← Back to AugustSchell.com
October 2026

Federal Cybersecurity
Insights & Updates

Mobile messaging rules, logging mandates, and what it means for your agency this quarter.

Q4 2026  ·  Issue 03  ·  August Schell Enterprises

Welcome

Texting has become part of how government gets work done. Inspectors coordinate site visits by text, response teams share updates in group chats, and staff reach the public on the apps people actually answer. That's good for the mission, but it creates a problem most agencies haven't solved: under federal law, many of those messages are official records, and most agencies have no reliable way to keep them.

This issue is about closing that gap. Our feature article explains what the rules require and why neither banning apps nor ignoring them works. Our Partner Spotlight introduces LeapXpert, and our new In the News section rounds up the headlines behind this topic and the related push for better security logging. You'll also meet Jennifer Huber and see where we'll be through year-end.

The August Schell Team

Feature

Getting Mobile Messaging On the Record

Why the texts and chats your staff send every day may be federal records, and how to keep them without banning the apps.

Federal employees conduct official business on Signal, WhatsApp, iMessage, and ordinary text messages every day, often on phones the agency's IT team can't see into. If a message documents agency business, it's a federal record, no matter which app sent it or whose phone it was on.

What the Rules Say, in Plain Terms

Govern, Don't Ban

Banning consumer apps doesn't stop their use. It pushes conversations onto personal phones, where nothing can be captured or produced. Ignoring the problem carries the same risk with no policy cover. The third path is to govern the channels your people already use: capture every message automatically, apply rules like sensitive-data blocking and retention in real time, and keep a tamper-evident record in one searchable place for FOIA, legal holds, and oversight.

Agencies are starting with field and inspection teams, emergency response, public outreach, and executive messaging.

Four Questions to Ask Your Team

Find out where your agency stands. Ask about a complimentary off-channel messaging risk assessment: info@augustschell.com

Partner Spotlight

LeapXpert: Govern the Channels. Keep the Record.

LeapXpert

LeapXpert lets agencies keep the messaging apps their people prefer while the agency keeps control of the record. It works across SMS/RCS, iMessage, WhatsApp, Signal, Telegram, WeChat, and LINE. Employees keep the app experience they know, with no second app or work phone, or they can work from Microsoft Teams, Slack, or the Leap Work app.

ISO 27001 SOC 2 Type II FedRAMP In Process Gartner Magic Quadrant Visionary

Better Together

LeapXpert brings the platform and support. August Schell brings the procurement path (quotes, licensing, and contract-vehicle alignment), and our Splunk practice puts captured message data to work in your security operations center (SOC). Getting started is simple: Assess → Pilot → Scale.

Upcoming Webinar  ·  October 27

On the Record: Compliant Mobile Messaging for Federal Civilian Agencies

August Schell CIO Mike Baca and LeapXpert's Kannan Sundararajan break down what GRS 6.1 (Capstone), the Federal Records Act 20-day rule, OMB M-23-07, NARA Bulletin 2023-02, and FOIA actually require, and how agencies can govern Signal, WhatsApp, iMessage, and SMS/RCS instead of banning them. Includes a live platform demo and Q&A. Built for records management, FOIA offices, OGC, and CIO teams. Recording shared with all registrants.

Online  ·  Microsoft Teams  ·  12:00 PM ET  ·  45 minutes

Register Now →
In the News

What's Behind the Push for Better Records and Logging

December 2025
Official Signal messages weren't preserved

The Defense Department's Inspector General found that messages in a Signal chat about military operations auto-deleted before they could be saved as records law requires.

January 2026
Financial regulators still enforce texting rules

FINRA fined a broker-dealer $750,000 for business texts it couldn't capture. The SEC's sweeps have wound down after more than $2 billion in penalties since 2021, but routine exams still catch violations.

June – August 2026
Scrutiny continues in 2026

Watchdog groups asked NARA to act on reports of disappearing-message Signal chats among senior officials, and an investigation opened at the Interior Department over alleged document shredding.

Fall 2026
M-26-14 logging plans are due now — and most OT is still invisible

OMB Memo M-26-14 replaced M-21-31, shifting agencies from collecting logs to actively using them for monitoring and threat hunting — including on operational technology (OT) and IoT devices. CISA's Logging Reference Architecture published in August. Agency logging plans are due this fall. For most agencies, OT and IoT remain the biggest blind spot. August Schell and partners Trellix and Armis are addressing exactly this challenge in a November 19 webinar.

