HRD Forensic Guidebook

← Back to Guidebook

Part I — Introduction and Foundational Concepts

Understanding the threat landscape, holistic security, threat modelling, and digital hygiene for Kenyan Human Rights Defenders

1.1 The Digital Threat Landscape for Human Rights Defenders

Human Rights Defenders (HRDs) and Social Justice Organisations (SJOs) in Kenya increasingly depend on digital platforms for advocacy, coordination, and mobilisation[2]. This dependence, while essential to their work, exposes them to a rapidly evolving array of cyber threats. Attacks have shifted from opportunistic social engineering to highly sophisticated, precisely targeted spyware campaigns designed to monitor, silence, and endanger defenders.

Think of it this way: a typical internet user worries about being targeted by a criminal looking for financial gain. An HRD may be targeted by a well-resourced state actor who already knows your name, your work, and your colleagues. The threat is personal, political, and persistent.

1.1.1 Who Are the Adversaries?

Understanding who might target you - and why - is the first step in designing an effective defence. Adversaries range widely in their resources, sophistication, and intent:

  • Non-state actors and government agencies seeking to monitor, intimidate, or gather intelligence on civil society organisations, journalists, and opposition figures.
  • Organised criminal groups conducting financially motivated attacks such as fraud, ransomware, and data theft.
  • Private surveillance companies selling spyware tools (e.g., Pegasus by NSO Group, FinFisher) to governments, which are then deployed against HRDs.
  • Internal threats including disgruntled employees, volunteers with excessive access, or individuals unwittingly manipulated into compromising an organisation.
  • Opportunistic attackers exploiting weak passwords, unpatched software, or unsecured devices with no specific political agenda.

From an adversary capability perspective, the most dangerous threat actors targeting Kenyan HRDs have demonstrated access to commercial spyware, signals intelligence, and the capacity for multi-vector attacks combining phishing, physical surveillance, and legal harassment simultaneously.

1.1.2 The Current Threat Picture in Kenya - Evidence

Survey data collected in preparation for this guidebook confirms that digital threats are not hypothetical for Kenyan defenders - they are routine. The following statistics represent the community's lived experience:

  • Account compromise, phishing, spyware infections, and surveillance monitoring are among the most frequently reported incidents.
  • 51% of defenders report lacking access to legal counsel when a digital incident occurs.
  • 82% rely on informal reporting channels - primarily WhatsApp - creating insecure, non-standardised, and legally inadmissible documentation trails.
  • Only 21% of Kenyan HRD organisations have a written Incident Management Policy.
  • 100% of surveyed defenders depend on mobile devices for their day-to-day work, yet technical forensic capacity for mobile triage remains critically underdeveloped.
  • Kenyan authorities have been documented using Cellebrite forensic extraction tools against activists and politicians (Citizen Lab, 2023).

1.1.3 Common Threat Types

The table below summarises the most common digital threats faced by Kenyan HRDs, their descriptions, and warning signs. Use this as a first-reference triage aid when an incident is reported.

Table 1: Common Threat types

Threat Type

Description

Common Signs

Account Compromise

Unauthorised access to email, social media, or cloud accounts

Unknown logins, password reset emails you did not request, missing messages

Phishing

Deceptive messages designed to steal credentials or install malware

Urgent or unexpected links, spoofed sender addresses, requests for passwords

Spyware / Stalkerware

Software covertly installed to monitor calls, messages, location, and camera

Rapid battery drain, device overheating, unexpected data usage, slow performance

Device Seizure

Physical confiscation of devices by authorities or hostile actors

Arrest situations, office raids, border crossings, checkpoint stops

DDoS / Website Attack

Overloading or defacing an organisation's website to silence it

Site inaccessible, unusual traffic spikes, altered homepage content

Social Engineering

Psychological manipulation to gain trust and extract information or access

Impersonation of colleagues, donors, or authorities; unusual requests

1.2 Holistic Security and Resilience

Holistic Security: An integrated approach to safety that recognises the deep and inseparable connection between digital, physical, and psychosocial (mental health) security. A threat in one domain can rapidly become a threat in all others.

Digital security is often described as less tangible than physical security. You cannot see a phishing email the way you can see a locked gate. This invisibility leads many defenders to underestimate digital threats until the consequences become very physical indeed. Digital tracking can lead directly to physical arrests. A compromised email account can expose the identities of vulnerable witnesses. A hacked device during a raid can give authorities access to years of sensitive documentation.

