Is Encryption Falling Out Of Favour?

Even the most security-conscious organisations can succumb to a data breach. Consider the Ministry of Defence (MoD)  - one of the most secure organisations in the world, you would hope. Despite its stringent measures, figures reveal that the MoD has lost 1,007 laptops, 462 mobile phones, 265 USB data sticks, and 183 hard disk drives containing sensitive and confidential data since 2019. The sensitivity of this data cannot be understated.

From critical national defence plans to the personal information of high profile undercover national security professionals, the loss of such devices could have catastrophic consequences.

Fortunately for the MoD, a key component of their security strategy has helped mitigate these potential damages – encryption. In today's world, where personal and sensitive information is constantly at risk, encryption has become a key tool in maintaining the security and privacy of data by encoding it to ensure it remains inaccessible to unauthorised users.

Even if there is a data breach, and a system or device is physically stolen, illegally accessed or lost, encryption is able to ensure that data remains protected. 

Encryption Lacking On Peripherals

Yet despite encryption being a vital component in the overall cybersecurity puzzle, there has been a concerning drop in the number of companies employing it as part of their standard security practices. According to research from Apricorn, little more than one in ten organisations encrypt data on all laptops - down from 68% in 2022. Looking at desktop computers (down from 68% to 17%), mobile phones (55% to 13%), USB sticks (54% to 17%) and portable hard drives (57% to 4%), we see a similar story.

An alarming number of organisations appear to have taken a backwards step in the protection of information during sharing, handling, and storage, heightening the risk of data exposure.

Notably, 17% of security leaders responding to the survey cited a lack of encryption as the primary cause of at least one data breach - up 5% versus 2021 - and lost or misplaced devices containing sensitive information resulted in breaches at 18% of firms surveyed.

Greater Visibility Of Data

With encryption being pushed aside, many businesses are now struggling to protect critical data - a trend that urgently needs to be reversed. Fortunately, many enterprises are actively working to implement the necessary changes, leading to a notable increase in the number of security leaders planning to encrypt data as standard which has risen from 12% to 23% on average across all devices.

Interestingly, the rise is particularly prevalent for removable devices. For example, over 42% of organisations now plan to introduce or expand encryption on USB sticks, up from 20% in 2022, and 48% plan to do the same for portable drives, up from 16% in 2022. This intent is promising, but what is needed to turn it into action?

Currently, a major stumbling block for enterprises revolves around the widespread shift to remote working. Among those who have embraced a decentralised workforce, 22% revealed they have no control over where company data is stored, while 14% admitted they lack a clear understanding of which data sets need to be encrypted. 

Bridging this visibility gap and enhancing control over data is absolutely vital if encryption is to be implemented on a company-wide basis. Any lack of oversight in relation to both data and devices significantly heightens the risk of data breaches.

Proactive Prioritisation

The imperative to standardise encryption across the enterprise shouldn't be seen merely as a burden but as an opportunity for advancement. Benefits associated with bridging the encryption gap include the secure sharing of files (20%), safeguarding against lost or stolen devices (18%), and avoiding regulatory penalties (14%).
It's evident that companies recognise the value of taking these strides.

However, with only 12% of organisations presently encrypting data on all laptops and 13% on all mobile phones, more proactive measures are urgently required.

Given the potential repercussions of sensitive data loss or leakage, mere intention is insufficient. Today, companies must proactively prioritise the automatic encryption of all company data as standard across the organisation.

Jon Fielding is Managing Director, EMEA, at Apricorn

Image: Unsplash

You Might Also Read: 

Have We Become Complacent About The ‘Insider Threat’?:

___________________________________________________________________________________________

If you like this website and use the comprehensive 7,000-plus service supplier Directory, you can get unrestricted access, including the exclusive in-depth Directors Report series, by signing up for a Premium Subscription.

