The Technology News Exchange (TechNX)
c/o Squall Inc.
P.O. Box 1484, Stn. B
Ottawa, Ontario, K1P 5P6

Companies not paying enough attention to security: BlackBerry survey

Gaps in knowledge around what encryption does, expert says

Christine Gadsby, chief security and AI advisor with BlackBerry. (Courtesy BlackBerry)

Many organizations are relying on external apps to communicate sensitive corporate information, and that’s causing potential headaches for security professionals.

But despite claims the programs are secure, the fact that they are also transmitting data that identifies the sender and its originating information — which is not secure — is not getting through to employees and organizations, according to a new survey by BlackBerry.

“We were watching this spinning storm happening, which is a lot of really important secrets and conversations and documents being shared over these free messaging apps,” Christine Gadsby, chief security and AI advisor with Waterloo-Ont.-based BlackBerry, said to TechNX in an interview.

“We thought, we should go ask some questions and see what everybody else is thinking,” she said.

“We were shocked by some of the results.”

"Disconnect" discovered among IT pros

In the survey of 700 security decision‑makers conducted in December 2025 and entitled The State of Secure Communications 2026, the company uncovered a “disconnect of security professionals really not having hard conversations, and as a practitioner myself for many years, sometimes those hard conversations to change the way you think, that’s difficult,” Gadsby said.

It included 175 responses from Canada, U.S., U.K. and Singapore.

The survey identified a gap in knowledge of exactly what apps such as WhatsApp do and how they work.

It found 83 per cent of respondents rely on WhatsApp for sensitive discussions, and the vast majority claim the apps are secured by encryption. However, “90 per cent of those same respondents don’t really understand what encryption actually protects,” Gadsby said.

To explain, Gadsby used the analogy of an armoured truck, with the cash inside being secured through encryption. “That locked box would represent the words that are in that message, but the armoured car is sitting on the street in plain view: the driver leaves at 8 a.m. every Wednesday and he makes the same trip to meet his colleague at noon and drop off the money. Everybody can see that.”

While the payload remains sacrosanct, everything else around it becomes vulnerable as the armoured truck travels through city streets.

“That encryption may help the message, the tiny bit of words, but it doesn’t do anything to protect the metadata: the person sending the message, their location, the time; all of those things are discoverable, and some of that information is actually sold.”

“Adversaries, they’re not breaking encryption anymore in messaging apps; they’re just bypassing it,” she said.

Encryption myths abound

The report showed there is a widespread misunderstanding of basic security concepts:

  • 52 per cent of respondents wrongly feel encryption protects location data, IP addresses and communication patterns;
  • 47 per cent mistakenly believe encryption blocks impersonation, such as deepfake or spoofing attacks; and
  • 41 per cent assume communications are secure even after a device (PC or mobile phone) has been compromised.

As well, the industry isn’t doing enough to stress-test communications protocols during a crisis, according to Gadsby. “There’s not a lot of threat modeling in the industry.”

When something happens, either a malware attack or a natural disaster that threatens communications systems such as mobile phone networks or the internet, companies are mistakenly relying on antiquated methods to manage the crisis.

“We’ve got 90 per cent confidence” that the organization has the capability to effectively handle a crisis, however, the reality is that only “49 per cent have capability in the critical-events management space that’s more exposed. Spreadsheets don’t scale. Phone trees don’t have accountability; group chats don’t have an audit trail,” Gadsby said.

Crisis management response planning

So, what should be done today to plug critical security holes?

“One of the biggest things for IT leaders across the board, they’re going to need to be able to bring together that crisis response internally and with agencies together quickly to coordinate.”

And don’t rely on old-fashioned tools to coordinate such a response. “Being able to have a critical-events management platform to check in and share critical exploits; that coordination right now for the most is happening with spreadsheets and email, and maybe ticketing systems, but nothing is coordinated instantly,” Gadsby said.



Industry Events