Q4 2026 · Issue 03
Mobile messaging rules, logging mandates, and what it means for your agency this quarter.
Texting has become part of how government gets work done. Inspectors coordinate site visits by text, response teams share updates in group chats, and staff reach the public on the apps people actually answer. That's good for the mission, but it creates a problem most agencies haven't solved: under federal law, many of those messages are official records, and most agencies have no reliable way to keep them.
This issue is about closing that gap. Our feature article explains what the rules require and why neither banning apps nor ignoring them works. Our Partner Spotlight introduces LeapXpert, and our new In the News section rounds up the headlines behind this topic and the related push for better security logging. You'll also meet Jennifer Huber and see where we'll be through year-end.
The August Schell Team
Why the texts and chats your staff send every day may be federal records, and how to keep them without banning the apps.
Federal employees conduct official business on Signal, WhatsApp, iMessage, and ordinary text messages every day, often on phones the agency's IT team can't see into. If a message documents agency business, it's a federal record, no matter which app sent it or whose phone it was on.
Banning consumer apps doesn't stop their use. It pushes conversations onto personal phones, where nothing can be captured or produced. Ignoring the problem carries the same risk with no policy cover. The third path is to govern the channels your people already use: capture every message automatically, apply rules like sensitive-data blocking and retention in real time, and keep a tamper-evident record in one searchable place for FOIA, legal holds, and oversight.
Agencies are starting with field and inspection teams, emergency response, public outreach, and executive messaging.
Find out where your agency stands. Ask about a complimentary off-channel messaging risk assessment: info@augustschell.com
LeapXpert lets agencies keep the messaging apps their people prefer while the agency keeps control of the record. It works across SMS/RCS, iMessage, WhatsApp, Signal, Telegram, WeChat, and LINE. Employees keep the app experience they know, with no second app or work phone, or they can work from Microsoft Teams, Slack, or the Leap Work app.
LeapXpert brings the platform and support. August Schell brings the procurement path (quotes, licensing, and contract-vehicle alignment), and our Splunk practice puts captured message data to work in your security operations center (SOC). Getting started is simple: Assess → Pilot → Scale.
August Schell CIO Mike Baca and LeapXpert's Kannan Sundararajan break down what GRS 6.1 (Capstone), the Federal Records Act 20-day rule, OMB M-23-07, NARA Bulletin 2023-02, and FOIA actually require, and how agencies can govern Signal, WhatsApp, iMessage, and SMS/RCS instead of banning them. Includes a live platform demo and Q&A. Built for records management, FOIA offices, OGC, and CIO teams. Recording shared with all registrants.
Online · Microsoft Teams · 12:00 PM ET · 45 minutes
Register Now →The Defense Department's Inspector General found that messages in a Signal chat about military operations auto-deleted before they could be saved as records law requires.
FINRA fined a broker-dealer $750,000 for business texts it couldn't capture. The SEC's sweeps have wound down after more than $2 billion in penalties since 2021, but routine exams still catch violations.
Watchdog groups asked NARA to act on reports of disappearing-message Signal chats among senior officials, and an investigation opened at the Interior Department over alleged document shredding.
OMB Memo M-26-14 replaced M-21-31, shifting agencies from collecting logs to actively using them for monitoring and threat hunting — including on operational technology (OT) and IoT devices. CISA's Logging Reference Architecture published in August. Agency logging plans are due this fall. For most agencies, OT and IoT remain the biggest blind spot. August Schell and partners Trellix and Armis are addressing exactly this challenge in a November 19 webinar.
As Senior Digital Forensics Analyst, Jennifer Huber is dedicated to advancing cybersecurity, digital forensics, and incident response capabilities. Drawing on more than 10 years of experience supporting government and private-sector organizations, Jennifer has led complex digital forensic investigations and enterprise-scale incident response efforts involving endpoint and mobile device analysis, litigation support, and the protection of sensitive digital evidence.
Prior to joining the private sector, Jennifer served with the Department of Energy Office of the Chief Information Officer (DOE OCIO) in the Security and Compliance Office, where she supported federal oversight of the 24/7 Security Operations Center (SOC), incident response team, and foreign travel security programs. Her work helped strengthen security compliance, continuous monitoring, and cyber defense across the DOE enterprise and associated cloud environments.
Jennifer applies her technical expertise and investigative experience to help organizations better understand and respond to cyber threats. Her ability to bring together digital forensics, incident response, and cybersecurity strengthens our ability to solve complex problems and improve an organization's overall security posture.
From Honolulu to San Antonio, here's where August Schell will be through year-end. See the full 2026 calendar →
8 events this quarter, including 2 webinars, 3 conferences, 2 networking events, and 1 partner event.
Have questions or want to talk through anything in this issue? Our team is here.
Contact Us →