Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errorsA newsroom source-protection plan should make confidentiality part of incident response: identify which sources and information are at risk, limit exposure in everyday workflows, and assign people to contain, assess and recover from an incident. The right controls depend on the newsroom’s systems, resources, likely adversaries and jurisdiction; no single tool or legal rule fits every organization.
Start with the sources, information and risks you need to protect
Before choosing tools, map how a source could be identified or harmed if a device, account, system or document were exposed. Consider risks to both the journalist and the source, including physical safety as well as digital exposure. The Committee to Protect Journalists (CPJ), in its 2021 guidance on protecting confidential sources, recommends assessing an adversary’s authority, resources and technical capacity.
Make a practical risk inventory
- Source categories: Identify reporting relationships that need heightened safeguards, such as confidential sources or people whose identification could put them at risk.
- Information: List contact details, messages, recordings, drafts, submitted files, notes and any copies or backups that could reveal a source or the reporting relationship.
- Systems and people: Trace where that information is created, received, reviewed, shared, stored and deleted—and who can access each step.
- Threats and consequences: Consider who might seek the information, what access or technical capability they could have, and what exposure would mean for the source and newsroom.
Revisit the assessment when a story, reporting environment, travel situation or threat changes. A plan written for one set of sources and systems may not fit another.
Set source-handling practices before an incident
Staff need agreed ways to communicate and handle sensitive material before a breach or suspected compromise makes decisions urgent. Make the practices specific to the newsroom’s capacity and risk assessment; avoid promising anonymity that the actual workflow cannot provide.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →#1 Best Overall
Communications, devices and accounts
- Define approved channels for routine contact and for sensitive conversations, along with a secure fallback and a procedure for escalating concerns.
- When a source first contacts a journalist through a less secure service, take care before moving the conversation or sharing sensitive details. Agree how staff will handle that transition.
- CPJ recommends end-to-end encrypted messaging where possible and considering dedicated devices for sensitive-source work. These measures can reduce some exposure, but do not by themselves protect a source if a device or account is compromised.
- Review who can access accounts and source records, and avoid creating unnecessary copies. Include messaging-app data in that review: deleting a message from an account may not delete copies retained by a service provider.
Documents and data lifecycle
Set rules for receiving, reviewing, exporting, retaining and deleting documents. Limit collection and duplication, restrict access to people who need it, and consider whether file metadata could identify a source or reveal sensitive details. Specify how the rules apply to working copies, backups and messages—not just the original submitted file.
SecureDrop’s guidance for working with documents describes using an encrypted USB export device, typically protected with VeraCrypt, when a file must be transferred digitally from its isolated review station to an everyday workstation. That is a specific workflow example, not a universal recommendation: any transfer method should be approved for the newsroom’s environment and threat model.
Assign incident roles and escalation paths
Write down who leads the response and who can make time-sensitive decisions. SecureDrop’s installation guidance calls for monitoring and an incident-response plan covering outages and compromised environments. CISA’s 2021 guidance for corporate leaders says incident plans should include senior leadership as well as security and IT teams; newsrooms can adapt that principle to include editorial responsibility.
Name primary and backup decision-makers
- Incident lead: A primary and backup person to coordinate the response and track decisions.
- Technical responders: People responsible for investigating alerts, assessing systems and carrying out authorized containment steps.
- Editorial decision-maker: Someone empowered to weigh reporting needs against source safety and newsroom operations.
- Legal contact: Qualified counsel who can advise on the applicable jurisdiction and situation.
- Source communications: A designated person or role authorized to contact affected sources, using a channel assessed as safe for that situation.
- Monitoring recipients: Named recipients for alerts, with backups so an alert does not depend on one unavailable staff member.
State what triggers escalation, who is authorized to isolate a system, and how technical findings reach editorial and legal decision-makers. Arrange appropriate professional technical and legal help in advance where the newsroom’s capacity requires it.
Free tools Windows power users keep installed
One-click scans. No signup required.
Respond to a suspected compromise without increasing source exposure
A cyber incident can involve uncertainty: the newsroom may not yet know what was accessed, copied or altered. The plan should therefore separate containment and investigation from assumptions about whether a source has been identified.
- Escalate through the agreed channel. Notify the designated incident lead and responders when a defined trigger is met, such as a suspected compromise or a critical service outage.
- Limit further exposure. Have authorized responders take containment steps appropriate to the affected system. Avoid ad hoc sharing of source details or moving sensitive files into new systems before their safety is assessed.
- Preserve enough evidence for assessment. Coordinate with technical responders so the newsroom can investigate what happened while limiting additional access to sensitive information. The plan should establish who makes that judgment; avoid treating either blanket deletion or unrestricted retention as an automatic answer.
- Assess possible source impact. Determine which systems and information may have been exposed, who could access them, and whether a source may face risk. Involve editorial leadership and qualified counsel as appropriate.
- Coordinate communications. Assign responsibility for any contact with affected sources and for internal or external communications. Choose a channel based on the circumstances rather than assuming the compromised service remains safe.
- Recover and review. Restore critical operations using the newsroom’s recovery priorities, then update the plan and practices in light of what the incident revealed.
Keep essential journalism running during recovery
Identify the systems and services that support critical newsroom functions, their dependencies, and the order in which they would need to be restored. CISA recommends identifying systems that support critical functions and testing continuity so those functions can remain available after an intrusion.
Rank #4
For a newsroom, continuity planning should name safe fallback workflows for essential publishing and communications. Decide in advance who can approve those alternatives and how staff will avoid putting source information into an unassessed replacement system. Test the plan through tabletop exercises involving editorial, technical and senior leadership, then revise it when exercises, incidents or system changes expose gaps.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Choose tools as part of a wider operating model
SecureDrop is an open-source whistleblower submission system used by media organizations. Its documentation describes sources and journalists connecting over Tor to dedicated, on-premises infrastructure, with a segmented network and a separate workstation process for handling submitted files. The design aims to limit metadata and exposure of decrypted files; its installation guidance also calls for dedicated physical servers, separation from the corporate network, a trusted hosting location, monitoring and plans for outages and compromised environments.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallBest Value
Those characteristics do not make SecureDrop a turnkey guarantee or a fit for every newsroom. The project warns that no system can guarantee safety, and operating the system requires technical setup, operational-security practices and staff familiarity. CPJ’s guidance also highlights risks that a submission tool cannot eliminate, including device access, spyware, provider-held message copies and file metadata. Assess any channel against the likely adversary, infrastructure access, exposure if devices or files are compromised, training needs, legal context and continuity requirements.
Review legal and jurisdictional questions with qualified counsel
Source-protection laws, reporting obligations, cross-border risks and law-enforcement procedures depend on the jurisdictions and facts involved. A general technical plan cannot settle those questions. Ask qualified counsel to identify what applies to the newsroom, its staff, sources, systems and data flows, and define how legal advice enters incident escalation.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

