Skip to content

Home Expertise / Data protection

DAT / DAT-04

Encryption, key and certificate management

Protect data and communications through cryptography while organising key and certificate storage, rotation and recovery. Encryption that prevents recovery can itself become a risk.

WHEN IT HELPS

A focused response
to a defined need.

Untracked certificate expiry, unencrypted disks, scattered secrets, contractual encryption requirements or dependence on one person holding recovery keys.

AT A GLANCE

Family
Data protection

Engagement
Implementation and advisory

Reference
DAT-04

SCOPE & OUTCOMES

What the engagement covers.

Scope

  • Inventory
  • use cases
  • encryption at rest/in transit
  • key management
  • PKI where needed
  • renewal
  • revocation
  • key backup
  • access controls
  • recovery

Deliverables

  • Cryptographic architecture
  • certificate register
  • lifecycle rules
  • recovery procedures
  • separation of duties
  • tests
  • operations instructions

Acceptance evidence

Encryption works for selected use cases; renewal and revocation are tested; key access is restricted and logged; authorised people can perform recovery.

DELIVERY

How the work is structured.

Approach

Identify data and owners; define policies; pilot on sensitive scope; measure errors; roll out and organise exceptions.

Prerequisites & responsibilities

Customer: business data owners, DPO/legal/HR as relevant, administrators and retention rules. Provider: technical design and verification within agreed permissions.

Scope factors

Repositories, volumes, categories, channels, populations, formats and permission quality. DLP/classification licensing and event handling are separate from deployment.

Questions to clarify

Who holds and can use keys? What happens when a certificate expires? How are encrypted data restored after losing the primary system?

IMPORTANT BOUNDARIES

Encryption does not fix excessive access in an application that decrypts data. Cryptographic choices and any qualification requirements need specialist validation.

Minimisation, proportionality and investigation confidentiality must be scoped. No guarantee of zero leakage or comprehensive legal opinion.

IN PRACTICE

Illustrative situations.

These examples describe possible engagements and target outcomes. They are not customer references or achieved results.

Scenario 01

A company suffers certificate-related outages. Project: establish inventory, ownership and controlled renewal. Target outcome: tracked expiry and testable renewal, with non-automatable certificates explicitly managed.

Scenario 02

A team encrypts backups without recovery procedures. Project: secure keys and perform an independent restore. Target outcome: protected yet recoverable data; old backups without keys are not labelled recoverable.

Technology and reference context

Examples: key-management services, PKI and platform encryption capabilities; HSMs when justified by requirements.

The final technology set is agreed during scoping, based on interoperability, licensing, access rights and operating requirements.

CONNECTED SERVICES

Build the next step.

These services can complement the engagement. They are not automatically included.

START A CONVERSATION

Make the scope clear.

We will clarify the objective, dependencies and responsibilities of this service before proposing delivery.