Join our Newsletter — 33% off our NHI Course

PGP and enterprise file encryption: where the governance gap is

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 21730
Topic starter  

TL;DR: PGP remains widely used for protecting sensitive enterprise files, but SSH Communications Security argues it creates operational friction through manual key management, weak trust verification, poor collaboration, and limited fit with onboarding, offboarding, and audit processes. The enterprise problem is not encryption strength alone, but whether identity, policy, and compliance can govern file access at scale.

Editorial analysis by NHI Mgmt Group, based on content published by SSH Communications Security: “Why PGP Breaks in the Enterprise and How FQX Fixes It”.

Key questions

Q: What breaks when PGP depends on user-managed keys in enterprise environments?

A: The control breaks when key custody depends on individual behaviour instead of governed identity.

Q: Why does PGP create compliance and audit problems for file security?

A: Because audit and compliance need clear evidence of who could access what, when access changed, and how revocation was enforced.

Q: What are the signs that encrypted file sharing is not operationally governable?

A: Warning signs include users exchanging keys manually, partners struggling to join the workflow, help desks handling recovery issues, and audit teams lacking a clean record of access changes.

Practitioner guidance

  • Align file encryption with directory identity Bind decryption rights to enterprise directories such as Active Directory or LDAP so access follows approved identity state rather than user-managed keys.
  • Remove manual key custody from end users Shift key handling, recovery, and revocation into centrally managed workflows so employees do not become their own key administrators.
  • Tie access to data classification Require confidential files to inherit policy decisions from classification rules, so trust is enforced consistently rather than verified informally.

Bottom line: PGP can protect data cryptographically while still failing as an enterprise control because its trust and key model depends on manual user behaviour.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 1 day ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

PGP fails as enterprise governance because it treats key custody as an individual duty rather than an identity lifecycle process. The article shows that lost keys, forgotten passphrases, and device churn are not edge cases, they are the normal operating condition. That is why PGP does not behave like a controllable enterprise access mechanism. The practitioner conclusion is that file encryption must be managed through the same lifecycle discipline used for other governed identities.

A question worth separating out:

Q: How should teams choose between user-managed encryption and policy-driven file access?

A: Choose policy-driven file access when the organisation needs predictable onboarding, offboarding, collaboration, and auditability. User-managed encryption can protect files, but it rarely scales into a governed enterprise control unless identity, classification, and revocation are enforced centrally.

👉 Read our full editorial: PGP fails enterprise file security because trust and keys break


This post was modified 1 day ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.