When the Newsroom is Hacked, Public Trust is Hacked Too

As journalists increasingly depend on digital platforms to gather, produce and distribute news, NITA-U is urging newsrooms to treat cybersecurity as an editorial responsibility not merely an IT concern.
A newsroom’s credibility can take years to build, but a single careless click can place it at risk.
An editor may open what appears to be an urgent document. A reporter may respond to a message requesting account details. A producer may upload a confidential interview transcript to an unsecured artificial-intelligence platform. Within minutes, a newsroom account can be hijacked, unpublished material exposed or a confidential source placed in danger.
It is against this background that Johnson Tumusiime, Manager for Governance and Risk at the National Information Technology Authority-Uganda (NITA-U), called upon editors, newsroom leaders and journalists to place digital security at the centre of their work.

Speaking during the 4th Annual Editors’ Convention, Tumusiime delivered a presentation titled, “Strategic, Secure Communication: The Power to Make Ugandans ‘Beera Ku Guard’ Online.”
His central message was that cybersecurity is no longer simply an information-technology issue. For media organisations, it is now a question of editorial credibility, source protection, organisational safety and public trust.
A breach can become an editorial crisis
Journalists increasingly rely on mobile phones, emails, messaging applications, social-media platforms and cloud-based systems to communicate with sources, exchange documents and publish stories.
While these tools have made journalism faster and more accessible, they have also created new vulnerabilities.
A compromised newsroom account can be used to distribute false information under the name of a trusted media organisation. An exposed email or messaging account can reveal confidential conversations, unpublished investigations and the identities of vulnerable sources.
Tumusiime warned that when digital platforms are compromised, the consequences extend beyond the immediate loss of information. The credibility and reputation of the entire media organisation can be damaged.
For editors, this means cybersecurity must be treated with the same seriousness as accuracy, fairness and verification. A newsroom cannot credibly promise to protect its sources while its digital systems and information-handling practices remain weak.
Data protection, Tumusiime stressed, is part of credible journalism because reporters routinely handle sensitive information, confidential sources and unpublished material.

