Top Digital Security Tips for Civil Society Activists
Simple, field-tested digital security habits that help civil society activists lower their risk online and keep doing their work with more confidence.
- Author
- Abdelghani Achahoud
- Reading
- 8 min
- Focus
- Digital Security
Article
Civil society activists work in a difficult digital environment. From my experience working with activists, journalists and human rights defenders across the MENA region, online security is one of the most pressing problems they deal with every day. Activists are often targeted on purpose, exactly because of the work they do. That is why a set of solid digital safety habits is not optional, it is part of the job.
In this article I want to share some of the key tips I have learned from the capacity-building programs I have been delivering since 2018. These are not complicated. Most of them take a few minutes to set up, and together they will make you a much harder target.
Start with a Simple Threat Model
Before we talk about tools, we need to talk about thinking. The most common mistake I see is people rushing to install apps without asking the basic question first: what am I actually protecting, and from whom?
This is called threat modeling, and it does not require any technical skills. Sit down and answer four simple questions:
- What do I want to protect? Your accounts, your sources, your location, your organization's data.
- Who might want it? A hostile government, a hacker, a competitor, an abusive individual.
- How likely is it that they will try?
- What happens if they succeed?
Your answers decide where you put your effort. A journalist protecting confidential sources has a different risk profile than a volunteer running a community page. When you know your own risks, every other decision in this article becomes easier, because you stop trying to defend against everything at once and start defending against what really matters to you.
It Starts with Strong, Unique Passwords
Your accounts are only as safe as the passwords that guard them. This is something I repeat in every cybersecurity training I run. A strong password is long, hard to guess, and different for every account.
The word "long" matters more than "complicated". A passphrase made of four or five random words is easier to remember and harder to crack than a short word with a few symbols added. But here is the real problem: nobody can remember a different long password for dozens of accounts. So people reuse the same one everywhere, and that is dangerous. I have seen too many cases where one leaked password opened the door to a person's email, then their social media, then their organization's files.
The solution is a password manager. Tools like Bitwarden or a similar trusted manager create and store unique passwords for you, so you only need to remember one strong master password. Please stop saving passwords in your browser, and please stop keeping them in a notebook or a phone note. A password manager is one of the highest-impact changes you can make today.
Turn On Two-Factor Authentication
A password alone is a single wall. Two-factor authentication, or 2FA, adds a second wall. Even if someone steals your password, they still cannot log in without the second factor.
Not all 2FA is equal, so it helps to know the order from strongest to weakest:
- A physical security key is the strongest option and is worth it for high-risk accounts.
- An authenticator app such as Aegis, Authy or Google Authenticator is the next best choice and works well for most people.
- SMS codes sent to your phone are the weakest, because attackers can sometimes take over your phone number and receive those codes.
SMS is still better than no 2FA at all, but move to an app or a key when you can.
Turn on 2FA at least for your email and your main social media accounts. Your email is the master key to your digital life, because most password resets go through it. Protect it first.
Learn to Recognize Phishing
Most successful attacks against activists do not rely on breaking encryption. They rely on tricking a person. This is called phishing, and it is the threat I worry about most, because it targets human trust rather than technology.
A phishing attack usually arrives as a message that looks urgent and familiar. It might pretend to be from a platform you use, a colleague, or a funder. It asks you to click a link, log in, or open an attachment. The link leads to a fake login page that steals your password, or the attachment installs something harmful.
Slow down before you click. Check the sender's real address, not just the display name. Hover over links to see where they truly go. Be suspicious of any message that pressures you to act fast. When something looks like it comes from an important contact, confirm through another channel, for example a quick call or a message on Signal. Taking thirty extra seconds has saved many people I have worked with from a serious breach.
Use Encrypted Communication Tools
In digital spaces, ordinary messages and calls can be intercepted. Encrypted tools protect your conversations so that only you and the person you are talking to can read them.
Signal is my first recommendation. It is end-to-end encrypted by default, it collects very little information about its users, and it is free. WhatsApp is also end-to-end encrypted, but it keeps more metadata about who you talk to and when. For sensitive discussions, turn on disappearing messages so old conversations do not stay on your device forever, and take a moment to verify the identity of the person on the other side.
For activists working on sensitive issues, which I supported for years through my work at the Innovation for Change MENA Hub, encrypted communication is not just a nice extra. It is a basic protection for you and for the people who trust you with information.
