Active Incident? 24/7 Response →
SleuthX

Read this first

Are you on a device or network the person can see?

  • If they might be able to see this device, use one they can’t access — a friend’s phone, a library or public computer, or a domestic-violence shelter’s safe device. If you continue here, your visit may be visible on a synced iCloud, Google account, or shared family plan.
  • The Quick Exit button(top right) replaces this page with weather.com immediately — but it does noterase this visit from your history, and private/incognito mode doesn’t fully hide it either. To be safe, use a device the person can’t access.
  • If you’re in immediate danger, call 911. If you have a few quiet minutes, keep reading.

National Domestic Violence Hotline: 1-800-799-7233 · text START to 88788 · thehotline.org — 24/7, free, confidential.

988 Suicide & Crisis Lifeline: call or text 988 · 988lifeline.org — free, confidential crisis and emotional support, 24/7.

NNEDV Safety Net: techsafety.org — technology-safety help for survivors.

Threat Modeling

Threat Modeling Your Reporting

Security advice only makes sense once you know what you're protecting and from whom. A threat model is the short, honest exercise that turns a vague sense of danger into a handful of concrete, doable steps.

You cannot defend against everything, and trying to leaves you exhausted and no safer. Threat modeling, in the EFF’s framing, is just answering five plain questions about a specific story or beat — and then doing the few things the answers point to. It is a half-hour of thinking that prevents a lot of wasted worry.

The five questions

Turn answers into action

The point is to right-size your effort. A reporter facing harassment and account takeover should prioritize strong, phishing-resistant account protection and good backups. A reporter on a national-security beat who could plausibly be targeted by state-grade tools should add device hardening like Apple Lockdown Mode and stricter source-contact discipline. Same questions, different answers.

Revisit it

A threat model is a snapshot, not a one-time ritual. A new beat, a hostile legal threat, travel to a higher-risk place, or a sensitive new source all change the answers. Redo the five questions whenever the situation shifts — it takes minutes.

Build the plan with help

You do not have to do this alone. The free helplines in the sources below will work through a plan with you, and our digital security for journalists guide covers the hardening steps a model usually points to. If a model surfaces a real suspected compromise, move to checking the device carefully.

Primary sources

  1. Electronic Frontier Foundation, Surveillance Self-Defense — Your Security Plan (the threat-model framework). https://ssd.eff.org/module/your-security-plan
  2. Committee to Protect Journalists (CPJ), Digital Safety Kit — assessing risk before an assignment. https://cpj.org/2019/07/digital-safety-kit-journalists/
  3. Access Now, Digital Security Helpline — free help building a plan that fits your risk. https://www.accessnow.org/help/

Meet Your Practitioner

Quinnlan Varcoe

Founder & CEO

GIAC-certified · 15 industry certifications

With operational experience across Fortune 50 security programs and the defense industrial base, Quinnlan founded SleuthX in 2022 to provide clients with the caliber of expertise typically reserved for the largest enterprises. Her work in threat intelligence and digital forensics has earned the trust of 26,000+ cybersecurity professionals who follow her analysis.

“26,000 professionals follow my work because I say what others won't — and I can back it up technically.”

Fortune 50 BackgroundDefense IndustryThreat IntelligenceDigital PrivacyIncident Response
Quinnlan Varcoe, Founder & CEO

Certified Expertise

GIAC · AWS · Splunk · CompTIA

Transparent pricing

Trusted by partners across the practice

DAS Health
Exhibit A Cyber
Ally Security
KIRO Group
Black Mirage
Kalles Group
Gridware
CQR
Archstone Security
Cyvergence
Sentinel Cyber
Cloud Underground
Seron Security
Hexen
Koru Risk Management
DAS Health
Exhibit A Cyber
Ally Security
KIRO Group
Black Mirage
Kalles Group
Gridware
CQR
Archstone Security
Cyvergence
Sentinel Cyber
Cloud Underground
Seron Security
Hexen
Koru Risk Management