Understanding the threat landscape, holistic security, threat modelling, and digital hygiene for Kenyan Human Rights Defenders
Human Rights Defenders (HRDs) and Social Justice Organisations (SJOs) in Kenya increasingly depend on digital platforms for advocacy, coordination, and mobilisation[2]. This dependence, while essential to their work, exposes them to a rapidly evolving array of cyber threats. Attacks have shifted from opportunistic social engineering to highly sophisticated, precisely targeted spyware campaigns designed to monitor, silence, and endanger defenders.
Think of it this way: a typical internet user worries about being targeted by a criminal looking for financial gain. An HRD may be targeted by a well-resourced state actor who already knows your name, your work, and your colleagues. The threat is personal, political, and persistent.
Understanding who might target you - and why - is the first step in designing an effective defence. Adversaries range widely in their resources, sophistication, and intent:
From an adversary capability perspective, the most dangerous threat actors targeting Kenyan HRDs have demonstrated access to commercial spyware, signals intelligence, and the capacity for multi-vector attacks combining phishing, physical surveillance, and legal harassment simultaneously.
Survey data collected in preparation for this guidebook confirms that digital threats are not hypothetical for Kenyan defenders - they are routine. The following statistics represent the community's lived experience:
The table below summarises the most common digital threats faced by Kenyan HRDs, their descriptions, and warning signs. Use this as a first-reference triage aid when an incident is reported.
Table 1: Common Threat types
Threat Type | Description | Common Signs |
Account Compromise | Unauthorised access to email, social media, or cloud accounts | Unknown logins, password reset emails you did not request, missing messages |
Phishing | Deceptive messages designed to steal credentials or install malware | Urgent or unexpected links, spoofed sender addresses, requests for passwords |
Spyware / Stalkerware | Software covertly installed to monitor calls, messages, location, and camera | Rapid battery drain, device overheating, unexpected data usage, slow performance |
Device Seizure | Physical confiscation of devices by authorities or hostile actors | Arrest situations, office raids, border crossings, checkpoint stops |
DDoS / Website Attack | Overloading or defacing an organisation's website to silence it | Site inaccessible, unusual traffic spikes, altered homepage content |
Social Engineering | Psychological manipulation to gain trust and extract information or access | Impersonation of colleagues, donors, or authorities; unusual requests |
Holistic Security: An integrated approach to safety that recognises the deep and inseparable connection between digital, physical, and psychosocial (mental health) security. A threat in one domain can rapidly become a threat in all others.
Digital security is often described as less tangible than physical security. You cannot see a phishing email the way you can see a locked gate. This invisibility leads many defenders to underestimate digital threats until the consequences become very physical indeed. Digital tracking can lead directly to physical arrests. A compromised email account can expose the identities of vulnerable witnesses. A hacked device during a raid can give authorities access to years of sensitive documentation.
Effective resilience requires attention to all three dimensions, not just technical controls:
If you have experienced a digital attack - your account hacked, your messages read by a hostile actor, your location tracked - you may feel violated, anxious, hypervigilant, or unable to trust digital tools. These reactions are normal responses to a real threat. Effective incident response always includes acknowledging and addressing this emotional dimension alongside the technical response.
Online activity increasingly carries offline consequences for HRDs in Kenya. Social media posts, WhatsApp coordination, and online mobilisation have been directly linked to physical arrests, intimidation, and abductions - as observed during recent civic mobilisation moments. This guidebook treats physical safety as inseparable from digital safety.
Digital threats cause genuine psychological trauma[3]. Unlike a physical break-in, in which the victim has a clear before and after, a digital compromise may feel permanent. Defenders often do not know what was accessed, by whom, for how long, or what will be done with the information. This uncertainty generates lasting anxiety and can cause a defender to self-censor, withdraw from advocacy, or abandon digital tools entirely - outcomes that serve the adversary's goals as effectively as any technical attack.
Incident responders working with HRDs must therefore approach every engagement with emotional intelligence as a prerequisite - not an add-on.
Key principles include:
1. Listen before diagnosing - When an HRD reports a suspected incident, their first need is to feel heard and believed. Jumping immediately to technical questions or instructions can feel dismissive and can silence important contextual information.
2. Do not blame the victim - Every person, regardless of technical skill, can be deceived by a sophisticated, targeted attack. Framing the incident as the defender's fault is inaccurate, harmful, and counterproductive to building the trust needed for effective response.
One of the most effective and underutilised resilience strategies available to HRD networks is structured information sharing. When one organisation experiences an attack, the technical indicators of that attack (the malicious domain, the phishing email template, the file hash of a malware attachment) are valuable intelligence that can protect every other organisation in the network.
Effective information sharing delivers three core benefits:
Information sharing must be conducted carefully to protect source confidentiality, avoid alerting adversaries, and respect the consent of the affected organisation. Part V of this guidebook covers the structures and protocols for doing this safely.
Threat Modeling: A structured process for proactively identifying what you are protecting, who might attack it, how likely that is, and what the consequences would be - enabling you to prioritise your limited resources on the risks that matter most.
