The security questionnaire asks: “Is data encrypted at rest and in transit?” You check “yes” for everything. But your public blog images are not encrypted. Your marketing email list is. Your internal wiki is not. Your customer database is.
At Metaluxo we review encryption strategies for SMEs. The correct answer is not “everything is encrypted.” It is “sensitive data is encrypted appropriately, and here is the evidence.” This post explains when each type of encryption matters.
Encryption at rest
Protects against: Physical theft, unauthorised access to storage, backup compromise, disposal failures.
When it matters:
- Databases containing personal data
- File storage with confidential documents
- Backups and archives
- Mobile devices and laptops
- Removable media (USB drives, external disks)
When it does not matter:
- Public marketing content
- Already-public source code
- Anonymous analytics data
Standard: AES-256. For databases, transparent data encryption (TDE) or volume-level encryption. For files, client-side encryption before upload.
Encryption in transit
Protects against: Interception, man-in-the-middle attacks, eavesdropping on networks.
When it matters:
- Any data sent over the internet
- Internal API communication between services
- Data sent between offices or to cloud providers
- Email containing confidential information
When it does not matter:
- Internal traffic on a fully isolated, physically secure network (rare in cloud environments)
- Public content served over HTTPS (the encryption protects integrity, not confidentiality, because the content is public)
Standard: TLS 1.3, or TLS 1.2 with strong cipher suites. Never SSL, never unencrypted HTTP for authenticated traffic.
The decision matrix
| Data type | At rest | In transit | Notes |
|---|---|---|---|
| Customer personal data | Yes | Yes | Non-negotiable |
| Payment card data | Yes | Yes | PCI DSS requirement |
| Health records | Yes | Yes | GDPR special-category requirement |
| Employee records | Yes | Yes | Employment law and GDPR |
| Marketing content | No | Yes (HTTPS) | Public content, but TLS protects integrity |
| Internal documentation | Yes | Yes | Confidential business information |
| Public API responses | No | Yes | Encryption protects against tampering |
| Logs and monitoring | Yes | Yes | May contain sensitive operational data |
| Backups | Yes | Yes | Separate key management from production |
Key management
Encryption is only as strong as key management. Every SME should:
- Use a key management service (AWS KMS, Azure Key Vault, Google Cloud KMS) rather than hardcoding keys
- Separate keys by environment — production, staging, and development must not share keys
- Rotate keys annually or after a suspected compromise
- Restrict key access — only the services that need the key should have it
- Maintain a key inventory — what keys exist, what they protect, who has access, when they rotate
At Metaluxo we review encryption strategies for SMEs as part of our security assessments. If you are preparing for an audit and need to document your encryption controls, book a free 30-minute consultation and we will map your data against the appropriate standards.
Common questions
Is encryption at rest required by GDPR?
Not explicitly, but it is the most commonly cited technical safeguard. The ICO recommends encryption as a means of ensuring security and preventing unauthorised access.
What encryption standard is considered secure?
AES-256 for data at rest and TLS 1.3 (or TLS 1.2 with strong cipher suites) for data in transit are the current standards. MD5, SHA-1, and SSL are obsolete.
Do we need to encrypt backups?
Yes. Unencrypted backups are a common source of data breaches. Backup encryption should use the same standard as production data, with separate key management.