Political Security · Australia

Secure phones for Australian politicians — communications security done properly.

Politicians hold sensitive information, communicate with constituents and colleagues on matters of consequence, and operate in an environment where both foreign intelligence services and domestic actors actively seek to compromise their communications. This guide explains the practical steps to take.

The political threat model

Australian politicians face a distinct combination of threats: foreign state-sponsored espionage (ASIO has repeatedly warned of foreign interference campaigns targeting political figures), opposition research operations, media scrutiny, and opportunistic targeting via public Wi-Fi and compromised devices at conferences and travel destinations. A stock iPhone or Android phone was not designed to defend against any of these.

Why politicians are a high-value target

The information that flows through a politician's phone is disproportionately valuable to a wide range of actors. Legislative priorities before they are announced, coalition negotiations, committee deliberations, constituent disclosures, and internal party communications are all commercially, politically, and strategically significant. Foreign intelligence services operate active programs targeting political figures in Australia — the Australian Security Intelligence Organisation (ASIO) has been explicit about this in its public annual reports.

The threat is not hypothetical. The Australian Parliament House network was compromised in 2019 in an intrusion attributed to a foreign state actor. Australian political parties have been targeted by sophisticated phishing campaigns. Individual politicians and their staff have had accounts compromised through credential theft, SIM swapping, and malware delivered via seemingly legitimate apps.

At the same time, the legal and professional requirements of political office create constraints: politicians need to remain reachable, need to use standard government systems for much of their work, and cannot disappear behind a completely isolated device. The goal is not invisibility — it is appropriate separation of what should be private from what is legitimately public.

The specific risks for political communications

Foreign intelligence targeting

State-sponsored actors from multiple countries run active programs targeting Australian political figures. Spearphishing, watering-hole attacks, and malicious apps disguised as legitimate tools are common delivery mechanisms. A hardened operating system significantly raises the bar for these attacks.

SIM swapping

Attackers convince a carrier to transfer your phone number to their SIM card, giving them access to SMS-based two-factor authentication and the ability to impersonate you. Using a separate, non-public SIM for a secure device removes this exposure entirely.

Public Wi-Fi interception

Parliamentary buildings, hotels, airports, and conference venues — the regular locations for political activity — are environments where network interception is plausible. Always-on VPN with a kill-switch prevents any unprotected traffic from leaving the device.

Staff and associate compromise

A politician's communications security is only as strong as the weakest link in their regular contact network. Staff using compromised devices or insecure messaging apps can expose the politician's communications even when the politician's own device is well-configured.

Physical device access

Devices left unattended at events, handed to repair technicians, or surrendered at border crossings can have malware installed or data extracted. Encrypted devices with short auto-lock intervals and proper before-first-unlock protection make physical access far less valuable.

Cloud account compromise

Most stock phones back up to Apple iCloud or Google accounts. A compromised cloud account gives an attacker access to messages, photos, call history, and location data going back years. Removing cloud backup dependency is one of the most impactful changes available.

What a secure political phone looks like

A properly secured device for a politician combines several layers that, together, provide meaningful protection without making the device unusable for professional work.

GrapheneOS — the hardened operating system

GrapheneOS is an open-source operating system for Google Pixel phones that removes all Google services from the base OS, hardens the kernel and memory allocation, enables per-app permission controls, and relocks verified boot to GrapheneOS's own keys. This is the foundation. Without a hardened OS, application-layer security measures can be undermined by the operating system itself.

Critically for political use, GrapheneOS supports multiple fully isolated user profiles. A politician can maintain a work profile, a personal profile, and a public-facing profile — each entirely separate from the others at the OS level. A compromise of one profile cannot spread to another. Sensitive legislative work and personal communications never share storage or memory space with apps that may have broader internet access.

Encrypted messaging — Signal and Threema

Signal provides end-to-end encrypted calls and messages with minimal metadata retention. For communications where even the contact's phone number should not be recorded, Threema provides fully anonymous messaging with no phone number required. Both are configured on Privacy Devices prepared phones with recommended settings: disappearing messages, screen security, and network protection active.

For communications between politician and staff, a shared Threema group or Signal group removes all metadata from the conversation thread that would exist if the same conversation occurred on WhatsApp, standard SMS, or email.

Always-on VPN and network protection

A Mullvad VPN subscription with kill-switch enforced ensures that all traffic from the device leaves via an encrypted tunnel, regardless of which network the device is connected to. This prevents interception at public Wi-Fi access points and prevents the carrier from recording DNS queries and browsing metadata. The kill-switch means the device will not connect to any network without the VPN active — there is no window during which unprotected traffic could leak.

Private eSIM and SIM configuration

A global eSIM provides a separate data connection that is not linked to the politician's primary identity or phone number. For travel — particularly to countries with more aggressive interception capabilities — using a data-only eSIM over VPN means the device's network activity cannot be correlated to the politician's identity by the local carrier or authorities.

