Security leaders across governments and critical infrastructure are putting national security at risk by leaning on consumer messaging apps to conduct official business, according to new findings from BlackBerry.
The mobile maker turned security software provider’s latest report, The State of Secure Communications 2026, reveals a stark disconnect between how secure nationally important organisations believe their communications are and the risks they’re actually facing, fuelled by widespread misunderstanding of security basics.
Virtually all of the 700 security leaders BlackBerry polled from governments and CNI organisations across the UK, US, Canada and Singapore (98%) said they rely on foreign-hosted platforms not built for confidential communications or high-security environments, apps like WhatsApp or Signal.
The vast majority (83%) report using WhatsApp in particular for sensitive discussions inside their organisations – despite their intelligence agencies warning about state-backed attacks targeting the accounts of public officials.
Misplaced confidence is high, with the study finding 88% are certain of their current messaging app security, but far fewer understand what these platforms actually protect.
BlackBerry discovered critical gaps in encryption literacy among the very leaders responsible for safeguarding communications, with 52% mistakenly believing encryption protects metadata, including location data, IP addresses, and communication patterns, and 41% assuming their communications remain secure, even if a device has been compromised.
Perhaps worse, almost half (47%) believe that encryption prevents impersonation, deepfake, or spoofing attacks, a blind spot leaving officials wide open to the misuse of genAI.
This overreliance on consumer messaging apps is most visible when organisations are under pressure.
While 90% say they are confident in managing major incidents, fewer than half (49%) have a unified platform to coordinate response, forcing them to turn to a patchwork of everyday tools, from group chats (54%) and email threads (51%) to shared spreadsheets (29%) and phone trees (19%).
BlackBerry cautioned that, while such tools might be familiar, they were never designed for crisis coordination, and cannot deliver the real-time visibility, command and control or secure cross-agency communication that major incidents demand.
Recommended reading
- UK Ministers Sound Alarm Over “Superhacker” AIs
- AI and Geopolitical Tensions Accelerate Cyberwarfare Threats
- UK Business Leaders Struggling to Cope With AI and Cyber Threats
The firm said the findings point to a consistent pattern of security leaders in critical positions settling for a “secure enough” approach to keep up with growing risk.
That may be changing, however, with 55% of those polled now prioritising sovereign control of their communications, while 52% are growing increasingly concerned that telecom networks and foreign-controlled platforms could be monitored or disrupted.
“Consumer messaging apps were never designed to handle sensitive communications, protect confidentiality, or meet the demands of high-security environments,” said Christine Gadsby, chief security advisor at BlackBerry Secure Communications.
“They rely on phone numbers, not verified identities – and encryption protects the channel, not who is on it.
“That gap is already being exploited, as recent intelligence warnings show, and governments and critical infrastructure organisations are responding by moving toward communications infrastructure they own and trust.”





