Why this guide exists
Most digital security advice wasn't built for the work you do.
It assumes you have an IT department. It leads with scary statistics and ends without anything actionable. It sells tools that gather dust because nobody had time to set them up properly.
That's not your fault. The digital security landscape was built mostly for corporate environments — protecting trade secrets, financial data, brand reputation. It wasn't built for organizing in environments where being identified can mean harassment. It wasn't built for holding sensitive information from community members who trusted you. It wasn't built for sustaining movements with small teams and limited time.
In a recent cohort of movement-led organizations we surveyed, 57% rated their confidence to protect their digital spaces at 1 or 2 out of 5.
This isn't a story about apathy. It's a story about tools and training that weren't designed for this work.
This Quickstart is the short version of what we teach in our 1:1 coaching. Pick one of the four C's. Take the action that's described. Don't do everything at once — that's how this work fails.
Twenty minutes to read. Ninety minutes to act. Real change in your digital posture by Friday.
The 4C Self-Defense Model
Four practices, in order of where most movement orgs benefit from starting. Each one builds on the last.
Control Exposure
Decide what's public on purpose. Privacy settings, safer profiles, secure channels.
Create Strong Credentials
Make passwords the system's job, not your memory's. Password managers, MFA, device hardening.
Confirm Authenticity
Build the habit of verifying before you trust. Phishing checks, second-channel verification.
Clean Up Footprints
Remove what shouldn't be findable. Self-doxing, data broker removal, stale account cleanup.
This week's actions
One action per C. You don't have to do all four. Pick the one that fits your week.
Audit what's public about your org
Time required: 30 minutes
Open an incognito browser window. Search the way someone trying to harm your work would search.
- Search the organization's name. Note anything on the first two pages of results that surprises you.
- Search the executive director's full name, then their name plus your city.
- Search a public-facing staff member's name and look at their social media as a logged-out viewer.
- Search your org's office address — what's visible in Google Maps Street View?
- Do an image search of your org's logo and a key staff headshot. Where else do they appear?
Write down what you find. The finding itself is the first action. The cleanup comes later — for now, you just need to see what's there.
This exercise can be unsettling. People often discover things they didn't realize were public. Do it with a colleague when you can. Don't process it alone.
Adopt a password manager
Time required: 60 minutes (one-time)
The single highest-leverage security change most organizations can make is adopting a password manager. Not "stronger passwords." A password manager. It's the foundation everything else rests on.
Pick one
- Bitwarden — free tier is excellent. Open source. Strong default choice for tight budgets.
- 1Password — paid (~$8/user/month). Polished UX. Often discounted for nonprofits.
- Proton Pass — included with Proton Mail subscriptions if you already use Proton.
Set it up
- Create an account with a strong master password (4+ random words, written down somewhere physically safe)
- Install the browser extension on every browser you use
- Install the mobile app
- Turn on multi-factor authentication on the password manager itself — this is non-negotiable
- This week, migrate your top 10 most-used accounts. Don't try to migrate everything at once.
Rule that works: every time you log into something, update it in the password manager. Within two weeks you'll have naturally migrated your top 30 accounts.
Adopt the 30-second phishing check
Time required: 5 minutes to learn. The rest is building the habit.
Phishing is the most common way movement organizations get compromised. Not by sophisticated nation-state actors — by emails that look like they're from a funder, a journalist, or a colleague, and aren't.
Four questions you ask before clicking anything. Works for email, text, DMs, any unsolicited request.
Before you click anything, ask:
Share this card with your team. Tape it next to the screen if that helps. The check works only if pausing is culturally safe — leadership sets that tone.
Self-dox yourself once
Time required: 45 minutes for the audit. Removals are a separate ongoing process.
The best way to understand what an attacker can find is to find it yourself first. Self-doxing is just systematically searching for everything findable about you, the way an adversary would. The act of doing it changes what you do with the findings.
The walkthrough
- In incognito mode, search your name, your name + city, your name + employer, your name + role.
- Search your name on the major people-search sites: Spokeo, BeenVerified, Whitepages, Radaris, PeopleFinder.
- Reverse image search a headshot. Often surfaces forgotten profiles.
- Search for your home address. Look in property records and voter registration lookups.
- Check Have I Been Pwned with your email addresses for breached accounts.
Then submit one removal request
For this week, just one. Pick whichever broker surfaced the most prominent information. Search "[broker name] opt out." The process is usually deliberately annoying but works. You'll set up a recurring quarterly reminder to keep doing this — for now, just complete one.
Services like DeleteMe, Optery, or Kanary will do the broker removal work for you (~$100–250/year per person). For leadership and high-profile staff, this is one of the highest-leverage investments a movement org can make.
What's next
If the Quickstart was enough, you're set. Use it. Come back to it. Share it with colleagues. Send a reply to any of our emails when something falls apart.
If you want to go deeper, two options:
The 4C Digital Self-Defense Masterclass
Self-paced. Seven modules. Roughly six to eight hours of content. Takes you from this Quickstart all the way to a custom-built "Security Practices We Can Actually Keep" document your team co-creates, plus a trained security champion on staff who keeps the work alive. Scholarship route available for movement-led organizations.
A free 30-minute discovery call
Talk through your actual situation, what's working, what isn't. We figure out together what would actually help. No sales pitch. If the masterclass is right, we'll say so. If 1:1 coaching is right, we'll say that. If you need a referral elsewhere, we'll send one.
Who's behind this
Hacking the Workforce
HtW provides 1:1 digital security coaching and technical assistance for frontline organizations. We use the 4C Self-Defense Model to move teams from awareness into embedded daily practice. Our approach is trauma-informed and tailored specifically to Black, Brown, LGBTQ+, and justice-focused movements.
Dr. Safi Mojidi founded HtW. Nigerian American, neurodiverse, trans man with a Doctor of Science in Cybersecurity. Almost two decades of work at the intersection of technical expertise and movement organizing. The 4C model came out of conversations with brilliant movement leaders who deserved better than what the security field was giving them.