Active Incident? 24/7 Response →
SleuthX

For Journalists

Digital Security for Journalists

Harden your devices and accounts against the threats your reporting attracts — and know what to do, and what forensics can confirm, when prevention is not enough.

By Quinn Varcoe, Founder & CEO, SleuthX

Security is a process, not a product

The strongest sentence in journalist digital security is the one the EFF keeps repeating: it is a process, not a product.

There is no single app, setting, or purchase that makes a reporter safe.

What works is a habit — threat-model honestly, apply the controls that match, and revisit them when the beat or the adversary changes.

This guide does not try to out-checklist the organizations that maintain the canonical baselines.

It points you to them, then focuses on the part most guides skip: what to do, and what forensics can establish, when prevention has already failed.

Start with a threat model

Before any tool, answer four questions: what are you protecting, who wants it, what can they realistically do, and what happens if they succeed? A local-corruption reporter and a national-security reporter face different adversaries and need different defenses.

The EFF’s Surveillance Self-Defense calls this making a security plan, and it is the step that makes every later choice rational instead of superstitious. EFF Surveillance Self-Defense is the reference we send people to first.

The hardening that earns its place

A small set of controls does most of the protective work for a working journalist:

The step-by-step versions of all of this are maintained, and kept current, by the people whose job it is: the Freedom of the Press Foundation and the Committee to Protect Journalists.

We treat those as the canonical baseline.

We are not affiliated with them; we apply the same standards and cite them as the reference.

When prevention is not enough

Hardening shrinks your attack surface dramatically, and against most opportunistic and criminal threats that is decisive.

It is not immunity.

Mercenary spyware has been delivered through zero-click exploits that require no mistake from the target — no link tapped, no attachment opened.

When a credible reason exists to think something already happened, the answer is not a longer checklist.

It is confirmation.

What forensic confirmation can establish

A prevention guide cannot tell you whether you were already breached.

A forensic examination can look for indicators of compromise — anomalous sign-ins, planted mail-forwarding rules, unexpected configuration profiles, artifacts consistent with known spyware families — and document what is and is not present, to a standard that can support an insurance claim, a police report, or your counsel.

This is lawful defense and verification: we examine your own — or your newsroom’s authorized — devices and accounts, with consent, never to gain access to anyone else’s system.

We are candid about the limit: forensics can report “no known indicators of compromise found,” which is not the same as proving a device is clean.

If you suspect a targeted intrusion right now, move to newsroom device compromise response, which covers preservation and the confirmation method in detail.

What working with us means

Related guides

Protecting a specific source or intake channel is its own discipline — see protecting journalistic sources.

Verifying open-source material for a story is covered in OSINT for journalists, and where a matter needs a lawful open-source investigation conducted for you, see our OSINT investigation services.

If the concern is monitoring software on a personal phone rather than mercenary spyware, our guide to stalkerware detection and removal covers that.

The overview of how a forensic practice supports reporting is on the For Journalists hub.

Plain terms

What we are — and what we are not

What we are

A digital forensics practice with an AI agent at the center. Credentialed examiners, documented chain of custody, explainable findings you can verify, and court-admissible reports under FRE 901/902. When field work is needed — backgrounds, locates, physical surveillance — we coordinate with licensed private investigators. Lawful, confidential, on your side.

What we are not

Spyware, stalkerware, or a way to secretly monitor another person. We do not “hack back,” promise guaranteed money recovery, or touch any account or device without its owner's lawful authorization — and we decline engagements that ask us to.

Meet Your Practitioner

Quinnlan Varcoe

Founder & CEO

GIAC-certified · 9 industry certifications

With operational experience across Fortune 50 security programs and the defense industrial base, Quinnlan founded SleuthX in 2022 to provide clients with the caliber of expertise typically reserved for the largest enterprises. Her work in threat intelligence and digital forensics has earned the trust of 26,000+ cybersecurity professionals who follow her analysis.

“26,000 professionals follow my work because I say what others won't — and I can back it up technically.”

Fortune 50 BackgroundDefense IndustryThreat IntelligenceDigital PrivacyIncident Response
Quinnlan Varcoe, Founder & CEO

Certified Expertise

GIAC

Frequently asked about journalist digital security

Isn't digital security just a checklist I can follow once?
No. Security is a process, not a product — the phrase the EFF uses for a reason. A checklist completed once protects you against last month's threat model, not this month's beat. The right baseline is to threat-model honestly (who would want this material, what can they do, and what happens if they get it), apply the controls that match, and revisit them when the beat or the adversary changes. We point you to the established baselines first, then add what forensics can verify.
What hardening actually moves the needle for a working journalist?
A short list does most of the work: phishing-resistant two-factor authentication using FIDO2 security keys or passkeys (not SMS codes), full-disk encryption on every device, Signal for sensitive conversations, a password manager with unique credentials, prompt OS and app updates, and compartmentalization so a sensitive beat does not share accounts or devices with everyday life. The Freedom of the Press Foundation, CPJ, and EFF maintain the canonical step-by-step guides — we treat those as the standard, not something to out-checklist.
If I do all of that, am I safe from spyware like Pegasus?
Hardening reduces your exposure substantially, but it is not immunity. Mercenary spyware has used zero-click exploits that need no mistake from the target, and good operational security does not change that. What hardening does is shrink the attack surface and make most opportunistic and criminal threats far harder. For the rare targeted-spyware case, the answer is not a stronger checklist — it is forensic confirmation. That is the line where this guide hands off to device compromise response.
What does forensic confirmation add after a suspected breach?
Prevention guidance cannot tell you whether something already happened. A forensic examination can look for indicators of compromise on a device or account — anomalous sign-ins, planted forwarding rules, configuration profiles, artifacts consistent with known spyware families — and document what is and is not present, to a standard that can support a report, an insurance claim, or counsel. The honest output is “indicators found” or “no known indicators of compromise found,” never a guarantee that a device is clean.
Do you work with our existing IT or security staff?
Yes. On a newsroom team we slot in alongside in-house IT — we are the forensic and incident-confirmation layer, not a replacement for your day-to-day security operations. Where a matter needs legal direction we work with your media-law counsel, and where it needs field investigation we coordinate with licensed private investigators.
Quinnlan Varcoe, Founder & CEO
Quinnlan Varcoe
GIAC-certified · Founder & CEO

Schedule Your Session

Hardened, or already breached? We can tell you which.

A direct, confidential conversation with Quinn, the founder and CEO who reviews every case. We work alongside your in-house IT and your media-law counsel. NDA-protected. No sales process.

Free, confidential · NDA-protected · no obligation.

  1. 1. Book a 15-minute call — we scope your situation, no charge.
  2. 2. You get a written scope — deliverables, timeline, and price — before any work begins.
  3. 3. Approve it and we start; most engagements begin within 48 hours.

Transparent pricing

Trusted by partners across the practice

DAS Health
Exhibit A Cyber
Ally Security
KIRO Group
Black Mirage
Kalles Group
Gridware
CQR
Archstone Security
Cyvergence
Sentinel Cyber
Cloud Underground
Seron Security
Hexen
Koru Risk Management
DAS Health
Exhibit A Cyber
Ally Security
KIRO Group
Black Mirage
Kalles Group
Gridware
CQR
Archstone Security
Cyvergence
Sentinel Cyber
Cloud Underground
Seron Security
Hexen
Koru Risk Management