Your Messages Say They're Encrypted. But Who Can Actually Read Them?

Keep up with IT Club
Add IT Club as a preferred source in Google Search.
A practical SME guide to encryption in transit, encryption at rest, end-to-end encryption and the wider controls that determine whether business communications are actually private.
When a messaging service says that your conversations are encrypted, that sounds reassuring. It is reassuring. Encryption is one of the most important protections available for business communications.
But the word encrypted can describe several different protections. It does not, by itself, tell you who controls the account, where a backup is stored, which devices are signed in or what happens when an employee leaves.
The key distinction
Encryption protects the conversation. It does not automatically protect everything around the conversation.
Why encrypted does not always mean the same thing
There are three terms that are often used together but should not be treated as interchangeable.
Encryption in transit
Encryption in transit protects information while it is moving between systems. It helps prevent somebody who intercepts a connection from reading the message as it travels.
That protection is essential, but it does not describe what happens once the information arrives. The receiving service may still store, process or back up the message according to its design and your settings.
Encryption at rest
Encryption at rest protects stored information, such as a database, mailbox or device. It can reduce the value of stolen storage, but the service still needs a way to decrypt data for an authorised user or process.
End-to-end encryption
End-to-end encryption is designed so that the communication is decrypted at the endpoints rather than by an intermediary service. In simple terms, the sender and recipient hold the useful conversation keys while the service carries the protected content.
Do not assume that WhatsApp, Microsoft Teams, Outlook and every other collaboration platform use the same encryption model. Check the provider's documentation and the specific feature you are using.
The easiest way around encryption may not be breaking it
An attacker who successfully logs in as an authorised user may simply be able to read the information that account can legitimately access. The encryption can be working exactly as designed while the business still suffers a serious data exposure.
That is why strong communications privacy depends on more than cryptography. It also depends on identity, authentication, device security, permissions and the way people use the service.
- Compromised user accounts.
- Stolen or unlocked devices.
- Weak authentication or reused passwords.
- Cloud backups with different protection settings.
- Screenshots and copied text.
- Forwarded messages and exports.
- Malware or an unsafe browser session.
- Session theft.
- Poor offboarding when somebody leaves.
- Metadata that reveals who communicated and when.
What the UK privacy debate gets right
The current UK debate about private messaging has made a technical subject visible to a much wider audience. Polling commissioned by the Center for Democracy & Technology reported strong public support for the right to private online conversations and opposition to access without appropriate legal safeguards.
The policy arguments are not simple. Governments have legitimate interests in targeted, lawful investigation. Encryption advocates warn that weakening protection for everyone can create new opportunities for criminals, hostile states and ordinary data thieves. This article is not taking a party-political position. The business lesson is that a deliberate weakening of a technical boundary can affect every user, not only the person being investigated.
Reports about the Apple Advanced Data Protection dispute have also shown why businesses should distinguish between a provider's marketing language, a particular backup feature and the legal or technical controls around it. The exact service and jurisdiction matter.
Business messaging is an operating decision
SMEs often use WhatsApp for quick conversations, Teams for internal collaboration and Outlook for formal communication. That can work well, but only if the business understands what each service is allowed to carry and who controls it.
- What is encrypted in this service and feature?
- Where is the information stored?
- What is backed up, and under whose account?
- Which devices and browsers can access it?
- Who controls the business account?
- How quickly are former employees removed?
- Is multi-factor authentication enabled?
- What confidential information should not be shared there?
The practical security test
If an attacker obtained one employee's session today, what business information could they read, download or forward?
IT Club Communications Privacy Check
- 1Which messaging systems does the business use?
- 2Which systems are approved for business use?
- 3Is MFA enabled for every important account?
- 4Which devices can access each system?
- 5What happens when somebody leaves?
- 6Where are messages and backups stored?
- 7What confidential information is being shared?
- 8Are personal devices being used?
- 9Could somebody access messages simply by compromising the account?
- 10Does the business understand what encrypted means for each service?
The IT Club view
Strong encryption is valuable. Businesses should not dismiss it or weaken it casually. But encryption is one layer in a wider communications system.
Secure business communications also depend upon identity, devices, access control, authentication, backups, user behaviour and offboarding. The safest message is not that encryption solves privacy. It is that privacy needs the whole system to be understood.
Encrypted is the beginning
Encrypted should be the beginning of the conversation, not the end.
Not sure whether your business communications are actually private?
Ask the IT Club Advisor. Tell us which services you use and what you are trying to protect, and we will give you an independent view of the practical risks.
Sources and further reading
This is original IT Club commentary. Provider features and encryption models vary, so review the current documentation for the exact service and feature your business uses.
MK Link: Britons want their messages kept private →
Center for Democracy & Technology: UK encryption polling brief →
Plain-English Takeaway
Encrypted should be the beginning of the business-privacy conversation, not the end.
Frequently asked questions
Does encryption mean nobody else can read a business message?
No. It depends on which kind of encryption is being described, and whether an attacker can access an authorised account, unlocked device, backup, screenshot or forwarded copy.
Is end-to-end encryption the same as encryption in transit?
No. Encryption in transit protects information as it moves between systems. End-to-end encryption is designed so that only the communication endpoints can decrypt the content. The service, account and device controls still matter.
What should a small business check first?
List the messaging systems in use, confirm which are approved, enable MFA, review device access and make sure former staff are removed promptly. Then check where messages and backups are stored.
Can an encrypted service still leak business information?
Yes. A compromised account, stolen device, screenshot, forwarded message, exposed backup or revealing metadata can all undermine confidentiality without anyone breaking the underlying encryption.
Related Articles
Can a Webpage Trick Your AI Agent Into Doing Something Dangerous?
When an AI agent can read untrusted content and use powerful tools, the information it consumes becomes part of the attack surface.
Read articleWhen Cyberattacks Move at Machine Speed, Can Your Defences Keep Up?
An AI model has reportedly completed a full attack chain in controlled testing. The bigger question is what happens when attackers no longer need a human to choose every next step.
Read articleYou Can't Fix Every Cybersecurity Risk at Once. So What Comes First?
There will always be more cybersecurity work than time and budget. Here is a practical way to decide what genuinely needs fixing first.
Read article