Site icon TechTalks

Why don’t more businesses encrypt their emails?

Businesses rarely encrypt their email messages because good encryption is too hard to use.  That’s changing.

By Randy Battat, PreVeil

Most business-to-business communication involves sensitive information – stuff that the parties really don’t want others to know about. Whether it’s contracts, customer communications, supplier information, dialog with consultants and contractors, or other things, there’s a lot of sensitive information that travels via plain old email.

These emails really should be protected, i.e. encrypted. But the vast majority of B2B communication remains unencrypted, despite wide availability of very good technology and tools. Why?

The answer is that good encryption is too hard to use – there’s too much friction involved in encrypting an email versus sending a message unprotected. The bad news is that huge amounts of important business communication is at risk. The good news is that apps are starting to emerge that provide both excellent usability and strong encryption.

The risks are real

Many people think that it’s only necessary to protect information that’s obviously sensitive or private – credit card information, social security numbers, medical records, etc.  But consider the opposite:  try to think of email messages which, if plastered all over the Internet, would not cause concern. The conclusion is that almost every message really should be protected.

If this thought experiment isn’t convincing, consider the impact of several well-publicized attacks:

Proper encryption would likely have prevented much of this damage.

A brief overview of encryption technology and apps

The basic technology behind encrypted email has been around for 40 years. The idea is to encrypt a message using a key that’s known only to the sender and recipients. The message can be sent over a public medium, i.e. the Internet, because it appears to be gibberish to anyone except those who possess the decryption key.

The usability issues arise not from encryption itself, but from key management. There must be secure ways of getting keys from sender to recipients. This is accomplished through something called Pubic-key Cryptography, where each user is assigned a pair of keys. The first is called a public key, and it’s given to anyone who wishes to send a message to a particular user. The second is called a private key, it’s kept only by the user themselves as it’s the key used to decrypt messages sent by some using the corresponding public key.

The complexity lies in creating, distributing, and managing all these keys. It usually takes a sophisticated user or an IT administrator to do this. Managing keys for email users within an organization is complicated enough; doing so for users across organizations is even more so. As a result, encryption is used only in limited circumstances where critical information must be protected.

Encrypted email and messaging that people can actually use

New apps are emerging that combine ease-of-use with end-to-end encryption. End-to-end encryption means that only the sender and recipient can see a message. The information is never made visible to anything in-between, including network routers or message servers.

Mobile apps started the trend. Facebook’s WhatsApp is a great example of an app that’s extremely easy to use, encrypts all messages end-to-end, and manages keys automatically and transparently for the user. WhatsApp shows how key management complexities can be hidden so that encryption doesn’t interfere with users sending and receiving messages.

What about plain old email? Well, this is the problem we’re trying to solve at my company PreVeil.  The app uses end-to-end encryption and is compatible with mail programs like Microsoft Outlook and Apple Mail, and can be used in PC browsers and on mobile devices.  There are no passwords in the system, and keys are managed for the user. It offers the protection and usability of WhatsApp, but for email. We’re excited about making encryption usable for anyone who uses email, and expect continued innovation in this market to solve the email security problem.

Encrypt everything

With strong encryption that’s easy to use, businesses and individuals will soon be able to encrypt all of their communications. After all, the most precious resource to an organization is its information. It’s time we started protecting it a lot better.

Randy Battat is founder, president and CEO of PreVeil, the application for end-to-end encrypted email, file sharing and storage for people and organizations that want to protect their data.

Exit mobile version