Digital Security
Definition
The practice and pedagogy of protecting activists, their data, devices, communications, and organisations from digital surveillance, harassment, account compromise, and infrastructure attack. A sibling discipline — not a subset — of physical security, legal-security, and security-culture; each protects a different threat surface.
It operates across four overlapping layers. Device hygiene — automatic updates, full-disk encryption, screen locks, recovery keys held offline. Account hygiene — unique strong passwords (in a manager), hardware-security-key 2FA, no SMS-based 2FA, prompt offboarding. Communications hygiene — encrypted messaging (Signal / Wire) for operational threads, encrypted-email for long-lived sensitive correspondence, threat-aware channel choice. Organisational hygiene — least-privilege access, written security policies, an incident-response plan rehearsed before it is needed.
Most real-world compromises succeed at the easy layers (reused password, phished 2FA, unpatched laptop), not the sophisticated ones. The canonical curriculum (Tactical Tech’s Holistic Security, the EFF’s Surveillance Self-Defense) embeds digital security in the group’s protective practice and treats threat-modelling — the upstream discipline that identifies what to protect, against whom, at what cost — as the entry point.
FAQ
What is Digital Security?
Digital Security is the practice and pedagogy of protecting activists, their data, devices, communications, and organisations from digital surveillance, harassment, account compromise, and infrastructure attack. It is a sibling discipline, not a subset, of physical security, legal-security, and security culture, with each discipline protecting a different threat surface.
What are the four layers of digital security?
The four overlapping layers are device hygiene, account hygiene, communications hygiene, and organisational hygiene. Device hygiene covers automatic updates, full-disk encryption, screen locks, and offline recovery keys. Account hygiene covers unique strong passwords, hardware-security-key 2FA, no SMS-based 2FA, and prompt offboarding. Communications and organisational hygiene address secure channels, access, policies, and incident response.
How should activists protect their accounts?
Account hygiene means using unique strong passwords stored in a manager, hardware-security-key 2FA, and no SMS-based 2FA. It also includes prompt offboarding. These practices are one layer of digital security, alongside device, communications, and organisational hygiene. The definition places them within the broader protection of activists, data, devices, communications, and organisations from digital threats.
Why does digital security use threat modelling?
Threat-modelling is the upstream discipline that identifies what to protect, against whom, and at what cost. It is the entry point to digital security and embeds the practice in a group’s protective work. It complements the four hygiene layers rather than replacing device, account, communications, or organisational safeguards.
What causes most real-world digital security compromises?
Most real-world compromises succeed at the easy layers rather than the sophisticated ones. The definition gives reused passwords, phished 2FA, and an unpatched laptop as examples. Digital security therefore treats device and account hygiene as part of the group’s protective practice, alongside communications and organisational hygiene, rather than focusing only on sophisticated attacks.
Full page: [[digital-security]].
