What Is Encryption?

Also called: Data encryption

Related problems: Auditors and customers asking whether our data is encrypted; Worried about data exposed if a laptop or backup drive is lost; Not sure who holds the keys to our cloud data; Sensitive data sent between offices or to the cloud

Encryption is the process of converting readable data into scrambled ciphertext using a mathematical algorithm and a key, so that only someone with the right key can turn it back into readable form. Businesses use it to protect data stored on devices, servers and in the cloud, and data moving across networks and the internet. It is one of the most basic security controls and one of the first that auditors, customers and insurers ask about.

At a glance

  • Encryption protects data “at rest” (stored) and “in transit” (moving across a network); sensitive data generally needs both.
  • Its strength depends heavily on key management: who holds the keys, where they are stored and how they are rotated.
  • It protects against people without the key, such as someone who finds a lost laptop, but not against an attacker using a legitimate login.
  • Most modern devices, cloud services and web traffic support it, but it is not always switched on or configured the same way.
  • Compliance frameworks commonly expect encryption of sensitive data, with details varying by framework and jurisdiction.

What problem it solves

Data gets out of your control in many ordinary ways: a laptop left in a taxi, a backup drive shipped offsite, a database copied by an attacker, traffic intercepted on public Wi-Fi, or a cloud storage bucket misconfigured. Without encryption, whoever ends up with the data can read it. With encryption, they get scrambled content that is useless without the key.

That matters for more than security. Lost or stolen data can trigger breach notification duties, regulatory penalties, contract obligations and lost customer trust. Strong encryption, with keys kept separate from the data, can reduce the impact of many of these events. It is also a common line item on data security compliance checklists, security questionnaires and cyber insurance applications.

How it works

Algorithms and keys. An encryption algorithm uses a key to scramble data and, with the matching key, unscramble it. Symmetric encryption uses the same secret key for both steps and is fast, so it is used for bulk data such as disks and files. Asymmetric (public-key) encryption uses a pair of keys, one public and one private, and is used to exchange keys securely and to help verify identity. Systems commonly combine the two.

In transit. Web sessions, email between servers, APIs and many applications use Transport Layer Security (TLS), the successor to Secure Sockets Layer (SSL), to encrypt traffic. Site-to-site and remote access connections often use IPsec or TLS-based virtual private networks (VPNs). Certificates issued through a public key infrastructure (PKI) let systems verify who they are talking to.

At rest. Full-disk encryption protects laptops and servers if the hardware is lost. Databases, file systems, backups and cloud storage services offer their own encryption, often enabled by default in major clouds. Some applications also encrypt specific fields, such as payment card or health data.

Key management. Keys need to be generated, stored, rotated, backed up and revoked. Options include provider-managed keys, customer-managed keys in a cloud key management service, and hardware security modules (HSMs) for stricter control. Weak key management, such as keys stored next to the data or shared widely, can undo the protection.

When it matters for buyers

  • When a compliance deadline or audit arrives. Expect questions about which data is encrypted, with what, and who controls the keys.
  • When choosing cloud storage or SaaS. Default encryption is common; customer-managed keys, key location and access logging vary by provider and tier.
  • When connecting sites or remote users. Check which links carry sensitive traffic unencrypted, including private circuits that people assume are safe.
  • When retiring hardware. Encrypted drives make secure disposal simpler, since destroying the key can render the data unreadable.
  • When inspecting traffic. Security tools such as a cloud access security broker (CASB) or data loss prevention (DLP) may need to decrypt traffic to inspect it, which raises privacy and certificate-management questions.

Questions to ask vendors

  • Is data encrypted at rest and in transit by default, and which algorithms and protocol versions do you use?
  • Who manages the keys? Can we bring or hold our own keys, and what happens to our data if we revoke them?
  • Where are the keys stored, and in which countries or regions?
  • Who at your company can access our decrypted data, under what circumstances, and is that access logged?
  • Is backup and replica data encrypted the same way as primary data?
  • What encrypted throughput does this appliance or service support, compared with unencrypted throughput?
  • How do you handle certificate expiry and key rotation, and who is alerted?

How it differs from hashing

Encryption is reversible: with the right key, ciphertext turns back into the original data. Hashing is designed to be one-way: it turns data into a fixed-length fingerprint that cannot practically be reversed, which is why it is used for storing passwords and checking that files have not changed. Both are cryptographic tools, but they solve different problems. For encrypting and controlling access to data in the cloud, see our cloud access security broker overview.

Frequently Asked Questions

What is the difference between encryption at rest and in transit?
Encryption at rest protects stored data, such as files on a laptop, databases or backups. Encryption in transit protects data as it moves across a network, such as a web session or a connection between offices. Most security frameworks expect both for sensitive data.
If our data is encrypted, is it safe?
Not on its own. Encryption protects data from people who do not have the key. If an attacker steals a valid user's login, or malware runs on a device where the data is already decrypted, encryption does not stop them reading it. It is one layer alongside access control, monitoring and backups.
Who should hold the encryption keys for our cloud data?
By default, many cloud and SaaS providers manage the keys for you. Many also offer customer-managed keys, where you control key creation, rotation and revocation, sometimes in your own hardware security module. Holding your own keys gives more control but adds operational work, and losing keys can mean losing the data.
Does encryption slow systems down?
Modern processors include hardware support for common encryption algorithms, so the overhead is usually small for typical business workloads. Very high-throughput links or older devices can see a noticeable impact, so check the encrypted throughput figures for network appliances you are sizing.
Do regulations require encryption?
Many frameworks and laws expect or strongly encourage encryption of sensitive data, and some breach-notification rules treat properly encrypted data differently if it is lost. Requirements vary by framework, industry and jurisdiction, so confirm with your compliance team or counsel what applies to you.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.