Join our Newsletter — 33% off our NHI Course
Home› FAQ› Authentication, Authorisation & Trust› Why do journalists and PR professionals need more…
Authentication, Authorisation & Trust

Why do journalists and PR professionals need more than passwords to stay secure online?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 27, 2026 Domain: Authentication, Authorisation & Trust

Passwords protect only one layer of access. Journalists and PR teams face password theft, brute-force attacks, surveillance, and message interception, so a second verification factor materially reduces account takeover risk. When communication involves sources, leads, or sensitive internal data, layered controls matter because a single compromised credential can expose both identities and content.

Why passwords are not enough for journalists and PR teams

Passwords are a single secret, and a single secret is easy to steal, guess, reuse, or phish. For people whose work attracts targeted surveillance or account takeover attempts, the real issue is not just login failure, it is the blast radius after one credential is exposed. Adding a second factor changes the attack from “find the password” to “defeat another control too.”

That matters because journalists and communicators often operate under asymmetric risk. A compromised inbox, social account, or cloud workspace can expose sources, embargoed material, media lists, internal drafts, or sensitive contact details. Second-factor protection does not make an account invulnerable, but it materially raises the cost of opportunistic abuse and many credential-based attacks.

How stronger login protection changes the attack path

Two-factor or phishing-resistant authentication adds a checkpoint that is harder to reuse at scale than a password alone. That is especially important when credentials are recovered through phishing, credential stuffing, malware, or intercepted login sessions. If an attacker gets only the password, they still face an additional barrier before they can read mail, send messages, or reset other accounts tied to the same address.

Modern guidance increasingly prefers phishing-resistant methods for higher-risk users because one-time codes can still be intercepted, replayed, or socially engineered. A stronger factor should also be paired with careful recovery settings, because account recovery often becomes the weakest link once the primary password is no longer the main line of defense.

What practical protection should look like in media and communications work

For journalists and PR professionals, the goal is not simply “turn on 2FA,” but choose a setup that matches the sensitivity of the work. That usually means protecting email first, then the accounts that depend on email for password resets, then collaboration tools, cloud storage, and social platforms. If one account is used to reach many others, it deserves the strongest available sign-in controls.

It also helps to treat authentication as part of a broader operational security posture. Secure sign-in does not replace device hygiene, secure messaging, or careful sharing of links and attachments. It works best when the account is tied to a trusted device, recovery methods are limited, and login alerts are actually monitored. For broader control design, NIST’s Digital Identity Guidelines are a useful reference point for stronger authentication choices.

Risk and Threat Considerations

Account takeover is the main risk, but the downstream impact is often larger than the login itself. A single compromised mailbox or social account can reveal source relationships, enable impersonation, expose unpublished material, and give an attacker a trusted channel for fraud or surveillance.

Failure mechanism: Password-only access fails when passwords are reused, phished, brute-forced, or recovered through weak support processes, and the attacker then leverages the trusted account to read, impersonate, reset, or pivot into connected services.

Impact: The compromise can expose confidential communications, damage source trust, create reputational harm, and extend into other accounts if email or SSO is the recovery path.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-63, NIST SP 800-53 Rev 5, NIST CSF 2.0 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-63Digital Identity GuidelinesDirectly governs stronger authentication choices and phishing-resistant login methods.
Recommendation — Adopt phishing-resistant authenticators for high-risk accounts and tighten recovery controls.
NIST SP 800-53 Rev 5IA-2 — Identification and Authentication (Organizational Users)Journalists and PR teams need stronger user authentication than passwords alone.
Recommendation — Require multifactor authentication for accounts that access sensitive communications.
NIST CSF 2.0PR.AA-05 — Managed AccessThe question is about reducing account takeover through layered access control.
Recommendation — Implement managed access with stronger authenticators for sensitive accounts.
CIS Controls v8CIS-6 — Access Control ManagementThis topic centers on limiting unauthorized account access and takeover.
Recommendation — Enforce access control measures that reduce unauthorized logins and account misuse.
ISO/IEC 27001:2022A.5.17 — Authentication informationPasswords and second factors are authentication information that must be protected and managed.
Recommendation — Protect authentication information with stronger enrollment, storage, and recovery practices.

Practitioner Guidance

What to prioritise: Protect the accounts that unlock other systems first, especially email, cloud storage, and social platforms used for outreach or publishing. Those accounts usually provide the fastest route to wider compromise.

What to verify: Prefer phishing-resistant authentication where it is available, and check that recovery methods, backup codes, and support procedures are not easier to abuse than the login itself. A weak recovery path can undo a strong factor.

Common mistake: Treating SMS codes or one-time passcodes as the end state. They are better than passwords alone, but they are not the same as a phishing-resistant second factor, especially for high-risk users.

Practitioner takeaway: For journalists and PR professionals, secure login is really about reducing the chance that one stolen password becomes full visibility into people, plans, and communications.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 27, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org