Collaboration / Source date:

Threema Work: Swiss Privacy for Enterprise Messaging

Threema Work brought Swiss-grade encrypted enterprise messaging to organizations that couldn't accept the surveillance risk of US-hosted messaging platforms.

Returned company phone and work-access review checklist at an illustrative custody station.

Two days ago, a consortium of news organisations began publishing the results of a forensic investigation into commercial spyware sold to governments: a leaked list of tens of thousands of phone numbers, technical analysis of infected handsets, and evidence of intrusions that required no action at all from the target — no link clicked, no attachment opened. The detail that should reshape how enterprises think about secure messaging is this: the intrusions defeated end-to-end encryption without breaking any of it. Messages were read on the device, after decryption, by software with the same privileges as the messaging app itself. Every cryptographic guarantee held perfectly and made no difference. This is an awkward week to be evaluating a Swiss messaging product, and also the best possible week for it, because it forces the buyer to be precise about what such a product actually provides. Encryption in transit is now a commodity; the consumer apps have had it for years. What differentiates enterprise messaging is metadata, jurisdiction and administrative control — and none of the three survives a compromised handset.

What "Swiss" buys, and what it does not

Operator jurisdiction is a real variable, and it is routinely oversold. What it changes is process. A provider established in Switzerland responds to Swiss legal process; authorities elsewhere must generally work through mutual legal assistance, which is slower, narrower, better documented and frequently refused. That friction has practical value for an organisation whose risk is civil discovery, commercial espionage through legal channels, or a foreign authority making a broad request about a business it does not otherwise regulate. What it does not change is the existence of lawful access. Switzerland has its own surveillance framework, and Swiss providers have spent years litigating exactly how far their obligations to retain and hand over data extend. A Swiss operator that is compelled by a Swiss court will comply. Anyone selling jurisdiction as immunity is selling something that does not exist. The honest formulation is that jurisdiction determines who can ask, how quickly, with how much scrutiny, and whether you are likely to find out.

Metadata is the actual difference

The more consequential design question is how much the operator knows in the first place. A mainstream encrypted messenger cannot read your messages and still knows a great deal: which number spoke to which number, at what time, how often, from which device, with which app version, in which country. That social graph is often more revealing than content — it identifies the deal team, the unannounced counterparty, the whistleblower and the lawyer without a single message being decrypted. The architecture worth paying for minimises what exists to be requested: identities that are randomly generated rather than tied to a phone number or email address, contact discovery that does not upload your address book in readable form, messages deleted from the server the moment they are delivered, and no retained log of who spoke to whom. Encryption protects what was said. Only architecture protects the fact that you spoke. This is the question to put to any vendor, in one sentence: if a court ordered you to produce everything you hold about this account, what would arrive?

The enterprise layer

The business edition of a secure messenger is not primarily about stronger cryptography. It is about administration, and administration is where most organisations are actually losing. What matters: provisioned identities that belong to the company rather than to an employee's personal number; central policy over whether media can be exported, backed up or forwarded; management through your existing mobile device management; an announcement channel for one-to-many operational communication; directory integration so people can find each other without exchanging numbers; and, critically, the ability to revoke an identity when somebody leaves. Against that, weigh a genuine tension. Ephemeral, minimal-retention design conflicts with record-keeping obligations. In regulated sectors, business communications are records whether or not they were sent from a phone, and a platform built to forget is a platform that cannot produce what a regulator asks for. Decide deliberately which conversations must be retained, put those on a system built to retain them, and do not let the messaging choice make the records decision by default.

After this week, assume the endpoint

No messaging product defends against a compromised phone. What reduces exposure is mundane: keep mobile operating systems current and install security updates within days rather than months; restart devices periodically, since much implant persistence is more fragile than the initial infection; issue separate, minimally provisioned devices to the handful of individuals genuinely at elevated risk; and reduce what a compromised device is worth by ensuring the phone is not the system of record for anything important. That last point is the one leaders can act on immediately, and it has nothing to do with which app you buy.

Questions around a secure work conversationArticle-derived questions, not verified Threema capabilities or security/legal assurances.
AreaQuestion
ContentWhat happens if an endpoint is compromised?
MetadataWho holds communication records and under which jurisdiction?
IdentityHow is work access removed when people leave?
RetentionWhich conversations need a retained business record?

Qualitative summary of this article's source text, not a measured outcome or performance estimate.

Practical Guidance for Secure Messaging Strategy Consultation

  • Classify conversations into three tiers — informal coordination, operational decisions that must land in a system of record, and confidential material that should not be on a phone at all — and write the rule for each.
  • Ask every vendor what they would produce under legal compulsion, and compare answers rather than marketing claims about encryption.
  • Separate work identity from personal phone number so that departures, device changes and contractor turnover are administrative events rather than losses.
  • Decide the retention position explicitly, especially in regulated activities, before the platform decides it for you.
  • Accept a two-channel reality: a controlled channel internally, the counterparty's channel externally, with a clear rule about what may be discussed outside your own platform.
  • Deploy against a removed use case. Every new app that does not displace an old one simply adds a place where information hides.
  • Harden the endpoint with enforced OS updates, managed devices for sensitive roles, and a short list of people who get separate hardware.
  • Rehearse the leaver process, including group membership, device wipe scope and the counterparties who only know that person's number.

