Hire the Best Internet Security Specialists

More than 3,000 reviews on G2
Rating is 4.5 out of 5.
4.5/5
of Upwork by G2 peer reviewers
David M.

Tonbridge, United Kingdom

$75/hr
5.0
3 jobs

๐Ÿ”’ You need security that actually works โ€” not a report that says it does. The organisations I work with want to find the vulnerabilities that matter, fix them with confidence, and get on with growing their business without security becoming the thing that stops them. I have delivered over 1,000 commercial penetration tests across 27 years. Not side projects. Not internal assessments. Full mission-critical engagements for high street and investment banks, hedge funds, insurance firms, government departments, police, military, national infrastructure, retailers, law firms, airports and more. I led the security architecture for the Athens 2004 Olympics internet-facing systems. I was lead architect on the UK Cyber Essentials scheme at launch. I have published in commercial security press and guest lectured at universities. There is a difference between someone who does penetration testing and someone who has seen every flavour of environment, every attack pattern, and every way organisations deceive themselves about their security posture. That difference is what you are hiring. ๐ŸŽฏ Where can I help: ๐Ÿ—ก๏ธ Network & Infrastructure Penetration Testing โ€” adversarial testing of internal and external infrastructure, finding exploitable exposures before an attacker does. ๐ŸŒ Application Penetration Testing โ€” web application and API security testing against real attack patterns: authentication, authorisation, input handling and business logic flaws. โ˜๏ธ Microsoft 365 Security Assessment โ€” Entra ID, Conditional Access, PIM, Intune, DLP, sensitivity labelling, Exchange Online and Defender for Office 365. ๐Ÿ”ท Azure Security Assessment โ€” identity and access management, network controls, storage and key management, Defender for Cloud posture, and monitoring coverage. ๐ŸŸข Google Workspace, GCP & AWS Security Assessments โ€” configuration and access control assessments across Google and Amazon cloud environments. ๐Ÿ›๏ธ Security Architecture and Risk Advisory โ€” senior technical input on architecture decisions, control design and risk without a full engagement commitment. ๐Ÿ‘ค Every engagement is delivered directly by me โ€” David Morgan, founder of Metis Security. No account management layer, no junior handoffs, no templated output. You work with the person conducting the analysis and writing the report. ๐Ÿ“‹ How I work is as important as what I find Every finding in my reports is one I will defend as genuinely material to your environment. No padding, no low-hanging fruit included to justify the fee, no default risk ratings copied from a scanner. If your context changes the risk, the rating reflects that. What you receive: โœ… A visually structured report with clear separation between executive summary, findings and remediation roadmap โ€” written to be read by people who are not security specialists โœ… Risk ratings adjusted to your specific environment and context, not defaulted from a tool โœ… A prioritised remediation roadmap so your team knows exactly what to fix first and why it matters commercially โœ… Immediate escalation of any high-risk finding or schedule-affecting issue during the engagement โ€” you are never waiting until the end to hear something important โœ… Daily status updates so you always know where the engagement stands โœ… A debrief call at close to walk through findings, answer questions and finalise the report before it is delivered CISSP | ISSAP | Microsoft Security certifications | 27 years If you need to know whether your environment is genuinely secure โ€” not whether it looks configured โ€” I am worth a conversation.

  • Penetration Testing
  • Web Application Security
  • Network Penetration Testing
  • Office 365
  • Microsoft Azure
  • Cloud Security
  • Network Security
  • Vulnerability Assessment
  • Security Assessment & Testing
  • Security Infrastructure
  • Cybersecurity Management
  • Zero Trust Architecture
  • Security Analysis
  • Google Cloud Platform
  • Google Workspace
  • Amazon Web Services
  • ISO 27001
  • NIST Cybersecurity Framework
  • NIST SP 800-53
  • Network Administration
Pankaj R.

