Skip to content

Protective Security Guidance - Staying Safe Online

  • Knowledge Level: Introductory
  • Protection Stage: All Stages
  • Time to read:

This series is for anyone working in the election space, including but not limited to central or local government officials, candidates, campaigners, returning officers and polling station staff.

Last Updated: 04 April 2025
Share this article:

Why am I of interest?

Your involvement in the electoral process puts you in a position of influence because you may: 

  • Have access to people involved in the election, which a hostile actor may seek to exploit. This might include an understanding of their personalities, their behaviour, points of tension, split opinions and off-the-record views held.
  • Have an ‘insider’ view of the electoral process which may give a hostile actor, through you, the potential to cause disruption to the proceedings.
  • Have access to sensitive information which may not be publicly available. This access may continue after the election and will still be of interest to a hostile actor.
  • Have access to facilities or physical locations which are not normally publicly accessible.

Managing your Digital Footprint

A digital footprint is the data that’s left behind whenever you use a digital service, or whenever someone posts information about you onto a digital forum, such as a social network. 

Having a digital footprint is normal – they’re very difficult to avoid. Working in the election space you may have quite an active digital footprint. Online activities such as photo sharing, dating, banking, shopping, gaming, and social networking can also all add to your digital footprint. Given that your digital footprint is publicly accessible, we recommend you know exactly what looks like and how to actively manage it.

Protective Security Advice

A badly-managed digital footprint could mean the ‘digital you’ makes the ‘real you’ vulnerable. But, by taking some practical steps you can minimise the security risks while still making full use of the many digital services available. 

During an election period some practical steps you could take are: limit the sharing of personal details, location and travel plans such as your intended route or timings online.

Know what your footprint looks like, what information is out there about you? What can someone learn about you, your family, your work and your interests?

Be proactive and shape your digital footprint into something that you are happy with. Review your passwords and privacy settings on devices, apps and social media sites.

Review what personal and work related data is available online about you. Can you delete parts or ask for them to be removed? Think carefully about what you share – you don’t always know who’s looking at it, how it will be protected, or who it might be shared with.

Looking after your digital footprint is an ongoing job, so monitor it regularly. Social media privacy setting change, the devices you use change, and the information about you online changes as you and others add to it. Keep an eye on your digital footprint to ensure you, your friends, your family, and your colleagues stay safe.

Social Engineering

Social engineering is the process of obtaining information from others under false pretences; it is based upon building an inappropriate trust relationship in order to facilitate, for example, unauthorised entry to a site, access to an organisation’s secure IT systems, or to persuade someone to share some protected information. 

A social engineer will establish a level of trust so that the staff member feels comfortable to disclose information or grant the social engineer access without a second thought.

The important point about social engineering is that your organisation might have sophisticated firewalls, good password protection and robust entry procedures, but without a good understanding of how you may be exploited by a social engineer your workforce remain vulnerable to the threat.

How might I be targeted?

A social engineer is unlikely to ask a direct question – e.g. ‘What’s the access code?’ Rather, they’ll ask small, seemingly innocuous questions, picking up little bits of information, cues and signals from staff who maybe don’t realise the value of that information, e.g. ’Are the access codes changed often?' and ’Which team is responsible for the access codes?'. 

The social engineer may also manipulate your desire to be helpful or exploit any non-savvy use of the internet (for instance, maybe you’re the type that regularly opens email attachments without checking where they’re from).

The social engineer might use information drawn from an individual’s social media, or those linked to them, or even readily available organisational information (such as that found on the organisation’s ‘About Us’ section) to give the illusion that they have insider knowledge and are therefore trustworthy. 

The attack may appear to come from known contacts or affect your personal accounts. These may be contacts which have been compromised and/or impersonated.

When might this happen?

This can happen at any time but could increase the closer you get to an election event. 

In person – a social engineer may target you at a networking event, showing an excessive interest and knowledge in your work. 

Through communications – you could be targeted by social engineers through your phone or IT devices, where you might be vulnerable to phishing emails, attachments containing malware or bogus phone calls. 

Via social networks – online activity is particularly susceptible and you must be mindful of being targeted by social engineers on social media sites, both professional networking or personal sites.

What types of attack are there?

Social engineering attacks can be either dispersed or direct:

How do I protect myself?

  1. Use common sense when you encounter something unusual or suspicious (e.g. an unusual telephone call, email, or social networking invite)
  2. Verify the details of unknown individuals before disclosing organisational information
  3. Think about what information is shared externally and whether this is too much
  4. Check whether email addresses from unknown senders are genuine or bogus
  5. Be alert to phishing attacks and be careful not to click on malicious links or attachments
  6. Do not be pressurised into making decisions when being put on the spot without first checking security policy

Additional Mitigations

Information on social engineering can be found here, but everyone can access comprehensive election security guidance on GOV.UK. Updated regularly, this guidance brings together expertise from the across the security community including the Police, the NCSC and others to help you implement quick and effective protective security measures.

