Best Practices: Encrypted Communications

Every business exchanges sensitive information, whether client passwords, internal credentials, or private documents. Unfortunately, most common communication tools, like standard email and SMS text, are not designed to keep this information secure.

This bulletin outlines why it’s critical to encrypt sensitive communications, what can go wrong if you don’t, and what steps you can take right now to avoid a breach. It doesn’t mean encrypting everything, just the things that matter most.

1. Understand When Encryption Is Necessary

Risks to Avoid

  • Intercepted login credentials or passwords shared over regular email or text

  • Identity theft or fraud from leaked personal client data

  • Compliance violations for sending unprotected sensitive information

Steps to Take

  • Use encrypted platforms only when sending sensitive or confidential data

  • Continue using regular email/text for routine communication, but never for passwords, login info, SSNs, credit card numbers, or private documents

  • Make it standard practice to ask: “Is this sensitive?” before hitting send

📌 Why This Matters

Most email and text services don’t use end-to-end encryption. That means your message might pass through multiple servers before reaching the recipient, and any one of those could be compromised. If the message includes sensitive data, it’s exposed.

2. Real-World SMB Breaches

Risks to Avoid

  • Believing you’re “too small” to be targeted

  • Assuming one-time info sharing (like a client password) is harmless

  • Underestimating how much damage a small leak can cause

Steps to Take

  • Always send sensitive info via an encrypted platform, even once is enough to cause a breach

  • Create a company policy: Never email credentials or financial data unprotected

  • Review and replace any workflows that involve sending sensitive info over unsecured email

📌 Why This Matters
These aren’t hypothetical risks. Real small businesses have been hit hard:

  • Automation Personnel Services (Staffing Firm): A data breach exposed SSNs, bank details, and contact info. Settlement cost: $1.375 million

  • KNP Logistics Group (UK): Hackers accessed internal data using a weak password. Operations collapsed. The company shut down after 158 years.

  • Small Tax Firm (U.S.): A client’s W-2 was emailed unencrypted. The client’s email was hacked within hours, and the W-2 was used to file fraudulent tax returns. There was no regulatory fine, but the firm lost several clients and suffered reputational damage.

3. Yes, This Includes PDFs, even Password-Protected Ones

Risks to Avoid

  • Thinking a PDF with a password is “good enough”

  • Sharing tax returns, banking data, or logins in attached files

  • Using easily guessed or reused document passwords

Steps to Take

  • Avoid sending sensitive info as attachments, PDFs included, unless transmitted through an encrypted channel

  • If you must send a password-protected PDF, use a unique, strong password and do not send the password in the same email or text

  • Update any old workflows that rely on “locking” documents with PDF passwords instead of encrypting transmission

📌 Why This Matters

Modern versions of Adobe Acrobat offer strong encryption, but that protection is only as good as the password used. Weak passwords can be cracked with simple tools. Even strong passwords are vulnerable if the file is intercepted and stored for later decryption. Password protection is better than nothing, but it’s not a substitute for true end-to-end encryption.

4. New Technologies Make the Threat Worse

Risks to Avoid

  • AI-generated phishing that looks like it's from your staff or clients

  • Quantum computing developments that will soon crack older encryption standards

  • “Harvest now, decrypt later” attacks targeting sensitive files today

Steps to Take

  • Use modern encryption tools now, they’re already built to resist AI-based fraud

  • Don’t delay switching from unsecured tools, even for internal use

  • Stay updated on quantum-safe encryption options for long-term protection

📌 Why This Matters

AI and automation are helping attackers just as much as defenders. In fact, 42% of organizations saw a spike in phishing and social engineering attacks in 2024 alone, largely driven by AI tools.

Quantum computing isn’t mainstream yet, but attackers are already collecting encrypted messages to decrypt later. Encrypted now is not enough, your tools must be built for what’s coming.

  • Source: World Economic Forum

  • Source: KPMG Cyber Risk from Quantum

5. Use These Trusted Encryption Tools

Risks to Avoid

  • Emailing passwords or credentials through Outlook, Gmail, or your phone’s Messages app

  • Assuming built-in encryption (like Gmail’s in-transit TLS) is good enough

  • Relying on links, PDF passwords, or ZIP files for “security”

Steps to Take

  • Signal: For encrypted mobile and desktop messaging. Free, open source, and widely trusted by security experts

  • PreVeil: For encrypted email and file sharing, fully integrated into Outlook and Gmail. Free plans offered.

  • Other excellent options:

📌 Why This Matters

You don’t need to encrypt everything, but when sending something sensitive, it must be encrypted end-to-end. These tools make that easy, affordable, and scalable, even for teams of one.

6. Don’t Overlook Website Form Submissions

Risks to Avoid

  • Website forms collecting sensitive info (e.g. SSNs, logins, health or financial data) and emailing it in plain text

  • Storing sensitive entries in insecure databases or sending them to unprotected inboxes

  • Thinking form submissions are safe just because the site uses HTTPS

Steps to Take

  • Avoid emailing full form content when it includes sensitive information

  • Use a secure portal with login access to view or manage submitted data

  • Redact or remove sensitive data from email notifications entirely

📌 Why This Matters

Even if your website is secure, what happens after someone submits a form matters just as much. Many platforms email full form contents to an address, potentially exposing names, financial data, or passwords in unencrypted messages.

If you need assistance, we can help by:

  • Setting up secure login-based access to form entries

  • Configuring notification emails that don’t include sensitive content

It’s a small change that can make a big difference, especially for forms that collect client-facing or high-risk information.

Closing Note

We’re not suggesting that you overcomplicate your communication. We’re asking you to protect your business, your clients, and your data, by taking encryption seriously whenever it involves sensitive information.

Notice: The information provided in this document is for informational purposes only and does not constitute legal, financial, or professional advice. All materials and guidance offered by Generose Corporation dba Risingline are subject to its Client Services Agreement and Website Terms of Use and are provided without warranty as to accuracy, completeness, or applicability to any specific situation. While Risingline takes reasonable precautions to ensure the reliability of the information presented, compliance with regulatory requirements varies based on specific circumstances, jurisdiction, and evolving standards. Recipients are encouraged to conduct independent due diligence and consult with qualified professionals before implementing any recommendations. Generose Corporation dba Risingline expressly disclaims any liability for actions taken or not taken based on this document. Receipt of this information does not establish a client, advisory, or fiduciary relationship between Risingline and the recipient.

All articles