Employee Spotlight

Meet Jennifer Huber

Jennifer Huber
Senior Digital Forensics Analyst
Jennifer Huber

As Senior Digital Forensics Analyst, Jennifer Huber is dedicated to advancing cybersecurity, digital forensics, and incident response capabilities. Drawing on more than 10 years of experience supporting government and private-sector organizations, Jennifer has led complex digital forensic investigations and enterprise-scale incident response efforts involving endpoint and mobile device analysis, litigation support, and the protection of sensitive digital evidence.

Prior to joining the private sector, Jennifer served with the Department of Energy Office of the Chief Information Officer (DOE OCIO) in the Security and Compliance Office, where she supported federal oversight of the 24/7 Security Operations Center (SOC), incident response team, and foreign travel security programs. Her work helped strengthen security compliance, continuous monitoring, and cyber defense across the DOE enterprise and associated cloud environments.

Jennifer applies her technical expertise and investigative experience to help organizations better understand and respond to cyber threats. Her ability to bring together digital forensics, incident response, and cybersecurity strengthens our ability to solve complex problems and improve an organization's overall security posture.

Where to Find Us

Q4 2026 Events

From Honolulu to San Antonio, here's where August Schell will be through year-end. See the full 2026 calendar →

8 events this quarter, including 2 webinars, 3 conferences, 2 networking events, and 1 partner event.

Oct 27
Webinar
On the Record: Compliant Mobile Messaging for Federal Civilian Agencies
Online  ·  Microsoft Teams  ·  12:00 PM ET  ·  45 minutes
August Schell CIO Mike Baca and LeapXpert's Kannan Sundararajan break down what GRS 6.1, the Federal Records Act 20-day rule, OMB M-23-07, and FOIA actually require, and how agencies can govern Signal, WhatsApp, iMessage, and SMS/RCS. Live platform demo and Q&A.
Oct 27–29
Conference
AFCEA TechNet Indo-Pacific 2026
Honolulu, HI  ·  Booth #117
AFCEA International and AFCEA Hawaii's flagship Indo-Pacific event, bringing together industry, academia, and government to address regional challenges through emerging technologies.
Oct 27
Networking
Sips & Sunsets at TechNet Indo-Pacific
Moana Surfrider  ·  Waikīkī, Honolulu, HI  ·  5:00–7:30 PM HST
August Schell is hosting a sunset happy hour at the VIP Beach Club with Clairvoyant, Cribl, Dun & Bradstreet, Ivanti, and Trellix. Island bites, drinks, ocean views. About a mile from the Hilton Hawaiian Village. Registration required, space is limited.
Nov 3
Conference
LabTech – Berkeley Lab
Lawrence Berkeley National Laboratory  ·  Berkeley, CA
August Schell joins the Annual LabTech Symposium at Lawrence Berkeley National Laboratory, connecting with Lab technologists from Berkeley, Livermore, SLAC, UCB, and Stanford.
Nov 18
Partner Event
2026 AFCEA Bethesda EIE Summit
Westin DC Downtown  ·  Washington, DC  ·  9:30 AM–5:30 PM ET
AFCEA Bethesda's flagship Energy, Infrastructure & Environment Summit, a full day of federal leadership sessions on how agencies are modernizing energy, infrastructure, and environmental systems. August Schell is a Panel Session sponsor.
Nov 19
Webinar
Bridging IT and OT: Unified Asset Visibility for Defense Missions
Online  ·  1:00 PM ET
August Schell joins Armis, ServiceNow, and Trellix Endpoint for a live session on complete asset discovery across on-prem, cloud, and air-gapped environments, including real-time asset relationship mapping and fly-away kit deployment for distributed and disconnected missions.
Dec 3
Networking
EIE VIP Reception
Mastro's Steakhouse  ·  Washington, DC  ·  5:30–7:30 PM ET
An invitation-only reception closing out AFCEA Bethesda's EIE program year. August Schell will be there, an evening of conversation with federal energy and infrastructure leaders.
Dec 7–10
Conference
Alamo Cybersecurity Exposition (ACE) 2026
JW Marriott San Antonio Hill Country  ·  San Antonio, TX
AFCEA Alamo Chapter's nationally drawing cybersecurity exposition for the military cyber community, with acquisition and small business tracks, expert panels, and keynote speakers across multi-domain and ISR operations.

Stay Connected

Have questions or want to talk through anything in this issue? Our team is here.

Contact Us →