Join our Newsletter — 33% off our NHI Course

How should journalists protect accounts that hold sensitive reporting materials and source access?

Journalists should use strong, unique passwords for every account, turn on two factor authentication wherever it is available, and avoid reusing usernames or credentials across services. A single reused password can expose email, social media, and newsroom tools if one site is breached. Use a password manager to create and store unique credentials, then review recovery settings so access cannot be quietly taken over.

Protecting reporting accounts starts with reducing credential reuse and recovery abuse

For journalists, the most common failure mode is not a sophisticated intrusion, but account reuse across email, social platforms, newsroom systems, and cloud storage. If one service is breached, a reused password can turn a single compromise into access to source communications, drafts, document stores, and account recovery channels. A password manager and unique credentials change that from a single-point failure into isolated exposure.

Two factor authentication matters because sensitive reporting accounts are high-value targets even when the password itself is strong. The practical priority is to protect the account paths that attackers and insiders often use first: login, password reset, backup email, phone recovery, and session tokens. If recovery settings are weak, an attacker may not need to defeat the password at all.

Journalists should also treat usernames and recovery details as part of account hygiene. Reused usernames make credential stuffing and account correlation easier, while predictable recovery answers or shared phone numbers can create quiet takeover paths. The goal is to make each account harder to link, harder to guess, and harder to recover without the right person noticing.

Why source protection needs more than login security

Reporting accounts often hold material that is sensitive before publication, including source identities, notes, contact lists, and document trails. That makes these accounts attractive not only to criminals, but also to anyone trying to map a reporter’s network or anticipate future coverage. Protecting the login is therefore necessary, but it is not sufficient if the account can still expose drafts, inbox history, or synced files after compromise.

The strongest practical control is to reduce the amount of sensitive material concentrated in any one account. Separate systems for communications, storage, and publishing can limit blast radius when a password, token, or recovery path is exposed. Where a platform supports it, review device sessions and connected apps so old access does not persist long after the journalist stops using a device or service.

Source access should also be protected as a relationship, not only as content. If one account controls both inbox and file storage, compromise can reveal who is in contact with the reporter and what evidence is being gathered. That is why account protection, storage segregation, and session review belong in the same security decision.

What newsroom practice should look like in day-to-day use

For a journalist, the right control set is one that can actually be sustained under deadline pressure. Use a password manager that is trusted, locked with a strong master credential, and available on every device you regularly use. Turn on two factor authentication for email first, then for chat, cloud storage, CMS, and any platform that can expose a source list or a story draft.

When possible, prefer authentication methods that resist phishing and push fatigue. App-based one-time codes are better than nothing, but accounts with the highest sensitivity are safer when protected by stronger factors or hardware-backed methods. The key judgment is to reserve the most robust protection for the accounts that could reveal sources or newsroom access if compromised.

Review account recovery options as part of the same routine. A backup email address, phone number, or recovery app that is itself weak or widely shared can undo the value of the primary login controls. If a recovery path cannot be protected to the same standard as the account, it should be changed or removed.

Risk and Threat Considerations

Sensitive reporting accounts create a high-value target for credential stuffing, phishing, account recovery abuse, and session theft. The operational risk is not just unauthorized access, but exposure of source networks, unpublished material, and related accounts that are linked through the same login or recovery chain.

Failure mechanism: A reused password, exposed backup channel, or hijacked session lets an attacker bypass the normal login path and pivot into email, cloud storage, and newsroom tools. Once inside, the attacker may search for source names, attachments, and recovery settings that extend access further.

Impact: A single account compromise can expose confidential reporting, identify sources, and create secondary risk for people who trusted the journalist with information. It can also undermine the safety of future reporting by revealing patterns, contacts, and timelines.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP API Security Top 10 addresses the attack surface, OWASP ASVS and NIST SP 800-53 Rev 5 set the technical controls, and ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
OWASP ASVS V6 — Authentication Strong passwords and MFA directly address account authentication for sensitive reporting accounts.
Recommendation — Require strong authentication and MFA for all reporting accounts.
NIST SP 800-53 Rev 5 IA-5 — Authenticator Management Unique passwords, recovery settings, and password managers are authenticator lifecycle controls.
IA-2 — Identification and Authentication (Organizational Users) Journalists need strong user authentication for access to newsroom and source systems.
Recommendation — Manage authenticators, recovery paths, and rotation as part of account protection. Enforce strong user authentication for newsroom and source-access accounts.
ISO/IEC 27001:2022 A.5.15 — Access control Account protection depends on restricting access and limiting account misuse.
Recommendation — Apply access control to limit who can reach sensitive reporting systems.
OWASP API Security Top 10 API2 — Broken Authentication Recovery and login weaknesses can enable unauthorized account access.
Recommendation — Harden authentication paths to prevent unauthorized account takeover.

Practitioner Guidance

What to prioritise: Protect the primary email account first, then the storage and messaging services that can reveal sources or reset other logins. If only one account gets stronger controls, make it the one that can unlock the rest.

What to verify: Confirm that recovery email, phone, backup codes, and linked devices are all under your control and cannot be guessed or socially engineered through shared contact details. Also check whether old sessions and connected apps still have access after a device change.

Common mistake: Treating two factor authentication as complete protection while leaving recovery paths, tokened sessions, and reused usernames untouched. That leaves a quieter route to the same account.

Practitioner takeaway: For journalists, account protection is really source protection, so the best control is the one that closes both direct login abuse and the less visible recovery paths that can quietly reopen access.