← Privacy Guides

Start here

Operational security: turn your plan into daily habits

Turn a written threat model into daily discipline: reveal less, keep boring routines, share on a need-to-know basis, assume something is already compromised, and recognise the targeted phishing and social engineering aimed at you.

  • High threat
  • Time 45 minutes to read, then ongoing practice
  • Difficulty Advanced
  • Last verified

What this protects, and what it doesn't

Protects

  • Against the small leaks that add up: who you meet, when and where, and what you are working on, pieced together from many ordinary details.
  • Against a single mistake becoming a disaster: compartmentalising and assuming compromise limit how far one stolen phone, account or careless message reaches.
  • Against targeted phishing and social engineering, by making "verify through a second channel before you act" a reflex instead of a decision made under pressure.
  • Against your own inconsistency: a routine you actually keep protects more than an elaborate one you abandon after a week.

Does not protect

  • It is discipline, not a tool. It protects nothing by itself; it makes the tools in the other guides actually work.
  • It cannot undo information already public. Operational security limits future exposure; it does not erase what an adversary has already collected.
  • It does not defeat a lawful legal process, device seizure or a court order. This guide is about protecting at-risk people from hostile surveillance and targeted attacks, not about evading a lawful investigation.
  • It is only as strong as the people you work with. If an ally reuses a password, talks loosely, or loses an unlocked phone, your own discipline cannot fully cover for them.
  • It does not make you anonymous or untraceable. A well-resourced adversary who can watch your network or your contacts may still infer a great deal.

Prerequisites

  • A written threat model: what you protect, from whom, how likely and how bad, and how much effort you will sustain. Start with the Threat modeling guide if you have not done this.
  • The habit of writing plans somewhere your adversary cannot read (an encrypted note or paper), not a synced document on an account they could reach.
  • Agreement from the people you work with to use the same tools and routines. Your security overlaps with theirs.

Step by step

  1. Reveal less: decide what the world does not need to know

    Operational security starts by deciding, in advance, what information about your work and your life you will not put out. Every detail you publish or mention is something an adversary does not have to steal. Small, ordinary facts combine: a photo with location data, a public calendar, a "checking in from" post, a reply that confirms who you are meeting, and the picture builds itself.

    Go through where your details appear and cut what is not needed: social media profiles, out-of-office replies, forum signatures, the metadata inside files you share, and the people-search and data-broker sites that resell your address and phone number. Before you post or send, ask one question: does this reveal where I am, who I am with, or what I am working on?

    Strip metadata from photos and documents before you share them, so a file does not carry a GPS position, a camera serial or an author name you did not intend to hand over.

  2. Compartmentalise: share on a need-to-know basis

    Compartmentalisation means a person learns only what they need for their part, and no single device, account or person holds the whole picture. If one compartment is breached, the others stay intact.

    In practice: keep sensitive work off your everyday accounts and everyday device; use separate accounts, and if your threat model is high, separate devices, for separate roles. Do not copy a contact list, a source list or a plan into a general-purpose app "to be convenient". Ask, for each person, what is the least they need to know to do their part.

    Example: Alice Example coordinates a sensitive project at Example Corp. The logistics contact knows the meeting time and place but not the subject; a colleague knows the subject but not the participants' real names. No one list ties all of it together, so no single stolen phone exposes everything.

  3. Keep consistent, unremarkable routines

    Security that depends on remembering to be careful fails the day you are tired or rushed. Turn protections into defaults so the safe path is the easy path: a password manager that fills credentials only on the real site, disk encryption that is simply always on, a messaging app set to encrypt by default, automatic software updates, and a locked screen with a strong passcode.

    Make the routine the same every time. Decide once which device you use for which role, which app you use to reach a given person, and how you confirm a request before you act on it — then do it that way every time, including when it is inconvenient. Predictable-to-you, boring routines leave fewer gaps than clever exceptions. Rehearse the few that matter (how you verify an urgent message, what you do if a device is lost) so the habit is there before the pressure is.

  4. Assume something is already compromised

    Plan as if any one device, account or channel could already be in hostile hands, and limit how far that reaches. This is not paranoia; it is how you keep one failure from becoming total failure.

