Skip to content
lesson Data security and encryption Beginner 3 min read

What is encryption?

Encryption uses a key to turn readable data into a scramble and back again. What it protects, where it stops, and what to check in your business.

Encryption turns readable data into a scramble that means nothing to anyone who does not hold the key. With the right key, the scramble turns back into the original. The readable form is called plaintext and the scrambled form is called ciphertext.

How a key does the work

Two things are involved: a method and a key. The method, called an algorithm, is public. The Advanced Encryption Standard (AES) is the one the Australian Signals Directorate (ASD) approves for this kind of encryption, and anyone can read how it works. The key is a very long number, and it is the only secret.

A combination lock is a fair comparison. Everybody knows how the lock is built, and it still holds because only you know the combination. In the simplest kind of encryption the same key locks and unlocks the data, so everyone who needs to read it must have a copy of that key and keep it safe.

What it protects, and what it leaves open

Encryption protects confidentiality: it makes data unreadable to everyone except the people meant to read it. Someone who steals a laptop with an encrypted drive, or copies a message on its way across the internet, ends up with ciphertext.

It has limits. Encrypted data can still be copied or intercepted, and the person who takes it simply cannot read it. Once someone signs in and unlocks an encrypted device the data is readable again, so an unlocked laptop or a stolen password gets past it. ASD is blunt about this: encrypting data does not make it less sensitive, it reduces the immediate consequences when someone else gets hold of it.

Where a business uses it

The Office of the Australian Information Commissioner (OAIC) lists the places where a business that holds personal information should consider encryption:

  • Laptops, phones and tablets, including ones that staff own.
  • USB sticks and portable drives.
  • Servers and databases.
  • Backups.
  • Information kept with a cloud provider.
  • Data sent over the internet, and email and file shares inside the office.

Much of this is already built in. Windows can encrypt a drive with BitLocker, and Microsoft 365 encrypts stored files and the connections that carry them. The work is checking that it is switched on everywhere, and that no unencrypted copy of the same data sits somewhere else.

Look after the keys

Whoever holds the key can read the data, and without the key the data stays scrambled, for you as much as for a thief. ASD’s Information Security Manual expects an organisation to have a process for how keys are created, stored, recovered and destroyed. For a small business that comes down to a few questions:

  • Is encryption turned on for every laptop, phone and portable drive?
  • Where are the recovery keys kept, and who can get to them?
  • Are the backups encrypted too?
  • Who is able to decrypt the data we keep in the cloud?

Encryption is one line in A cyber security checklist for small business. If you would like the devices and accounts checked for you, see security best practices.

Sources

  1. Glossary: encryption (NIST Computer Security Resource Center) csrc.nist.gov
  2. Glossary: symmetric key algorithm (NIST Computer Security Resource Center) csrc.nist.gov
  3. Information security manual: Guidelines for cryptography (Australian Signals Directorate) cyber.gov.au
  4. Guide to securing personal information (Office of the Australian Information Commissioner) oaic.gov.au
  5. Encryption in Microsoft 365 (Microsoft Learn) learn.microsoft.com

Written by Only Tech Solutions.

This is general information, not advice for your situation. See the terms and conditions.

We can sort this for you

More lessons

All lessons

Tell us what needs sorting.

Book a call or send an email. We reply within one business day.