Decide what needs protection

Start with the information being shared, the intended recipient, and the consequences of accidental disclosure. A routine event update may need no private details. A contact list or access record needs more careful handling. Remove unnecessary personal information before choosing a transmission method, and keep public announcements separate from protected records.

Distinguish the goals. Confidentiality concerns who can read a message. Checking the sender and detecting altered or outdated instructions address different problems. Delivery confirmation establishes that a recipient received something. A single label such as secure does not explain which of these needs a particular tool or process actually meets.

Understand what a code can do

A short agreed code can make a routine message concise. For example, a team might define a word meaning that a scheduled check-in was received. Record the exact meaning and context, and test that participants interpret it consistently. Use plain language whenever a code creates more confusion than it saves.

A simple substitution puzzle, hidden wording, or unfamiliar phrase should not be relied on to protect sensitive information. Knowing the code also does not prove who sent a message. Keep operational shorthand separate from confidentiality and sender-verification arrangements, especially when a message changes an important instruction or requests access.

Choose established protection and access arrangements

For confidential digital communication, use an established, maintained service appropriate to the task and follow its current instructions. CISA's mobile-communications guidance discusses end-to-end encrypted messaging. Understand what the chosen service protects, how recipients are identified, and what information may remain outside the protected message content.

Protect the devices and accounts involved, and plan authorized recovery using the service's supported process. For encrypted stored files, CISA emphasizes safeguarding recovery information. Losing required keys or passwords can prevent legitimate access. Do not invent a cryptographic system or keep recovery secrets in the same ordinary shared note used to explain the workflow.

Practice with harmless content

Suppose a small archive needs to send a restricted contact document to a newly authorized custodian. Before sending the real file, the participants confirm the recipient through their agreed trusted route and send a harmless test document. The recipient opens it and acknowledges the test identifier. No real contact details or access secrets belong in this rehearsal.

The participants then review how the file will be retained, who else may access it, and what happens if a device is replaced or access is lost. They follow the provider's recovery instructions without disrupting the live account. Record missing steps and resolve them before sensitive material depends on the process.

Keep messages clear and responsibility limited

Include an identifier, sender, date, intended recipient, requested action, and relevant expiry or replacement information in important operational messages. Verify unexpected requests through an established independent contact route rather than trusting a familiar display name alone. A recipient should be able to question an instruction without being pressured to act immediately.

For group conversations, review the participant list before posting a protected update. Agree who may add members and how departures are handled. If information was sent to an unintended recipient, tell the responsible coordinator promptly and follow the established response process; silently deleting your own copy does not resolve the disclosure.

Working alone, begin with a low-risk test and secure recovery arrangements. A community group should grant access according to responsibilities and update it when roles change. Encryption cannot control what an authorized recipient chooses to disclose or repair an unclear message. Review the whole process: necessary content, correct recipient, suitable protection, usable recovery, and a clear acknowledgment of what was received.