Essential Data Encryption Guide for Small Businesses
A practical encryption guide for small businesses covering file transfer, cloud storage, email, and device encryption essentials for 2026.
A small business needs encryption in four places: on employee devices (FileVault on Mac, BitLocker on Windows 11 Pro), in cloud storage (Google Workspace CSE, Microsoft 365 encrypted at rest, Cryptomator for BYOC), in email (S/MIME via Microsoft 365 E3 or ProtonMail Business), and for file transfers to clients (HexaTransfer, Tresorit Send, SwissTransfer). Total monthly cost for a 10-person team sits between $80 and $300 depending on which services you pick. You don't need a CISO to set this up — you need a weekend and a checklist.
The Regulatory Floor Most Small Businesses Miss
GDPR applies to any business that handles data of EU residents, regardless of company size — there's no small-business exemption, only reduced reporting obligations under Article 30(5) for organizations under 250 employees. CCPA (California) and its successor CPRA kick in at $25M revenue, 100,000+ consumer records, or 50% revenue from data sales. HIPAA covers every healthcare provider, regardless of headcount. PCI DSS 4.0 applies the moment you touch a credit card number.
Encryption isn't explicitly mandatory in most of these, but it's the single cheapest safe-harbor mechanism. Under 45 CFR 164.402 (HITECH), properly encrypted ePHI that's breached doesn't require notification. GDPR Article 34(3)(a) waives notification requirements when data was encrypted. That math alone often pays for the tooling.
Device Encryption: Free and Mandatory
FileVault (macOS) and BitLocker (Windows 11 Pro) are free and enabled by default on most new hardware. Both use AES-XTS-128 or AES-XTS-256. Your job is to verify it's actually on across every laptop:
- macOS:
System Settings → Privacy & Security → FileVault - Windows:
Settings → Privacy & Security → Device encryption - Linux: LUKS2 with
cryptsetup, typically configured at install
Store recovery keys in a password manager or 1Password Teams vault, not in a spreadsheet or sticky note. A stolen unencrypted laptop containing customer PII triggers full GDPR Article 33 notification within 72 hours — a four-figure fine minimum, plus reputational damage.
Cloud Storage: Provider Encryption vs Client-Side
Google Workspace, Microsoft 365, and Dropbox Business all encrypt data at rest (AES-256) and in transit (TLS 1.3). But they hold the keys. A subpoena, rogue employee, or provider breach exposes plaintext. For most small businesses, this provider-managed encryption is adequate — your threat model is probably ransomware and lost laptops, not state-level adversaries.
Step up to client-side encryption for anything regulated. Google Workspace Client-Side Encryption (CSE) lets you integrate a Thales or Fortanix KMS so Google stores only ciphertext. Microsoft offers Double Key Encryption (DKE) in the E5 tier. Below that price point, Cryptomator ($5 one-time mobile, free desktop) wraps any cloud with AES-256-GCM transparently.
Email Encryption Without a PhD
Small businesses have three practical options:
- ProtonMail Business ($7.99/user/month): E2EE by default between ProtonMail users, password-protected messages for external recipients, PGP export for power users.
- Microsoft 365 Message Encryption (included in E3): web-portal-based encrypted email for external recipients, S/MIME inside the tenant.
- Tutanota Business (€3/user/month): EU-based, E2EE subjects and bodies, calendar and contacts included.
For contract-level communications with law firms or accountants, either ProtonMail or S/MIME via M365 is sufficient. The trap is using regular Gmail for anything sensitive and hoping TLS covers you — it doesn't, because Gmail itself reads every message.
File Transfer to Clients
Email attachment limits (25 MB Gmail, 20 MB Outlook.com) push every business into some file-transfer solution. The choices that keep you compliant:
- HexaTransfer: client-side AES-256-GCM, 10 GB per transfer, no account required, 7-day expiry. Free tier covers most small-business needs.
- Tresorit Send: E2EE, 5 GB free tier, unlimited on Business ($14/user/month).
- SwissTransfer: 50 GB per transfer, optional E2EE mode, hosted by Infomaniak in Switzerland.
- WeTransfer Pro: 20 GB, password protection, but not end-to-end encrypted — files are readable by WeTransfer servers.
For HIPAA workflows, verify the provider will sign a Business Associate Agreement. For GDPR, check where servers are located — Article 44 restricts transfers outside the EEA without specific safeguards.
Password Management Is Part of the Encryption Stack
Every encryption tool depends on a secret: a device password, a vault master key, a shared transfer password. If employees use Summer2025! across every service, the cryptography is theater. Deploy 1Password Teams ($7.99/user/month), Bitwarden Business ($6/user/month), or Dashlane Business ($8/user/month) before rolling out anything else. All three use AES-256-GCM locally with PBKDF2 or Argon2id key derivation.
Enforce MFA (Microsoft Authenticator, 1Password built-in TOTP, or hardware YubiKeys at $50 each) on admin accounts at minimum, ideally everywhere. A leaked password + no MFA is how 80% of small-business breaches actually happen — not exotic cryptanalysis.
A Realistic 30-Day Rollout
Week 1: audit every laptop, verify FileVault/BitLocker, document who holds what. Week 2: deploy a password manager and migrate shared credentials out of spreadsheets. Week 3: pick an encrypted-email and encrypted-file-transfer solution, train the team on both. Week 4: write a one-page data-handling policy covering which tool to use for which type of file, and run a tabletop exercise pretending a laptop was stolen. Revisit quarterly.
Budget Cheat Sheet for 10 People
| Layer | Product | Monthly | |---|---|---| | Devices | FileVault / BitLocker | $0 | | Password manager | 1Password Teams | $80 | | Cloud + email | Google Workspace Business Standard | $144 | | Encrypted email add-on | ProtonMail Business (5 execs) | $40 | | File transfer | HexaTransfer (free) | $0 | | MFA hardware | YubiKey 5 (one-time, amortized) | $42 | | Total | | ~$306 |
Drop ProtonMail and you're under $270 — the cost of one hour of an incident-response consultant. For the file-transfer slot, try it at hexatransfer.com — free, no account, 10 GB max.
Send large files securely with end-to-end encryption
Transfer files up to 10 GB for free with end-to-end encryption. No account required. Your files are encrypted in your browser before upload — no one else can read them.
Send a file