  • Individual £5 per month or £50 per year. Sign Up
  • Multi-User, Corporate & Library Accounts Available on Request

Cyber Security Intelligence: Captured Organised & Accessible


 

 

 

 

 

« OpenTofu's New State File Encryption Is A Boon For IaC Security
Kinsing Malware Attacks Analysed »

Infosecurity Europe
CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

DigitalStakeout

DigitalStakeout

DigitalStakeout enables cyber security professionals to reduce cyber risk to their organization with proactive security solutions, providing immediate improvement in security posture and ROI.

Practice Labs

Practice Labs

Practice Labs is an IT competency hub, where live-lab environments give access to real equipment for hands-on practice of essential cybersecurity skills.

LockLizard

LockLizard

Locklizard provides PDF DRM software that protects PDF documents from unauthorized access and misuse. Share and sell documents securely - prevent document leakage, sharing and piracy.

CSI Consulting Services

CSI Consulting Services

Get Advice From The Experts: * Training * Penetration Testing * Data Governance * GDPR Compliance. Connecting you to the best in the business.

Infosecurity Europe, 3-5 June 2025, ExCel London

Infosecurity Europe, 3-5 June 2025, ExCel London

This year, Infosecurity Europe marks 30 years of bringing the global cybersecurity community together to further our joint mission of Building a Safer Cyber World.

Qualitèsoft Technology

Qualitèsoft Technology

Qualitèsoft Technology is a leading Software Development and Quality Assurance organization. We specialize in Custom Development, Mobile Application, Software Testing and Quality Assurance.

Cyber Data-Risk Managers

Cyber Data-Risk Managers

Cyber Data-Risk Managers Pty Ltd is an insurance broker based in Melbourne, Australia specializing in Cyber insurance / Data breach insurance.

Governikus

Governikus

Governikus provides solutions for secure data transport, authentication, the use of electronic signatures and cryptography as well as for long-term storage.

Unitrends

Unitrends

Unitrends helps IT pros do more with less by providing an all-in-one enterprise backup and continuity solution.

Entel CyberSecure

Entel CyberSecure

Entel CyberSecure is a portfolio of Cybersecurity solutions and services for the protection, defense, risk management and regulatory compliance of ICT Systems for corporations and Government.

QuickLaunch

QuickLaunch

QuickLaunch transforms how cloud-savvy institutions and companies manage human and device authentication, authorization, access control and integration.

OutThink

OutThink

OutThink is a web-based platform (SaaS) that has been developed specifically to identify and reduce risky workforce behaviours and build a risk aware culture.

Cyfirma

Cyfirma

CYFIRMA offers Cyber threat visibility and intelligence suite and services aimed at keeping your organization’s cybersecurity posture up-to-date.

Cyber Risk Aware

Cyber Risk Aware

Cyber Risk Aware provide a security awareness and phishing simulation platform that focuses on real threats and educates and empowers employees to be the first line of defence.

Opticks Security

Opticks Security

Opticks provides fraud detection and monitoring solutions for leading brands. agencies and networks. Our relentless mission is to deliver reliable and innovative software to beat digital fraud.

Cybergroot

Cybergroot

Cybergroot provides Cybersecurity Assessment services and professional Information Security trainings.

Endor Labs

Endor Labs

Endor Labs gives developers and security teams the context they need to prioritize open source risk.

Lodestone

Lodestone

Lodestone partners with clients to help them mitigate business and reputational risk, through our human-based, approach to cyber security, digital forensics and incident response.

Cytidel

Cytidel

Cytidel is a vulnerability and risk management platform that utilises threat and business intelligence to help IT Security teams.

ClearFocus Technologies

ClearFocus Technologies

ClearFocus Technologies provides advanced cybersecurity services that secure our nation’s most sensitive assets.

Dial A Geek

Dial A Geek

Dial A Geek are a Bristol-based B Corp that provides Managed IT Services to companies of 20+ users. We help businesses with a smart use of tech, including compliance and cybersecurity solutions.