The 4C Quickstart — Hacking the Workforce
A free guide · For justice-led organizations

The 4C Quickstart

Digital security you can act on this week. Written for movement-led organizations by someone who actually does this work.

~20 min read ~90 min to act Zero fluff

Why this guide exists

Most digital security advice wasn't built for the work you do.

It assumes you have an IT department. It leads with scary statistics and ends without anything actionable. It sells tools that gather dust because nobody had time to set them up properly.

That's not your fault. The digital security landscape was built mostly for corporate environments — protecting trade secrets, financial data, brand reputation. It wasn't built for organizing in environments where being identified can mean harassment. It wasn't built for holding sensitive information from community members who trusted you. It wasn't built for sustaining movements with small teams and limited time.

57%

In a recent cohort of movement-led organizations we surveyed, 57% rated their confidence to protect their digital spaces at 1 or 2 out of 5.

This isn't a story about apathy. It's a story about tools and training that weren't designed for this work.

This Quickstart is the short version of what we teach in our 1:1 coaching. Pick one of the four C's. Take the action that's described. Don't do everything at once — that's how this work fails.

Twenty minutes to read. Ninety minutes to act. Real change in your digital posture by Friday.

The 4C Self-Defense Model

Four practices, in order of where most movement orgs benefit from starting. Each one builds on the last.

C

Control Exposure

Decide what's public on purpose. Privacy settings, safer profiles, secure channels.

C

Create Strong Credentials

Make passwords the system's job, not your memory's. Password managers, MFA, device hardening.

C

Confirm Authenticity

Build the habit of verifying before you trust. Phishing checks, second-channel verification.

C

Clean Up Footprints

Remove what shouldn't be findable. Self-doxing, data broker removal, stale account cleanup.

This week's actions

One action per C. You don't have to do all four. Pick the one that fits your week.

1
Control Exposure

Audit what's public about your org

Time required: 30 minutes

Open an incognito browser window. Search the way someone trying to harm your work would search.

  1. Search the organization's name. Note anything on the first two pages of results that surprises you.
  2. Search the executive director's full name, then their name plus your city.
  3. Search a public-facing staff member's name and look at their social media as a logged-out viewer.
  4. Search your org's office address — what's visible in Google Maps Street View?
  5. Do an image search of your org's logo and a key staff headshot. Where else do they appear?

Write down what you find. The finding itself is the first action. The cleanup comes later — for now, you just need to see what's there.

A NOTE ON EMOTION

This exercise can be unsettling. People often discover things they didn't realize were public. Do it with a colleague when you can. Don't process it alone.

2
Create Strong Credentials

Adopt a password manager

Time required: 60 minutes (one-time)

The single highest-leverage security change most organizations can make is adopting a password manager. Not "stronger passwords." A password manager. It's the foundation everything else rests on.

Pick one

  • Bitwarden — free tier is excellent. Open source. Strong default choice for tight budgets.
  • 1Password — paid (~$8/user/month). Polished UX. Often discounted for nonprofits.
  • Proton Pass — included with Proton Mail subscriptions if you already use Proton.

Set it up

  1. Create an account with a strong master password (4+ random words, written down somewhere physically safe)
  2. Install the browser extension on every browser you use
  3. Install the mobile app
  4. Turn on multi-factor authentication on the password manager itself — this is non-negotiable
  5. This week, migrate your top 10 most-used accounts. Don't try to migrate everything at once.

Rule that works: every time you log into something, update it in the password manager. Within two weeks you'll have naturally migrated your top 30 accounts.

3
Confirm Authenticity

Adopt the 30-second phishing check

Time required: 5 minutes to learn. The rest is building the habit.

Phishing is the most common way movement organizations get compromised. Not by sophisticated nation-state actors — by emails that look like they're from a funder, a journalist, or a colleague, and aren't.

Four questions you ask before clicking anything. Works for email, text, DMs, any unsolicited request.

The 30-Second Phishing Check

Before you click anything, ask:

1
Was I expecting this? If someone you've never communicated with is suddenly asking for something, pause. Even if it's someone you know — was this conversation actually in motion?
2
Does the sender look right? Hover over the sender's name to see the actual email address. "Funder Name <[email protected]>" is fine. "Funder Name <[email protected]>" is not.
3
Is there urgency or pressure? "Reply within 24 hours" or "Don't tell anyone yet" are red flags. Real legitimate requests almost never have artificial urgency.
4
What's the ask? Click a link? Reply with sensitive info? Wire money? The ask itself often gives the game away.
If anything failed the check, verify through a second channel before acting. Email request? Confirm by text. Slack message? Confirm by phone. It is always okay to delay. The world will not end if you take an extra hour.

Share this card with your team. Tape it next to the screen if that helps. The check works only if pausing is culturally safe — leadership sets that tone.

4
Clean Up Footprints

Self-dox yourself once

Time required: 45 minutes for the audit. Removals are a separate ongoing process.

The best way to understand what an attacker can find is to find it yourself first. Self-doxing is just systematically searching for everything findable about you, the way an adversary would. The act of doing it changes what you do with the findings.

The walkthrough

  1. In incognito mode, search your name, your name + city, your name + employer, your name + role.
  2. Search your name on the major people-search sites: Spokeo, BeenVerified, Whitepages, Radaris, PeopleFinder.
  3. Reverse image search a headshot. Often surfaces forgotten profiles.
  4. Search for your home address. Look in property records and voter registration lookups.
  5. Check Have I Been Pwned with your email addresses for breached accounts.

Then submit one removal request

For this week, just one. Pick whichever broker surfaced the most prominent information. Search "[broker name] opt out." The process is usually deliberately annoying but works. You'll set up a recurring quarterly reminder to keep doing this — for now, just complete one.

FOR HIGHER-RISK STAFF

Services like DeleteMe, Optery, or Kanary will do the broker removal work for you (~$100–250/year per person). For leadership and high-profile staff, this is one of the highest-leverage investments a movement org can make.

What's next

If the Quickstart was enough, you're set. Use it. Come back to it. Share it with colleagues. Send a reply to any of our emails when something falls apart.

If you want to go deeper, two options:

The 4C Digital Self-Defense Masterclass

Self-paced. Seven modules. Roughly six to eight hours of content. Takes you from this Quickstart all the way to a custom-built "Security Practices We Can Actually Keep" document your team co-creates, plus a trained security champion on staff who keeps the work alive. Scholarship route available for movement-led organizations.

A free 30-minute discovery call

Talk through your actual situation, what's working, what isn't. We figure out together what would actually help. No sales pitch. If the masterclass is right, we'll say so. If 1:1 coaching is right, we'll say that. If you need a referral elsewhere, we'll send one.

Who's behind this

Hacking the Workforce

HtW provides 1:1 digital security coaching and technical assistance for frontline organizations. We use the 4C Self-Defense Model to move teams from awareness into embedded daily practice. Our approach is trauma-informed and tailored specifically to Black, Brown, LGBTQ+, and justice-focused movements.

Dr. Safi Mojidi founded HtW. Nigerian American, neurodiverse, trans man with a Doctor of Science in Cybersecurity. Almost two decades of work at the intersection of technical expertise and movement organizing. The 4C model came out of conversations with brilliant movement leaders who deserved better than what the security field was giving them.

Want to go deeper?

The Quickstart stands alone. But if you're ready for more, two paths forward.

Hacking the Workforce · The 4C Quickstart · v1.0