“Think before you click”
Many cyberattacks do not begin with highly sophisticated technology. They begin with an ordinary-looking message.
It may be a warning that an account is about to be disabled, an invitation to download a document or a request to verify personal information. The sender may even appear to be a familiar colleague or institution.
The attacker relies on urgency, fear, curiosity or familiarity to persuade the recipient to act before verifying the request.
Tumusiime described people as both the “weakest and strongest link” in cybersecurity. Technology can provide protective systems, but human judgement often determines whether an attack succeeds.
His advice to journalists and other internet users was simple: “Think before you click.”
Before opening a link, downloading an attachment or sharing personal information, journalists should pause and establish who sent the request, why the information is required and whether the communication can be confirmed through another channel.
The need for greater caution is reinforced by the low levels of public understanding of digital risks. Tumusiime told Convention participants that approximately 48.8 per cent of people are aware of cybersecurity issues, while only 13.6 per cent understand data protection and privacy.
He pointed to the financial losses associated with mobile-money fraud and SIM-swap fraud as evidence of the consequences of poor digital-security awareness.
For newsrooms, however, the risk goes beyond financial loss. A successful attack can expose sources, compromise investigations, disrupt publication and destroy the confidence that audiences place in a media organization.
AI must not replace the editor
The growing use of artificial intelligence in journalism has introduced another layer of opportunity and risk.
AI tools can help journalists transcribe interviews, analyse large documents, generate ideas and perform routine tasks more efficiently. But they can also generate inaccuracies or expose sensitive information when used without adequate safeguards.
Tumusiime described AI as both an opportunity and a risk for the newsroom. Its output depends heavily on the information and instructions it receives, and it can produce mistakes that may appear convincing.
He therefore emphasised that human beings must retain editorial accountability.
This means every claim produced with the assistance of AI must be independently verified before publication. Journalists must also be careful about uploading confidential transcripts, unpublished investigations, internal documents or source details to external AI platforms.
The presence of AI in the production process does not transfer responsibility away from the newsroom. The reporter remains responsible for the information gathered, while the editor remains accountable for what is eventually published.
Three questions every newsroom should ask
To strengthen editorial judgement, Tumusiime proposed a simple verification approach that editors and journalists can use before publishing or sharing information.
The first question is: “Who is providing the information, and can the source be verified?”
Online identities, documents, photographs and social-media accounts cannot be accepted at face value. Journalists must establish the origin of the material and verify the person or institution behind it.
The second question is: “What exactly is being communicated, and what is the context surrounding it?”
A genuine photograph or statement can still mislead audiences when removed from its original context. Editors must therefore examine where and when the information originated, what may have been omitted and whether the material has been altered.
The third question is: “What could happen if the information is published or shared?”
This requires editors to consider the possible harm to sources, individuals, communities and the credibility of the media organisation. Speed remains important in journalism, but it should not override verification and responsible editorial judgement.
Together, the three questions; source, content and context, and consequences, offer newsrooms a practical defence against misinformation, manipulated material and unverified digital content.
Making cybersecurity understandable
Tumusiime also challenged the media to improve how it communicates cybersecurity and data-protection information to the public.
Technical language may accurately describe a cyber threat, but it will not necessarily help an ordinary citizen understand what action to take. Effective communication must be simple, relatable and connected to people’s everyday experiences.
To illustrate the power of localisation, Tumusiime offered a memorable comparison: “Your NIN is your house key; don’t leave it where everyone can pick it.”
The message transforms an abstract discussion about personal data into a familiar warning about protecting one’s home.
Cybersecurity communication should also recognise that one message cannot serve every audience. Young people, older people, traders and rural communities use technology differently and face different forms of risk.
Newsrooms must therefore identify their audiences and adapt both the language and the channel of communication. Radio, television, SMS, WhatsApp and community-based platforms can complement one another in reaching different groups.
Repetition is equally important. Cybersecurity messages cannot be communicated once and then abandoned. They must be repeated consistently if they are to influence behaviour.
Above all, every message should direct the audience towards a safe action. It is not enough to report that online fraud is increasing. Journalism should explain how people can identify suspicious messages, verify requests, protect personal information and report security incidents.
From individual caution to newsroom policy
“Think before you click” is an important starting point, but individual vigilance alone cannot secure a media organisation.
Newsroom leaders must create institutional safeguards for protecting accounts, devices, documents and sources. Media organisations need clear procedures covering password management, access to institutional platforms, storage of sensitive material, use of AI tools and responses to security breaches.
Digital-security responsibility should also extend beyond reporters and technical staff. Editors, producers, administrators, freelancers and senior managers all have access to information or systems that can be exploited.
Regular training is essential because cyber threats continue to evolve. Newsrooms should also periodically review who has access to organisational platforms particularly when employees or contractors leave the organisation.
The most important change, however, must be in how the media understands cybersecurity.
When a source is exposed, journalism is weakened. When a newsroom account is hijacked, audiences can be deceived. When manipulated information is published under a trusted media brand, public confidence is damaged.
Digital security is therefore not simply about protecting devices. It is about protecting the information, relationships and credibility on which journalism depends.
For editors, newsroom leaders and journalists, NITA-U’s message was urgent and practical: “Beera Ku Guard” online and always think before you click.
Recent Updates
- Digital Security Is Newsroom Security: Protecting Sources, Stories and Public Trust
- Safer Newsrooms Cannot Wait: Confronting Sexual Harassment in Uganda’s Media
- When Illness Interrupts the Assignment: How Insurance Helped a Koboko Journalist Access Treatment
- Hon. Lumumba Calls for Stronger Media–Government Dialogue and Responsible Journalism
- AI in the Newsroom: Opportunity Must Come with Accountability