1.2.1 The Three Dimensions of Holistic Security

Effective resilience requires attention to all three dimensions, not just technical controls:

  • Digital Security - protecting devices, accounts, communications, and data from unauthorised access, surveillance, and manipulation.
  • Physical Security - protecting people, offices, equipment, and documents from physical threats, including raids, seizure, surveillance, and intimidation.
  • Psychosocial Security - protecting the mental health, wellbeing, and emotional resilience of defenders and their teams, recognising that digital attacks can cause lasting psychological harm.

If you have experienced a digital attack - your account hacked, your messages read by a hostile actor, your location tracked - you may feel violated, anxious, hypervigilant, or unable to trust digital tools. These reactions are normal responses to a real threat. Effective incident response always includes acknowledging and addressing this emotional dimension alongside the technical response.

1.2.1 Physical consequences of digital activity

Online activity increasingly carries offline consequences for HRDs in Kenya. Social media posts, WhatsApp coordination, and online mobilisation have been directly linked to physical arrests, intimidation, and abductions - as observed during recent civic mobilisation moments. This guidebook treats physical safety as inseparable from digital safety.

1.2.2 Why Psychosocial Safety Cannot be Separated from Technical Response

Digital threats cause genuine psychological trauma[3]. Unlike a physical break-in, in which the victim has a clear before and after, a digital compromise may feel permanent. Defenders often do not know what was accessed, by whom, for how long, or what will be done with the information. This uncertainty generates lasting anxiety and can cause a defender to self-censor, withdraw from advocacy, or abandon digital tools entirely - outcomes that serve the adversary's goals as effectively as any technical attack.

Incident responders working with HRDs must therefore approach every engagement with emotional intelligence as a prerequisite - not an add-on.

Key principles include:

1. Listen before diagnosing - When an HRD reports a suspected incident, their first need is to feel heard and believed. Jumping immediately to technical questions or instructions can feel dismissive and can silence important contextual information.

2. Do not blame the victim - Every person, regardless of technical skill, can be deceived by a sophisticated, targeted attack. Framing the incident as the defender's fault is inaccurate, harmful, and counterproductive to building the trust needed for effective response.

1.2.3 Information Sharing as a Resilience Strategy

One of the most effective and underutilised resilience strategies available to HRD networks is structured information sharing. When one organisation experiences an attack, the technical indicators of that attack (the malicious domain, the phishing email template, the file hash of a malware attachment) are valuable intelligence that can protect every other organisation in the network.

Effective information sharing delivers three core benefits:

  • Proactively sharing Indicators of Compromise (IOCs) such as IP addresses, domains, and file hashes provides advance warning and increases collective preparedness. An attack detected by one organisation can be blocked by all others before it reaches them - Early Warning and Preparedness
  • Modern targeted campaigns, such as those using spyware, are designed to evade individual detection. Comparing notes across organisations often reveals patterns invisible to any single victim - Faster Identification of Sophisticated Attacks
  • When one organisation has already encountered and remediated a specific attack, sharing their playbook dramatically reduces the response time and error rate for subsequent victims - Reduced Duplication and Faster Recovery

Information sharing must be conducted carefully to protect source confidentiality, avoid alerting adversaries, and respect the consent of the affected organisation. Part V of this guidebook covers the structures and protocols for doing this safely.

1.3 Threat Modeling and Risk Assessment

Threat Modeling: A structured process for proactively identifying what you are protecting, who might attack it, how likely that is, and what the consequences would be - enabling you to prioritise your limited resources on the risks that matter most.

Most organisations respond to security incidents reactively after they occur. Threat modelling shifts security from a crisis-driven response posture to a proactive, living strategy. It does not require specialised technical knowledge. It requires honest, systematic thinking about your organisation's specific situation.

1.3.1 Step 1. Identify Your Assets

Begin by asking: what do we have that is worth protecting? Assets are not only technical, they include information, relationships, and capabilities:

  • Communications - emails, Signal messages, WhatsApp chats, phone calls, meeting notes.
  • Documents - case files, witness statements, evidence of violations, financial records, donor information.
  • Devices - laptops, mobile phones, USB drives, backup drives, routers.
  • Accounts - email accounts, social media accounts, cloud storage, website admin accounts, banking access.
  • People and relationships - the identities and locations of staff, volunteers, witnesses, beneficiaries, and informants.
  • Organisational reputation and continuity - the trust and credibility that sustains your advocacy work.

