For many crisis managers, WhatsApp has long occupied an awkward position in incident communications. It is ubiquitous, fast, and intuitive – yet often viewed as insecure, informal, and risky. As a result, organizations have frequently discouraged or prohibited its use during incidents, despite the reality that it is often used anyway.
Meta’s recent launch of WhatsApp’s new Strict Account Settings feature may begin to shift that balance.
Strict Account Settings is a new high-security mode that applies the most restrictive privacy and security controls with a single toggle. When enabled, it reduces the attack surface by limiting interactions with unknown contacts, restricting media and attachment handling, disabling certain previews, and tightening privacy controls.
WhatsApp reluctance: security vs operational reality
Many organizations have resisted using WhatsApp in organizational crisis communications for three main reasons:
Security concerns: fear of malware, phishing, spyware, and data leakage via uncontrolled messaging channels.
Governance and compliance issues: lack of audit trails, retention controls, and integration with enterprise systems.
Loss of organizational control: the building of ‘shadow crisis communications networks’ operating outside of official incident management structures.
Yet in practice, WhatsApp has often become the default tool during crises – especially when corporate systems fail, are unavailable, or are too slow.
This gap between formal policy and operational reality has been a persistent resilience weakness for many organizations.
Does Strict Account Settings change the equation?
Strict Account Settings does not transform WhatsApp into an enterprise-grade incident management platform. However, it does appear to materially reduce some of the most acute technical risks:
- Reduced exposure to malicious attachments and unknown contacts,
- Mitigation of certain zero-click attack vectors,
- Tighter default privacy and interaction controls.
For crisis managers, this raises an important question: ‘Should WhatsApp move from being a prohibited tool to a controlled, risk-managed component of crisis communications?’ Crisis and business continuity managers need to determine the answer to this in their own organizational context, but some considerations include:
- Crisis response increasingly depends on tools that people already use and trust. Attempting to ban these tools outright may be less effective than defining controlled use cases and security baselines.
- Rather than asking “Is WhatsApp secure enough?” organizations may need to ask: “Under what conditions, with what settings, and for which roles is WhatsApp acceptable?” Strict Account Settings provides a technical foundation for that conversation.
Strict Account Settings should not be interpreted as a blanket green light for the use of WhatsApp in crisis management. Key limitations remain:
- Lack of enterprise governance and records management,
- Limited integration with formal incident management systems,
- Dependence on user behaviour and configuration discipline.
However, it does offer something new: a credible basis for revisiting long-standing assumptions.
Rather than treating WhatsApp as either forbidden or unavoidable, organizations may begin to incorporate it deliberately into layered crisis communication strategies, supported by clearer policies, threat modelling, and role-based guidance.
More details about Strict Account Settings can be found here






