Keeping Compliant: How Effective Encryption Can Secure Your Clients’ Data
Your clients trust your organisation with information they would not necessarily share publicly. Depending on your sector, this may include contact details, financial records, contracts, employee information, medical data, legal documents, intellectual property or confidential business plans.
That trust comes with responsibility.
Cybercriminals are constantly looking for opportunities to steal valuable information, but data can also be exposed through lost laptops, misdirected emails, incorrectly configured cloud storage and inappropriate access permissions. Even a simple human error can create a serious security and compliance issue.
Encryption is one of the most effective ways to reduce these risks. It helps prevent unauthorised people from understanding information, even when they manage to obtain the files, intercept a communication or access a storage device.
For organisations working to meet their data-protection responsibilities, encryption should form an important part of a wider security strategy.
What is encryption?
Encryption converts readable information, known as plaintext, into an unreadable form called ciphertext.
The information can only be returned to its original form using the correct decryption key or an authorised system. Without access to that key, an unauthorised person should not be able to understand the protected data.
Encryption can be applied to information:
- Stored on laptops, servers and mobile devices
- Held within databases and cloud platforms
- Transferred across the internet
- Shared through email and collaboration tools
- Stored within backups
- Saved to removable media
- Sent between offices and remote workers
The Information Commissioner’s Office describes encryption as a process that uses a secret key to encode information so that only those with access to the key can read it.
Why data protection matters to your clients
Clients do not simply expect your organisation to provide a good service. They also expect you to handle their information responsibly.
A data breach can expose people to fraud, identity theft, financial loss, reputational damage and distress. It may also damage the relationship between your organisation and the people who trusted it.
The impact can extend beyond the immediate incident. Businesses may experience:
- Loss of customer confidence
- Contractual disputes
- Operational disruption
- Legal and regulatory scrutiny
- Increased insurance costs
- Remediation and recovery expenses
- Damage to their reputation
Once confidential information has been exposed, it may be impossible to retrieve every copy. Preventing unauthorised access is therefore far more effective than trying to control information after it has been stolen.
Encryption creates an important additional barrier. Although it cannot prevent every security incident, it can make compromised data significantly less useful to an attacker.
How encryption supports UK GDPR compliance
The UK GDPR requires organisations to process personal information securely and implement appropriate technical and organisational measures based on the risks involved.
It does not state that every piece of personal information must always be encrypted. However, it specifically recognises encryption as an example of an appropriate technical measure. The ICO recommends considering encryption when personal information is transmitted electronically or stored on computers, laptops, smartphones, tablets and removable media.
What is considered appropriate will depend on factors such as:
- The sensitivity of the information
- The number of individuals affected
- How the data is used
- Where it is stored
- Who can access it
- The potential impact of a breach
- The available technology
- The cost and practicality of implementing protection
A business holding publicly available contact information may face different risks from an organisation processing medical records, bank details or confidential legal documents.
Encryption should therefore be applied according to a proper risk assessment rather than treated as a simple compliance tick box.
Compliance is about demonstrating appropriate protection
Regulatory compliance is not only about having a policy document. Your organisation should be able to demonstrate that its security controls are appropriate, implemented correctly and regularly reviewed.
This means understanding:
- What personal and confidential information you hold
- Where that information is stored
- Which systems process it
- Who has access to it
- How it is transferred
- How long it is retained
- Which encryption controls are enabled
- Who manages the encryption keys
- Whether the controls are still effective
The UK GDPR follows a risk-based approach. The appropriate level of protection depends on the organisation’s circumstances, the nature of the data and the risks posed to individuals. There is no single security configuration that will suit every business.
Protecting data at rest
Data at rest is information stored on a device or within a system rather than actively moving between locations.
This could include information held on:
- Business laptops
- Mobile phones and tablets
- File servers
- Cloud storage
- Databases
- Backup systems
- External drives
- Virtual machines
Full-disk encryption can protect the contents of a laptop or mobile device when it is switched off and locked.
For example, if an employee loses an encrypted laptop, someone finding the device should not be able to remove the drive and read its contents without the correct credentials or recovery key.
Without encryption, a strong Windows or application password may not be enough. An attacker could potentially remove the storage drive or use another method to access its contents.
Solutions such as Microsoft BitLocker can help organisations centrally manage device encryption, but they must be configured correctly. Recovery keys should be stored securely and should not depend entirely on individual employees remembering where they saved them.
The National Cyber Security Centre advises protecting sensitive information wherever it is stored, including on mobile devices, removable media, temporary storage locations and systems used for remote access.
Protecting data in transit
Data in transit is information moving between devices, users, offices or services.
Examples include:
- A client submitting information through your website
- An employee sending an email attachment
- A remote worker accessing a business application
- A file being transferred to cloud storage
- Information synchronising between two offices
- A system sending data to an external supplier
Encryption in transit helps protect information against interception and tampering while it travels across a network.
