The face of the moon was in shadow
Somebody in your organization has been asked to confirm that internal communications are secure. They are looking at a WhatsApp group with forty people in it, some of whom left the organization, and they are trying to work out what to write.
This article is for them.
What a security review is actually asking
Reviews vary, but the questions underneath them are consistent, and none of them is about encryption strength.
- Who has access to this system, and how do we know?
- How is access granted, and how is it removed?
- Where is the data, and under whose jurisdiction?
- How long is it kept, and who decided that?
- Can we produce records if we are required to?
- Who administers it, and who watches the administrators?
- How does it integrate with our identity and device management?
A consumer messaging app answers none of these, because it was not built to. That is not a defect in the app. It is a mismatch between the tool and the question.
Where the failures actually happen
Offboarding
The single most common finding. Someone leaves, their organizational accounts are disabled the same day, and they remain in six operational groups on a personal phone that nobody controls. There is no administrative action available that removes them, because there is no administrator.
Group membership
Nobody can produce a list of who is in which group, or who added them, or when. In a review that is not a minor gap. It means the organization cannot state who has seen its sensitive information.
Retention
Messages persist on individual devices according to individual habits. Some staff keep everything for years, others clear weekly. Neither is policy, and both are the organization's exposure.
Records and legal hold
If the organization is asked to preserve or produce communications relating to a matter, the honest answer is that it would have to ask individuals to search their own phones and trust the result.
Data location
Rarely knowable, frequently outside the jurisdiction the organization is answerable to, and not selectable.
Why banning it does not work
The standard response to these findings is a policy prohibiting consumer messaging for work. It fails, and it fails predictably.
Staff use consumer apps because they are fast, everybody already has them and they work on a poor connection. If the sanctioned alternative is slower or clumsier, people will use both, and the organization ends up with the same exposure plus a policy it is visibly not enforcing, which is worse in a review than having no policy at all.
The replacement has to be at least as good to use. That is not a soft requirement; it is the condition on which everything else depends.
What to do about the groups that already exist
Remediation is where these reviews usually stall, because the honest position is uncomfortable: the organization has years of operational conversation sitting on personal devices it does not control, and no way to retrieve or delete it.
You cannot fix the past. What you can do is stop it accumulating, and there is a sequence that works.
- Identify the groups that carry genuinely sensitive traffic. It is usually far fewer than people assume, operations, security, leadership, and anything touching beneficiaries or personnel
- Move those first, with a date after which the old group is not used for that class of conversation
- Leave the social and low-sensitivity groups alone. Fighting them costs goodwill and buys nothing
- Ask departing staff to leave work groups as part of the exit checklist. It is imperfect and it is better than nothing, and it costs a line in a form
An organization that has done those four things has a defensible answer, which is the realistic goal. A perfect answer is not available.
What a useful finding looks like
Reviews fail to change anything when findings are written abstractly. Compare two versions of the same finding.
Weak: 'Use of unmanaged messaging applications presents a data governance risk.' Nobody disagrees, nobody acts.
Strong: 'Three former staff members remain in the operations coordination group. The organization cannot remove them, cannot establish what they have seen since leaving, and cannot produce a record of the group's membership at any past date.'
The second is the same risk, stated so that it cannot be filed. It also points at the remedy without arguing for a particular product, which is the right way round.
Taking it to a board
Boards do not act on control gaps described in control language. They act on consequences they can picture.
Three framings tend to work. What we would say to a regulator or a major client who asked how we protect their information. What happens if a departing employee takes a group's contents to a competitor or a journalist. And what we would be able to produce if a matter went to dispute and we were asked for the communications.
None of those requires the board to understand encryption, and all of them are true.
If you are the person running the review
Three things make the exercise useful rather than performative.
- Write down what is actually used, not what policy says. The gap between those two is the finding.
- Test offboarding specifically. Pick someone who left three months ago and establish what they can still see. It is the fastest way to make an abstract risk concrete for a board.
- Frame the recommendation around control rather than encryption, because encryption is where the conversation goes to die. Everyone agrees encryption is good and nothing changes.
The outcome worth aiming for is not a more secure app. It is an organization that can state, with evidence, who could see what and when their access ended.


PLACEHOLDER
AGPO Certified 



