How to Build a Personal Security Team
Kill the lone wolf. That solitary operator grinding alone in a hardened bunker is quietly sabotaging your opsec. Isolation breeds mistakes. No one catches your slip, no one audits your setup, and burnout is when protocols get skipped. A single operator has no cross-coverage, no redundancy, no early warning. Worse, mentally isolating yourself from the people around you trains them to treat your security as your weird hobby — so they casually photograph you, tag you, and mention your plans without a second thought. Your friends and family are your single largest attack surface, and the only way to control that surface is to train the people who operate on it. The fix isn’t higher walls. Stop managing your circle as a liability. Recruit them and build a personal security team where everyone benefits.
Phase 1: Selection and Vetting — The Recruitment Drill
Identify one or two trusted confederates outside the candidate pool. Their devices follow the same baseline standards — otherwise your verifier becomes the breach.
Test One — The Tool Migration. Give them one tool to install within 24 hours. Session or Briar for encrypted messaging, since neither requires phone-number identification the way Signal does. Written instructions included. Verification is direct. Message them on the new tool and confirm the fingerprint in person or by voice call. Done on time, done late, or ignored. Someone who won’t switch one app today will not scrub metadata tomorrow. This test runs first deliberately — now the candidate has a real encrypted channel, and the probes that follow ride on it.
Test Two — The Social Pressure Probe. You cannot watch a group conversation without contaminating it, so stage it. Float a sensitive topic with a canary baked in — a detail unique to this conversation, oddly specific, like “the Tuesday appointment with the specialist.” Later, a confederate probes about it directly. If that detail comes back to you through anyone else, you know what leaked and where it traveled. The question isn’t loyalty. It’s whether they can hold a line when the room pushes them to talk.
![]()
Test Three — The Black Box Drill. Send each candidate a document marked with a detail unique to them — a different date, a different room number, a differently-named file. That’s your canary. If it surfaces, the version that surfaced names the source. Instructions: do not forward, do not screenshot, this stays internal. Three detection nets run for 48 hours. Passive nets — search the canary phrase on the major engines and any platform the candidate uses. Active nets — your confederates, primed on which detail to listen for. Behavioral nets — leaked information rarely reappears as a forwarded file. It reappears as a dinner-table “so I heard.”
The Why Conversation and Briefing. Sit down and explain the threat model — not “it’s safer,” but what actually breaks and when. Dismissal is disqualification. Candidates who pass get the contract, spoken plainly. You’re part of a unit now, and the unit has rules. No unencrypted comms for sensitive topics. Photos get scrubbed. We correct each other without judgment. Then give them the out, explicitly, and cash the everyone-benefits promise here: they get hardened devices, better scam resistance, and people who watch their back the same way they watch yours. Assign rotating roles — Comms Lead, OpSec Watch, Debrief Lead — monthly.
One caveat stated up front: a 48-hour clean result is probative, not proof. That’s why the drills keep retesting, and why the canary logic ports everywhere — cover stories, red team injections, breach forensics. Vary the details, trace the leak.
Phase 2: The Qualification Ladder
Rung Zero — Threat Model and Compartments. No tool gets installed until the recruit has walked through two threat models — their own and the group’s. Four questions on paper. What am I protecting? Who wants it? What happens if they get it? How likely is each adversary, honestly? Then the group’s collective risk — your risk becomes theirs the moment they join, and if they’re not comfortable absorbing that, this is the exit and it costs nothing.
Then compartmentalization, before any tool. There is no universal map — the compartments follow the life. An employed person with a side hustle separates employer, hustle clients, and personal at minimum. A retiree with a volunteer role walls the charity roster and donation systems off from family and medical life just as firmly. Care giving, dating after divorce, a health condition — any sphere where cross-referencing would embarrass you or cost you something becomes a compartment. Most people land on three to five. The map itself is sensitive — it stays on paper or in their own encrypted volume, never shared with the group. Exit condition: the recruit presents the map and can answer any question about it from memory.