Protect Your Devices Themselves
We often focus on accounts and forget the device in our hand. But a lost, stolen or confiscated phone can expose everything on it at once.
Turn on full-disk encryption. On most modern phones this is on by default once you set a screen lock, and on computers you can enable it through built-in tools like BitLocker on Windows or FileVault on Mac. Use a strong screen lock, a PIN or passphrase rather than a simple pattern. Keep your screen set to lock quickly when idle. And be careful about which apps you install and what permissions they ask for, because a flashlight app does not need your contacts or your location.
Protect Your Connection with a VPN
A Virtual Private Network, or VPN, hides your IP address and encrypts the traffic between your device and the VPN server. This is genuinely useful in two situations: when you are on public or untrusted Wi-Fi, and when you need to reach a website that is blocked in your country.
But let me be clear about what a VPN does not do, because there is a lot of marketing that overpromises. A VPN does not make you anonymous, and it does not protect you from phishing or weak passwords. It also moves your trust from your internet provider to the VPN company, so the provider you choose matters. Pick a reputable service with a real no-logs policy, and be careful with free VPNs, since some of them make money by selling your data.
Back Up Your Data Regularly
Devices get lost, stolen, confiscated or simply break. I have supported activists who lost years of work because they had no backup. Do not let that be you.
A good rule to follow is 3-2-1: keep three copies of your important data, on two different types of storage, with at least one copy kept somewhere else, such as encrypted cloud storage or an external drive stored in another location. Encrypt your backups so a stolen drive does not become a leak. And test your backups from time to time, because a backup you cannot restore is not really a backup.
Keep Everything Updated
Software updates are not just about new features. Most of them fix security holes that attackers already know about and actively use. Running outdated software is like leaving a door unlocked after everyone knows the lock is broken.
Update your operating system, your apps and your browser regularly. Turn on automatic updates where you can, so you do not have to remember. This one habit quietly closes a large number of attacks before they can reach you.
A Final Word on Digital Safety
I always tell the activists and organizations I work with the same honest truth: no one can promise you one hundred percent safety. Anyone who does is selling something. The real goal is to lower your risk enough that you can keep doing your important work with more confidence.
The steps in this article are a strong start. Threat modeling tells you where to focus. A password manager and 2FA protect your accounts. Awareness protects you from phishing. Encryption protects your conversations, backups protect your work, and updates keep the door closed. None of these are hard, and together they make a real difference.
Security is also not a one-time task. It is a habit and a mindset that grows with practice and awareness, something I try to support through resources like AmanRaqmy.org. Stay safe, stay alert, and keep doing the work that makes our societies more just and inclusive. Your security matters, and the time you invest in it is an investment in the future of your activism.
Topics
Frequently asked questions
What are the most important first steps for an activist to improve digital security?
Start by writing down who might target you and what you need to protect. This is called threat modeling. After that, the highest-impact steps are a password manager with strong unique passwords, two-factor authentication on your key accounts, and learning to spot phishing messages.
Which type of two-factor authentication is the safest?
A hardware security key is the strongest option, followed by an authenticator app such as Aegis, Authy or Google Authenticator. SMS codes are better than nothing, but they are the weakest form of 2FA because attackers can sometimes hijack your phone number.
Which messaging apps are safest for sensitive conversations?
Signal is my first recommendation because it is end-to-end encrypted by default and collects very little data. WhatsApp is also end-to-end encrypted, but it keeps more metadata. For sensitive topics, turn on disappearing messages and confirm the identity of the person you are talking to.
Does a VPN make me anonymous online?
No. A VPN hides your IP address and encrypts your traffic between you and the VPN server, which is useful on public Wi-Fi or when a website is blocked. But it does not make you anonymous. Choose a trusted, no-logs provider, because the VPN company can see your traffic.
How should activists back up important files?
Follow the 3-2-1 rule: keep three copies of important data, on two different types of storage, with one copy kept off-site or in the cloud. Encrypt your backups, and test from time to time that you can actually restore them.
Can I ever be one hundred percent safe online?
No, and anyone who promises that is not being honest. The goal is not perfect safety, it is reducing risk to a level you can manage so you can keep doing your work. Good habits, regular updates and ongoing learning make a real difference.

