Skip to content

Digital First Aid

Definition

The emergency-response discipline for activists, organisers, and small organisations whose accounts, websites, devices, or social-media presence are under active attack — the reactive counterpart to preventive digital-security hygiene. It is to digital compromise what field first aid is to clinical medicine: short checklists, time-pressure decisions, and a clear chain of escalation.

It operates as triage. Contain the incident first — revoke sessions, force password resets, take the affected service offline if compromise is confirmed, preserve evidence. Stabilise — restore from the most recent clean backup, move comms onto channels the attacker cannot reach, reset second-factor credentials. Notify — alert staff, supporters, regulators where required, the press when silence does more harm than disclosure. Post-mortem — record what happened, what worked, and what to change next time.

The reference resources are the Access Now Digital First Aid Kit and the EFF’s Surveillance Self-Defense, both designed for use under time pressure by non-specialists. The triage frame is the same logic any general incident-response practice uses; the activist-specific content is the threat-modelling layer — the upstream discipline that identifies which assets the campaign needs to protect, against which adversaries, at what cost.

FAQ

What is Digital First Aid?

Digital First Aid is the emergency-response discipline for activists, organisers, and small organisations whose accounts, websites, devices, or social-media presence are under active attack. It is the reactive counterpart to preventive digital-security hygiene, using short checklists, time-pressure decisions, and a clear chain of escalation to respond to digital compromise.

What should you do first in a digital security incident?

The first step is to contain the incident: revoke sessions, force password resets, take the affected service offline if compromise is confirmed, and preserve evidence. Digital First Aid treats this as triage, before stabilising the situation or notifying staff, supporters, regulators where required, or the press when silence would do more harm than disclosure.

How does digital first aid stabilise a compromised account or service?

Stabilisation means restoring from the most recent clean backup, moving communications onto channels the attacker cannot reach, and resetting second-factor credentials. In the triage sequence, it follows containment and precedes notification. The aim is to establish a clean operational position after the affected account, website, device, or social-media presence has come under active attack.

What happens after a digital first-aid incident?

After containment and stabilisation, the process calls for notification and a post-mortem. Staff and supporters are alerted, regulators are notified where required, and the press may be informed when silence does more harm than disclosure. The team then records what happened, what worked, and what should change next time.

Full page: [[digital-first-aid]].