Resilience & Support

Defence is more than prohibition

This page sets out the defensive floor a society should field against psychological operations — and practical, grounded guidance for individuals who fear they may be in someone's sights. If that is you, start here.

01 · The Societal Floor

Four defences a society should field

Prohibition without capability is a plaque on a wall. Alongside the legal framework, a society needs standing defences, in place before any attack begins — the equivalent of public health infrastructure for the information environment.

Detection and monitoring

Detection should cover coordinated abuse aimed at individuals as well as disinformation aimed at whole populations. Platform teams, researchers, and civil-society organisations need ways to examine links between incidents, and to test whether apparent coordination has other explanations.

Victim support

People facing coordinated abuse need accessible routes to technical assistance, evidence preservation, and clinical support. Responses should take distress seriously while investigating its cause. The specialist organisations below provide starting points for different kinds of help.

Public inoculation

Prebunking exposes people to manipulation techniques in weakened form, before they meet them in earnest. The research, including Cambridge's Inoculation Science programme, finds that populations familiar with the techniques are measurably harder to manipulate with them. This matters doubly for decomposition, because bystanders are the weapon: a smear campaign works only if colleagues believe it, and a manufactured pile-on works only if real people join it. Manipulation literacy is armour for the community around every potential target.

Design safeguards

The capabilities that enable decomposition — profiling, synthetic media, persona automation — are mostly commercial products being used as designed, just not as intended. Design safeguards mean building AI systems so that misusing them for psychological targeting is harder to do, easier to detect, and costlier to attempt: provenance standards, abuse-pattern monitoring, and accountability engineered in rather than bolted on. Such safeguards fall under Element 5, Industry Accountability, of the Psychosecurity Framework.

AI assistants connected to a person's email, documents, and accounts carry a risk of their own: they act with whatever permissions they have been given. Useful safeguards include separate records of what an agent does, narrow access grants, and human approval for consequential changes. Monitoring should cover patterns as well as individual alerts, using evidence that can tell misuse from error. See the briefing on compromised AI assistants.

02 · For Individuals

If you believe you may be targeted

Some readers arrive at this site because something in their own life feels wrong. This section is for you, and it begins with honesty: distressing patterns can have ordinary explanations, such as coincidence, conflict, technical problems, or stress. A pattern alone does not establish that someone is targeting you. The steps below are worth taking either way, because they are good practice and because they replace rumination with method.

If you are in crisis: contact your local emergency services or a crisis line now — Samaritans 116 123 (UK & Ireland), 988 (US & Canada), or findahelpline.com anywhere in the world. Nothing on this page matters more than that.

1 · Take care of your mind first

If fear or uncertainty is affecting your sleep, relationships, or daily life, speak with a doctor or mental-health professional you trust. Describe what you have observed and how it is affecting you. You deserve support while the cause remains uncertain.

2 · Write things down at the time

Keep a brief, factual log of specific incidents: what occurred, when, and what evidence is available. Separate what you observed from what you think it might mean. Set limits on time spent documenting, and seek support if checking becomes consuming or increases distress.

If you use an AI assistant that can edit your files or email, keep a backup of important records somewhere it cannot alter or delete. That protects against mistakes as well as misuse. Choose a storage method that is safe for your circumstances.

3 · Preserve evidence properly

Screenshot abusive or suspicious material together with its URL, date, and account handle before reporting it (reporting often removes it). Save messages, emails with full headers, and voicemails. Do not edit or annotate originals; keep copies in two places. If content concerns you enough to consider legal action, ask a lawyer or one of the organisations below how to preserve it in a form a third party can verify.

4 · Secure your accounts and devices

Use unique passwords, two-factor authentication, and up-to-date devices. Check account-recovery settings and which devices are signed in. If an abusive person may be monitoring your devices or accounts, use a safer device to seek help before you change passwords or access settings: changes can alert them or destroy evidence. The Coalition Against Stalkerware recommends making a safety plan with a survivor-support service.

Review what connected assistants and plugins can read or change, including email, documents, and calendar entries. Remove unnecessary permissions when it is safe to do so. Unfamiliar activity does not always mean an intruder: configuration errors and automated features can cause it too. Ask a trusted technical adviser to help check specific events.

5 · Do not engage, and do not investigate alone

Responding to provocation supplies material and satisfaction to any real adversary, and deepens your distress whether or not one exists. Investigating alone, late at night, is corrosive whatever the truth. Work from your log, with other people, in daylight.

6 · Recruit a trusted second pair of eyes

Choose one or two people you trust and discuss the specific events with them. They can help test alternative explanations, identify evidence worth preserving, and decide whether technical, legal, or clinical support would be useful.

7 · Report through formal channels

Report platform abuse to platforms, threats and stalking to police (many jurisdictions' harassment and stalking statutes can apply to coordinated online campaigns), and press-freedom attacks to the organisations below. Bring the log and the preserved evidence; patterns persuade where anecdotes cannot.

What we can and cannot do. Psychosecurity.ai is a research and policy initiative. We cannot investigate individual cases, identify who is behind an attack, or provide emergency help. Be wary of anyone who guarantees they can identify an attacker or put things right without first examining the evidence. What we can do is work to build the norms, detection capacity, and support pathways this page describes, so that the next person has somewhere real to turn.

04 · For Institutions

Duty of care for exposed staff

Newsrooms, universities, research institutes, NGOs, and platforms employ many of the people most likely to be targeted: journalists, researchers, moderators, and public-facing experts. An institution that benefits from a person's public voice owes them a floor of protection when that voice draws fire:

  • A named pathway. Staff should know, before anything happens, exactly who to tell and what will happen next. Ad hoc responses arrive too late and vary with the manager.
  • Institutional evidence handling. Preservation, reporting, and liaison with platforms and police should be done by the institution, not left to the exhausted target.
  • Clinical support without career cost. Psychological support should be offered proactively, confidentially, and without consequence for the person's standing or assignments.
  • Public backing. Where a smear campaign targets an employee's integrity, institutional silence reads as confirmation. Measured, factual public support is protective.

Other questions this page raises are answered in the FAQ.