Chandigarh, India

$20/hr
4.9
123 jobs

Is your digital infrastructure secure against today's sophisticated threats? I specialize in identifying and mitigating security vulnerabilities before they can be exploited. With a focus on real-world penetration testing and comprehensive malware cleanup, I ensure your systems are robust and resilient. ๐Ÿ› ๏ธ Services I Provide: Web & API Penetration Testing: Combining manual and automated techniques to uncover vulnerabilities. WordPress Security & Malware Removal: Protecting your site from threats and ensuring smooth operation. Network & Server Vulnerability Scanning: Utilizing tools like OpenVAS and Wireshark for thorough assessments. Compliance-Oriented Security Assessments: Ensuring adherence to standards such as PCI-DSS and ISO 27001. Email Setup & Security Hardening: Securing communications with platforms like Gmail, Hostinger, and SendGrid. ๐Ÿ“ˆ Highlights: 4+ Years Experience | CEH Certified 20+ Projects Delivered with 5-Star Ratings Expertise in OWASP Top 10, CVSS, and MITRE ATT&CK Post-audit Guidance and Remediation Support 100% Confidentiality | NDA-Friendly I am committed to delivering high-quality security solutions tailored to your needs. Let's work together to fortify your digital presence.

  • Information Security
  • Security Assessment & Testing
  • Penetration Testing
  • Malware Removal
  • Ethical Hacking
  • Compliance
  • Web App Penetration Testing
  • Cloud Security
  • WordPress Security
  • Cloudflare
  • DNS
  • Google Workspace
  • Firewall
  • Technical Support
  • Linux System Administration
  • Windows Administration
  • Email Deliverability
Nandy B.