The Regional Angle

Three things determine whether this works in a Gulf organisation, and none of them is cryptographic. The first is population segmentation and price. A per-seat secure messenger for an entire workforce is not a realistic purchase for a regional group where several thousand people are site staff, drivers, technicians and retail crew on personal low-cost handsets, on prepaid data, already coordinating through the free consumer app that came with the phone and works on a weak connection. Trying to standardise everyone onto a paid product fails on cost and on adoption at the same time. The workable architecture is tiered: identify the five to ten per cent of the organisation that actually handles confidential commercial, financial, legal or personal-data conversations — leadership, finance, HR, legal, deal teams, key account managers — and buy properly for them. For everyone else, the deliverable is not a product but a rule: what may never be sent through a consumer channel, in the working language of the floor, communicated by supervisors rather than by policy document. The second is that this region runs on personally owned devices with company data on them, and the exit process is broken almost everywhere. The company pays the bill, the SIM may be in the company's name, the handset belongs to the employee, and the customer relationships, the pricing conversations and the photographs of documents live in group chats on that handset. When the person leaves — and in a visa-linked workforce, departures can be fast and final — there is no mechanism to retrieve any of it and no realistic legal route to wipe a personal phone. A managed work identity that can be revoked centrally, with company content confined to a container that can be removed without touching the employee's personal data, is the single strongest argument for the enterprise edition of any secure messenger in this market. It is also becoming a compliance argument rather than a hygiene one, with data protection regimes now in force in the financial free zones and in several Gulf jurisdictions, and national laws in preparation elsewhere: customer personal data sitting in an ex-employee's personal chat history is an exposure that was invisible three years ago and will not stay invisible. The third is threat model realism, and this week has made it concrete. The reporting names several governments, including two in this region, among the customers of the spyware vendor. Whatever view one takes of the investigation, the procurement implication is straightforward: for executives in this market, device-level compromise is a scenario to plan for rather than a hypothetical borrowed from elsewhere, and the appropriate response is device discipline for a named handful of people rather than a platform migration for everyone. Add one practical constraint for groups operating across several countries: the availability of a messenger's voice and video calling varies by jurisdiction here and has changed more than once. Standardise on the platform for messaging, keep calling on channels that are permitted everywhere you operate, and confirm function-by-function availability in each country before you promise a single global rollout.

The objection worth taking seriously

The strongest objection is that this is jurisdictional theatre. Your counterparties will not install your Swiss app; the endpoint is the weak point, as this week demonstrates in the most vivid possible way; Switzerland has surveillance law of its own; and the practical difference between a mainstream encrypted messenger and a privacy-maximising one is close to zero against any adversary capable of causing you real harm. Meanwhile the disruption is certain: two apps, fragmented history, people defaulting back to the channel their customers use. If the deployment is conceived as a swap — same behaviour, different logo — that objection wins outright, and the money would be better spent on mobile device management and update enforcement. The case for doing it anyway rests on a different threat model, and a more common one. The realistic loss for most organisations is not a state implant. It is commercial information accumulating for years in a consumer service the company does not administer, on devices it does not control, in groups nobody curates, unrecoverable when a key salesperson resigns on Thursday, unproducible when a regulator or a court asks, and uncontainable when a phone is lost. Custody, administration, revocation and metadata minimisation address that, and they do so regardless of how sophisticated the adversary is. Jurisdiction is a secondary benefit that costs nothing extra once you have decided to buy administration. Buy it for the boring reasons and the privacy properties come free; buy it for the privacy claims alone and you will be disappointed by August.

Common Questions

Is a mainstream encrypted messenger good enough?

For confidentiality of content against most adversaries, generally yes. For metadata, administrative control, revocation and records, generally no — and those are the properties an enterprise buyer is actually short of.

How do we handle external parties who will not change apps?

Do not fight it. Define what may be said on external channels, move decisions and documents into systems of record promptly, and reserve the controlled channel for internal and genuinely sensitive exchanges.

Does self-hosting improve this?

It changes who holds the metadata to you, which is a real gain if you can operate it securely. It also transfers availability, patching and key management responsibilities to a team that may be smaller than the vendor's. Choose deliberately rather than reflexively.

What should we expect over the next twelve months?

Expect this week's disclosures to keep expanding — more forensic findings, parliamentary inquiries in several countries, and a serious possibility of export controls or sanctions against commercial spyware vendors within the year. Expect the encryption debate in Europe to harden rather than settle, with proposals to scan content on the device itself gaining ground as the workaround to end-to-end encryption; that fight will move from the network to the handset. Expect more European public-sector and defence adoption of Swiss and self-hosted messengers, which will pull enterprise procurement along behind it. Expect mobile operating system vendors to ship stronger hardening options for high-risk users. And expect financial regulators to start enforcing record-keeping obligations against messaging apps in earnest, which will make the retention question the most expensive part of this decision.


Secure Messaging Strategy Consultation — we classify your conversations, size the population that genuinely needs a controlled channel, and design a rollout that removes a use case instead of adding an app.

Continue reading

Talk to OPS

Start with the operating problem.