← All playbooks

Incident Playbook

Spyware & Surveillance

SIIRF-PB-06Devices and malwareTypical severity: CriticalVersion 1.0 · October 2026

Summary

There are signs that a phone or computer is being secretly monitored by spyware or stalkerware.

Category
Devices and malware
Typical severity
Critical
Response led by
Incident lead, with technical support and an external forensic expert

First 15 minutes

  1. Take threat notifications seriously.
  2. Stop using the device for sensitive conversations, and move to a clean device.
  3. Don't factory reset the device before it's examined: that destroys evidence.

1. Overview

Spyware secretly monitors a phone or computer. It ranges from commercial "stalkerware" installed by someone with access to the device, to advanced mercenary spyware sold to governments, which can read messages, record calls, turn on the microphone and camera, and track location.

2. How it happens

  • Malicious links sent by message, email or social media.
  • Fake or modified apps installed from outside official stores.
  • Someone with brief access to an unlocked phone installing monitoring software.
  • "Zero-click" attacks against high-risk people, which need no action from the target at all.
  • Network-level surveillance of unencrypted communications.

3. Indicators

Signs that this incident may be happening:

  • A threat notification from your phone or account provider saying you may be targeted.
  • Unfamiliar apps, profiles or device management settings.
  • Battery draining quickly or the device running hot when idle (though these have many innocent causes).
  • Someone appears to know things they could only have learned from your device.

4. Triage questions

Answer these first to understand scope and severity:

  1. What triggered the concern: a threat notification, unusual behaviour, or someone knowing private information?
  2. Whose device is it, and what is their role and risk level?
  3. Who has had physical access to the device?
  4. What sensitive conversations and contacts are on it?
  5. Could others in the network be targeted too?

5. Severity guide

Use your plan's severity levels. As a guide for this incident:

LevelTypical situation
LowVague concern with no specific indicators; checks find nothing.
MediumSuspicious app or profile found and removed; no evidence of data access.
HighStalkerware confirmed, or clear signs of compromise.
CriticalOfficial threat notification or confirmed mercenary spyware on a high-risk person's device.

6. Response steps

Work through these in order. Record every action, with the time and who did it, in your incident log.

  1. Take threat notifications seriously.
  2. Stop using the device for sensitive conversations, and move to a clean device.
  3. Don't factory reset the device before it's examined: that destroys evidence.
  4. Get a forensic check from a digital security expert.
  5. Think about which sources, contacts and colleagues may need warning.

7. Communication

Who to inform, and when:

  • Incident lead and an external forensic expert, using a clean device.
  • The device owner, with support: this can be very distressing.
  • Sources, contacts and colleagues who may be exposed, once advised by the expert.
  • Leadership, if organisational communications may be compromised.
  • Decide on any public disclosure only with expert and legal advice.

8. Evidence to preserve

Keep these before making changes, wherever it's safe to do so:

  • The device itself, unchanged and not factory reset.
  • Screenshots of any threat notifications, with dates.
  • A timeline of suspicious events.
  • Lists of installed apps and device management profiles.
  • Who has had physical access to the device, and when.

9. Recovery and review

  • Follow the expert's advice on cleaning or replacing the device.
  • Change passwords for accounts used on the device, from a clean device.
  • Review who and what may have been exposed, and support them.
  • Decide carefully, with expert advice, whether and when to go public.

10. Prevention checklist

  • Keep phones, computers and apps updated: most spyware relies on known flaws.
  • High-risk people should use the strongest protection modes their phones offer, such as Lockdown Mode on iPhones.
  • Only install apps from official stores, and review app permissions regularly.
  • Lock devices with a strong passcode, and never leave them unlocked and unattended.
  • Use end-to-end encrypted messaging for sensitive conversations.
  • Keep a separate, clean device for the most sensitive work.