When cataloguing assets, apply data minimisation principles from the outset: document only what you need to protect, and consider securely deleting assets that are no longer necessary. Under the Data Protection Act (2019), limiting the personal data you hold also limits your liability in the event of a breach.

1.3.2 Step 2. Identify Your Adversaries

Not all threats come from the same source or carry the same risk. Being honest about who might target your organisation - and why - is often uncomfortable but always essential. Consider:

  • Government actors - are you documenting human rights violations, corruption, or activities that threaten powerful political interests?
  • Private sector actors - are you investigating corporate misconduct, environmental violations, or land-grabbing?
  • Criminal actors - do you hold financial information, personal data, or assets that could be monetised?
  • Internal actors - Internal threats are not limited to the workplace. Intimate partners, family members, and close associates with physical access to a defender's device present a distinct and frequently underestimated threat vector. Stalkerware - software covertly installed by a trusted person - is among the most commonly reported tools of digital abuse in personal relationships.
  • Opportunistic actors - are your systems and devices protected against broadly targeted, automated attacks?

Different adversaries have different capabilities, resources, and motivations. A well-resourced state actor deploying commercial spyware requires a very different response than an opportunistic criminal exploiting a weak password. Your threat model must account for the specific adversaries most relevant to your context.

1.3.3 Step 3 - Assess Likelihood and Impact

Once assets and adversaries are identified, evaluate each potential threat on two dimensions:

  • Likelihood - how probable is this threat, given your adversaries' capabilities, motivation, and your current vulnerabilities?
  •  Impact - if this threat materialises, what is the physical, psychological, legal, reputational, and operational harm to your organisation and to the people you serve?
1.4 Foundations of Digital Hygiene

Digital hygiene refers to the routine, daily practices that form an organisation's first line of defence against the most common and preventable security incidents. The table below summarises the seven most critical digital hygiene practices for HRDs, with guidance on implementation:

Table 2: Digital hygiene practices

Practice

Why It Matters

Recommended Tool / Action

PASSWORDS

Use unique, long passwords (12+ chars) for every account

A single reused password means one breach exposes all accounts

Fully-featured, open source password manager with cloud-sync. Bitwarden is easy-to-use with a clean UI and client apps for desktop, web and mobile

https://bitwarden.com/

2FA

Enable two-factor authentication on all critical accounts

Even if a password is stolen, 2FA blocks unauthorised access

Authenticator app such as https://2fas.com/ is open source and at no cost.

UPDATES

Keep your operating system and all apps fully updated

Attackers exploit known vulnerabilities in outdated software

Enable auto-update; patch within 48 hours of security releases

BACKUPS

Maintain regular, encrypted off-site backups

Ransomware and device seizure can permanently destroy data

Encrypted external drive + a separate cloud backup

APP PERMISSIONS

Audit permissions granted to installed apps regularly

microphone, camera and location access

Android: Settings > Privacy; iOS: Settings > Privacy & Security

SECURE COMMS

Use end-to-end encrypted channels for sensitive communications

Unencrypted channels can be intercepted by adversaries

Signal for encrypted messaging- free, open-source

ProtonMail for email-Free tier available; paid for advanced features

VPN

Use a reputable VPN when on public or untrusted networks

VPNs prevent your real IP address from being logged by attackers

 ProtonVPN-Free tier available; paid for full features

1.4.1 Passwords and Authentication in Depth

Despite advances in authentication technology, the use of weak, reused, or stolen passwords remains the primary cause of account compromise across all sectors. For HRDs, a compromised account is not merely a personal inconvenience; it can expose witnesses, beneficiaries, and colleagues to physical danger.

Credential Stuffing: An attack in which criminals take username and password combinations leaked from one service and automatically test them against hundreds of other platforms. If you reuse passwords, one data breach can compromise all your accounts simultaneously.

Password Best Practices
  • A 16-character passphrase (e.g., "Nairobi-Rains-July-Safe") is more secure than a short, complex password like "P@55w0rd!". Length over complexity:
  • Every account must have its own password. No exceptions - particularly for email, which is the recovery route for all other accounts. Unique per account:
  • Web browsers are frequent targets for credential-stealing malware. Use a dedicated password manager instead. Never stored in browsers:
  • Bitwarden (free, open-source, cloud-synced) or KeePassXC (free, open-source, local storage). Both are verified by independent security audits. Recommended managers:

Two-Factor Authentication (2FA): Two-factor authentication adds a second verification layer beyond the password, requiring something you know (the password) plus something you have (a physical device or code). Even if your password is stolen, 2FA prevents unauthorised access.

