Sooner or later a customer, an insurance carrier, or a bank sends you a security questionnaire, and two lines on it look almost identical. Is data encrypted in transit? Is data encrypted at rest? Most owners read those, feel reasonably sure the answer is yes, and have no idea how they would prove it.

These are not trick questions, and they are not technical once the words are translated. They describe two different moments in the life of your data, they protect against two different problems, and there is a third problem neither one touches. Knowing the difference lets you answer the form honestly and spot the gaps you actually have.

The Armored Truck and the Vault

Picture a bank moving cash. Encryption in transit is the armored truck. While the money travels between buildings it is inside a locked vehicle, so someone watching the road cannot see or take it. That is what happens when data moves between your laptop and a website, your email program and the mail server, or your office and a cloud application. The information is scrambled while in motion, so anyone intercepting traffic on the coffee shop network gets nothing readable.

Encryption at rest is the vault. Once the money arrives it sits inside something that resists being opened by whoever holds the building. That is what happens when the hard drive in a laptop, the storage behind a cloud service, or a backup drive is encrypted. If the device is stolen or the drive is pulled out and plugged into another computer, the contents are unreadable without the key.

The Federal Trade Commission puts both in one sentence in its Start with Security guide for business: “Use strong cryptography to secure confidential material during storage and transmission.” Storage is the vault. Transmission is the truck. You need both, because they cover different moments.

What Neither One Protects Against

This is the part that gets skipped, and it is the most important thing here. Encryption does nothing against an attacker who has a valid login.

Go back to the vault. Encryption stops someone who hauls the vault away and tries to cut it open. It does nothing about someone who walks up with the right combination, because the vault opens for a correct combination without asking who is holding it.

The National Institute of Standards and Technology said this plainly in Special Publication 800-111, its Guide to Storage Encryption Technologies for End User Devices, published in 2007. Describing full disk encryption, NIST wrote that “When the device is booted, then FDE provides no protection; once the OS is loaded, the OS becomes fully responsible for protecting the unencrypted information.” The same publication warns that “if an end user device is compromised at any time, any storage encryption technologies on it may become partially or wholly ineffective.”

In business terms: an encrypted laptop sitting in a locked car protects your data. That same laptop, powered on and signed in while an attacker has remote control of it, protects nothing. The disk is decrypted the whole time the user is working, because otherwise the user could not work.

So encryption is not a substitute for access control, and the FTC guidance pairs cryptography with a separate instruction to “Restrict access to sensitive data” on a need to know basis. Stolen passwords remain the common way in, which is why we spend so much time on sign in strength in our comparison of security keys, passkeys, and multi factor authentication.

What You Already Have Turned On

Some of this is already handled and you may not have noticed. For most small businesses the transit half is largely solved by default.

  • Your website traffic. If your site loads with a secure connection and browsers do not warn visitors, traffic to and from your site is encrypted in transit. That is now the default expectation, not an upgrade.
  • Mainstream cloud services. Major business email, file storage, and accounting platforms encrypt connections and encrypt stored data on their side. Check the provider’s security or trust documentation and keep a copy, because that page is your evidence when a questionnaire asks.
  • Company phones and tablets. Modern mobile devices encrypt their storage once a passcode is set. The passcode is what turns it on, so a device with no passcode is a device with no vault.
  • Newer business laptops. Recent Windows and Mac computers often arrive with disk encryption available and sometimes already enabled. Available and enabled are different things, which brings us to the gaps.

What Is Usually Missing

When we audit a small business, the same three gaps show up over and over, and all three are on the at rest side.

The first is laptop disk encryption nobody confirmed. Windows offers BitLocker and Mac offers FileVault, both in the security or privacy area of system settings, and on many machines it is simply switched off. Nobody notices, because an unencrypted laptop works exactly like an encrypted one right up until it is left in an airport.

The second is backups. Your live systems may be well protected while the copies are not, and a backup holds the same customer records as the original. CISA, the federal cybersecurity agency, advises businesses to “Leverage protections for backups, including physical security, encryption and offline copies.” That covers the external drive somebody carries home and the archive nobody has looked at in years.

The third is the old server in the closet. Bought years ago, still running because it works, holding every contract and payroll file the company has produced. It usually has no disk encryption, and it is often the richest target in the building. The same goes for the retired computer in storage and the box of USB drives in a desk drawer.

Answering the Questionnaire Honestly

Do not answer yes because it seems like the answer they want. A yes you cannot support is a written statement to a customer or an insurer, and the wrong time to discover it was wrong is after an incident.

  1. List where your data actually lives. Cloud services, laptops, phones, servers, backups, and removable drives. You cannot answer for systems you have not listed.
  2. Check each one instead of assuming. Confirm disk encryption is enabled on every company computer, verify the backup software’s encryption setting, and pull the security documentation for each cloud provider.
  3. Answer with specifics. Something like: data in transit is encrypted for all web and email traffic, data at rest is encrypted on all company laptops and phones and by our cloud providers, and backups are encrypted. That reads far better than an unqualified yes.
  4. Say so when there is a gap, and say what you are doing. A known gap with a plan and a date is a normal finding. An inaccurate yes is a different kind of problem.

The Bottom Line

In transit is the armored truck protecting data while it moves. At rest is the vault protecting data while it sits still. Between them they cover interception on the network and physical theft of a device. Neither does anything about an attacker holding valid credentials, so encryption belongs next to strong sign in and tight access rather than in place of them.

For most small and mid-sized businesses the transit side is already handled, and the work is on the at rest side: laptops that were never encrypted, backups nobody checked, and the old server everyone forgot. None of that is expensive to fix. It is mostly a matter of confirming settings you already own, which is the same practical mindset behind our piece on why cybersecurity is no longer optional for mid-sized businesses.

If a questionnaire is sitting on your desk and you would rather answer it from evidence than from memory, we can go through your systems and tell you exactly where you stand. Harrison Ward Technology helps businesses across Denton County verify encryption, tighten access, and document what is actually in place. Contact us today


Sources:

Comments are closed

This website uses cookies and asks your personal data to enhance your browsing experience. We are committed to protecting your privacy and ensuring your data is handled in compliance with the General Data Protection Regulation (GDPR).