The control breaks when key custody depends on individual behaviour instead of governed identity. Lost keys, forgotten passphrases, and device changes turn encryption into an availability and support problem, while revocation becomes slow and uncertain. Enterprises need access decisions that survive turnover and can be administered centrally.
Why user-managed PGP keys break down in enterprises
PGP is designed around user-held key custody, but enterprises need continuity, recoverability, and auditable administration. Once the private key lives on a person’s laptop, in a browser plugin, or in a local export file, security becomes tied to that person’s habits and devices rather than to governed access. Cloud Workload Identity Guide illustrates the broader move away from static key custody toward centrally governed, keyless or short-lived identity patterns.
That shift matters because PGP key management is not just about encrypting data, it is about whether the enterprise can still decrypt, rotate, and recover access when employees leave, change devices, or forget a passphrase. The weak point is the human-operated key lifecycle, not the cipher itself. When key ownership is individual and informal, the organisation loses reliable control over availability and revocation.
In practice, the enterprise stops being able to treat encrypted mail or files as a managed service. A supposedly secure message becomes inaccessible if the user is unavailable or the key is gone, and support teams end up depending on ad hoc exports, shared escrow habits, or informal workarounds. Central control is what turns encryption from a personal tool into an operationally supportable control. NIST SP 800-57 Key Management is useful here because it frames the core issue as lifecycle discipline, not just cryptography.
Where the operational failure shows up first
The first break is usually availability. Lost keys, forgotten passphrases, device resets, and mailbox or laptop replacement can make encrypted content unreadable long after the original sender expected it to remain accessible. If recovery depends on a single user remembering a local secret, the enterprise has already accepted a hidden single point of failure.
The second break is revocation. When a person leaves, changes role, or is compromised, the organisation needs a fast, confident way to stop relying on that key. With user-managed PGP, revocation may be slow, inconsistent, or not operationally enforced across all recipients and archives, which means the enterprise cannot clearly prove who can still decrypt what.
The third break is supportability. Help desks and security teams are forced into exception handling, manual recovery, and one-off key export workflows that are hard to audit and even harder to standardise. That creates a gap between the encryption policy on paper and the reality of how people keep working. NIST Cybersecurity Framework 2.0 maps well to this because the issue spans governance, protection, and recovery rather than a single technical control.
What enterprises should replace it with
Enterprises usually need a model where access survives personnel change and is administered centrally, even if the underlying cryptography remains strong. That means key storage, issuance, revocation, and recovery should be governed through an organisational process, not left to each user to improvise. The goal is not to remove encryption, but to remove dependence on fragile individual custody.
For many environments, that translates into managed key directories, policy-driven rotation, escrow or recovery controls where justified, and integration with identity and device governance. For other cases, especially cloud and workload workflows, it may be better to avoid long-lived user-held keys entirely and use short-lived credentials or federated identity patterns instead. NIST Privacy Framework is useful as a governance lens when the organisation must balance access continuity with exposure and recovery expectations.
For teams operating in mixed environments, PGP can still be used, but only where the key lifecycle is genuinely manageable at scale and the recovery model is explicit. If the answer to “who can restore access after loss or turnover?” is “the user,” the design is already too brittle for enterprise use.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-57 and NIST CSF 2.0 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-57 | Key Management | PGP failure here is fundamentally a key lifecycle problem. |
| Recommendation — Define issuance, storage, rotation, recovery, and revocation procedures for enterprise keys. | ||
| NIST CSF 2.0 | PR.AA-05 — Managed Access Control | Centralised access decisions are needed when key custody cannot depend on users. |
| RC.RP-01 — Recovery Plan Execution | Lost or replaced keys create a recovery requirement for encrypted business data. | |
| Recommendation — Enforce centrally managed access paths instead of user-held custody alone. Test recovery procedures for encrypted content after loss, turnover, or device changes. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | Enterprise key custody must be governed as part of access control policy. |
| A.8.24 — Use of cryptography | The subject is the operational use of cryptography in a managed environment. | |
| Recommendation — Specify centrally governed access control rules for encryption keys and recovery. Control cryptographic use with lifecycle, ownership, and recovery requirements. | ||
Practitioner Guidance
What to prioritise: Treat recovery and revocation as first-class requirements, not afterthoughts. If encrypted data must remain useful after leave, device loss, or passphrase failure, the operating model needs an administrative recovery path before rollout.
What to verify: Confirm who owns each private key, how backups are handled, how revocation propagates, and whether encrypted business content remains decryptable during offboarding and incident response. If those answers depend on informal user behaviour, the control is not enterprise-ready.
Common mistake: Assuming that strong encryption automatically means strong control. In this case, the brittle part is custody and lifecycle management, so stronger cryptography can still produce weaker operations if the enterprise cannot govern the keys.
Practitioner takeaway: The decisive question is not whether PGP works technically, but whether the organisation can still administer access when the individual user is absent, compromised, or gone.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 10, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org