Media practitioners in Ghana have been urged to prioritize cybersecurity as a core part of editorial safety to protect their sources, stories and credibility.
At a training on cybersecurity in journalism, it was emphasized that cybersecurity is the practice of protecting devices, accounts and information from people who want to steal, manipulate or destroy them.
According to facilitators, this involves securing devices like phones, laptops and tablets, protecting email and social media accounts, safeguarding information such as sources, drafts and recordings, building awareness of how attackers operate, and having a plan when things go wrong.
They explained that cybersecurity in journalism is critical because media work involves handling sensitive information and public trust.
A compromised phone, email account or contact list can expose confidential sources and put people at risk. Drafts and investigations can be stolen, altered or destroyed. Hacked accounts can mislead audiences and damage credibility. they noted.
Participants were taken through the core ideas of
Confidentiality, Integrity and Availability (CIA) and the risk formula. Asset+Threat+ Vulnerability+Impact= Priority action.
Common threats facing journalists include phishing emails, fake login pages, social engineering, account takeovers, malware from USB drives, device theft and targeted surveillance.
The training noted that media is a prime target because journalists sit at the intersection of public visibility and sensitive information. Account takeovers, ransomware, spear-phishing, spyware and disinformation were listed as major threats.
Reference was made to real cases, including the hacking of President John Mahama’s official X account in March 2025 to promote a fraudulent crypto scheme called Solanafrica, and spyware attacks on journalists in Togo, Uganda and Angola.
In one case, Angolan journalist Teixeira Cândido’s phone was infected with Predator spyware in May 2024 after clicking a malicious WhatsApp link.
Journalists were advised to adopt a minimum daily protection standard: use unique passwords with a password manager, turn on two-factor authentication (2FA), update devices promptly, lock screens, encrypt devices, and back up work in a separate trusted location.
Organisations were also urged to appoint a Digital Security Lead, establish basic security policies, develop a “Go-Bag” protocol and build a human firewall through regular training.












