Skip to content
lesson Data security and encryption Intermediate 3 min read

Encryption at rest vs encryption in transit.

Data can be encrypted where it is stored and while it travels. What each one protects against, where each stops, and why you need both.

Encryption at rest protects data where it is stored: on a laptop drive, a server, a USB stick or a backup. Encryption in transit protects data while it moves across a network, such as the internet or the office Wi-Fi. They guard against different events, and a business needs both.

Encryption at rest

This is for the day a device goes missing. Without it, whoever picks up a lost laptop can move the drive into another computer and read the files. With it, they find a scramble. BitLocker on Windows is a common example. Microsoft describes it as protection against data theft from lost, stolen or carelessly retired devices.

The limit is that it only works while the device is locked or switched off. Once someone signs in, the data is unlocked for them. The Australian Signals Directorate (ASD) says a device in that state should be treated as unprotected until it is shut down or the lock screen comes on. So encryption at rest is no help against an attacker who is working through a signed-in account.

Encryption in transit

Data crossing a network passes through equipment you do not control, and someone along the way may be able to read it or alter it. Encryption in transit wraps the data for the trip so that it arrives unread and unchanged. Transport Layer Security (TLS) is the usual tool for web and email connections. A virtual private network (VPN) can do the same job for all the traffic leaving a device.

The limit here is at the ends. Protection covers the journey from your device to the other party’s servers. The data is decrypted when it arrives, and from then on it is only as safe as the place it is stored.

Why one without the other leaves a gap

A file sent over an encrypted connection and then saved to an unencrypted laptop is exposed when the laptop is stolen. A file kept on an encrypted drive and then sent over an unprotected connection is exposed on the way. The Office of the Australian Information Commissioner makes the same point: the scope of encryption has to be wide enough that an attacker cannot go and find another, unencrypted copy.

Neither kind covers what happens after a legitimate sign-in. A stolen password opens encrypted data as easily as it opens anything else, which is why multi-factor authentication sits alongside both.

What to check

  • Device encryption is on for every laptop, phone and tablet, and the recovery keys are saved to a business account.
  • USB sticks and external drives are covered. Windows device encryption does not include them automatically.
  • Backups are encrypted, including the copy kept off site.
  • Your website, email and remote access use a current version of TLS.
  • For each cloud service, you know whether data is encrypted in both states and who is able to decrypt it.

Microsoft 365 is a useful example of both working together: Microsoft says stored content is encrypted at rest, and that TLS protects files and email while they move.

The off-site backup copy is explained in The 3-2-1 backup rule. To see whether the certificate that protects connections to your website is current, run the free domain and certificate expiry check.

Sources

  1. Information security manual: Guidelines for cryptography (Australian Signals Directorate) cyber.gov.au
  2. Device security principles: protect data at rest and in transit (UK National Cyber Security Centre) ncsc.gov.uk
  3. BitLocker overview (Microsoft Learn) learn.microsoft.com
  4. Encryption in Microsoft 365 (Microsoft Learn) learn.microsoft.com
  5. Guide to securing personal information (Office of the Australian Information Commissioner) oaic.gov.au
  6. End-to-end encryption trends and challenges: position statement (eSafety Commissioner) esafety.gov.au

Written by Only Tech Solutions.

This is general information, not advice for your situation. See the terms and conditions.

We can sort this for you

More lessons

All lessons

Tell us what needs sorting.

Book a call or send an email. We reply within one business day.