Secure Your Emails

ENCRYPTION IS NOT AS WIDELY USED AS IT SHOULD BE

Most emails sent from the typical organization are not encrypted, that allows them to be easily intercepted. While this applies primarily to email given its dominant role in corporate communications and collaboration, instant messages, social media posts and other external communications sent by users are also sent unencrypted in most cases.

A large proportion of application-generated content, such as diverse as flight schedules or payment statements, is also sent unencrypted. For example, Osterman Research has found that less than one-half of organizations enable users to manually encrypt sensitive content, while less than one-third encrypt messages based on corporate policies.

There is a significant unmet need to protect communications via encryption. Even content that traditionally is sent in clear text -embargoed financial statements, press releases, purchase orders and the like – must be sent encrypted to prevent its unauthorized interception. Plus, there is also value in removing access to content at a later date by revoking decryption rights, as in the case of a former employee or business partner who should no longer have access to encrypted content after a certain date or a change in their status.

Many believe that email communications will be supplanted by other communication and collaboration tools in the relatively near future. While other tools are finding increased use, the mainstay of communications is and will continue to be email, including personal Webmail that is often used for work-related purposes.

Consequently, this content must be encrypted to ensure compliance with good governance practices and regulatory requirements, as discussed later in this white paper.

MOST CONTENT IS NOT ENCRYPTED

The majority of decision makers are not happy with the status quo of their email policies with regard to encryption. Osterman Research found in a study published in 2012 that only 38% of mid-sized and large organizations find that their policies for encryption of confidential email and attachments meet their needs. Add to this the fact that only about one-half of organizations have automated systems in place to scan outbound content for policy violations, sensitive information, credit card numbers, and information that should be encrypted. The primary actions with outbound email at such organizations are to automatically apply policy requirements (such as encryption or distribution through a secure channel), or to remind users of corporate policies through a pop-up message.

CLOUD-BASED TOOLS ARE COMPOUNDING THE PROBLEM

Encryption challenges are growing due to the use of cloud-based file synchronization and storage tools that are used in organizations of all sizes. For example, Dropbox is widely employed and currently has roughly 60 million users worldwide. A survey conducted in 2013 found that Dropbox and many other cloud-based tools are used extensively in organizations of all sizes, often without IT’s blessing or even their knowledge.

BYOD IS MAKING THE PROBLEM WORSE

The Bring Your Own Device (BYOD) craze is exactly what its name implies: the practice of employees to use personally-owned smartphones, tablets, laptops and other personal computing tools to access corporate applications like email, databases, CRM systems and other tools; and to create, store and manage data using these platforms.

BYOD is a key element of a broader trend toward mobile interaction with corporate applications and cloud-based services from a variety of platforms. It is being fuelled by several factors, including employees’ desire to use newer platforms at a time when IT budgets often are not able to afford them, the trend toward telework in many organizations, and the general trend toward more employee autonomy. Plus, employee-specified applications and devices enable employees to be more productive, complete their work more quickly, and avoid the frustration and delays of dealing with an overtaxed and underfunded IT department.

The key is that BYOD – and, by extension email because it is so widely employed on personally owned devices – means that IT is losing control over content and the process of communications. This makes it even more critical to employ encryption as a tool in the arsenal to prevent the unauthorised access of corporate information whether in transit or at rest.


Why is Data Encryption not more common?
Why Encrypt Emails?