By Seli Baisie
Sena receives a message while working on a story. It appears to be from a trusted contact and carries an urgent request to open a link. There is nothing unusual about the message. Sena is not alone. Like her, journalists receive links, documents, emails and WhatsApp messages throughout the working day.
But what if the link is designed to steal a password?
What if clicking it gives an attacker access to the journalist’s email, social media accounts, unpublished stories and conversations with confidential sources? And what happens if the journalist does not know whom to call after the attack?
These questions are becoming increasingly important as journalism moves deeper into the digital space.
Phones have replaced notebooks for much of the reporting process. WhatsApp has become a newsroom communication tool. Social media platforms are now publishing channels. Cloud storage holds documents, photographs and recordings. Email accounts contain years of correspondence.
The same tools that make journalism faster and more efficient can also make journalists vulnerable.
Methodology
To assess the readiness of media practitioners, Seli Baisie surveyed 15 journalists at GBC to examine what they know, how they apply that knowledge when presented with practical scenarios, and how they would respond when faced with a cyber threat. The findings revealed gaps in everyday digital security practices, including password management, two-factor authentication, phishing awareness, source protection and incident response. The findings suggest that while journalists recognise cyber threats as a real concern, good digital security practices are not always reflected in their daily routines.
All participants gave informed consent. The survey does not claim statistical representativeness; rather, the findings provide a snapshot that goes beyond awareness to examine how cybersecurity knowledge translates into everyday practice.
The password problem

Passwords remain one of the first lines of defence for journalists, yet the survey found that only four of the 15 respondents, about 26.7 per cent, said they use unique passwords for all their work accounts.
Nine, or 60 per cent, said they use unique passwords for only some accounts, while two were unsure.
The situation was similar when respondents were asked how often they update their work passwords.
Only four journalists said they do so regularly. Eight said they rarely change their passwords, while three said they never do.
The findings matter because a reused or compromised password can become a gateway into multiple accounts.
A journalist may use email to receive information from a source, social media to publish a story and cloud storage to keep documents. If the same password protects several of those accounts, one breach can quickly become several.
Password managers can help users create and store strong, unique passwords.
But even that basic tool is not widely understood.
Seven respondents said they use a password manager. Four do not use one, three said they did not know what a password manager was, and one had a password manager but rarely used it.
Three of the 15 journalists surveyed, or 20 per cent, said they did not know what a password manager was.
The 2FA gap

Two-factor or multi-factor authentication is an important layer of protection because it can make unauthorised access more difficult even if a password is compromised.
Yet the survey found that fewer than one-third of respondents had 2FA/MFA enabled on their work email.
Five journalists said it was enabled, while seven said it was not. Three others did not know whether it was enabled.
The picture was better for work-related social media accounts, although significant gaps remained.
Six respondents said 2FA was enabled on all their work-related social media accounts, while another five had it enabled on some accounts.
Three had no 2FA and one said they did not know how to enable it.
For journalists whose professional identity is increasingly tied to social media, an account takeover can have consequences beyond losing access.
An attacker could impersonate the journalist, publish false information, contact sources or use the credibility of the account to deceive members of the public.
The encouraging side of the survey
Not all the findings were worrying.
Eleven of the 15 journalists surveyed said they update their phones, computers and other work devices immediately when updates become available.
One said they do so within a few days, two rarely update their devices and one did not know.
Nine respondents also said they separate their personal and work accounts on their devices.
That is important because separating digital identities can limit the damage if one account or device is compromised.
But five respondents said they do not separate their work and personal accounts, while another said they had never considered doing so.
Device encryption also showed room for improvement.
Nine respondents said encryption was enabled on their primary work device, while three said it was not and another three did not know.
That uncertainty is itself a security concern.
If journalists do not know whether their devices are encrypted, they may also not know how much protection their information has if a phone or laptop is lost or stolen.
Disinformation emerges as the leading concern among respondents

Perhaps the most striking finding was what journalists themselves considered the biggest cybersecurity threats facing their newsroom.
Disinformation came out on top.
Twelve of the 15 respondents, 80 per cent, identified it among their top three concerns.
Account takeover, device theft or loss and data leaks each received six responses, representing 40 per cent .
Phishing was selected by four respondents, or 26.7 per cent, while social engineering and impersonation received three responses.
Spyware and surveillance and doxxing or online harassment were each selected by two respondents.
The findings highlight how journalists view cybersecurity through the wider lens of their work.
For them, a cyber threat is not simply a technical problem. It can affect the credibility of a story, expose sources, damage a journalist’s reputation or allow false information to spread through trusted media platforms.
But can journalists spot phishing?

