Curriculum / Module 3

OPSEC for researchers

Protecting yourself, your organisation and your subjects while you research.

45 min

3.1 What OPSEC means for a researcher

Operational security (OPSEC) is the habit of asking what your activity gives away, to whom, and what they could do with it. For an open-source researcher it protects three groups:

  • you: your identity, home, family, accounts and devices
  • your organisation: its clients, its interests and the fact that it is looking at a subject at all
  • the people in your material: subjects, bystanders and the people who filmed or wrote what you study

OPSEC is not about hiding wrongdoing. Everything in this course is lawful research on information as it is published (module 2). Good OPSEC stops lawful work from exposing people to harm it was never meant to cause.

3.2 A simple threat model

A threat model is a short written answer to five questions. Write it before you start, and revisit it whenever the task changes.

  1. What am I protecting? Your identity, your organisation's interest, your sources, the material you collect and the people in it.
  2. From whom? The subject of the research and their supporters, opportunistic harassers, anyone who could misuse your findings, and plain accidents such as a lost laptop.
  3. How likely is it, and how bad would it be? A subject with a history of harassing critics raises both.
  4. What will I do about it? The controls in sections 3.3 to 3.6.
  5. What risk remains, and who has accepted it? If the remaining risk is too high, change the plan or stop.

3.3 Keep research separate from your personal life

Mixing research with personal activity is the most common way researchers expose themselves.

  • Use a separate browser profile or device for research, with no personal accounts signed in. Browsers carry cookies, history and saved logins from one site to the next.
  • Stay logged out where you can. Many platforms show public pages without an account.
  • If you need an account for work, make it an honest work account. It must be allowed by the platform's terms, used only to read public content, and must not pretend to be a real or invented person. It is never used to join closed groups, contact subjects or influence anything. Module 2 explains why deception is outside this course, and SITREP's Community Guidelines do not allow fake accounts.
  • Do not interact with what you study. A like, follow, reply, poll vote or accidental tap can tell the subject that someone is looking, and from which account. This rule covers the accounts and people you are researching. Asking someone openly for an original file, or posting a correction on SITREP, is a separate public act that you decide on deliberately, after your threat model (module 6).
  • Keep your own location out of your work. Research files, screenshots and posts should never point to where you live or are staying.

3.4 What your browser, network and accounts reveal

Every page you open learns something about you. Common leaks, and what to do about them:

LeakWhat it can revealA practical control
Signed-in accountsYour name, profile and contacts. Some platforms tell people who viewed their profileResearch logged out, or from an honest work account. Check each platform's viewing notices
IP addressYour approximate location and your organisation's networkUse your organisation's approved network setup. A VPN changes who can see your traffic; it does not make any activity lawful, and it is never a way around a block, ban or access control
Links and attachmentsA tracking link or embedded image can tell the sender that you opened it, and roughly from where. A file can carry malwareDon't open links or files from unknown senders on your everyday machine. Use your organisation's approved way of opening them
ScreenshotsYour open tabs, bookmarks, account picture, time zone and language settingsCrop to the content, and check the whole image before you share it
Your own photosMetadata such as GPS location and device model, and whatever the picture showsRemove metadata before sharing. SITREP removes metadata from uploads, but a window view, a sign or a skyline can still give a location away
Online toolsSearch, translation and analysis sites may keep what you uploadDon't upload sensitive or personal material to a third-party tool unless your organisation has approved it for that use

Basic security hygiene matters as much as anything in the table: keep software updated, use a password manager, and turn on multi-factor authentication for every work account.

3.5 The no-live-positions rule applies to you too

The rule from module 2 protects other people, and it also protects you. A post about what you can see from where you are can reveal where you are.

SITREP builds the same logic in. Never pin yourself or anyone's home in an incident report, keep "Approximate my pin" on unless you have a reason not to, and expect posts that look like they contain a position to be held for review. A hold is not an accusation.

3.6 Store, share and dispose of material securely

What you collect can hurt people if it leaks: images of victims, personal data you could not avoid collecting, or notes that show what your organisation is interested in.

  • Store: keep each task in one case folder on an encrypted device or approved storage, with access limited to the people working on it. Keep the research log (module 1) with it.
  • Share: share on a need-to-know basis, through access-controlled links, never public ones. Remove personal data the reader does not need. Don't discuss live research in public channels or open group chats.
  • Label: mark distressing files so that a colleague does not open them unprepared.
  • Dispose: set the retention period at the start (module 2, storage limitation). When it ends, delete the files, copies, downloads and backups, and record in the log what you deleted and when.

3.7 Distressing material and your wellbeing

Open-source work can mean hours of violent or upsetting images. Repeated exposure can cause lasting harm, including to people who feel fine at the time. Treat it as a hazard of the work, not a test of toughness.

  • Reduce exposure: mute audio by default, view images small or blurred first, and look only for as long as the task needs. If a written description will do, read that instead.
  • Warn and be warned: tell colleagues before you share distressing material, and say what it shows.
  • Pace yourself: take regular breaks, stop well before you sleep, and share difficult tasks across a team.
  • Talk about it: debrief after hard material. Notice warning signs such as intrusive images, poor sleep, irritability or numbness, and ask for support early.

3.8 An OPSEC checklist

Before you start a research task:

  1. I have written a short threat model, and someone has accepted the remaining risk.
  2. I am using a separate research profile or device with no personal accounts signed in.
  3. Any work account I use is allowed by the platform's terms and does not pretend to be anyone.
  4. I will not interact with the people or accounts I am studying.
  5. My case folder is encrypted, access-limited and has a deletion date.
  6. I know how I will handle distressing material and who I can talk to.

Before you share or post anything:

  1. My screenshots and images show nothing about me, my location or my organisation that the reader does not need.
  2. Nothing reveals a live position or movement, including my own.
Module 2: Ethics and lawTake the module 3 quiz

Next: Module 4: Source evaluation and verification