TL;DR: PGP remains widely used for protecting sensitive enterprise files, but SSH Communications Security argues it creates operational friction through manual key management, weak trust verification, poor collaboration, and limited fit with onboarding, offboarding, and audit processes. The enterprise problem is not encryption strength alone, but whether identity, policy, and compliance can govern file access at scale.
At a glance
What this is: This analysis argues that PGP is a poor fit for enterprise file protection because its trust and key model depends on manual user behaviour instead of centrally governed identity and policy controls.
Why it matters: IAM, PAM, and NHI teams should care because file encryption that cannot align with directory identity, lifecycle processes, and auditability becomes a governance problem, not just a security tool choice.
Context
PGP is a file encryption model that assumes users can create, exchange, protect, and validate keys reliably. In enterprise settings, that assumption breaks down because access, collaboration, and accountability need to be governed through identity systems, not individual discipline.
The core governance gap is not encryption strength. It is whether file access can be tied to enterprise identity, policy, onboarding, offboarding, and audit trails without forcing employees to act as their own key administrators.
Key questions
Q: What breaks when PGP depends on user-managed keys in enterprise environments?
A: The control breaks when key custody depends on individual behaviour instead of governed identity. Lost keys, forgotten passphrases, and device changes turn encryption into an availability and support problem, while revocation becomes slow and uncertain. Enterprises need access decisions that survive turnover and can be administered centrally.
Q: Why does PGP create compliance and audit problems for file security?
A: Because audit and compliance need clear evidence of who could access what, when access changed, and how revocation was enforced. PGP often pushes those decisions outside enterprise identity systems, so the organisation cannot reliably prove access state or lifecycle control. That makes accountability harder, not easier.
Q: What are the signs that encrypted file sharing is not operationally governable?
A: Warning signs include users exchanging keys manually, partners struggling to join the workflow, help desks handling recovery issues, and audit teams lacking a clean record of access changes. Those symptoms show that encryption is working as a technical feature but failing as a business control.
Q: How should teams choose between user-managed encryption and policy-driven file access?
A: Choose policy-driven file access when the organisation needs predictable onboarding, offboarding, collaboration, and auditability. User-managed encryption can protect files, but it rarely scales into a governed enterprise control unless identity, classification, and revocation are enforced centrally.
Technical breakdown
Manual key management breaks enterprise file governance
PGP pushes key generation, storage, exchange, and recovery onto individual users. That model creates operational fragility because the security control depends on people remembering passphrases, replacing devices correctly, and preserving private keys across turnover and device changes. In enterprise environments, that is not a minor usability issue. It is a governance failure because the control plane is distributed across end users instead of being anchored in managed identity and lifecycle systems. Practical implication: centralise key and identity control so file access does not depend on personal key handling.
Practical implication: centralise key and identity control so file access does not depend on personal key handling.
Web of Trust does not scale to policy-driven trust
PGP’s Web of Trust expects humans to verify keys manually, but enterprises need trust decisions that are repeatable, auditable, and bound to business policy. When trust is informal, file access can drift away from approved identity state, data classification, and entitlement rules. The result is that the security decision is made outside the system that should govern it. That creates weak assurance for confidential files and makes compliance evidence hard to assemble. Practical implication: tie file decryption to directory-backed identity and classification policy, not peer-to-peer key validation.
Practical implication: tie file decryption to directory-backed identity and classification policy, not peer-to-peer key validation.
Collaboration fails when encryption is not identity-aware
Enterprise file sharing needs the same identity context that IAM already manages for applications and systems. PGP struggles here because external collaboration, group access, and directory integration are awkward or inconsistent, which slows legitimate work and encourages workarounds. Encryption becomes a barrier when it cannot recognise organisational identities or support controlled sharing with partners. That makes the control operationally brittle even if the cryptography itself remains sound. Practical implication: use file encryption that maps access to enterprise directories and shared identity workflows.
Practical implication: use file encryption that maps access to enterprise directories and shared identity workflows.
Breaches seen in the wild
- iOS apps leaking hard-coded secrets: Cybernews found 71% of 156,080 iOS apps leak hard-coded secrets, with open cloud storage and Firebase databases exposing user data.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
PGP fails as enterprise governance because it treats key custody as an individual duty rather than an identity lifecycle process. The article shows that lost keys, forgotten passphrases, and device churn are not edge cases, they are the normal operating condition. That is why PGP does not behave like a controllable enterprise access mechanism. The practitioner conclusion is that file encryption must be managed through the same lifecycle discipline used for other governed identities.
