

Before asking a high-risk source to send material, decide who handles intake, what channel is used, and where files go.

Example: Editor approves the intake plan first; source contact starts on Signal; files go into a restricted workspace.

Accounts, devices, and access

Source protection breaks down if newsroom accounts and devices are easy to compromise.

Is MFA enabled on newsroom-critical accounts?

Include email, file storage, publishing, password manager, social accounts, and admin accounts.

Example: Done for email and files; Needs work for social accounts.

Do reporters and editors use a password manager?

Unique passwords matter most for source-facing and publishing systems.

Example: Not sure: some staff use a password manager, but freelancers are not covered.

Are sensitive-reporting devices updated and protected?

Look for OS updates, disk encryption, screen lock, basic malware protection, and a plan for lost or suspicious devices.

Example: Needs work: staff laptops are updated, but freelancer devices are unmanaged.

Is departed staff and freelancer access removed?

Review files, accounts, workspaces, shared devices, publishing systems, and source-facing inboxes.

Example: Not sure: full-time staff offboarding is tracked, but contractors are inconsistent.

Pre-publication materials

Drafts, source notes, FOIAs, claims, timelines, and web captures need a clear home.

Where should sensitive reporting materials live?

Name the approved place for drafts, FOIAs, notes, claims, timelines, web captures, and sensitive files.

Example: Sensitive investigations use a private project workspace with limited access, not personal drives or ad hoc links.

Are personal drives and unmanaged folders avoided?

Personal storage makes access, retention, and source protection harder to explain.

Example: Needs work: some reporters still keep interview files in personal cloud folders.

Is access limited by project or investigation?

Sensitive files should not be open to the whole newsroom by default.

Example: Done: each investigation has a restricted folder approved by the editor.

What happens when the investigation closes?

Decide whether materials are archived, exported, restricted, or deleted, and who approves it.

Example: Editor and legal review the project folder; final evidence is archived; temporary exports are deleted.

Escalation path

These answers help the newsroom avoid improvising during a source, device, leak, or legal concern.

Who is called first for a source safety concern?

Name the first person or role, the first action, and what should not happen.

Example: Editor-in-chief is called first; pause outreach; do not discuss source identity in broad channels.

What happens if a reporter device seems compromised?

Avoid wiping evidence too soon. Decide who helps contain, preserve evidence, and protect accounts.

Example: Reporter stops using the device, calls the security contact, preserves screenshots, and resets key account sessions from another device.

What happens if a draft or sensitive file leaks?

Name who coordinates the response and what information should be gathered before public speculation.

Example: Managing editor coordinates; collect file names, access list, timestamps, and last known changes before notifying the wider team.

More resources

Keep going with related resources.

Need help scoping this?

Source protection is a workflow problem.

Secure Origin helps newsrooms and press freedom teams choose the right next step: Protect Devices for staff endpoints, Protect People for account risk, Protect The Organization for reporting workflows, Security Testing & Validation for proof, or a managed workspace for sensitive collaboration.

PGP for sensitive email
hello@secureorigin.io fingerprint:
0BA7 6A2D 2761 340E 394F 7F13 129B A65D 2CA7 34C5
Request review Book call