It depends on what you send. Whether email encryption for small business is worth arranging comes down to the files that move through your inboxes. Where those files carry sensitive personal data, such as Social Security numbers, passwords or account information, the FTC’s business guidance on protecting personal information says regular email is not a secure method for sending sensitive data and calls encrypting any transmission that contains information fraudsters or identity thieves could use the better practice. So the safer course is to use encryption or another secure way to deliver them.

Encryption scrambles a message or file so that only someone with the right key or access can read it. A sensitive file sent by regular email can end up in inboxes, sent folders, phones and forwarded copies your business doesn’t control. If a mailbox is compromised, or a message reaches the wrong person, client information can go with it. That may cost you client trust and create cleanup work.

Where nothing sensitive leaves your office by email, the pressure is lower. Your staff still need a rule that tells them the difference.

Is regular email safe for sending sensitive client files?

For a sensitive client file, treat regular email as the wrong carrier. The FTC’s guidance for businesses puts it plainly: regular email is not a secure method for sending sensitive data. Ordinary messages that carry nothing sensitive are a different matter. The question is what the attachment holds.

What the FTC says

The same guidance says the better practice is to encrypt any transmission that contains information a fraudster or identity thief could use. It also tells businesses to caution employees against sending sensitive personally identifying data, such as Social Security numbers, passwords and account information, by email, and adds that unencrypted email is not a secure way to transmit information. That is general guidance for businesses that handle personal information. It isn’t a law or a contract term, and nothing in this article is legal advice.

Where a copy can end up

An attachment is a copy. Once you send it, that copy can sit in several places, some of which you can’t reach:

  • your own sent folder
  • the recipient’s inbox
  • phones and tablets that sync either mailbox
  • backup copies of either mailbox
  • anywhere the recipient decides to forward it

One sent file may therefore exist in more places than you can account for. Deleting your copy doesn’t recall the others.

Which client files count as sensitive?

Start with the FTC’s examples: Social Security numbers, passwords and account information. Then build your own list, because you know what your clients hand you. A business may reasonably add signed forms, copies of ID, bank or card statements and tax documents. Nothing here decides that list for you.

Two cautions are worth carrying into the exercise. Don’t assume a file is ordinary because it’s routine for you, since a client may see it differently. And a document can be sensitive because of one line inside it, not because of its title. If you want to know what else belongs on your list, that’s a conversation for your own advisers.

A two-bucket sort

You can do this in one sitting. Open your sent folder and read back through the last stretch of outbound mail. Write down the kinds of files that went out, not every message. Then drop each kind into one of two buckets: sensitive, which travels by the secure method, or ordinary, where regular email is fine.

Anything you’re unsure about goes in the sensitive bucket until you decide otherwise. That’s a recommendation, and it keeps the judgment call off a staff member’s shoulders while a client waits.

What does email encryption do, and what does it leave open?

Encryption can protect contents. It can keep a message or attachment from being read by someone who gets hold of it along the way. What it may not do is control people. It may not stop a message going to the wrong address, a recipient forwarding your file after opening it, or someone taking over a mailbox.

Where the encryption comes from depends on your email platform and plan. It may be built in, available as an add-on, or offered through a secure link or portal instead of the message itself. Your IT provider can say which applies to your setup.

One difference matters more than the labels. Some setups can encrypt certain outbound messages automatically, by rule. Others rely on the sender to remember a step. A step people can forget is a step that can fail, so ask which one you’d be living with.

Mailbox takeover is its own subject, and our article on phishing and business email compromise covers the attacks that can lead to it.

How can a sensitive file reach a client more safely?

Pick a method your client can open, then use it every time. Encrypted email is one route, whether the platform applies it by rule or the sender chooses it. A secure link to a file kept in business storage is another. So is a client portal. A password on the document is a fourth option, with limits.

  • Encrypted email. The message can travel protected, either by a rule your platform applies or by a choice the sender makes.
  • A secure link. The file can stay in your business storage and the client opens it there, which may let you control who opens it and for how long, depending on how that storage is set up.
  • A client portal. Clients sign in to collect and send documents, so the file may never ride in a message at all.
  • A password on a document. This may add protection, though how much depends on how the file was protected and how the password reaches the client. A password sent in the same message may add little.

