Here are some device security best practices
Digital devices enable us to access, store and share useful information on the internet. Our devices such as mobile phones, laptops, computers and tablets act as a gateway to sensitive information stored within. For civil society organizations, this information can put us and those we work with at risk. We are constantly targeted with threats like surveillance, device seizures and even theft. Securing and protecting our devices is crucial. Today, we will discuss how civil society organizations and non-profits can secure their devices and protect the data stored within.
Here are some steps you can take to secure your devices:
Most software updates include security updates. Install updates as soon as they are available to protect from latest vulnerabilities and prevent attackers from exploiting those weaknesses. Using cloud-based software often avoids manual updates. Where possible, enable automatic software updates and your applications will always be up to data.
- Use Licensed Software and Apps (explore nonprofit licences and TechSoup)
Pirated software increases the risk of installing malware/ransomware onto your devices. When applications are modified by third parties, it increases the risk of your data being stolen or even the installation of spyware. We recommend that you download from official sources. For example, for mobile devices, install from the application store. For organizational applications, consider applying for nonprofit licenses.
See TechSoup for nonprofit discounts
- Encrypt, encrypt, encrypt
Device encryption (also called full-disk encryption or FDE) will protect your computer, mobile phone, and tablets against physical access by encrypting your hard drive if your device is lost or stolen. Remember, your device must be turned off for this to work.
To enable full disk encryption on all devices containing organizational information and access, follow the steps below:
Encrypt your phone and tablets:
For laptops / computers, most operating systems come with inbuilt encryption.
To enable:
-
Mac: encrypt with FileVault
-
Windows: encrypt with BitLocker
-
Linux: encrypt during installation, just opt in!
Encryption for external media
If USBs, hard drives, or other external media contain sensitive or confidential information, ensure they are encrypted and kept in safe locations. For Mac devices, encrypt with FileVault, cross-platform, encrypt VeraCrypt
We mentioned that civil society organizations are often targeted using surveillance. Malware, or malicious software is what is mainly used to do this. You might have heard of spyware such as Pegasus which has been used to spy on journalists and activists globally. To protect against malware, ensure you have an antivirus installed on your device.
Even with all these protections, sometimes we lose our devices, or the devices are corrupted, leading to loss of data. To prevent permanently losing data, we recommend keeping data backups, which means keeping additional copies of the same data in external storage. This back up can be restored in case of a data loss. For example, you can keep backups on cloud storage such as google drive, one drive, Tresorit, Proton Drive etc. The best backup strategy is what we call a 3-2-1 rule. The 3-2-1 backup rule is a data protection strategy that recommends having three copies of your data, stored on two different media types, with one copy kept off-site.
- If possible, separate work and personal.
Use a dedicated work device. If not, consider using secure cloud (Google workspace, Proton Drive, Microsoft 365, Tresorit) to avoid storing any data in your personal devices. On shared personal devices, you can also create a dedicated work account/profile on the device, ensuring work data is separated from personal data.
When connecting on public or untrusted networks, we recommend the use of Virtual Private Networks (VPNs) to protect your internet connection and the data you transmit between your device to the internet. VPNs usually create an encrypted tunnel between your device and the internet, preventing attackers from eavesdropping on your communication. We recommend VPN services like TunnelBear. Avoid using free VPNs because these services have a track record of collecting, sharing and selling of user data to third parties. There’s a common security adage that goes: if it’s free, you are the product.
- Create an organizational device policy
These are agreements on how organizational devices are used and secured. It provides directions to staff on what is acceptable. If you do not give organizational devices, consider creating a Bring Your Own Device (BYOD) policy. Policies should also include how staff should respond to incidents, for example, what should they do in case a device is lost or stolen?
This policy will provide guidelines to be followed when staff are travelling. Some of the things that should be included:
-
Practice “clean device” travel if going to high-risk countries. Delete any sensitive information from the devices.
-
Backup important files to an encrypted cloud or offline drive.
-
Factory reset your devices and only reinstall what's absolutely necessary.
-
Consider using a travel-only phone or laptop with minimal data and apps.
-
Use secure cloud storage (e.g., Tresorit, Proton Drive) and access only via VPN when needed.
-
Don't store contact lists, chat logs, or work files locally.
-
Use strong passwords to lock down your devices. Turn off fingerprint/face unlock at borders. Authorities can compel biometric unlocking more easily than passwords.
-
Enable remote wipe: Set up Find My iPhone, Google Find My Device, or similar services. This can help you delete all data from your devices if it’s stolen or lost.
-
Research laws about encryption, VPNs, and digital searches in the destination country.
-
Use secure communication apps: Install apps with strong end-to-end encryption like Signal and set messages to auto-delete.
-
Use a trusted VPN: Choose a reliable, privacy-respecting VPN (ProtonVPN, TunnelBear etc).
Resources