Join our Newsletter — 33% off our NHI Course
Home FAQ Cyber Security Why can encrypted communication still fail in practice…
Cyber Security

Why can encrypted communication still fail in practice for sensitive organisations?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated August 28, 2026 Domain: Cyber Security

Encryption protects message content, but it does not automatically solve identity assurance, device compromise, poor configuration, or insecure user workflows. Secure communication fails when the surrounding system is built for convenience rather than resilience. Organisations need controls for verified participants, secure onboarding, managed endpoints, and governance over where sensitive conversations can happen.

Why This Matters for Security Teams

Encrypted communication is often treated as the finish line, but for sensitive organisations it is only one layer of protection. If identity is weak, endpoints are compromised, or users are pushed into unmanaged channels, the content of the message can still be exposed through screenshots, forwarding, mailbox takeover, or metadata leakage. NIST’s NIST SP 800-53 Rev 5 Security and Privacy Controls makes clear that communications security depends on the surrounding control environment, not encryption alone. NHIMG’s DeepSeek breach analysis shows how exposed credentials and poor exposure management can undermine otherwise sensitive systems. The same pattern appears in communications: the technical channel may be encrypted, yet the operational path remains open.

Security teams also underestimate how quickly trust breaks when onboarding, device posture, and user behaviour are inconsistent. A secure channel with weak participant verification is still a risky channel, because the wrong person can be invited, impersonate a user, or inherit access from a compromised account. In practice, many security teams encounter encrypted-message failures only after a mailbox compromise, phishing event, or shadow-IT messaging app has already widened the blast radius.

How It Works in Practice

Encrypted communication fails when organisations focus on transport secrecy and ignore identity assurance, endpoint health, and conversation governance. Strong practice starts with verified participants, device checks, and explicit rules for which tools may carry sensitive data. The goal is not just to encrypt the message, but to ensure that the sender, recipient, and device are all trustworthy at the moment of exchange.

That usually means combining several controls:

  • Require strong identity proofing and phishing-resistant authentication for access to sensitive channels.
  • Enforce managed or attestable endpoints so encryption is not defeated by malware, unmanaged backups, or browser extensions.
  • Use short-lived access and session controls so exposed accounts do not retain broad communications access.
  • Define approved communication paths for regulated, legal, or executive content instead of letting teams choose convenience-first tools.
  • Log and review message creation, sharing, invitation changes, and export activity so misuse is visible after the fact.

This is where communication security becomes a governance problem as much as a cryptographic one. Encryption protects data in transit and often at rest, but it does not prevent a compromised recipient device from reading the message, copying attachments, or forwarding content to a less secure workspace. Current guidance suggests treating collaboration systems like high-risk identity surfaces, not simple productivity tools. The operational lesson aligns with NIST control thinking and with NHIMG’s reporting on The State of Secrets in AppSec, where fragmented control and human workflow gaps repeatedly create exposure.

These controls tend to break down when organisations rely on unmanaged mobile devices, personal messaging apps, or cross-border collaboration workflows because identity assurance and policy enforcement become inconsistent across endpoints and jurisdictions.

Common Variations and Edge Cases

Tighter communication controls often increase friction, requiring organisations to balance confidentiality against speed, usability, and business continuity. That tradeoff is real, especially for executive teams, incident response groups, clinicians, lawyers, and international operations where quick coordination matters.

Best practice is evolving for several edge cases. For example, end-to-end encrypted consumer apps may be acceptable for low-risk discussion, but they are usually unsuitable for sensitive records because organisations cannot reliably govern retention, eDiscovery, device posture, or participant vetting. Similarly, email encryption may satisfy content protection requirements while still leaving metadata, subject lines, forwarding paths, and account recovery flows exposed. In highly sensitive environments, the question is not whether encryption exists, but whether the full communication lifecycle is controlled.

There is no universal standard for this yet, but practitioners increasingly pair encryption with NIST SP 800-53 Rev 5 Security and Privacy Controls, strict device governance, and policy restrictions on approved channels. NHIMG’s DeepSeek breach coverage is a reminder that exposure often starts outside the encryption layer, in the credentials, systems, or workflows around it.

Encrypted communication becomes unreliable when the organisation cannot prove who is participating, where the message is being opened, or whether the surrounding workflow is already compromised.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-63, NIST Zero Trust (SP 800-207) and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC-1Identity assurance is central when encrypted channels are accessed by sensitive users.
NIST SP 800-63Strong authentication and identity proofing reduce impersonation in secure messaging.
OWASP Non-Human Identity Top 10NHI-01Compromised identities and secrets undermine secure communications despite encryption.
NIST Zero Trust (SP 800-207)Zero trust requires continuous verification of users, devices, and sessions.
NIST AI RMFGovernance must cover how sensitive communications are authorised and monitored.

Use phishing-resistant authentication and higher assurance identity proofing for sensitive channels.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 28, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org