Whatever you choose, a method clients can’t open can get bypassed. Staff may fall back to a plain attachment to finish the job, and the rule can quietly stop existing. So ask how a client opens an encrypted message or link, then try it with a friendly client before it becomes the rule.

There’s an administrator side to this as well — who can open a shared link, whether a file can be forwarded outside the business — and our post on where customer data leaves a small office covers those controls.

What should you ask your IT provider?

Ask what your current email setup can already do before you buy anything. A provider can answer that in plain terms, and the answer may change what you need. Keep the questions in business language, and write the answers down. You’re deciding how client files travel, and that decision should outlive one conversation.

  • What can our current email plan already encrypt?
  • Can sensitive messages be encrypted automatically, or does a staff member have to remember a step?
  • How does a client open an encrypted message or link, and what happens when they can’t?
  • Who can see a file after we send it, and for how long?
  • What happens to access to shared files when a staff member leaves?

O&O Systems’ email security and spam protection page lists automatic encryption for outbound messages among what its service includes. That’s what the page offers, not a verdict on your office. Whether any setup fits depends on how your business sends files, and no tool or provider can promise that nothing will go wrong.

Separately, O&O Systems offers a free Domain Security Risk Assessment, and its page describes a scan of your own domain with a summary of risks across email, cloud, web and infrastructure, including risky email configurations such as missing DKIM and DMARC. That’s a scan of a domain, and it’s a separate check from the questions above.

Then get the answers in writing. The memory of a phone call won’t help the next person who has to send something sensitive.

How do you turn the answer into a rule your staff will follow?

Write it on one page. Name what counts as sensitive and the method that carries it. Name the person to ask when someone isn’t sure. Then say what to do when a client sends something sensitive to you by regular email. A short rule is easier to follow.

On that last point, a reasonable approach is to reply through the safer method so the next exchange goes that way, and to ask your IT provider before forwarding the file around the office. Those are recommendations. Your provider may suggest something that suits your setup better.

Review the page when staff change, when your provider changes, or when your email setup changes. And walk through it with the people who send the files. Training is where a rule stops being paperwork.

Frequently Asked Questions About Email Encryption for Small Business

What should we do when a client emails us a sensitive file?

Answer the client, then fix the path. A reasonable approach is to reply through the method you want used, so the next document arrives that way, and to ask your IT provider before forwarding the file around the office. There’s no need to scold the client, who may simply have used the easiest route.

Does putting a password on an attachment count as encryption?

It may add protection, but it isn’t the same as a method your platform or provider sets up. How much it adds depends on how the file was protected and on how the password reaches the client. A password typed into the same message may add little, because whoever reads the message has both halves.

Will encryption make our messages harder for clients to open?

It can add a step for the recipient, depending on the method. Test that before you commit. Ask how a client opens the message or link, then try it with a client who’ll tell you honestly. A method your clients can’t manage can get worked around, and a worked-around rule protects little.

Is email encryption the same thing as a spam filter?

No. The two do different jobs. A spam filter concerns what reaches your inbox. Encryption concerns whether a message’s contents can be read on the way, including mail that leaves your office.

Does email encryption make our business compliant?

No tool or provider can promise compliance, and nothing here is legal or compliance advice. What your business has to do can depend on factors such as your industry, the data you hold and the agreements you’ve signed with clients and partners. That’s a question for your own attorney or other advisers. Encryption is a practical step, not a guarantee.

Who in the office should own the rule?

One named person, with the authority to answer in the moment. It can be an operations lead, an office manager or the owner. What matters is that staff know who to ask when a file is borderline, and that the same person keeps the page current when the email setup or the provider changes.

Want to know what your email setup can already encrypt?

Start with what you’re sending. Sort the files, write the one-page rule, then put the questions above to whoever supports your email. If that’s a conversation you’d rather have with a technology partner, contact O&O Systems about how your business sends sensitive client files.