Secure websites use HTTPS and Transport Layer Security to encrypt communications between the website and the visitor’s browser. Secure remote-access services may use encrypted virtual private network connections.
The ICO recommends using encrypted communications when transmitting personal information. It also warns that encryption during transfer does not necessarily mean the information remains encrypted after it reaches the recipient’s system.
Businesses must therefore protect information throughout its full lifecycle, not only while it is moving.
Securing client information in Microsoft 365
Many organisations hold large quantities of client information within Microsoft 365.
This may include emails, documents, Teams messages, SharePoint sites and OneDrive accounts. Microsoft provides various security and encryption capabilities, but businesses still need to configure access, sharing and data-protection policies appropriately.
Depending on the organisation’s licensing and requirements, controls may include:
- Encrypted email
- Sensitivity labels
- Restricted forwarding
- Expiring access
- Controlled external sharing
- Data loss prevention
- Conditional Access
- Multi-factor authentication
- Device-compliance requirements
- Retention policies
Encryption can protect the content, while identity and access controls determine who is authorised to open it.
This distinction is important. Encrypting a document does not help when an attacker signs in using a legitimate user’s stolen password and is granted authorised access.
That is why encryption should always be combined with strong authentication and appropriate permissions.
Email encryption and secure document sharing
Email remains one of the most common ways for businesses to share confidential information, but it is also a frequent source of data exposure.
Sensitive information may be:
- Sent to the wrong recipient
- Forwarded without permission
- Downloaded to an unmanaged device
- Intercepted through an insecure connection
- Accessed through a compromised mailbox
- Retained longer than necessary
Sending an ordinary attachment means the organisation may lose control of the file as soon as it leaves the mailbox.
A secure sharing platform can provide greater control by requiring the recipient to authenticate before accessing the information. It may also allow the sender to revoke access, prevent downloads or set an expiry date.
Email encryption can provide additional protection for messages that must be sent directly. However, employees need clear guidance about when and how to use it.
Security controls that are too difficult will often be bypassed. The safest process should also be the easiest approved way for employees to complete their work.
Encryption and cloud services
Cloud providers often offer encryption for data in transit and at rest, but businesses should not assume that every service is configured correctly by default.
Before placing client information within a cloud platform, organisations should establish:
- Whether stored data is encrypted
- Whether transfers are encrypted
- Who controls the encryption keys
- Which administrators can access the data
- Where the information is hosted
- How backups are protected
- How data is deleted
- What happens when the contract ends
- Whether activity is logged and monitored
The NCSC recommends being confident that cloud data is encrypted at rest and in transit. Depending on the service, encryption may be enforced automatically or may need to be enabled and configured by the customer.
Your cloud supplier may provide the underlying technology, but your organisation remains responsible for understanding how client information is being used and protected.
Protecting your backups
Backups often contain a complete copy of an organisation’s most valuable information.
They may include client databases, financial records, emails, contracts and confidential documents. This makes backup systems an attractive target for cybercriminals.
Backups should be encrypted both while they are being transferred and while they are stored.
However, encrypted backups must remain recoverable. Organisations should securely protect recovery keys and regularly test the restoration process.
A backup offers limited value when:
- Nobody knows the encryption password
- The recovery key has been lost
- The backup is corrupted
- The attacker has deleted the backup
- The restoration process has never been tested
- The backup account uses the same compromised credentials as the main system
Effective backup protection should combine encryption with access separation, monitoring, immutability and regular recovery testing.
Encryption key management
The strength of an encryption system depends heavily on how its keys are managed.
If an attacker gains access to the decryption key, the protected information may become readable. If the organisation loses the key, it may permanently lose access to its own data.
Keys should be:
- Stored securely
- Restricted to authorised people and systems
- Separated from the encrypted information where appropriate
- Backed up safely
- Revoked when compromised
- Replaced according to an agreed process
- Removed when they are no longer required
- Monitored for unauthorised use
Passwords used to protect encryption keys must also be strong and properly managed. The ICO warns that a weak or compromised password can significantly reduce—or eliminate—the protection encryption provides. It also recommends having processes to revoke compromised keys and securely manage replacements.
Cloud-based key management services can provide centralised generation, storage, use and destruction of cryptographic keys. The NCSC notes that effective encryption relies on secure key management and recommends using an appropriate key management service where it meets the organisation’s requirements.
Encryption does not replace access control
Encryption protects information from people who do not have the correct key or authorisation.
It does not prevent an authorised user from:
- Sharing data with the wrong person
- Downloading files to a personal device
- Taking screenshots
- Copying information into another system
- Falling victim to phishing
- Using an insecure password
- Keeping access after changing roles
- Intentionally misusing client information
Access should follow the principle of least privilege. Employees should only be able to access the information required for their role.
Permissions should also be reviewed regularly, especially when someone changes department, takes on different responsibilities or leaves the organisation.
