Runa Sandvik is a cybersecurity researcher and consultant who builds security around the people at risk, the technology they use and the consequences of a compromise. Her work has included Tor, press-freedom organizations and newsroom security; through Granitt, she advises journalists and other people facing elevated digital or physical threats.
Who is Runa Sandvik?
Sandvik is a security researcher whose work focuses on people who may be targeted because of their reporting, advocacy, legal work or investigations. Her career began with Tor Project work connected to Google Summer of Code in 2009. A 2011 Tor Project presentation lists her as a Tor developer, security researcher and translation coordinator. In a 2022 Q&A, she recalled discovering Tor while studying computer science and being drawn to the possibility of making online anonymity technically achievable.
She later brought that experience into press-freedom and newsroom-security work, including roles with the Freedom of the Press Foundation and The New York Times. In summer 2022, she made Granitt a full business, according to SecurityWeek’s January 3, 2024 profile.
What does “situative” security research mean?
Sandvik describes herself as a “situative researcher.” Rather than treating a vulnerability or device as an isolated technical puzzle, she considers the people involved, the technology, their intent and how the system is used in practice. Those details change what needs protecting and which safeguards are realistic.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstall#1 Best Overall
That is especially important when security work affects people facing serious consequences. A measure that suits one newsroom or activist may not suit another; the right response depends on the user’s circumstances and threat. Sandvik’s approach therefore connects technical security with the broader conditions in which people work.
For aspiring researchers, her advice is to pursue a subject that genuinely interests them, find the community working on it, learn what has already been done and identify unanswered questions. As she puts it, “You need to have fun.”
What is Granitt, and whom does it help?
Granitt is Sandvik’s consultancy for journalists and other people at elevated risk. Her examples include activists, lawyers, politicians, election workers, high-net-worth individuals and people investigating government corruption or war crimes. Its purpose is to help clients work securely, with advice tailored to their circumstances rather than a single checklist applied to everyone.
Sandvik describes effective protection as broader than cybersecurity alone: it must also take physical, emotional and legal security into account. That perspective reflects the reality that a digital incident can affect someone’s safety, work and legal position at the same time.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Rank #3
What happened with the hacked smart rifle?
In 2015, Sandvik and her husband, Michael Auger, examined a TrackingPoint self-aiming rifle. SecurityWeek reported that the $13,000 rifle used a Linux-powered smart scope and smartphone applications. The researchers found that remote access could let them view or change the target, or prevent the rifle from firing. The firing process itself remained manual.
The case illustrates why internet-connected devices deserve security scrutiny when they can affect the physical world. A connected feature can create consequences well beyond data privacy or account access. It is a historical security case study, not a product recommendation.
Rank #4
What security steps does Sandvik recommend?
For a general baseline, Sandvik names three actions:
- Install device updates promptly. Apply the latest available update as soon as it is available.
- Use a password manager. It can help maintain strong, unique passwords across online accounts rather than reusing the same password.
- Enable two-factor authentication. This adds another layer of protection to online accounts beyond the password.
These measures are a starting point, not a complete plan for everyone. People facing targeted threats may need a more specific assessment of their devices, accounts, work practices and physical circumstances.
Best Value
How does Sandvik think about disclosure and exploit ethics?
Sandvik says there is no universal rule for vulnerability disclosure: “There’s no right or wrong rule here. It all depends on the context.” Responsible disclosure may lead to full disclosure if a developer does not respond, but the appropriate choice depends on the situation and its risks.
She also warns that selling zero-day information means giving up control over how it may be used. The concern is who could be affected downstream: an exploit might be used against journalists or political activists. Her emphasis is on accountability and the consequences of a decision, not a claim that every disclosure path has the same risks.
Why Sandvik’s work matters
Sandvik’s career links technical research with practical protection for people whose work can put them in danger. Her situative approach asks not only whether a system can be compromised, but who could be harmed, how the technology is used and what security means in that person’s circumstances. That lens is visible in both Granitt’s holistic client work and the smart-rifle case, where software security had potential physical consequences.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Recommended Free Tools

