In a recent testimony before the House Intelligence Committee, Director of National Intelligence Tulsi Gabbard revealed that the encrypted messaging app Signal is now pre-installed on government devices. Gabbard highlighted guidance from the Cybersecurity and Infrastructure Security Agency, which recommends that government personnel use only end-to-end encrypted communications, naming Signal as a preferred application. This shift raises questions about the security of sensitive communications, especially after reports surfaced that top officials used Signal in planning a military strike. Historically, Signal has been largely unauthorized for government use, with officials previously warned of its vulnerabilities.
Speaking of CISA, enterprises are seeking alternative support for cybersecurity needs as the U.S. Cybersecurity and Infrastructure Security Agency downsizes. Experts, including former CISA executives, express concern that recent cuts, which reportedly affected over 130 positions, could compromise essential services like threat intelligence and incident response. With CISA’s personnel count previously at around 3,200, the 2025 budget overview indicates significant impacts. Experts recommend that businesses strengthen relationships with private security firms, which can provide vital resources and support that CISA may no longer fully offer. They emphasize the importance of investing in advanced threat intelligence and building internal capabilities to address the growing threat landscape effectively.
Oh, and speaking of that use of Signal for planning a military strike… U.S. National Security Adviser Michael Waltz reportedly used his Gmail account to discuss sensitive military positions and weapons systems related to an ongoing conflict. Although Waltz emphasized that he did not send classified information via the open account, emails have surfaced showing that he communicated technical details with colleagues from other government agencies using Gmail, while they used their government-issued accounts. The situation has drawn attention, especially after Waltz’s public Venmo account revealed information about numerous associates, including journalists and military officers.
Why do we care?
The pre-installation of Signal on government devices signals a shift towards prioritizing end-to-end encryption. That said, this isn’t about the technology. It’s about people using it properly.
The revelation that National Security Adviser Michael Waltz used Gmail to discuss military details highlights a glaring gap in cybersecurity training and protocol adherence among top officials. Even if no classified information was shared, the perception of lax security can harm public trust and raise questions about the government’s cybersecurity posture, as well as damage the entire industry if lawmakers can disregard the law. Listen to my detailed piece on Monday.
Providers should be aware they are going to have to fill the gaps left by CISA themselves.