Trust-by-assertion is the real weakness in enterprise PGP deployments. The Web of Trust only works when people actually verify keys, and the article correctly notes that this usually does not happen. In enterprise terms, that means trust is inferred rather than enforced, which undermines both data classification and auditability. The practitioner conclusion is that trust decisions need to be policy-bound, not socially negotiated.
File encryption that is disconnected from directory identity creates collaboration friction that teams will route around. When employees and partners must manage separate keys, the control competes with productivity and loses. This is why enterprise encryption fails in practice even when the algorithm is strong. The practitioner conclusion is that secure file sharing must inherit enterprise identity context to remain usable at scale.
PGP exposes a governance gap between cryptographic protection and enterprise accountability. The article’s strongest point is that onboarding, offboarding, and audit trails do not align naturally with user-managed key handling. That means the organisation cannot easily prove who had access, when access changed, or whether revocation was effective. The practitioner conclusion is that file security has to be evaluated as a governed identity process, not as standalone encryption.
Policy-driven file access is the named concept that replaces PGP’s broken trust model. In this context, the control challenge is not stronger encryption but enforceable trust tied to classification and approved identity state. That changes the unit of control from the person holding a key to the enterprise system issuing access. The practitioner conclusion is that file protection should be governed where identity already lives.
What this signals
PGP is a key custody problem as much as an encryption problem. The enterprise failure mode is not weak algorithms, it is the assumption that end users can safely own the full trust lifecycle for sensitive files. Once that assumption is removed, the control has to move into directory-backed identity and policy enforcement.
File protection only becomes governable when access state lives in the same place as identity state. That is the real operational lesson here for IAM and NHI programmes. If encryption cannot inherit onboarding, offboarding, and classification rules, the organisation will keep compensating with process workarounds.
Policy-driven file access is the right mental model for enterprise collaboration. It shifts the decision from person-to-person trust toward system-enforced entitlement. For practitioners, that means file security should be designed as part of identity governance, not treated as a standalone cryptographic choice.
For practitioners
- Align file encryption with directory identity Bind decryption rights to enterprise directories such as Active Directory or LDAP so access follows approved identity state rather than user-managed keys.
- Remove manual key custody from end users Shift key handling, recovery, and revocation into centrally managed workflows so employees do not become their own key administrators.
- Tie access to data classification Require confidential files to inherit policy decisions from classification rules, so trust is enforced consistently rather than verified informally.
- Test offboarding against file access revocation Check whether leavers and external partners lose encrypted file access cleanly when identity status changes, without relying on manual key collection.
Key takeaways
- PGP can protect data cryptographically while still failing as an enterprise control because its trust and key model depends on manual user behaviour.
- The practical weak points are collaboration, revocation, and auditability, not encryption strength alone.
- Enterprise file security works better when decryption rights are tied to directory identity and policy rather than private key custody.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 — Improper Offboarding | The article ties file access problems to weak revocation and lifecycle handling. |
| NHI-05 — Overprivileged NHI | Manual trust and broad sharing can leave file access wider than policy intends. | |
| NHI-09 — NHI Reuse | Directory-backed sharing and shared access models can create repeated credential or trust reuse across workflows. | |
| Recommendation — Map encrypted file access to NHI offboarding controls so revoked users lose access cleanly. Audit file access scope against NHI-05 and remove entitlement paths that exceed business need. Review reused access paths under NHI-09 and separate file-sharing trust from reusable credentials. | ||
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | The article centres on the lifecycle problems created by manual key and passphrase handling. |
| Recommendation — Apply IA-5 to manage credential lifecycle and remove unmanaged private key dependence. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The main issue is whether file access can be governed through enterprise authorisation state. |
| Recommendation — Use PR.AA-05 to align file access decisions with enterprise authorisations and classification policy. | ||
Key terms
- Web of Trust: Web of trust is a decentralized model for establishing identity by having multiple parties vouch for one another. Instead of depending on a central certificate authority, trust is built through endorsements across participants. It can work in narrow communities, but it has limited adoption for large-scale enterprise assurance needs.
- Policy-Driven Trust: A trust model where access is granted or denied through centrally defined rules rather than personal verification. In enterprise encryption, it replaces informal key validation with identity-aware controls, so data classification, directory identity, and auditability determine who can decrypt sensitive files.
- Key Custody: Key custody is the ownership and control of cryptographic keys across their lifecycle, including storage, rotation, emergency use, and retirement. Poor custody turns encryption into a weak barrier because any identity with key access can recover data that should have remained protected.
- Directory-Backed Access: A model where access decisions inherit from enterprise identity systems such as Active Directory or LDAP. It lets file protection follow organisational roles and lifecycle changes instead of relying on separate, user-managed encryption workflows.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 7, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org