Knowing that phishing is dangerous is one thing. Recognising it in a real message is another.
When asked how confident they were in identifying phishing emails, fake login pages and malicious links, only six respondents said they were very confident.
Eight said they were not very confident, while one said they were not confident at all.
The survey also included a practical phishing identification exercise.
Respondents were presented with two messages and asked to identify which contained a phishing link.
Eight selected option A, four selected B, two said they did not know and one believed both were phishing.
Their explanations revealed another important gap.
Some respondents correctly pointed to suspicious links or urgent requests for action. Others said they chose an option simply because it “looked” suspicious, while some admitted they did not know.
One respondent explained that they became suspicious because the message demanded urgent action, warning that an account could otherwise be lost.
Another questioned a supposed Jumia promotion because they had not entered any promotion that would have entitled them to a reward.
These responses show why cybersecurity training cannot stop at telling journalists to “beware of phishing”.
They need repeated, practical exercises that teach them why a message is suspicious and what they should do next.
The source protection dilemma

For journalists, digital security becomes particularly serious when confidential sources are involved.
Eight of the journalists surveyed said they normally rely on face-to-face meetings when communicating with sensitive sources.
Three use email, two use phone calls or SMS and two use WhatsApp.
None of the respondents selected Signal, a secure messaging platform commonly recommended for sensitive communication.
That finding deserves attention.
A source relationship can involve much more than the content of a conversation.
A journalist’s phone may contain the source’s name, number, photographs, voice notes, location information and previous conversations.
In effect, a compromised device can become a map of an investigation.
The risk is especially serious for journalists investigating corruption, organised crime, political abuse or other sensitive issues.
If an attacker gains access to a journalist’s device, the person at risk may not be the journalist alone.
It could be the source who trusted them.
When private information becomes a weapon

The survey also examined whether journalists know how to protect private or intimate photographs and videos from being leaked or accessed without consent.
Eight respondents said they knew how to protect such material.
Six said they did not, while one was unsure.
The issue is broader than intimate images.
Journalists, like other members of the public, store personal photographs, conversations and other private material on their phones and online accounts.
When these accounts are compromised, stolen material can be used for harassment, humiliation, blackmail or other forms of abuse.
Digital safety therefore has a personal dimension.
Protecting journalists also means helping them understand how to secure information that has nothing to do with their work but could nevertheless be used against them.
A newsroom that does not know what to do after a hack