Lehigh County, Pennsylvania

$85/hr
5.0
280 jobs

๐Ÿ—ฝ U.S. and ๐Ÿ Canada -only clients โ˜‘๏ธ Upwork Expert-Vetted ๐ŸŒŸ | 100% Job Success โœ… | 10,000+ hours ๐Ÿ’ป on 200+ projects Hi there! ๐Ÿ‘‹ Iโ€™m an Upwork veteran with over 10,000 hours delivered, 200+ successful projects, and $1M+ earned helping U.S. companies secure and scale their cloud and hybrid environments. โ˜๏ธ I specialize in Azure, Microsoft 365, and security-focused systems โ€” delivering: โ€ข Secure infrastructure using Zero Trust, IaC (Terraform/Bicep), and DevSecOps pipelines โ€ข Incident response, forensics, and breach containment across regulated industries โ€ข Compliance-ready solutions aligned to SOC 2, HIPAA, ISO 27001, and NIST 800-53 As a certified consultant, I work directly with technical teams to deliver secure cloud transformation, implement controls, and respond to threats โ€” fast. I also collaborate with Microsoftโ€™s internal dev teams, giving me early-access insights and practical fixes 3โ€“4 release cycles ahead of public rollout. Why Choose Me? โœ… $1M+ in security projects delivered across healthcare, fintech, crypto, and gov sectors ๐Ÿ” Architected Azure landing zones, GitOps pipelines, and zero trust cloud environments ๐Ÿšจ Led incident response and forensic investigations for Fortune 500 and defense clients ๐Ÿ“Š Built compliance workflows and policy-as-code enforcement for audit success ๐Ÿช™ Secured crypto CI/CD pipelines and smart contract environments with GitHub, Checkov, GHAS ๐Ÿง  Career Highlights: โ–ช Delivered security modernization and audit readiness for global government contractors and Fortune 500 companies โ–ช Led compliance remediation and data protection initiatives across healthcare, fintech, and public sector clients โ–ช Migrated global users to Microsoft 365 with security-first design โ€” Exchange, Purview, Intune, Defender โ–ช Built hybrid identity strategies (Entra ID, ADFS, GoDaddy 365, Azure AD B2C, custom policy support) โ–ช Managed VMware-to-Azure hardening with conditional access, audit enforcement, and security baselines ๐Ÿ”ง Solutions I Deliver: โ€ข Azure Infra Security: Terraform, Bicep, Azure Policy, RBAC, Defender for Cloud โ€ข DevSecOps: GitHub Actions, tfsec, Checkov, Trivy, GHAS, pipeline reviews โ€ข Microsoft 365 Hardening: Defender, Purview, Compliance Center, Intune, Exchange โ€ข Compliance & Audits: SOC 2, ISO 27001, HIPAA, GDPR, NIST, CIS Benchmarks โ€ข Incident Response & Forensics: Malware analysis, reverse engineering, breach recovery โ€ข Crypto Security: CI/CD for smart contracts, wallet infra hardening, Web3 audits โ€ข Reverse-engineered malware to identify attack vectors and harden systems post-breach โ€ข Hardened Microsoft Exchange Online and Defender for Email in phishing-prone orgs โ€ข Integrated Azure Sentinel analytics with dashboards for cross-cloud visibility ๐Ÿค Retainer & Advisory Support: โ€ข Ongoing guidance for CISOs, security architects, and compliance teams โ€ข Monthly retainers for SOC 2 evidence collection, security tool reviews, and policy automation โ€ข Rapid-response engagements for forensics, malware recovery, and breach root cause analysis ๐Ÿงฐ Platforms & Tools: โ€ข Azure, Microsoft 365, Azure Sentinel, Microsoft Defender (all modules), Intune โ€ข Terraform, Bicep, GitHub, Azure DevOps, GitOps, GHAS โ€ข Splunk, FTK, EnCase, Wireshark, Autopsy, Cisco ASA/Firepower โ€ข Checkov, Trivy, Aqua Security, smart contract security tooling โ€ข Compliance: SOC 2, HIPAA, ISO 27001, CIS, NIST, GDPR ๐Ÿ“… Letโ€™s set up a free 30-minute consultation to explore how I can help you with security transformation, compliance readiness, or urgent recovery โ€” no fluff, just fast, proven results. I bring the calm in chaos โ€” whether you're planning secure growth or cleaning up after a breach, Iโ€™ll steady the course and deliver results. ๐Ÿ“Œ Helped a fintech client pass SOC 2 in under 60 days ๐Ÿ“Œ Responded to ransomware, restored 95% of systems in 48 hours ๐Ÿ“Œ Hardened crypto wallet infra securing $100M+ in assets Thanks again for stopping by. You can invite me to your job post or simply send a message to arrange a quick discovery call โ€” I respond fast, and weโ€™ll keep everything inside Upwork. โ€” Nandy Bo ๐Ÿ—ฃ๏ธโ ๐™„๐™ฉ ๐™๐™–๐™จ ๐™—๐™š๐™š๐™ฃ ๐™– ๐™ฅ๐™ก๐™š๐™–๐™จ๐™ช๐™ง๐™š ๐™ฉ๐™ค ๐™ฌ๐™ค๐™ง๐™  ๐™ฌ๐™ž๐™ฉ๐™ ๐™‰๐™–๐™ฃ๐™™๐™ฎ ๐™™๐™ช๐™ง๐™ž๐™ฃ๐™œ ๐™ฉ๐™๐™š ๐™ฉ๐™ง๐™–๐™ฃ๐™จ๐™ž๐™ฉ๐™ž๐™ค๐™ฃ ๐™ค๐™› ๐˜พ๐™–๐™ก๐™ก๐™˜๐™ค๐™ข. ๐™‰๐™–๐™ฃ๐™™๐™ฎ ๐™ž๐™จ ๐™ซ๐™š๐™ง๐™ฎ ๐™œ๐™š๐™ฃ๐™ช๐™ž๐™ฃ๐™š, ๐™๐™ค๐™ฃ๐™š๐™จ๐™ฉ ๐™–๐™ฃ๐™™ ๐™๐™š๐™ก๐™ฅ๐™›๐™ช๐™ก ๐™ž๐™ฃ ๐™ฃ๐™–๐™ฉ๐™ช๐™ง๐™š. ๐™ƒ๐™š ๐™–๐™ก๐™จ๐™ค ๐™๐™–๐™จ ๐™– ๐™ซ๐™š๐™ง๐™ฎ ๐™ž๐™ฃ-๐™™๐™š๐™ฅ๐™ฉ๐™ ๐™ ๐™ฃ๐™ค๐™ฌ๐™ก๐™š๐™™๐™œ๐™š ๐™ค๐™› ๐™„๐™ ๐™ฌ๐™๐™ž๐™ก๐™š ๐™ข๐™–๐™ž๐™ฃ๐™ฉ๐™–๐™ž๐™ฃ๐™ž๐™ฃ๐™œ ๐™– ๐™ซ๐™š๐™ง๐™ฎ ๐™—๐™ง๐™ค๐™–๐™™ ๐™ฅ๐™ง๐™ค๐™—๐™ก๐™š๐™ข-๐™จ๐™ค๐™ก๐™ซ๐™ž๐™ฃ๐™œ ๐™ค๐™ช๐™ฉ๐™ก๐™ค๐™ค๐™ . ๐™๐™๐™š๐™จ๐™š ๐™›๐™š๐™–๐™ฉ๐™ช๐™ง๐™š๐™จ ๐™ข๐™–๐™ ๐™š ๐™๐™ž๐™ข ๐™ฃ๐™ค๐™ฉ ๐™ค๐™ฃ๐™ก๐™ฎ ๐™– ๐™ฅ๐™ก๐™š๐™–๐™จ๐™ช๐™ง๐™š ๐™ฉ๐™ค ๐™ฌ๐™ค๐™ง๐™  ๐™ฌ๐™ž๐™ฉ๐™ ๐™—๐™ช๐™ฉ ๐™–๐™ก๐™จ๐™ค ๐™ซ๐™š๐™ง๐™ฎ ๐™ž๐™ฃ๐™จ๐™ฅ๐™ž๐™ง๐™–๐™ฉ๐™ž๐™ค๐™ฃ๐™–๐™ก. โž โ€” ๐™…๐™ค๐™ง๐™™๐™ค๐™ฃ ๐˜ฝ๐™ž๐™ก๐™ก - ๐™ˆ๐™–๐™ฃ๐™–๐™œ๐™ž๐™ฃ๐™œ ๐˜ฟ๐™ž๐™ง๐™š๐™˜๐™ฉ๐™ค๐™ง - ๐˜พ๐™–๐™ก๐™ก๐™˜๐™ค๐™ข ๐™„๐™ฃ๐™ฉ๐™š๐™ง๐™ฃ๐™–๐™ฉ๐™ž๐™ค๐™ฃ๐™–๐™ก