Rung One — Solo Hardening, weeks one through four. One layer per week. The phone — approved OS, verified boot, no vendor telemetry, checked physically by another member. The desktop — hardened Linux with full disk encryption via LUKS, keys stored offline; exit check is a recovery-boot attempt that fails without the key. The browser and authenticator — script blocking defaults, fingerprint consistency across three sessions, hardware security key enrolled on all critical accounts, SMS 2FA retired permanently. The channels and storage — fingerprints verified face-to-face, sensitive material on the encrypted volume, and a red team phishing attempt plus a metadata-laden file the recruit must flag. Graduation is brutal on purpose — another member replicates your setup from your notes alone. If they can’t, your documentation is the failure.
Rung Two — Pair Operations, weeks five through eight. Synchronized metadata scrubbing with hash comparison. Secure handoff with the key traveling a separate channel while a third member audits that key and payload never crossed paths. Comms shifting within sixty seconds of a channel dropping. Exit test: the Blind Handoff, timed, zero leakage.
Rung Three — Stress Conditions, weeks nine through twelve. Simulated interrogation of the cover story. Forced error injection with containment. Breach alerts mid-task, response inside sixty seconds. Exit test: the Compromise Response drill, measured on response time and accuracy. Both, or repeat.
Rung Four — Deployment, week thirteen onward. Rotating role, real coordinated activity, monthly after-action reviews. Progression is merit-based forever. Trust is renewable, never permanent.
Phase 3: Drills and Cross-Coverage
Be honest about the adversary. We aren’t training spies. The threat is the employer who scans Slack logs, the data broker aggregating footprints, the landlord recording entry times, the app reporting location to advertisers, the volunteer coordinator sharing rosters, the officer requesting cloud backups. Every drill simulates one of those vectors with four elements — objective, setup, execution, success metric — and every drill ends with an AAR (after Action Review) within twenty-four hours.
The library covers ten scenarios — the accidental geotag, the compromised device, the coordinated data broker removal campaign (quarterly, with receipts — this is work, not one-time setup), the workplace probe, the missing comms check, the vendor data request, the social engineer, the physical tail, the breach injection with member-specific canaries planted in the material, and the total blackout run on dead drops and physical meetups. Full step-by-step procedures are in the toolkit zip file below.
Cross-coverage runs on three protocols. The Watch Protocol — before any coordinated action, assign watch domains: one person on location tags, one on metadata, one on screenshots. Slips get the code word, silently corrected later. The AAR — shame-free, technically neutral correction. “That image had GPS data. Let’s scrub next time.” Track patterns, not individuals. The Two-Person Rule — sensitive files, location confirmations, and password changes require dual authorization, implemented as split-key or confirmation chains, so a single compromised member cannot unlock the system alone.
Phase 4: Breach Response and Offboarding
Minutes zero to five — contain. Panic code on the core channel, implicated channels go silent, suspect devices go dark. Contain first, investigate second.
Five to sixty — triage. All member statuses confirmed. Credentials rotated on clean devices only — never on the device you suspect.
Within two hours — the triage call, by voice. What leaked, how, and what the canary says. The member-specific detail in the leaked material names the source.
Forty-eight hours on alert, scaled to severity. A leaked restaurant geotag and a compromised password vault are not the same event; the SOP includes a three-tier severity rubric so nobody over-reacts — overreaction burns members out faster than breaches do. Then the AAR patches the SOP. A breach that produces no SOP change will repeat.
The removal matrix is decided while calm and applied while not. Three unintentional slips — training. One intentional breach — immediate off-boarding. Reckless compromise — investigation first. Refusal to train — off-boarding, because the probation terms were explicit.
Offboarding is a procedure, not a grudge. Within 24 hours — credentials rotated, shared passwords changed, core access revoked, wipes confirmed. At the same time — the departing member gets help securing their own systems. Send them off stronger than they arrived. A sloppily off-boarded ex-member is a threat vector who resents you. A well off-boarded one is an ally outside the perimeter, and friendship continues with boundaries.
Get Moving
Select your three to five candidates this week. Run the tool migration test. Book the threat-model conversation. Don’t wait for a crisis to build the unit you’ll need during one.
The lone wolf is dead. Long live the squad.
Personal Security Team Playbook (Zip)
Disclaimer:
This article is for individuals at higher risk or in places that have repressive governments. It is intended to augment freedoms that we all hold dear. I do not advocate anything illegal or immoral be done with this knowledge. Be safe out there. Find More Guerilla Privacy Articles.