While ACLED is in the process of assessing our digital security vulnerabilities and putting together a comprehensive guide, this page has been developed in the meantime to assist contractors in following best practices when it comes to digital security. If you have any further questions regarding digital security or this page, please reach out to ACLED’s Operations team (operations@acleddata.com).
Use a password manager – we recommend LastPass, it’s also what ACLED uses to share passwords with you.
Do not save work passwords in your browser! ACLED recommends you save all passwords, including your personal ones, in LastPass and never in the browser.
Make sure to never use “Remember Me” on devices that aren’t yours (i.e. your PC, laptop, mobile).
Use two-factor authentication (2FA) to access sensitive accounts you use for your work (including your email and Slack)
Note that on shared email addresses, such as the regional accounts (e.g. info.me@acleddata.com), using 2FA may take some additional steps to ensure all users (e.g. RM and ARM) can still access the account.
Be aware of suspicious looking emails and don’t open them and especially don’t click on links or attachments.
Use encrypted messaging apps like Signal or WhatsApp if you regularly talk to people about your work over text messages.
When browsing, use security add-ins, such as:
HttpsEverywhere: This plugin makes sure you use encrypted connections (https) when browsing. This add-in is install-and-forget.
UblockOrigin: This add-in is an adblocker that also blocks malicious content. It is install-and-forget. During initial setup, you can select a number of ‘lists’ of content types that you want to have blocked (social media buttons, lists for particular countries, etc.).
PrivacyBadger: This add-in blocks tracking cookies by learning from their behavior. It is install-and-forget, although on rare occasions it does break a website and you need to click the ‘badger’ icon and select ‘disable privacy badger for this site’ or tinker with setting the individual sliders that determine your level of ad-blocking from red (high) to orange (medium).
Install a mobile security app to extend your devices security features – Avast Mobile Security is a good choice for Android, while Avira Mobile Security is recommended for Apple.
Install security updates and always use the latest versions of your operating system (OS) and other software. Use web browsers such as Chrome or Firefox that receive frequent, automatic security updates.
Enable/install a virus scanner and firewall (Windows 10 built in versions are decent options, you can also check out Gizmo’s Freeware for no-cost options).
Be conscientious of what you plug into your computer (flash drives/USBs etc.) as malware can be spread through these devices as well.
Use a VPN. ACLED requires the use of a VPN when sourcing through Nexis. You can also use a VPN and ACLED recommends the use of a VPN when accessing public Wifi. If the country in which you reside has legal prohibition of VPN or you could get in trouble in any other way by using it, do not use a VPN and get in touch with your supervisor and the Operations team.
Accessing sources that are banned within a specific country via VPN should not be done. If you are asked to monitor a source you can’t access in country – speak to your Research Manager about this immediately and they will propose a solution. It may be that someone else can source for you and then you can code, provided you don’t download the materials from Google drive.
When using free/public Wi-Fi always assume your data is monitored.
If working in public beware of shoulder surfing and don’t review sensitive information (especially anything relating to anonymous partners) in plain view.
If working in public, avoid using shared networks if possible, use your phone’s hotspot if you have one.
Use screen-locks/passwords on all devices you use for your work and avoid leaving them unattended.
When travelling across international borders:
Always make sure to sign out of all accounts when going through customs/security (especially email accounts and Slack).
If you are worried about confiscation, you should de-install any apps from the device like Slack (to reinstall them later).
Make sure to close all work files that might be open on your laptop/mobile, and make sure these are not left in obvious places (e.g. having ACLED as a top-level file folder on your desktop or work files).
To the extent possible, it is best to store ACLED related documents in the ACLED google drive folders.
If you have any further questions regarding digital security or this page, please reach out to ACLED’s Operations team (operations@acleddata.com).