Phantom Protocol — duress and remote wipe

The Phantom Protocol adds an owner-controlled duress layer: a secondary PIN that triggers a silent wipe of sensitive profiles, an auto-reboot interval that ensures the device is always in a before-first-unlock encrypted state after a set period of inactivity, and remote wipe capability via a trusted contact. For a politician at a border crossing, at an overseas conference, or in a situation where device access is being demanded, this layer provides meaningful protection without requiring any visible action.

What to keep on a standard phone and what to move

Communication typeKeep on standard phone?Move to secure device
Public constituent enquiriesYes — expected to be on recordNo
Media enquiriesYes — if on the recordNo
Coalition or party negotiationsNoYes — Signal or Threema
Whistleblower or source contactNoYes — Threema preferred
Legal privilege communicationsNoYes — Signal or Threema
Pre-announcement policy discussionsNoYes — secure device
Personal and family communicationsSituationalSignal at minimum
Government system accessVia official government deviceNot on personal secure device

The two-device model

Most politicians who take communications security seriously operate on a two-device model: a standard phone (often a government-issued device or a standard iPhone) for public-facing, on-the-record communications and government system access, and a separate secure phone for sensitive political and personal communications.

This separation is important for several reasons. It prevents the secure device from being required for constituency work that should be accessible and auditable. It prevents cross-contamination — an app on the public phone that is compromised cannot access data on the secure phone. And it provides a clear operational principle: anything that would be embarrassing or harmful if disclosed goes on the secure device.

The secure device should have a different SIM or eSIM (not linked to the same account as the public phone), a different Apple ID or Google account (or none at all, in the case of GrapheneOS), and should not be associated with the politician's public identity in any easily searchable way.

Staff communications security

A politician's phone is only as secure as the communications practices of their immediate staff. A chief of staff using WhatsApp for sensitive internal discussions exposes the politician's position regardless of how well the politician's own device is configured. Implementing a communications security standard for core staff — at minimum, Signal for sensitive discussions — is a practical step that is far easier to implement than a full device upgrade for every staff member.

For offices that want to go further, we offer Enterprise Fleet Deployment — a service that extends GrapheneOS deployment and communications configuration to a group of staff devices, with a unified standard applied consistently across the office.

Travel security for politicians

International travel represents a specific uplift in risk. Countries with active foreign intelligence programs — which includes a significant proportion of conference and diplomatic travel destinations — represent an environment where standard Australian threat assumptions do not apply. For international travel:

See our full guide on executive travel phone security and our border crossing phone preparation guide for detailed protocols.

Politicians secure phone — FAQ

Are secure phones legal for politicians in Australia?

Yes, absolutely. There is no legal restriction on politicians using encrypted phones, end-to-end encrypted messaging apps, or privacy-hardened operating systems in Australia. These are standard communications security tools used by business executives, legal professionals, and journalists. Encrypted phones are not the same as burner phones — they are professionally configured security devices.

What messaging app should Australian politicians use?

Signal is the widely recommended choice for secure communications among political figures globally. It is end-to-end encrypted, collects minimal metadata, and has demonstrated in court that it has virtually nothing to hand over to law enforcement when asked. For communications where even Signal's knowledge of your phone number is a concern, Threema provides fully anonymous messaging with no phone number registration.

Should politicians use a government-issued phone or a personal secure phone?

Government-issued phones are appropriate for official government business and should be used for those purposes. However, sensitive political communications — coalition negotiations, source contact, personal legal matters — should not necessarily go through a government-managed device where IT staff or government IT policy may affect what is stored and accessible. A personal secure phone provides a layer that a government device cannot.

What is the biggest phone security risk for Australian politicians?

ASIO has consistently identified foreign state-sponsored interference as the leading digital threat to Australian political figures. Beyond that, SIM swapping (carrier-level account takeover), cloud account compromise, and physical device access at conferences and events are the most common attack vectors. A hardened device addresses multiple layers simultaneously.

Can politicians take a secure phone to international conferences?

Yes, and they should. International conference venues — particularly in countries with active foreign intelligence programs — are high-risk environments for standard phones. A properly configured device with GrapheneOS, always-on VPN, a global eSIM, and Phantom Protocol provides meaningful protection in environments where a stock iPhone or Android would not.

What device do you recommend for a politician?

The Pixel 10 Pro Secure Edition is the flagship recommendation. It combines a compact, professional form factor with the Titan M2 secure element and full GrapheneOS compatibility. The Pixel 10 Pro XL or Pixel 10 Fold Pro suit politicians who prefer a larger screen for reading documents on the move. All are prepared with our full configuration and Phantom Protocol before dispatch.

Secure communications for political office.

Fully prepared, discreetly shipped, operational from day one. Consultation available for groups and offices.

Browse Secure Devices → Arrange a Briefing