Perhaps one of the most important findings concerns what happens after an attack.
Asked whether they would know exactly what to do if their work email or social media account was hacked, four respondents said yes.
Four said no, while seven said they knew some of the steps.
Out of 15, seven respondents knew where to report a cybersecurity incident.
Eight did not.
This means more than half of the journalists surveyed could potentially face a cyber incident without knowing exactly where or to whom to report it.
A newsroom can invest in strong technology and still remain vulnerable if its journalists do not know what to do when something goes wrong.
The first few minutes can be critical.
The recommended approach is simple: stop, document, report and recover.
- Stop using the affected account or device, where necessary.
- Document suspicious messages, screenshots and other relevant evidence.
- Report the incident to the appropriate IT or cybersecurity expert, or call the Cyber Security Authority (CSA) on its emergency contact number, 292.
- Change your passwords, revoke active sessions and restore your files from secure backups.
Without a clear newsroom protocol, however, even experienced journalists may be left trying to work out what to do in the middle of a crisis.
The gaps are already visible
Asked to identify the biggest cybersecurity weakness in their newsroom, respondents pointed to a range of concerns.
Some cited a lack of knowledge and awareness.
Others mentioned data leaks, device theft, storage and encryption, social media hacking and the risk of fake publications created using similar logos, watermarks and templates.
One respondent raised concerns about broad access to systems where edited videos and scripts are stored, suggesting stronger individual passwords.
Another called for a secure cloud system protected by strong two-factor authentication.
The responses point to a common theme: cybersecurity is not only about individual behaviour.
- It is also about how news organisations design their systems.
- Who has access to unpublished material?
- Who can access the newsroom’s social media accounts?
- Are passwords shared?
- What happens when a journalist leaves the organisation?
- Where are sensitive recordings stored?
- Are backups encrypted?
- Who has authority to respond when an account is hacked?
- And perhaps most importantly, does every journalist know the answer?
The journalist is part of the security system
One of the most important lessons from cybersecurity training for journalists is that technology alone cannot protect a newsroom.
A security system can be weakened by an ordinary decision made during a busy working day.
A journalist clicks the link.
- A password is reused.
- A suspicious message is ignored instead of reported.
- A sensitive conversation is sent through an inappropriate channel.
- A phone is left unlocked.
- A software update is postponed.
These are ordinary actions, but they can have extraordinary consequences.
That is why cybersecurity should not be treated as a problem for the IT department alone.
Every journalist is part of the newsroom’s security system.
And every journalist should understand what is at stake.
A hacked phone can expose more than a story
The danger is not theoretical.
Angolan journalist Teixeira Cândido’s phone was infected with Predator spyware in 2024 after he clicked a malicious WhatsApp link.
Reflecting on the breach, he said:
“I feel as though I took a shower with the door wide open. They had access to my private life.”
For a journalist, that private life can overlap with professional life.
A phone may hold conversations with sources, unpublished photographs, recordings, documents, contacts and details about where the journalist has been.
A compromised device can therefore expose far more than one person’s private information.
It can expose an entire investigation.
From awareness to action
The survey should not be viewed as a test of which journalists are “good” or “bad” at cybersecurity.
Its real value is in showing where knowledge and practice do not yet match.
The findings point to several clear priorities for newsrooms.
First, make strong passwords and 2FA standard practice.
Journalists should use unique passwords, preferably stored in a trusted password manager, and enable multi-factor authentication on important accounts.
Second, establish a clear incident-response system.
Every journalist should know who to contact if an account is compromised, a device is stolen or suspicious activity is detected.
Third, strengthen source protection.
Journalists working with sensitive sources need practical guidance on secure communication, encrypted storage and the risks associated with metadata and compromised devices.
Fourth, restrict access to sensitive newsroom systems.
Not everyone needs access to every document, script, recording or investigation. Access should be based on genuine work requirements.
Fifth, make cybersecurity training practical and continuous.
One workshop is unlikely to change behaviour permanently. Regular simulations, phishing drills and refresher sessions can turn security awareness into routine practice.
The wider lesson for Ghanaian journalism
The 15 journalists who took part in this survey represent only a small group. The findings cannot be used to describe every newsroom in Ghana.
But they raise questions that the wider media industry cannot afford to ignore.
If journalists are increasingly working through digital platforms, then digital security must become part of journalism itself.
It belongs alongside fact-checking, source protection, verification and editorial ethics.
Because a journalist cannot fully protect a source without protecting the channels through which they communicate.
A newsroom cannot protect its credibility without protecting its accounts.
And a media organisation cannot claim to be resilient if its journalists do not know what to do when the first account is hacked.
The strongest lesson from the survey is therefore not that journalists are vulnerable.
It is that there are vulnerabilities that can be fixed.
- A password can be changed.
- 2FA can be switched on.
- A device can be encrypted.
- A secure messaging application can be installed.
- A backup can be created.
- A newsroom can establish an incident-response plan.
- And a journalist can learn to pause before clicking.
The next time an urgent message appears on a newsroom phone, the most important question may not be whether it looks convincing.
It may be whether the journalist has been trained to stop, question it and verify it before taking action.
In modern journalism, protecting the story begins long before it is published.
It begins with protecting the journalist, the source and the information they have been trusted to carry.
The survey formed part of a cybersecurity awareness project aimed at examining how well journalists understand and practise digital security in their daily work.




































































