Budget-Friendly Secure Communications in Risky Locations
Practical Guidance for Small and Mid-Sized Organizations Operating in High-Risk Environments
If you run or support a small- to mid-sized commercial company, nonprofit, humanitarian organization, or faith-based group, you already know the reality: you rarely have a Global Security Operations Center, a dedicated CSO, or an intelligence analyst on staff. Yet the threats to your people and information do not shrink just because your budget does.
I spent two decades as a U.S. Army intelligence officer and later as a security consultant working with large enterprises (JPMorgan, Amazon, General Dynamics). For the last several years my focus has been the organizations that need the same caliber of protection without the Fortune 100 price tag. This post distills a recent briefing I gave on secure communications—the practical, low-cost measures that actually move the needle when you are operating in high-risk locations or handling sensitive work.
Nothing is 100% secure. The goal is to raise the cost and complexity of targeting you so high that most adversaries move on to softer targets. Here is how to do that frugally.
1. Start with Target Size — The Most Important Question
Before you buy a single app or device, answer this: Who are you, and why would someone target your communications?
Most breaches people experience are not sophisticated signals-intelligence operations. They are targets of opportunity—phones seized at customs, devices lost or stolen, or open Wi-Fi at a hotel. True targeted collection by a government or organized crime group is expensive and labor-intensive. It usually requires multiple sensors (physical surveillance, social media, human sources) in addition to any technical means.
Ask yourself:
What are you doing in that location, and with whom?
Are you the executive or the person with consistent access to the high-value individual?
Are you operating in a closed country, during an election period, or in a high-crime environment that has the infrastructure to support targeted collection?
How long will you be there? Longer presence creates more patterns of life.
What is your actual concern—and is it proportional to your target size?
Listen to your gut, but calibrate it. Thousands of Americans and Europeans travel to conflict zones for humanitarian work every year. Their phones are almost certainly logged; that does not mean each individual is being actively hunted.
2. Types of Secure Communications — What Actually Works
Three main categories matter for most of us:
Cell phones — Your daily driver and also the richest source of data an adversary can seize. Treat it as a sophisticated computer that happens to make calls.
Push-to-talk handhelds (walkie-talkies) — Useful for short-range team coordination on compounds or in convoys. Almost none offer true encryption.
Satellite communications — The most difficult network for most adversaries to access, but slow, expensive, and cumbersome. Reserve for true emergencies when cellular is unavailable.
3. Cell Phone Security — Low-Cost Habits That Matter
Modern phones ship with solid encryption, but settings drift and user habits defeat the technology.
Verify encryption is enabled (automatic on most iPhones; check manually on Android).
Use a strong passcode, not biometrics, when traveling. Forced biometric unlocks happen at checkpoints. A six-digit or alphanumeric code is harder to compel.
Log out of social media apps and clear App Store / Play Store history if you remove the apps. Leaving the apps installed but logged out is often safer than a “clean” phone that screams “I have something to hide.” Prefer browser-based access when possible.
Turn Bluetooth off unless you need it. Require authentication for pairing.
Use a reputable VPN (ExpressVPN or equivalent) on every public network—especially hotel Wi-Fi. Choose a server location that is not the country you are physically in.
Leave the phone outside sensitive meetings—even if powered off. Capabilities that were experimental 15 years ago are operational today.
Log out of password managers before crossing borders or entering high-risk environments. One compromised master password unlocks everything.
4. Messaging Apps — Ranked for Real-World Use
Signal remains my primary recommendation for sensitive work. Open-source, non-profit, audited, end-to-end encrypted, minimal metadata retention. Hosted on highly secure AWS infrastructure. Use it for text, voice, and video when the conversation matters.
Threema is excellent for internal organizational networks. One-time fee (currently around $3–5), no phone number or email required, Swiss servers, Bitcoin payment option. Functionality is lighter, but privacy posture is strong. Ideal when you control who is on the network.
Telegram — Use only for open-source information gathering (public channels). Secret chats are encrypted; group chats and channels are not. Servers in the UAE raise additional concerns. Do not conduct client or operational traffic here.
WhatsApp — End-to-end encryption exists, but metadata is rich, contact lists are required, and the parent company has a different privacy philosophy. Move any sensitive conversation to Signal immediately. “Let’s talk on Signal” is a professional habit worth building.
5. Walkie-Talkies and Satellite — Know the Limitations
Most consumer and even many “professional” push-to-talk radios rely on CTCSS/DCS tones (squelch), not encryption. Anyone with a scanner can listen. The only widely available true encryption option in this class is frequency-hopping spread spectrum (FHSS) radios from Motorola (legal on certain bands in the U.S.). Even then, stationary compound use creates an easy interception target.
Satellite phones (Iridium, Thuraya) sit on closed networks that are harder for most actors to access. They remain emergency-only tools: slow to connect, expensive per minute, and line-of-sight dependent. Keep one charged and tested. For most daily work, cellular + Signal is more practical.
Avoid Garmin inReach-style text-only devices for high-risk emergency coordination. Text can be spoofed or used under duress. You need voice verification of the person on the other end.
6. Common Tactics You Are More Likely to Encounter
Forced unlocks or device seizures at customs / checkpoints
Physical downloading of phones left in “secure bags” during meetings
SIM registration data collection by local providers
Metadata pattern-of-life analysis that triggers further attention
Opportunistic compromise of open hotel or café networks
True wiretaps and sustained SIGINT collection remain resource-intensive. Unless you are a high-value target with sustained access to sensitive information or people, the everyday physical and procedural risks dominate.
The Bottom Line for Resource-Constrained Organizations
You do not need a six-figure security stack to operate more safely. You need disciplined habits, a realistic assessment of your target size, and a short list of tools that actually raise the bar:
Signal for sensitive messaging
Threema for controlled internal networks
A quality VPN on every public connection
Passcodes instead of biometrics when traveling
Phone left outside the room for truly sensitive conversations
Clear understanding of where you are, who you are with, and why someone would care
These measures cost almost nothing yet close the majority of the gaps I see when I work with nonprofits, humanitarian teams, faith-based organizations, and mid-market companies that cannot afford—or simply do not need—enterprise-grade GSOC support.
Information security and physical security are inseparable. A compromised phone can undo months of careful operational planning. The reverse is also true: good physical practices protect the devices that hold your data.
Need a Tailored Assessment?
Morton Executive Decisions exists for exactly this audience—organizations that require professional-grade security and intelligence support without the overhead of a large corporate program. Whether you are planning travel into a higher-risk environment, reviewing your communications posture, or building practical protocols for your team, we work within realistic budgets.
If the content above resonates with the challenges you face, reach out. A short conversation is often enough to identify the highest-leverage improvements you can make with the resources you already have.
Pete Morton, CPP Founder, Morton Executive Decisions
Practical security for the organizations that keep the world moving—without a Fortune 100 budget.