Encryption does not stop ransomware
There is an important difference between security encryption and criminal encryption.
Security encryption protects information using keys controlled by the organisation. Ransomware encrypts information using keys controlled by the attacker, preventing the business from accessing its own systems.
Encryption will not stop ransomware from damaging files that an infected user or system is authorised to access.
The ICO confirms that losing timely access to personal data because ransomware has encrypted it may constitute a personal data breach, even when there is no immediate evidence that information was stolen.
Ransomware protection therefore requires additional controls, including:
- Endpoint detection and response
- Patch management
- Email security
- Multi-factor authentication
- Network segmentation
- Privileged-access management
- Secure backups
- Security monitoring
- Employee awareness training
- Incident-response planning
Encryption is one layer of protection, not a complete cybersecurity strategy.
What happens if client information is breached?
A personal data breach can involve more than someone stealing a database.
It can include accidental destruction, loss, alteration, unauthorised disclosure, unauthorised access or a significant loss of availability. Examples include sending information to the wrong recipient, losing a device containing personal data or being unable to access records following a cyber incident.
Certain personal data breaches must be reported to the ICO within 72 hours of the organisation becoming aware of them, where feasible. When a breach is likely to create a high risk to individuals’ rights and freedoms, the affected people must also be informed without undue delay. Organisations must document personal data breaches even when they decide that reporting is not required.
Encryption can be highly relevant when assessing the potential impact of a breach. However, the organisation must determine whether the encryption was effective, whether the keys were also exposed and whether the information remained accessible through another route.
The existence of an encryption setting should not be treated as automatic evidence that the risk has been removed.
Common encryption mistakes
Businesses often believe they are protected because encryption is available somewhere within their systems. In reality, several gaps may remain.
Common problems include:
Only encrypting some devices
A company may encrypt newly purchased laptops while older devices, external drives or mobile phones remain unprotected.
Storing recovery keys insecurely
A recovery key stored in an unprotected spreadsheet or beside the device provides little meaningful security.
Sharing passwords in the same message
Sending an encrypted attachment and its password in the same email can undermine the purpose of encrypting it.
Using outdated protocols
Older encryption protocols and unsupported systems may contain weaknesses that attackers can exploit.
Failing to protect cloud accounts
Encrypted cloud data can still be accessed when an attacker compromises an authorised account.
Forgetting about copied data
Client information may be exported into spreadsheets, downloaded to laptops or copied into test environments that have weaker controls.
Not reviewing encryption
Technology and security threats change. The ICO recommends regularly reviewing whether encryption methods remain appropriate and maintaining an understanding of the tools and processes being used.
Creating an effective encryption strategy
An encryption strategy should start with understanding your information.
Your organisation should identify:
- What personal and confidential data it holds
- Where that information is stored
- How it moves between systems
- Which devices can access it
- Who controls the encryption keys
- Which data is not currently protected
- What would happen if a device or account were compromised
- How encrypted information would be recovered
- Whether employees understand the approved processes
- How regularly controls will be reviewed
Encryption should then be implemented according to risk.
High-risk information may require stronger access controls, more restrictive sharing policies and separate key-management arrangements. Lower-risk information may need simpler protection.
The objective is to create controls that are proportionate, manageable and consistently applied.
Supporting compliance through layered security
Encryption works best as part of a layered approach.
A compliant and secure environment should combine encryption with:
- Multi-factor authentication
- Secure identity management
- Role-based access
- Device management
- Endpoint protection
- Data loss prevention
- Reliable backups
- Security monitoring
- Patch management
- Staff training
- Documented policies
- Incident-response procedures
When one control fails, another should still help protect the information.
For example, device encryption can protect a stolen laptop, multi-factor authentication can reduce the risk of account takeover and data loss prevention can help stop an employee sending confidential information outside the organisation.
No single security product can remove every risk.
Protect your clients and strengthen their trust
Clients expect their data to be treated with the same care as any other valuable business asset.
Effective encryption can help protect information stored on devices, transferred between systems, shared through email and retained in backups. It can also help your organisation demonstrate that it has considered appropriate technical safeguards as part of its wider data-protection responsibilities.
However, encryption must be implemented correctly.
It requires secure key management, strong identity controls, appropriate permissions, effective monitoring and regular review. Simply enabling one setting does not guarantee compliance or protect the business from every cyber threat.
Hamilton Group can review how your organisation stores, processes and shares client information. Our experts can identify encryption gaps, assess your Microsoft 365 and cloud security, review device protection and recommend practical improvements based on your business and regulatory requirements.
We recommend booking an appointment with our experts to review your current encryption and data-protection arrangements before an incident exposes a hidden weakness.
Call Hamilton Group on 0330 043 0069 to book your appointment and take the next step towards protecting your clients’ data, maintaining compliance and strengthening trust in your organisation.
You can also use our live Calendar to book an appointment.