    • Limit the blast radius. Unique passwords per account (so one leak does not open the rest), phishing-resistant two-factor such as a hardware security key or passkey, and compartmentalised accounts mean a single breach stays contained.
    • Keep little on the device. Store only what you currently need; delete or move the rest. A phone that holds three days of messages exposes three days, not three years.
    • Watch for signs. Unexpected password-reset or login alerts, messages marked read that you did not open, or a contact saying you "sent" something you did not — treat these as possible compromise, not coincidence.
    • Know your recovery move in advance. Decide now how you would lock an account, revoke a device and warn the people you work with, so you are not improvising during an incident.
  5. Recognise targeted phishing and social engineering

    At-risk people are targeted deliberately, with messages built from details about them: a believable sender, a real project name, the right tone, and pressure to act now. The attacker may be phishing for a password on a fake login page, getting you to open an attachment that installs spyware, or impersonating a colleague or "support" by email, text or a spoofed phone call (including a cloned voice).

    Defences that hold up under a targeted attack:

    • Verify through a separate channel. Before acting on any urgent or sensitive request, confirm it using contact details you already have — not the ones in the message. Call the person back on a known number; do not "reply" to confirm.
    • Do not trust the sender field or a logo. Both are trivial to fake. Judge a request by what it asks for, not how official it looks.
    • Reach login pages yourself. Type the address or use a bookmark instead of following a link. A password manager that refuses to auto-fill is a warning: the domain is not the real one.
    • Treat unexpected attachments as hostile. Open a document you did not expect in a sandboxed viewer rather than directly, and never grant remote access or passwords to unsolicited "support".
    • Use phishing-resistant two-factor. A hardware security key or passkey will not hand a working login to a fake site the way a typed code can.
  6. Practise secure meetings and handoffs

    When the stakes are high, the most privacy-protective conversation is often in person, with no computers or phones involved — remembering that the fact two people met, and where, is itself information.

    • In person: agree the time and place over an end-to-end encrypted channel, keep the details inside the need-to-know circle, and consider leaving phones elsewhere or powered off, since a phone can reveal that two people were in the same place.
    • Remotely: use end-to-end encrypted messaging or calls, and make sure everyone is on the same tool with the right settings — a chat is only as encrypted as its weakest participant. Remember that encryption hides the content, not the metadata of who contacted whom and when.
    • Verify who you are talking to. For a sensitive contact, confirm their identity out of band — for example by comparing the app's safety number or verifying a key — so you are not end-to-end encrypted to an impostor.
    • Handing something over: prefer end-to-end encrypted transfer, set messages to disappear when the other side no longer needs them, and strip metadata from any file first. Agree in advance what each side deletes afterwards.
  7. Review, debrief and keep the plan current

    Operational security is a loop, not a one-off. After anything sensitive, take a few minutes to ask what revealed more than intended and what you will change. Put a recurring review in place — and review immediately after any big change in your life or work, because a new role, a public profile or a new adversary changes the whole plan.

    Keep the people you work with in sync: the same tools, the same verification habit, the same answer to "what do we do if a device is lost". A plan that lives only in your head protects only you.

Common mistakes

  • Treating operational security as a set of tools to install rather than habits to keep. The habit is the control.
  • Being careful only during the "important" task and loose the rest of the time, so the adversary learns everything from the ordinary moments.
  • Mixing identities or roles on one device or account for convenience, so a single compromise exposes all of them.
  • Acting on an urgent request without verifying it through a second channel — exactly the pressure a targeted phishing message is built to create.
  • Assuming end-to-end encryption hides the fact that you communicated. It protects the content, not the metadata of who, when and where.
  • Forgetting that a meeting leaves traces — location data, calendar entries, a phone that was in the same place as another phone.
  • Keeping the plan, or the people who share your risk, out of sync: your security is only as strong as the weakest person you work with.

Going further

Operational security ties the rest of the guides together. Anchor it to a written threat model so your effort matches your real risk, and build the underlying habits with the account, device, communications and encryption guides. If your situation is genuinely high-risk, do not do this alone: press-freedom and digital-rights organisations, and your own security team, run threat-modelling and operational-security sessions for people in exactly your position. Review the plan on a schedule and after every significant change.