Most organisations respond to security incidents reactively after they occur. Threat modelling shifts security from a crisis-driven response posture to a proactive, living strategy. It does not require specialised technical knowledge. It requires honest, systematic thinking about your organisation's specific situation.
Begin by asking: what do we have that is worth protecting? Assets are not only technical, they include information, relationships, and capabilities:
When cataloguing assets, apply data minimisation principles from the outset: document only what you need to protect, and consider securely deleting assets that are no longer necessary. Under the Data Protection Act (2019), limiting the personal data you hold also limits your liability in the event of a breach.
Not all threats come from the same source or carry the same risk. Being honest about who might target your organisation - and why - is often uncomfortable but always essential. Consider:
Different adversaries have different capabilities, resources, and motivations. A well-resourced state actor deploying commercial spyware requires a very different response than an opportunistic criminal exploiting a weak password. Your threat model must account for the specific adversaries most relevant to your context.
Once assets and adversaries are identified, evaluate each potential threat on two dimensions:
Digital hygiene refers to the routine, daily practices that form an organisation's first line of defence against the most common and preventable security incidents. The table below summarises the seven most critical digital hygiene practices for HRDs, with guidance on implementation:
Table 2: Digital hygiene practices
Practice | Why It Matters | Recommended Tool / Action | |
PASSWORDS | Use unique, long passwords (12+ chars) for every account | A single reused password means one breach exposes all accounts | Fully-featured, open source password manager with cloud-sync. Bitwarden is easy-to-use with a clean UI and client apps for desktop, web and mobile |
2FA | Enable two-factor authentication on all critical accounts | Even if a password is stolen, 2FA blocks unauthorised access | Authenticator app such as https://2fas.com/ is open source and at no cost. |
UPDATES | Keep your operating system and all apps fully updated | Attackers exploit known vulnerabilities in outdated software | Enable auto-update; patch within 48 hours of security releases |
BACKUPS | Maintain regular, encrypted off-site backups | Ransomware and device seizure can permanently destroy data | Encrypted external drive + a separate cloud backup |
APP PERMISSIONS | Audit permissions granted to installed apps regularly | microphone, camera and location access | Android: Settings > Privacy; iOS: Settings > Privacy & Security |
SECURE COMMS | Use end-to-end encrypted channels for sensitive communications | Unencrypted channels can be intercepted by adversaries | Signal for encrypted messaging- free, open-source ProtonMail for email-Free tier available; paid for advanced features |
VPN | Use a reputable VPN when on public or untrusted networks | VPNs prevent your real IP address from being logged by attackers | ProtonVPN-Free tier available; paid for full features |
Despite advances in authentication technology, the use of weak, reused, or stolen passwords remains the primary cause of account compromise across all sectors. For HRDs, a compromised account is not merely a personal inconvenience; it can expose witnesses, beneficiaries, and colleagues to physical danger.
Credential Stuffing: An attack in which criminals take username and password combinations leaked from one service and automatically test them against hundreds of other platforms. If you reuse passwords, one data breach can compromise all your accounts simultaneously.
Two-Factor Authentication (2FA): Two-factor authentication adds a second verification layer beyond the password, requiring something you know (the password) plus something you have (a physical device or code). Even if your password is stolen, 2FA prevents unauthorised access.
Types of 2FA Applications: Authenticator Apps (e.g 2FAS or Aegis Authenticator is a free, secure and open-source app for Android to manage your 2-step verification).
Full-disk encryption ensures that if a device is physically seized, the data on it cannot be accessed without the correct credentials. This is particularly important given the documented use of forensic extraction tools by state actors.
A Bring Your Own Device (BYOD) model is one in which staff and volunteers use their personal devices - phones, laptops, tablets - for organisational work. Many HRDs operate this way without formal recognition. If your organisation does not issue dedicated work devices, you are likely already in a BYOD environment.
Organisations operating on a BYOD model should implement the following minimum standards:
Secure communications are the foundation of safe coordination. The following principles apply to all sensitive exchanges - whether internal team communications, contact with sources, or incident reporting
Core principles for secure communications:
PART I SUMMARY | This part has introduced the foundational concepts every HRD and SJO in Kenya needs before an incident occurs: the specific threat landscape and adversaries you face; a holistic security framework that integrates digital, physical, and psychosocial dimensions; a practical threat modeling process; and the essential digital hygiene practices that form your first line of defence. Part II builds on these foundations to establish formal incident management structures - including the legal frameworks, playbooks, and role assignments that transform your organisation from reactive to prepared.
The Tatua Digital Resilience Centre, established by KICTANet, empowers Social Justice Organizations in East Africa to strengthen digital resilience, recover from threats, and harness technology for human rights work. Serving Kenya, Tanzania, and Uganda, it offers strategic support, fosters partnerships, and plans to expand across Africa with sustainable funding models.
Nine Planets, Earth Wing, Suite E9, Kabarnet Garden Road, Nairobi, KENYA | Phone: +(254) 751-000-001 | Email: info@tatua.digital
© 2026 TATUA DIGITAL RESILIENCE CENTRE