"The best intelligence operation is the one the target never knew happened."
Digital Threats and Cyber Awareness
Instructor Sele: The modern security threat is not always a man with a weapon. It is sometimes a compromised phone, a social media post, or a location-sharing app. Digital security is now a core competency for every SafeHaven professional — because your phone can betray your principal long before any physical threat appears.
Section 1 — Digital Threats to Security Operations
Location tracking: smartphones continuously broadcast location data. An attacker with access to a team member's phone can track the principal's movements in real time.
Social media exposure: posts, check-ins, and tagged photographs reveal locations, routines, and security arrangements without the operator realising.
Unsecured communications: standard SMS and unencrypted calls can be intercepted. Operational details communicated over unsecured channels are a serious vulnerability.
Phishing and social engineering: attackers impersonating colleagues or clients to extract operational information via messaging apps.
Doxxing: the public exposure of a person's private information (address, vehicle, family details) online, specifically to facilitate targeting or harassment.
Section 2 — Digital Security Protocols for SafeHaven Operators
All SafeHaven personnel on active operations must follow these protocols: disable location services on personal devices when on duty (or use a designated duty phone with location services off); use encrypted communications for all team coordination (SafeHaven-approved apps only — no WhatsApp for operational details); no operational content on personal social media; no discussion of operational details via standard SMS, personal email, or personal messaging apps; password-protect all devices (biometric + PIN); report any suspected device compromise immediately to the Operations Commander.
Section 3 — Social Media Conduct
A guard's personal social media presence is an intelligence source for anyone who wants to target the client. Do not post photographs in or near client premises. Do not mention clients, client locations, or client activities — ever. Do not check in to locations related to operations. Do not accept friend or follow requests from unknown persons during active deployments. Assume any social media post is visible to the threat.
Section 4 — Recognising Social Engineering
Social engineering is the manipulation of people into revealing confidential information or taking insecure actions. Common attack vectors: impersonation (a caller claiming to be from SafeHaven management, IT support, or the client's office); pretext (a plausible cover story — "I'm co-ordinating logistics for tomorrow's movement — can you confirm the departure time?"); urgency (pressure to respond quickly without verification).
If you receive an unusual request for operational information via any channel, verify the requestor's identity through an independent method before responding. Call them back on a known number. Do not respond to the request through the same channel.
- •Disable location services on personal devices when on duty
- •Use only SafeHaven-approved encrypted communications for operational coordination
- •Zero operational content on personal social media — ever
- •Assume your digital footprint is visible to the threat — act accordingly
- •Verify unusual requests for information through an independent channel before responding
"A guard on one of our EP details posted a photograph of himself in uniform outside the client's office. The post was public. It included the building in the background, the time stamp, and his location tag. In one post he told anyone watching exactly which building our client used, what day we were there, what time we arrived, and what our team member looked like. He was removed from the operation that day. Your phone is a security tool — or it is a security threat. There is no middle ground."
Digital security protocols require a SafeHaven operator to: