Cyber Security
Your Business Communications Are Encrypted. Is That Enough?
Encryption is essential, but confidential business information also depends on the accounts, devices, backups, permissions and people around it.
11 min read — Altitude IT Security Team
Businesses are increasingly reassured by one word:
Encrypted.
That is important. Encryption helps protect information while it is being transmitted and stored, so that somebody who intercepts or obtains the underlying data cannot simply read it.
But a confidential business conversation rarely exists only as encrypted data travelling between two endpoints.
It may also exist on a laptop, a mobile phone, a user's account, a cloud platform, a backup, a downloaded file, a screenshot, a forwarded email or an employee's personal device.
So the security question should not stop at:
“Is the service encrypted?”
It should become:
“How is the information protected throughout its lifecycle?”
Start with the privacy expectation
Recent polling reported by the Centre for Democracy & Technology found that 93 per cent of British adults believed they had a right to private conversations online, while 89 per cent said nobody should be able to access personal messages without a court order.
The wider public debate about encrypted messaging and government access is not the main business issue here. The useful lesson for organisations is simpler: people expect sensitive communications to remain private.
Businesses expect privacy too. Every day, organisations exchange customer information, financial information, contracts, employee data, legal correspondence, commercial discussions, password-reset information and supplier details.
Encryption is essential for that work.
But encryption alone does not determine whether the information is secure. The business also needs to understand who can access it, from which devices, through which accounts, and where else copies of it exist.
The message may be encrypted. What about the account?
An attacker does not necessarily need to defeat encryption. If they obtain legitimate access to the user's account, the information may simply be available to them in the same way it is available to the person who is allowed to read it.
This is why confidential communications need strong identity controls around them. Depending on the service and the risk, that may include:
- multi-factor authentication for every user who can access sensitive information;
- passkeys or other phishing-resistant authentication where appropriate;
- clear administrator roles and limited privileged access;
- Conditional Access policies that consider the user, device and sign-in context;
- session management and sign-in monitoring;
- secure password recovery; and
- immediate access removal when somebody leaves or changes role.
The easiest way around strong encryption may be to log in as the person who is allowed to read it.
That is not an argument against encrypted services. It is an argument for securing the identity that sits behind the service. A planned move towards passkeys and stronger authentication can help reduce reliance on reusable passwords, but it still needs to be implemented and managed properly.
What about the device?
Confidential information eventually appears somewhere a human can read it.
That device matters.
A business should consider device encryption, screen locking, supported operating systems, patch management, endpoint protection, malware protection, device compliance, mobile-device controls, remote wipe where appropriate, local downloads and browser sessions.
A perfectly encrypted message displayed on an unmanaged, compromised laptop is no longer perfectly protected. The encryption may have done exactly what it was designed to do. The exposure happened at the point where an unauthorised person gained access to the device or the active session.
This is why endpoint security should be considered alongside communication security. A broader security review can help establish whether the devices accessing business information are supported, patched, protected and still visible to the organisation.
Personal phones create a governance question
Bring-your-own-device arrangements need a sensible discussion rather than an automatic assumption that personal devices are insecure.
If employees use personal phones for Outlook, Teams, messaging applications, business files or customer conversations, the business should ask:
- Can the business control access?
- Can business data be separated from personal data?
- Can access be revoked?
- Can company information be removed without wiping personal information?
- Are devices required to be supported and updated?
- What happens when somebody leaves?
Microsoft 365 can provide management options for company data on personal devices, but the available control depends on the licensing, configuration, device type and policy choices. Microsoft 365 Business Premium includes capabilities such as Microsoft Intune, Microsoft Entra ID and Microsoft Defender for Business that can help manage several of these layers. Buying the licence does not, by itself, make an organisation secure.
The issue is not ownership alone.
It is control.
If business information can leave with the employee's device, encryption was only part of the problem.
The backup may have different protection
Businesses should understand what happens when information is backed up or copied. A secure original does not guarantee that every copy is equally secure.
Ask:
- Is the backup encrypted?
- Who controls the encryption keys?
- Who can restore it?
- Which administrators can access it?
- How long is it retained?
- Can deleted information remain in backup?
- Is the backup protected from compromised production credentials?
These questions apply whether the copy is a Microsoft 365 backup, a file export, a message archive or a document downloaded into another platform. The answer should be based on the actual service and configuration, not a general assumption about how the original application works.
A Microsoft 365 backup and recovery review can help identify where copies exist, who can restore them and whether recovery has been tested. Backup is part of communication security because a message or attachment can remain sensitive long after it has left the original conversation.
Microsoft 365: security is more than encryption
Microsoft 365 security involves multiple layers. Depending on the service and the organisation's requirements, those layers can include identity, MFA, Conditional Access, device management, Defender, sharing controls, administrative roles, audit capability, retention, session controls and data protection.
That is why a Microsoft 365 security review should not ask only whether information is encrypted. It should also ask:
- Who can sign in?
- Which devices can access the information?
- Which administrators can change the controls?
- How widely can files and conversations be shared?
- What audit evidence exists?
- What happens to information when a user leaves?
Microsoft 365 Business Premium can give a business useful capabilities across identity, device management, endpoint protection and data security. Configuration and ongoing management still matter. An organisation can own the right features and leave them poorly configured, inconsistently applied or unchecked.
The useful outcome is not a longer list of Microsoft 365 features. It is confidence that the controls match the information and the risks.
WhatsApp and other messaging platforms
A messaging platform may provide strong technical protection for messages while the organisation still needs to consider business information governance.
This is not the same as saying a reputable encrypted messaging service is unsafe. It means that technical message security and business control are different questions.
For any messaging platform, a business may need to understand:
- which devices contain conversations;
- who owns and controls the account;
- what happens when an employee departs;
- how conversation history is handled;
- whether screenshots can be controlled;
- where downloaded documents are stored;
- whether customer records are being created outside the main business systems; and
- how business continuity and retention obligations are met.
A technically secure application does not automatically provide every control a business needs. The right question is whether the platform, accounts, devices and processes are proportionate to the information being shared.
Sharing is often the real problem
Many data exposures are not caused by someone breaking encryption.
Information may simply be sent to the wrong person, shared too widely, left accessible through an old link, downloaded to an unmanaged device, stored in the wrong location, retained after it is needed or left accessible through an old employee account.
This is why permissions and information governance matter. A person who is already allowed into a system may still have more access than they need. A link created for a short project may remain available long after the project has ended. A document shared securely may be downloaded into a location where the original controls no longer apply.
Security isn't only about stopping somebody breaking in. It's also about controlling who you've already let in.
Offboarding is part of communication security
When somebody leaves a business, organisations should understand what happens to their Microsoft 365 access, email, Teams, shared files, mobile applications, business messaging groups, CRM access, browser sessions, VPN access, administrator accounts and company devices.
Removing an account from one system may not terminate every active session or remove every local copy. A former employee may also have access through a shared account, an application integration, a personal phone or a browser session that was never reviewed.
Good offboarding should be a defined process rather than an improvised checklist after somebody has already left. The process should identify the accounts and devices involved, revoke access promptly, transfer ownership where necessary, review shared information and record what was checked.
Seven questions for your IT provider
- Which of our business communications are encrypted, and how?
- Is MFA enforced for everyone who can access confidential information?
- Can unmanaged or unsupported devices access business data?
- What happens to business information stored on personal phones?
- Where are copies and backups stored, and who can access them?
- Can we quickly revoke accounts, devices and active sessions when somebody leaves?
- Are these controls actually checked, or were they simply configured once?
That final question is particularly important. Security controls are not permanent facts. They need an owner, evidence and a review cycle.
Security controls need checking
Security is not:
Configure → Forget
Controls change. Users change. Devices change. Licences change. New accounts appear. Permissions accumulate. Applications get connected. Employees leave.
The important question is therefore not only whether the organisation has security controls. It is whether somebody is checking that those controls continue to operate as intended.
This is the practical point behind an Operational Heartbeat approach: security and IT controls need regular attention as the business changes. A review should look for drift, not just confirm that a feature was enabled at some point in the past.
Assurance comes from checking the control, not simply knowing the feature exists.
A practical communication security review
A concise review can be structured around eight questions:
- Identity — Who can sign in?
- Device — What can they sign in from?
- Data — What can they access?
- Sharing — Who else can they give access to?
- Backup — Where else does the information exist?
- Retention — How long does it remain?
- Offboarding — How quickly can access be removed?
- Assurance — Who checks that all of this still works?
This framework can be applied to Microsoft 365, email, CRM systems, file-sharing platforms, business messaging and other services that hold confidential information. It also provides a more useful starting point than asking whether the business has bought a particular security product.
The Altitude IT view
Encryption is essential.
Businesses should expect modern services to protect information appropriately while it is being stored and transmitted.
But encryption is one layer of a much larger security model.
A confidential conversation can still be exposed through:
- a compromised account;
- an unmanaged device;
- excessive permissions;
- a forgotten backup;
- an old employee;
- an insecure download; or
- poor sharing controls.
So instead of asking only:
“Is our data encrypted?”
ask:
“Who can access it, from which devices, where else does it exist, and are those controls still working?”
Encryption protects the information.
Good IT security protects the environment around it.