Protect newsroom accounts with layers: unique passwords, strong multifactor authentication (MFA), secure recovery options, protected devices, and a clear process for granting and removing staff access. For journalists at elevated risk, standard account settings may not be enough; assess the threats to the people and information involved.
1. Identify the accounts and people that need the strongest protection
Start with an inventory of work email, cloud storage, messaging, social accounts used for publishing, administrator accounts, and the email addresses or phone numbers used for account recovery. Include shared mailboxes and services that can reset passwords for other accounts.
Prioritize accounts that hold source material, staff or contact data, publication systems, or administrator privileges. Consider who might target a particular journalist or source, what information they could access, and how sensitive it is. The Committee to Protect Journalists (CPJ) advises journalists to assess their circumstances and the capabilities of potential threats.
2. Turn on MFA and choose a phishing-resistant method where possible
Require MFA for work email, storage, remote access, and other high-value services. Start with administrators and people who handle sensitive information, then cover the rest of the newsroom. CISA recommends requiring MFA and using the strongest method a service supports.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Prefer FIDO2/WebAuthn authentication, such as a compatible security key or supported passkey. CISA describes FIDO/WebAuthn as the only widely available phishing-resistant authentication. A physical key is not guaranteed to work with every account or device, so verify compatibility with the newsroom’s identity provider and each relevant device before rollout.
For a critical account, arrange recovery access before relying on a single key or factor. A separately stored backup key or another supported recovery method can help if the primary factor is lost. Do not keep the backup in the same place as the primary key.
How common MFA options compare
| Method | Security guidance | Practical consideration |
|---|---|---|
| FIDO2/WebAuthn security key | CISA’s strongest listed option; phishing-resistant | Check service and device support, and plan a safe backup. |
| Authenticator app with number matching | Next in CISA’s listed order | Use when a security key is not supported or practical. |
| One-time code | Below number matching in CISA’s listed order | Keep recovery codes protected and accessible if the device is lost. |
| Biometrics | Below one-time codes in CISA’s listed order | Availability and implementation depend on the service and device. |
| Text or email code | Lowest in CISA’s listed order | Use only if stronger supported methods are unavailable. |
This ordering reflects CISA’s business MFA guidance; actual options and labels differ by service. If a service does not support the preferred method, use the strongest available option and revisit the choice when support changes.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
3. Use unique passwords and protect account recovery
Give every account a long, unique password. Do not reuse personal credentials for newsroom work or reuse one work password across services. A password manager can help staff maintain distinct credentials, but it does not replace MFA.
Store one-time backup codes somewhere protected and reachable if a phone or security key is unavailable. Before changing MFA settings, confirm that the recovery method works and is controlled by the right person or team. Google’s Advanced Protection guidance, for example, recommends recovery information and an optional backup passkey or security key.
Never approve an unexpected MFA prompt or enter a password through an unsolicited account-alert link. If an alert or sign-in request is unfamiliar, reach the service through a known address or contact the newsroom administrator. CPJ warns that phishing can imitate two-factor authentication.
Rank #3
- Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
- Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
- Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
- Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
- For the driver download and user guide, please visit TrustKey Solutions Home support page.
4. Secure messaging accounts, conversations, and devices
Use an end-to-end encrypted messaging app for sensitive conversations when appropriate, but treat both the sender’s and recipient’s devices as part of the security boundary. Encryption can protect message content in transit and at the service; it cannot protect content on an unlocked or compromised device.
Review available messaging and device protections. Depending on the app, these may include an app lock, a registration lock or account PIN, contact or safety-number verification, disappearing messages, and encrypted cloud-backup settings. Minimize sensitive material retained on devices and backups when newsroom policy and source needs allow. App names and settings change, so check the current in-app controls and policies.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →Encryption does not necessarily conceal metadata, such as who communicated and when. Someone with access to a sending or receiving device, or to a linked account, may still reach message content. Do not describe an app as making a conversation anonymous or safe from a compromised device.
Rank #4
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
5. Consider enhanced protection for journalists at elevated risk
Google’s Advanced Protection Program is a Google-specific option intended for people at elevated risk, including journalists. Google says sign-in requires security keys or passkeys and recommends adding recovery details; an optional backup factor should be kept safe. Check account eligibility, device support, and newsroom policy before enrolling. This program protects Google accounts, not every service or device a journalist uses.
For threats involving targeted surveillance or a live compromise, general account controls may not be sufficient. CPJ’s Digital Safety Kit, updated February 20, 2026, advises journalists to assess their own risk and the sensitivity of the information involved.
6. Make account access part of newsroom operations
Document how access is granted, reviewed, and removed for employees, freelancers, and other contributors. Include account creation, MFA enrollment, recovery contacts, and access to shared mailboxes, groups, publishing systems, and stored files. CPJ’s 2024 U.S. journalist safety kit recommends documenting newsroom onboarding and offboarding.
When someone leaves or changes roles, promptly revoke access they no longer need. Include shared credentials and linked applications in the review; disabling one individual login may not remove access granted through a group, shared mailbox, or connected service.
7. Respond safely to a suspected account takeover
- Use a trusted route. From a known-good device, contact newsroom IT or the provider through a known address or support channel. Do not use links in unexpected alert messages.
- Protect recovery accounts. Secure the recovery email and phone number, since control of either may help an attacker regain access.
- Remove unauthorized access. Revoke unfamiliar sessions and app access, then reset affected credentials and strengthen MFA where the service allows.
- Preserve relevant evidence. Follow newsroom policy before deleting messages, sessions, or other records that may help assess the incident.
- Get support if you do not have newsroom IT. CPJ directs freelancers and journalists without organizational technical support to the Access Now Helpline.
If you are unsure whether a sign-in prompt or recovery attempt is yours, do not approve it. Contact the service or administrator independently using a trusted route.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

