Innovation

Closing the Security Gaps in Government Communications

Written by Fed Gov Today | Sep 18, 2026, 3:55:42 PM

Presented by LeapXpert & Carahsoft

Government agencies may possess advanced cybersecurity tools and still lack resilience if their policies do not reflect how employees actually communicate. Andrew Schmitt, Sales Director for Public Sector at LeapXpert, says agencies must balance security and governance with the usability people need to complete their missions, particularly during a crisis.

Speaking at the Billington Cybersecurity Summit 2026, Schmitt distinguishes between being well equipped and being resilient. An organization can purchase leading security platforms without fully understanding how its employees work or where they turn when approved systems become inconvenient or unavailable.

Cybersecurity therefore includes more than defending networks and devices. It also requires agencies to understand communication behavior, manage compliance and maintain access to practical tools.

The Challenge of Consumer Messaging

Employees increasingly use consumer messaging applications such as Signal and iMessage in their personal lives. Those platforms are familiar, fast and accessible, making them attractive for professional communication as well.

Government agencies have traditionally treated those applications as unmanaged channels. Messages may not be captured through official systems, retained according to records requirements or governed by agency security policies.

Blocking them can appear to solve the problem, but it may create another risk. Employees who believe they need a messaging application to complete their work may find an unauthorized workaround.

That behavior can move communications even further outside the agency’s visibility.

The challenge becomes particularly acute during an emergency. When normal systems are unavailable or coordination must happen quickly, people naturally use the fastest and most dependable channel they can reach.

If that channel is prohibited without a practical replacement, the agency may force employees to choose between following policy and completing the mission.

Balancing Protection and Usability

Schmitt says resilient agencies provide communication tools that employees can use effectively while ensuring those interactions remain secure and governed.

Usability is not a secondary convenience. It directly affects whether people follow security policies. A tool that is too complicated or poorly suited to the mission can encourage behavior that creates new vulnerabilities.

The objective is to bring the channels employees need into an environment where the agency can apply appropriate controls. That may include securing the communication, capturing required records and enforcing governance policies.

Agencies should begin by examining how employees, contractors and partner organizations communicate in practice. They can then compare that behavior with existing policies and determine where gaps exist.

Some activities may already comply with security requirements. Others may require additional controls or changes to policy.

The analysis should focus on outcomes rather than maintaining a process simply because it has always been used.

Updating Policies as Work Changes

Technology and employee behavior evolve faster than many government policies. A communication method that was unusual several years ago may now be a standard part of daily life.

Schmitt argues that “this is how we always do it” should not be the status quo. Agencies should continually evaluate whether their policies still support the mission and adequately address current risk.

That review does not mean weakening security to make work easier. It means finding a sustainable balance in which employees have an effective experience without moving communications beyond the agency’s control.

A policy that people routinely bypass is not providing meaningful protection. Agencies need safeguards that account for predictable human behavior.

Maintaining Human Oversight of AI

Artificial intelligence will add another dimension to government communications and cybersecurity. Employees already use AI tools in daily work, and those capabilities will become increasingly embedded within applications and platforms.

Schmitt says AI can provide substantial value, but human checks and balances must remain part of the process.

Agencies should understand when AI is generating, reviewing or distributing information and determine where a person must validate the result. That oversight is especially important when communication affects public policy, operational decisions or sensitive information.

The larger lesson applies to both messaging applications and AI: effective cybersecurity cannot be built solely around technology. It must consider how people behave, which tools they need and how policies operate under real-world conditions.

A resilient agency protects its mission while giving employees secure ways to communicate when those communications matter most.

Key Takeaways

  • Cyber resilience depends on understanding how employees actually communicate, especially during emergencies.
  • Blocking familiar messaging channels without providing usable alternatives can encourage insecure workarounds.
  • Agencies should continually update communication policies while preserving governance, security and human oversight.