Why senior leaders keep trading secure channels for convenient ones, and what that habit costs.
The Three Tiers of Communication
Top leaders generally operate across three distinct tiers of communication:
- The Convenience Tier. Commercial apps like WhatsApp and Signal. In Panama and the broader region, WhatsApp is the unofficial infrastructure of government. The Varela Leaks proved that when a president uses a commercial app for state matters, they are operating without a safety net.
- The “Secure-ish” Tier. Platforms like Wickr or Threema. These provide better metadata protection but aren’t cleared for high-level secrets.
- The Classified Tier. A hardware-software ecosystem built on the NSA’s Commercial Solutions for Classified (CSfC) program. This tier doesn’t exist on a standard phone you can buy at the mall.
Hardened Hardware vs. Standard Devices
Leaders aren’t using “standard” iPhones. They use COTS (commercial off-the-shelf) devices that have been hardened.
In the US, this involves modified kernels — like Samsung Knox at its most restrictive — that can physically disconnect cameras or GPS. In our own region, the 2025 breach of President Claudia Sheinbaum’s phone in Mexico and our history with the Varela Leaks show that many leaders still use personal devices for professional secrets. Without a unified policy for device hardening, a leader’s phone is just a consumer product with a target on it.
The Encryption Gap: Nested vs. Single Protocol
There is a fundamental difference in how data is protected at the top:
- Commercial E2EE. Apps like Signal use the Signal Protocol. It is mathematically strong but offers only one layer. If the phone’s OS is compromised (via Pegasus or similar spyware), the encryption is bypassed before it even starts.
- Government-grade nested encryption. Under the CSfC framework, data is wrapped in two independent layers of encryption from two different vendors. If one algorithm is cracked or one vendor has a security flaw, the second layer keeps the data unreadable.
Auditing: Who Watches the Watchmen?
The US uses the NSA’s Communications Security Logistics Activity (CSLA) to audit leaders’ devices, following strict FIPS 140-3 standards.
In Panama, we are currently in a transition phase. As of 2026, the AIG (Autoridad Nacional para la Innovación Gubernamental) is launching a state-run Security Operations Center (SOC) to centralize the monitoring of government traffic. While our Personal Data Protection Law provides a framework, the actual technical auditing of a leader’s phone remains a gray area that is often only addressed after a leak occurs.
What This Means for You
The tech used by the elite is moving into the consumer space. In 2026, you should be looking for:
- Post-Quantum Cryptography (PQC). Apps using PQXDH are now essential to prevent “store now, decrypt later” attacks by quantum computers.
- Identity sovereignty. Moving away from phone numbers as identifiers to prevent SIM-swapping.
- On-premise control. More organizations are following the government’s lead by hosting their own private messaging instances (like Wire or Session) so that they, not a big tech company, own the server logs.
The Varela Leaks and Operation Rough Rider weren’t failures of technology; they were failures of discipline. As the tools for privacy become more accessible, the responsibility to use them correctly shifts to us.