In 2024, we published information about an interesting digital security tool - Alicia Sykes' Personal Security Checklist . Both the tool and the material have aroused constant interest, so we are updating and supplementing the publication. The checklist is alive and has grown noticeably, but he is not alone. Different self-test tools are suitable for different situations and different people. This part is about checklists and self-audits: forms where you mark items and see your level of security.
“If you think technology will solve your security problems, then you don’t understand the problems or the technology.”
Bruce Schneier, cybersecurity and cryptography expert
This idea explains well why checklists are needed at all. They are not a magic button, but a way to turn scattered advice into a habit and at the same time see where your hole is. Below is our updated selection of such tools. All of them appeared or were updated no earlier than 2022, so you won't stumble upon outdated advice from the past.
What happened to the checklist from the last article?The Personal Security Checklist of the Digital Defense project has not gone away and continues to evolve. Today there are more than 300 points. The main page is marked “for 2026”: the content is regularly revised. Everything else we praised him for is in place. This is still an interactive form where you check boxes directly on the site, see your progress in the form of visual charts, and can disable items that do not fit your threat model. No cookies are collected and no registration is required.
One change is worth noting for those who wish to reprint or adapt the checklist. Previously, the project was distributed entirely under a free license, but now it is divided. The checklist text itself is licensed under CC BY-NC-SA 4.0 with non-commercial use, and the program code is licensed under MIT. For personal use this does not change anything, but for reprinting it matters.
There were attempts to create a localized version in Russian, but now the service is unavailable, so we provide a link to the original digital-defense.io . Unfortunately, Russian-language interfaces are very rare in this segment, but you can count on machine translation.
There is no one checklist for all occasions. What is suitable for a private user will be of little help to the editorial office, and the tool of an investigative journalist is redundant for a person who simply wants to clean up his passwords. Therefore, we have arranged the finds not alphabetically, but according to situations when they are needed.
The security of the entire team is assessed by the Journalist Security Assessment Tool (JSAT) , also from GIJN. It's a free, comprehensive self-assessment tool that looks at digital and physical threats together. Such a circular diagnosis for editorial staff or non-profit organizations. Available in Russian, as well as English, Indonesian, Portuguese and Turkish.
A separate genre is self-diagnosis at the time of the incident. This is the Digital First Aid Kit from the Rapid Response Network and CiviCERT. You answer a series of questions about your situation and devices, and the tool leads you to specific steps: your account was hacked, your device was seized or lost, your website is down, doxxing or bullying has started, someone is impersonating you. The first aid kit was recently released in version 3.0, with updated navigation, a new website and languages, including Russian.
Separately about point scenarios. Sometimes you don’t need a general checklist, but a list for one specific situation. A good example is the Electronic Frontier Foundation's checklist for preparing devices to cross the US border (June 2025). It is narrow, but it shows a useful principle: for specific risks, it makes sense to look for or create a separate checklist, rather than rely on a universal one. Please note that its specificity is not entirely suitable for crossing the Russian border; Teplitsa has information material on this matter.
The words “checklist” and “self-audit” are often used interchangeably, but there is a difference between the tools in our selection.
A checklist is a list of specific actions or habits that are worth developing. You go point by point and close the gaps.
Checklists include: Personal Security Checklist, FPF and activist checklists. It's a tool for calm prevention as you get your digital security in order.
A self-audit is a more structured assessment of either your current situation or the state of the organization, often with conclusions about risks and priorities:
If you understand in advance which tool you need, you will save time and nerves. You shouldn’t grab the “first aid kit” when you just want to enable two-factor authentication, and vice versa, scroll through the general checklist when your account has already been hijacked.
A few rules that make any of these tools more useful.
Start with a threat model. Before checking boxes, answer yourself: what are you protecting, from whom and at what cost. The advice “turn off unnecessary Windows services” is useless if you have macOS, and some of the advanced measures are redundant for a person who is not opposed by the state. A good checklist allows you to disable or skip inappropriate items, use this.
Check the update date. Digital security becomes outdated quickly: yesterday's advice may be harmful today. Before you trust a list, look at when it was last updated. All tools from our selection pass this test.
Remember that no list is exhaustive. There will always be a critic with the exclamation “you forgot the most important thing!” The checklist gives direction, but does not replace common sense.
Be careful at the time of the incident. A separate warning for those who open the “first aid kit” when they suspect surveillance. If your device may be running stalkerware, hasty action can be harmful: removing the program can sometimes instantly notify the person spying on you, or destroy evidence that will come in handy. Digital First Aid Kit honestly warns about this, do not miss such clauses.