Types of 2FA Applications: Authenticator Apps (e.g 2FAS or  Aegis Authenticator is a free, secure and open-source app for Android to manage your 2-step verification).

  • It generates time-based codes on your device.
  • Significantly more secure than SMS.
  • Effective for most accounts.
  • Backs up your recovery codes securely.

1.4.2 Device Security

Operating System and App Updates:
  • Enable automatic updates on all devices. Where automatic updates are unavailable, establish a weekly update schedule and assign responsibility to a specific person.
  • Prioritise security updates even if feature updates are deferred.
  • Retire devices that no longer receive security updates from the manufacturer. An unsupported device is a permanent security liability.
Device Encryption

Full-disk encryption ensures that if a device is physically seized, the data on it cannot be accessed without the correct credentials. This is particularly important given the documented use of forensic extraction tools by state actors.

  • Android - Enable 'Encrypt phone' in Security Settings. Modern Android devices (Android 10+) encrypt by default but verify this is active.
  • iOS - Encryption is enabled automatically when a passcode is set. Use an alphanumeric passcode rather than a 6-digit PIN for stronger protection.
  • Windows - Enable BitLocker (available on Pro and Enterprise editions) and save the recovery key to a secure location outside the device.
  • macOS - Enable FileVault in System Preferences > Security & Privacy.
  • Linux - Enable LUKS encryption at the operating system installation stage.
Bring Your Own Device (BYOD) Considerations

A Bring Your Own Device (BYOD) model is one in which staff and volunteers use their personal devices - phones, laptops, tablets - for organisational work. Many HRDs operate this way without formal recognition. If your organisation does not issue dedicated work devices, you are likely already in a BYOD environment.

Organisations operating on a BYOD model should implement the following minimum standards:

  • Mandatory full-disk encryption on all devices used for organisational work.
  • Clear separation of personal and work data - use separate apps or profiles where possible.
  • A documented remote wipe procedure for devices that are lost, seized, or compromised.
  • Regular security audits of BYOD devices - at minimum, a quarterly app permission review.
  • An explicit policy defining what organisational data may and may not be stored on personal devices.

1.4.3 Secure Communications

Secure communications are the foundation of safe coordination. The following principles apply to all sensitive exchanges - whether internal team communications, contact with sources, or incident reporting

Core principles for secure communications:

  • Signal is the gold standard: open-source, independently audited, and free. Enable disappearing messages for the most sensitive conversations. Use end-to-end encrypted channels for all sensitive communications.
  • Standard email is not encrypted in transit and is routinely accessible to email providers, government agencies, and sophisticated adversaries. If email must be used for sensitive content, use PGP encryption or switch to ProtonMail.
  • If your primary device or account is suspected of being monitored, all coordination must shift to a separate device using a separate secure channel immediately. Never discuss incident response or sensitive investigation details on the channel you suspect is compromised.
  • The fastest verification is a voice call or video call on a separate channel - an attacker who has compromised a messaging account cannot easily fake a real-time voice. Verify contact identities out-of-band before sharing sensitive information.

PART I SUMMARY | This part has introduced the foundational concepts every HRD and SJO in Kenya needs before an incident occurs: the specific threat landscape and adversaries you face; a holistic security framework that integrates digital, physical, and psychosocial dimensions; a practical threat modeling process; and the essential digital hygiene practices that form your first line of defence. Part II builds on these foundations to establish formal incident management structures - including the legal frameworks, playbooks, and role assignments that transform your organisation from reactive to prepared.

The Tatua Digital Resilience Centre, established by KICTANet, empowers Social Justice Organizations in East Africa to strengthen digital resilience, recover from threats, and harness technology for human rights work. Serving Kenya, Tanzania, and Uganda, it offers strategic support, fosters partnerships, and plans to expand across Africa with sustainable funding models.

Nine Planets, Earth Wing, Suite E9, Kabarnet Garden Road, Nairobi, KENYA | Phone: +(254) 751-000-001 | Email: info@tatua.digital

© 2026 TATUA DIGITAL RESILIENCE CENTRE