Organisations have spent years strengthening the security of their networks, cloud environments and endpoints. While those investments have been necessary and have helped improve resilience across the enterprise, one area that often receives less scrutiny is mobile communications.
That matters because mobile devices have become central to how organisations operate. Important decisions are made over calls and messages, teams coordinate activity across multiple locations, and sensitive information is routinely shared through mobile channels.
For governments, critical infrastructure operators and highly regulated organisations, this presents a clear security risk. Mobile communications are no longer a secondary channel, but they are part of day-to-day operations.
BlackBerry’s State of Secure Communications 2026 research highlights how common this has become. The research found that 83% of security leaders report WhatsApp is used for sensitive discussions within their organisation.
The issue is not that employees are deliberately ignoring security policy. In many cases, they are simply choosing tools that are accessible and easy to use. External partners may rely on different platforms, approved tools may not always be practical, and, during disruption, people often turn to the channels that help them communicate quickly.
As a result, mobile communications have become part of organisations’ operational reality, whether they were originally designed for that purpose or not.
Encryption Is Important, But It Is Not the Whole Story
Many security discussions about mobile communications begin and end with encryption. Encryption is undoubtedly important because it helps protect the contents of a message in transit. However, it should not be mistaken for a complete communications security strategy.
Our research found that 52% of security leaders believe encryption protects metadata, including location data, IP addresses and communication patterns. Forty-seven percent believe it prevents impersonation, deepfake or spoofing attacks, while 41% assume communications remain secure even after a device has been compromised.
These findings suggest that many organisations may be placing too much confidence in what encryption alone can provide.
Encryption does not verify identities, nor does it secure a compromised device. It also does not eliminate risks associated with phishing, impersonation or malicious access to communications platforms.
Looking beyond the messaging app
When assessing mobile communications systems organisations should look beyond whether a particular application is encrypted.
Security leaders need to consider the wider picture, including identity verification, account security, metadata exposure and the networks that support these services.
This applies equally to messaging and voice communications. Organisations often focus heavily on messaging applications while giving less consideration to voice communications, despite the fact that sensitive information is routinely discussed over the phone.
The goal should be to understand where sensitive conversations take place, how they are protected and what happens if a device or platform is compromised.
More importantly, organisations need to recognise that attackers do not necessarily need to break encryption to gain valuable intelligence. In many cases, it is easier to target the people and devices surrounding a conversation than the conversation itself.
An attacker who gains access to an account can impersonate a trusted contact. A compromised device can expose messages after they have been decrypted. Metadata can reveal communication patterns and operational activity, even when message content remains protected. These vulnerabilities sit outside the encrypted channel, but they can still have significant consequences.
For governments, critical infrastructure operators and other highly regulated organisations, understanding these exposures is becoming increasingly important as mobile communications play a larger role in everyday operations.
Mobile communications Need the Same Security Attention as Other Systems
For many organisations, mobile communications are now as important to daily operations as networks and business applications. Security teams should understand which channels employees and partners rely on, what risks are associated with those channels and whether the controls in place are appropriate for the sensitivity of the information being shared.
Encryption remains an important part of that conversation, but it is only one part.
A more complete approach requires organisations to think about identity, device security and how information is shared across different channels.
Organisations should understand which channels employees and external partners rely on, how access is controlled and what safeguards are in place if a device, account or service is compromised. They should also consider what information can be exposed through metadata, even when message content remains encrypted, and whether they have sufficient visibility into how sensitive information is being shared.
Mobile communications do not exist in isolation; they sit alongside identity systems, networks and the operational processes people depend on every day. Security is often determined as much by the people, accounts and devices involved as by the application itself.
Join our LinkedIn group Information Security Community!
