Physical Security & Operational Security (OPSEC)
Physical Security & Operational Security (OPSEC)
Digital security cannot be separated from physical security. Your devices are only as secure as the environment they operate in. This guide covers the physical and operational practices necessary to protect your digital sovereignty.
The OPSEC Framework
Operational Security (OPSEC) is a process of identifying sensitive information and taking steps to protect it from adversaries. The OPSEC cycle consists of five steps:
- Identify Critical Information — What information, if compromised, could harm you or your objectives?
- Analyze Threats — Who wants this information, and what resources do they have?
- Analyze Vulnerabilities — How could the threat access the critical information?
- Risk Assessment — Evaluate the likelihood and impact of each vulnerability being exploited.
- Apply Countermeasures — Implement measures to eliminate or reduce the risk.
Physical Security Practices
1. Device Access Control
- Lock your devices: Use strong PINs, passwords, or biometric locks on all devices.
- Physical locks: Use Kensington locks or cable locks for laptops in public spaces.
- Room security: Never leave devices unattended in public spaces or vehicles.
- Workplace security: Lock your office door when unattended; use privacy filters on screens in open spaces.
2. Network Security at Home
- Secure your router: Change default credentials, disable WPS, enable WPA3 encryption.
- Network segmentation: Use separate VLANs or guest networks for IoT devices and personal devices.
- Physical port security: Disable unused Ethernet/Wi-Fi ports on your router and devices.
OPSEC for Digital Communication
1. Identity Hygiene
- Compartmentalize identities: Use different identities, accounts, and devices for different activities (work, personal, political).
- Digital footprint reduction: Minimize social media activity and remove personal information from public directories.
- Metadata awareness: Understand that even encrypted communications leak metadata—be aware of who you contact, when, and how often.
2. Operational Security for Travel
- Device sanitization: Before traveling to high-risk areas, wipe devices of sensitive data and carry only what is necessary.
- Temporary devices: Consider using disposable devices for sensitive activities in high-risk environments.
- Counter-surveillance: Learn to detect physical and electronic surveillance when traveling.
Supply Chain Security
Your devices are only as secure as their supply chain. Consider the following:
- Purchase from trusted sources: Avoid refurbished devices from unknown sources.
- Inspect devices: Check for tamper-evident seals before receiving hardware.
- Open-source hardware: Where possible, use devices with transparent supply chains and open firmware.
- Pre-deployment integrity: Verify firmware signatures and perform fresh OS installations on critical devices.
Emergency Preparedness
- Data backups: Maintain encrypted, offline backups of critical data.
- Emergency purge: Have a plan for quickly wiping sensitive devices if you are detained or threatened.
- Emergency contacts: Designate trusted contacts who can help if you are unable to access your accounts.
“The weakest link in your security chain is often not technology, but human behavior. OPSEC is as much about discipline as it is about tools.”
← Back to Online Protection
← Back to Worm Architecture
← Return to Digital Sovereignty Foundation