  • Solution Architecture Consultation
  • Cloud Implementation
  • Information Security
  • Cloud Security
  • Microsoft Endpoint Manager
  • Risk Assessment
  • Cloud Engineering Consultation
  • Microsoft Azure
  • Office 365
  • Email Security
  • Microsoft Exchange Online
  • Digital Forensics
  • Incident Response Readiness Assessment
  • Information Security Audit
Harwinder K.

Hoshiarpur, India

$25/hr
5.0
2,675 jobs

โšก TOP RATED Freelancer | โšก 14+ Years Experience in Web Security and WordPress Hello! I am Harwinder Kumar, a seasoned professional specializing in comprehensive Web Security and WordPress. I offer services in Malware Removal, Virus Removal, Ethical Hacking, Internet Security, Websites Migration, WordPress Development, SSL Installation, Linux Server Administration, Domain & DNS Management, WordPress Speed Optimization and Zen Cart / Drupal / MODX / Moodle / Joomla CMS Upgrades. Achievements: โœ… Cleaned 5000+ websites successfully from malware with security enhancement. โœ… Conducted 1,000+ seamless website migrations. โœ… Completed more than 500 SSL installations. โœ… Optimized speed of 200+ WordPress websites. Services Offered: 1. Malware and Virus Removal (Cleaning Hacked Websites and Servers): โœ” Guaranteed 100% cleanup of websites, including databases from malicious code. โœ” Remediation of WP-VCD malware, backdoors, malicious javascript and conditional redirects. โœ” Specialized solutions for japanese keyword hack, SEO spam / pharma hack, credit card stealers and ecommerce malware. โœ” Google blacklist removal (This site may be hacked, The site ahead contains malware), google deceptive warning fix. โœ” McAfee SiteAdvisor, norton blacklist or any VirusTotal based blacklist fix. 2. Website Security Maintenance: Strategic security enhancements and guidance for future-proofing your digital assets. 3. Website Transfer and Migration: Expert transfer of websites to new hosts or domains for any PHP-based CMS or custom-coded websites, including seamless email migration 4. WordPress Development and Troubleshooting: Comprehensive development and issue resolution, including critical and fatal error fixes. 5. SSL Installation and HTTPS Migration: Seamless migration from HTTP to HTTPS with secure padlock implementation. 6. HTTP Security Headers Fix: Implementation of essential security headers to protect your web application from common vulnerabilities and threats. 7. Linux Server Administration: Efficient server management promoting optimal performance and security. 8. WordPress Speed Optimization: Proven methods to enhance website performance following Google PageSpeed and GTmetrix standards. 9. Domain & Advanced DNS Management: โœ” Expert management of domain settings and DNS configurations to ensure seamless website accessibility and performance. โœ” Configuration and troubleshooting of DKIM, SPF, and DMARC records to enhance email security and deliverability. 10. CMS Upgrades: Upgrading Zen Cart, Drupal, MODX, Moodle and Joomla to their latest stable versions. If you're looking for a trusted partner to secure, optimize and enhance your digital operations, I am here to deliver superior solutions tailored to your needs. Let's collaborate to ensure your website is both secure and performing at its peak!