Exploitation of Social Media

Social media is a ubiquitous part of daily life. Using social media to engage with members of the public is an integral part of political life but the information shared on social media can be exploited by hostile actors. 

As social networking platforms evolve, the amount of personally identifiable information (PII) about us grows. This PII allows social networking platforms to provide a more tailored service to the user, but the increasingly available amount of PII can present a risk in both a professional and/or personal capacity. 

A number of hostiles, including state actors and terrorist groups are known to exploit social media platforms in their targeting of individuals, organisations and governments. Hostile actors conduct online research of social media to identify your interests, activities, personal and professional connections; anything that could make you vulnerable either online or in person.

What are the risks?

Individuals or groups with malicious intent can use information that’s been published on social media in order to cause harm to us, our families, our organisations, our communities or simply the public’s confidence in our democratic processes. Although not an exhaustive list, the threat source can include terrorists and states as well as criminal groups, disaffected employees, hackers and protest groups. 

The threat from social media exploitation is persistent, enduring and able to manifest itself in numerous ways. For example, and of concern from a national security perspective, state actors utilise social networking platforms on an industrial scale. Terrorist groups, although less sophisticated and less well financed than state actors, are nonetheless able to review publicly available information in order to support their attack planning. Protest groups may exploit this information to refine the timing or location of their planned activities. Burglars and petty criminals have been identified searching social media sites in an effort to identify when properties will be empty.

State Threats

Online social networking platforms – particularly professional networking sites – are used by hostile intelligence services for a range of intelligence related activity from open-source research, to identifying targets and conducting cyber operations. 

Terrorism

Social networking platforms represent a valuable source of information for terrorists. Although the majority of such targeting remains either opportunistic or reliant on physical hostile reconnaissance to identify targets, there is an increasing risk of terrorists looking for more creative ways of identifying and locating targets. This includes exploitation of social media. 

Protective Security Advice

Review how much detail you include on your social media profiles – does the information make the real you more discoverable in the real world? For example, an election campaigner may wish to avoid posting specific details about times, locations or routes that they will be using in advance. 

Do not publish excessive personal details, such as email addresses, phone numbers, information about where you live, about your family or your hobbies and interests. Consider having separate accounts for your professional and private lives with appropriate security and privacy settings for each. 

Think carefully about accepting connections from people or organisations you are unfamiliar with. Even if you are not directly being targeted, you are potentially helping boost the credibility of a hostile actor's profile or cover organisation. 

Be wary of offers of paid consultancy work or paper writing based on your understanding of politics or electoral affairs, particularly if the organisation or individual is seeking to exploit your current or past access to government officials, politicians or other individuals or organisations of influence such as academics, think tanks or lobby groups. 

Understand the risks: consider whether the people you engage with, or have only just met, might have a hidden or malicious agenda. Look out for suspicious behaviour and any attempt by someone to gain influence with you. If in doubt report any concerns you have.

The Threat

Criminals and hostile actors are known to be using social and professional networking sites and social media platforms to approach UK nationals working in sensitive employment across government. They act dishonestly in an attempt to connect with people who have access to valuable information, physical locations of interest, or people in positions of influence.

Why are they doing this?

Their end goal is to recruit UK and Western nationals to provide them with sensitive information, willingly or unwittingly. In these cases, individuals may not recognise that the information they provide is sensitive (e.g. they may be asked seemingly benign questions). Malicious actors piece together information from multiple sources to draw meaning from their intelligence gathering. They may do this to advance their own decision-making, or to influence local or national policy decisions, or even to intensify divisive issues within the wider general public.

How are they doing this?

They often do this by posing as recruiters or talent agents who will approach you with enticing opportunities, when their real intent is to gather information. The consequences of engaging with these profiles can be damaging to your career, the interests of your organisation, and the interests of UK national security and prosperity. 

Typically, hostile actors and criminals reach out posing as an interested ‘employer’ or recruitment consultant presenting a unique business opportunity. They ask for further details about your background, try to “sell” the business opportunity, and insist on discussing it privately, often on different messaging apps. 

This kind of engagement is an attempt to understand the level of access you have to information, draw it out from you, and build a longer-term relationship. Often, the malicious aspect of this approach goes undetected; and the target believes they are providing information to develop a legitimate business opportunity.

How do I protect myself?

Read the full Think Before You Link guidance for comprehensive advice on how to deal with potentially malicious approaches online and make sure to download the the app for additional training material and reporting tools – App store and Google Play.

Think Before You Link 4Rs

The National Cyber Security Centre (NCSC), national technical authority for cyber security, have further advice and guidance on how to stay safe online, how to secure your social media accounts. You may also qualify as a high-risk individual.

Did you find this page useful?
helpfulness rating