Encryption is the process of converting readable data into scrambled ciphertext using a mathematical algorithm and a key, so that only someone with the right key can turn it back into readable form. Businesses use it to protect data stored on devices, servers and in the cloud, and data moving across networks and the internet. It is one of the most basic security controls and one of the first that auditors, customers and insurers ask about.
At a glance
- Encryption protects data “at rest” (stored) and “in transit” (moving across a network); sensitive data generally needs both.
- Its strength depends heavily on key management: who holds the keys, where they are stored and how they are rotated.
- It protects against people without the key, such as someone who finds a lost laptop, but not against an attacker using a legitimate login.
- Most modern devices, cloud services and web traffic support it, but it is not always switched on or configured the same way.
- Compliance frameworks commonly expect encryption of sensitive data, with details varying by framework and jurisdiction.
What problem it solves
Data gets out of your control in many ordinary ways: a laptop left in a taxi, a backup drive shipped offsite, a database copied by an attacker, traffic intercepted on public Wi-Fi, or a cloud storage bucket misconfigured. Without encryption, whoever ends up with the data can read it. With encryption, they get scrambled content that is useless without the key.
That matters for more than security. Lost or stolen data can trigger breach notification duties, regulatory penalties, contract obligations and lost customer trust. Strong encryption, with keys kept separate from the data, can reduce the impact of many of these events. It is also a common line item on data security compliance checklists, security questionnaires and cyber insurance applications.
How it works
Algorithms and keys. An encryption algorithm uses a key to scramble data and, with the matching key, unscramble it. Symmetric encryption uses the same secret key for both steps and is fast, so it is used for bulk data such as disks and files. Asymmetric (public-key) encryption uses a pair of keys, one public and one private, and is used to exchange keys securely and to help verify identity. Systems commonly combine the two.
In transit. Web sessions, email between servers, APIs and many applications use Transport Layer Security (TLS), the successor to Secure Sockets Layer (SSL), to encrypt traffic. Site-to-site and remote access connections often use IPsec or TLS-based virtual private networks (VPNs). Certificates issued through a public key infrastructure (PKI) let systems verify who they are talking to.
At rest. Full-disk encryption protects laptops and servers if the hardware is lost. Databases, file systems, backups and cloud storage services offer their own encryption, often enabled by default in major clouds. Some applications also encrypt specific fields, such as payment card or health data.
Key management. Keys need to be generated, stored, rotated, backed up and revoked. Options include provider-managed keys, customer-managed keys in a cloud key management service, and hardware security modules (HSMs) for stricter control. Weak key management, such as keys stored next to the data or shared widely, can undo the protection.
When it matters for buyers
- When a compliance deadline or audit arrives. Expect questions about which data is encrypted, with what, and who controls the keys.
- When choosing cloud storage or SaaS. Default encryption is common; customer-managed keys, key location and access logging vary by provider and tier.
- When connecting sites or remote users. Check which links carry sensitive traffic unencrypted, including private circuits that people assume are safe.
- When retiring hardware. Encrypted drives make secure disposal simpler, since destroying the key can render the data unreadable.
- When inspecting traffic. Security tools such as a cloud access security broker (CASB) or data loss prevention (DLP) may need to decrypt traffic to inspect it, which raises privacy and certificate-management questions.
Questions to ask vendors
- Is data encrypted at rest and in transit by default, and which algorithms and protocol versions do you use?
- Who manages the keys? Can we bring or hold our own keys, and what happens to our data if we revoke them?
- Where are the keys stored, and in which countries or regions?
- Who at your company can access our decrypted data, under what circumstances, and is that access logged?
- Is backup and replica data encrypted the same way as primary data?
- What encrypted throughput does this appliance or service support, compared with unencrypted throughput?
- How do you handle certificate expiry and key rotation, and who is alerted?
How it differs from hashing
Encryption is reversible: with the right key, ciphertext turns back into the original data. Hashing is designed to be one-way: it turns data into a fixed-length fingerprint that cannot practically be reversed, which is why it is used for storing passwords and checking that files have not changed. Both are cryptographic tools, but they solve different problems. For encrypting and controlling access to data in the cloud, see our cloud access security broker overview.