  • Internet Security
  • Website Security
  • Network Security
  • Malware Removal
  • Penetration Testing
  • Virus Removal
  • SSL
  • WordPress
  • WordPress Malware Removal
  • Website Migration
  • Information Security
  • WordPress Security
  • Domain Migration
  • Malware Detection
  • DNS
  • WordPress Development
  • Elementor
  • Ethical Hacking
  • WordPress Migration
  • PSD to WordPress
Petar A.

Sabac, Serbia

$50/hr
4.9
264 jobs

โœ… Professional Penetration Tester โœ… 3500+ Hours โœ… Top Rated Plus Freelancer Security Researcher and Penetration Tester recognized by the U.S. Department of Defense, AT&T, Sony, and Semrush for the responsible disclosure of 40+ vulnerabilities via HackerOne. Since 2022, an active member of the Synack Red Team - an elite tier of offensive security specialists vetted through rigorous technical and background screening. Every engagement concludes with a comprehensive technical report built to satisfy the specific penetration testing controls required for HIPAA, ISO 27001, SOC2, and PCI-DSS. I provide a high-level executive summary for stakeholders alongside deep-dive technical findings, fully reproducible Proofs-of-Concept (PoCs), and prioritized remediation steps to ensure your team can effectively close every gap before your audit. Specializing in black and gray box testing of live web applications, cloud environments, and networks, covering all common attack vectors, business logic flaws, and discovering previously undisclosed vulnerabilities (0days) to prevent high-impact data breaches. Service Description: 1) Web Application Penetration Testing (OWASP Top 10, PTES, ASVS, Business Logic Testing) 2) Mobile Application Penetration Testing (OWASP Top 10, MASVS, MASTG, PTES) 3) Network Penetration Testing (Active Directory, Entra ID, Internal & External Network) 4) API Security Testing - REST, GraphQL, SOAP, gRPC, Webhooks (OWASP API Top 10) 5) Cloud Security Testing - AWS/Azure/GCP/OCI/Alibaba/IBM/DigitalOcean/SaaS/IaaS/PaaS 6) Cloud-Native & Container Security (Kubernetes, Docker, OpenShift, EKS/AKS/GKE) 7) LLM Security Testing (OWASP LLM Top 10, Prompt Injection, Data Poisoning) Tools used in engagements: BurpSuite Professional | Custom Python scripts | BloodHound | Impacket Framework | Responder | Metasploit | Mimikatz | Nuclei | Nmap | FRIDA | Android Studio | Pacu | Prowler | Postman Identify and secure your attack surface before threat actors do ! Message me to discuss your project requirements.

  • Internet Security
  • Vulnerability Assessment
  • Penetration Testing
  • Network Security
  • Security Testing
  • Network Penetration Testing
  • Web App Penetration Testing
  • Ethical Hacking
  • Black Box Testing
  • Reverse Engineering
  • JavaScript
  • Web Application Security
  • Cloud Security
  • API
  • AI Security
  • OWASP
  • NIST SP 800-53
  • HIPAA
  • PCI DSS
  • Bug Bounty
Jeff Q.

