Every business exchanges sensitive information, whether client passwords, internal credentials, or private documents. Unfortunately, most common communication tools, like standard email and SMS text, are not designed to keep this information secure.
This bulletin outlines why it’s critical to encrypt sensitive communications, what can go wrong if you don’t, and what steps you can take right now to avoid a breach. It doesn’t mean encrypting everything, just the things that matter most.
1. Understand When Encryption Is Necessary
❗ Risks to Avoid
Intercepted login credentials or passwords shared over regular email or text
Identity theft or fraud from leaked personal client data
Compliance violations for sending unprotected sensitive information
✅ Steps to Take
Use encrypted platforms only when sending sensitive or confidential data
Continue using regular email/text for routine communication, but never for passwords, login info, SSNs, credit card numbers, or private documents
Make it standard practice to ask: “Is this sensitive?” before hitting send
📌 Why This Matters
Most email and text services don’t use end-to-end encryption. That means your message might pass through multiple servers before reaching the recipient, and any one of those could be compromised. If the message includes sensitive data, it’s exposed.
2. Real-World SMB Breaches
❗ Risks to Avoid
Believing you’re “too small” to be targeted
Assuming one-time info sharing (like a client password) is harmless
Underestimating how much damage a small leak can cause
✅ Steps to Take
Always send sensitive info via an encrypted platform, even once is enough to cause a breach
Create a company policy: Never email credentials or financial data unprotected
Review and replace any workflows that involve sending sensitive info over unsecured email
📌 Why This Matters
These aren’t hypothetical risks. Real small businesses have been hit
hard:
Automation Personnel Services (Staffing Firm): A data breach exposed SSNs, bank details, and contact info. Settlement cost: $1.375 million
KNP Logistics Group (UK): Hackers accessed internal data using a weak password. Operations collapsed. The company shut down after 158 years.
Small Tax Firm (U.S.): A client’s W-2 was emailed unencrypted. The client’s email was hacked within hours, and the W-2 was used to file fraudulent tax returns. There was no regulatory fine, but the firm lost several clients and suffered reputational damage.
3. Yes, This Includes PDFs, even Password-Protected Ones
❗ Risks to Avoid
Thinking a PDF with a password is “good enough”
Sharing tax returns, banking data, or logins in attached files
Using easily guessed or reused document passwords
✅ Steps to Take
Avoid sending sensitive info as attachments, PDFs included, unless transmitted through an encrypted channel
If you must send a password-protected PDF, use a unique, strong password and do not send the password in the same email or text
Update any old workflows that rely on “locking” documents with PDF passwords instead of encrypting transmission
📌 Why This Matters
Modern versions of Adobe Acrobat offer strong encryption, but that protection is only as good as the password used. Weak passwords can be cracked with simple tools. Even strong passwords are vulnerable if the file is intercepted and stored for later decryption. Password protection is better than nothing, but it’s not a substitute for true end-to-end encryption.
4. New Technologies Make the Threat Worse
❗ Risks to Avoid
AI-generated phishing that looks like it's from your staff or clients
Quantum computing developments that will soon crack older encryption standards
“Harvest now, decrypt later” attacks targeting sensitive files today
✅ Steps to Take
Use modern encryption tools now, they’re already built to resist AI-based fraud
Don’t delay switching from unsecured tools, even for internal use
Stay updated on quantum-safe encryption options for long-term protection
📌 Why This Matters
AI and automation are helping attackers just as much as defenders. In fact, 42% of organizations saw a spike in phishing and social engineering attacks in 2024 alone, largely driven by AI tools.
Quantum computing isn’t mainstream yet, but attackers are already collecting encrypted messages to decrypt later. Encrypted now is not enough, your tools must be built for what’s coming.
Source: World Economic Forum
Source: KPMG Cyber Risk from Quantum
5. Use These Trusted Encryption Tools
❗ Risks to Avoid
Emailing passwords or credentials through Outlook, Gmail, or your phone’s Messages app
Assuming built-in encryption (like Gmail’s in-transit TLS) is good enough
Relying on links, PDF passwords, or ZIP files for “security”
✅ Steps to Take
Signal: For encrypted mobile and desktop messaging. Free, open source, and widely trusted by security experts
PreVeil: For encrypted email and file sharing, fully integrated into Outlook and Gmail. Free plans offered.
Other excellent options:
Proton Mail (secure web-based email)
Tuta Mail (formerly Tutanota)
Virtru (email encryption with admin control for teams)
📌 Why This Matters
You don’t need to encrypt everything, but when sending something sensitive, it must be encrypted end-to-end. These tools make that easy, affordable, and scalable, even for teams of one.
6. Don’t Overlook Website Form Submissions
❗ Risks to Avoid
Website forms collecting sensitive info (e.g. SSNs, logins, health or financial data) and emailing it in plain text
Storing sensitive entries in insecure databases or sending them to unprotected inboxes
Thinking form submissions are safe just because the site uses HTTPS
✅ Steps to Take
Avoid emailing full form content when it includes sensitive information
Use a secure portal with login access to view or manage submitted data
Redact or remove sensitive data from email notifications entirely
📌 Why This Matters
Even if your website is secure, what happens after someone submits a form matters just as much. Many platforms email full form contents to an address, potentially exposing names, financial data, or passwords in unencrypted messages.
If you need assistance, we can help by:
Setting up secure login-based access to form entries
Configuring notification emails that don’t include sensitive content
It’s a small change that can make a big difference, especially for forms that collect client-facing or high-risk information.
Closing Note
We’re not suggesting that you overcomplicate your communication. We’re asking you to protect your business, your clients, and your data, by taking encryption seriously whenever it involves sensitive information.