Palmer, Iowa

$40/hr
5.0
72 jobs

Networking support: SSLs, Security, DNS, malware & virus removal, bot protection, site transfers, server support: Linux, Redhat, Ubuntu, MacOS, Windows Server, IIS and Apache. I am A+ Comptia certified with a Cisco Networking Essentials certificate, and Amazon AWS Cloud Practitioner certificate. Can build custom WordPress plugins. We specialize in WordPress and eCommerce. We can get your business up and processing credit cards with Stripe, Braintree, PayPal, Authorize .Net, or just about anyone you want. I am an experienced PHP WordPress Developer with a strong background in web development, networking and SQL. I have a proven track record of building and maintaining WordPress sites, developing custom plugins, and managing complex network systems. My expertise extends to various programming languages, operating systems, and web technologies, making me a versatile and valuable asset. Jeff has years of experience with the web technology & computer networking and holds degrees in Technology, Business, plus has numerous certifications. Network Administrator for Windows Server 2022, 2019, 2016, 2012, also for Linux Redhat, and Ubuntu. Get your business online today with a 100% PCI Compliant payment solution. Don't take chances with your customer's credit card information; risking costly charge backs, lost revenue, or legal problems. Have us do your payment forms. SKILLS: Languages/Scripts: PHP, JavaScript, MySQL, MariaDB, HTML, XHTML, CSS3, Regular Expressions, XML & XSLT, ASP, VBScript, Perl, JQuery, JSON, SOAP, Pascal, Assembly Language for 680x0 processors Operating Systems: Windows Server 2022, 2019, 2016, 2012R2, 2008, 2003; Windows Desktop: 11, 10, 8.1, 8, 7, Vista, XP; Mac OS X, Classic Macintosh, Linux, RHEL (Red Hat), CentOS, Ubuntu, Oracle, Fedora, Debian, Rocky, Alma Linux, Cisco IOS, Apple iOS, Android, and more . . . Web: Internet Information Server (IIS) 10, 8, 7, 6 Apache 2, WordPress, Elementor, WooCommerce Software: Adobe CC, Creative Suites CS6, CS5, CS4, Dreamweaver CC, Visual Studio, MS Expression Web 4, Photoshop, GIMP, Illustrator, Inkscape, Office 365 Networking: Active Directory, VirtualBox, Hyper-V, VMWare, PowerShell, VPN, DNS, cPanel, WHM Accounting: Peachtree, Sage 50, QuickBooks, Tax Preparation, GnuCash, Deprecation, Payroll, Inventory Terms: Minimum billing is one (1) hour.

  • WordPress
  • Virus Removal
  • Website Migration
  • Linux System Administration
  • Apache HTTP Server
  • Windows Server
  • Microsoft IIS
  • Ubuntu
  • macOS
  • WooCommerce
  • Web Development
  • PayPal Integration
  • Ecommerce

How it works

Post a job for free Post a job

Tell us what you need. Create your own job post or generate one with AI then filter talent matches.

Hire top talent fast

Consult, interview, and hire quickly, so you can meet the freelancers you're excited about.

Collaborate easily

Use Upwork to chat or video call, share files, and track project progress right from the app.

Payment simplified

Manage payments in one place with flexible billing options. Only pay for approved work, hourly or by milestone.

Don't just take our word for it

How to Hire Internet Security Specialists

Encryption Basics: How It Works & Why You Need It

What is encryption and how does it work?

While IT security seeks to protect our physical assetsโ€”networked computers, databases, servers, etc.โ€”encryption protects the data that lives on and between those assets. Itโ€™s one of the most powerful ways to keep your data safe, and while it isnโ€™t impenetrable, itโ€™s a major deterrent to hackers. Even if data does end up getting stolen, it will be unreadable and nearly useless if itโ€™s encrypted.

How does it work? Encryptionโ€”based on the ancient art of cryptographyโ€”uses computers and algorithms to turn plain text into unreadable, jumbled code. To decrypt that ciphertext into plaintext, you need an encryption key, a series of bits that decode the text. The key is something only you or the intended recipient has in their possession. Computers are capable of breaking encrypted code by guessing an encryption key, but for very sophisticated algorithms like an elliptic curve algorithm, this could take a very, very long time.

Hereโ€™s a very simple example. Say you want to encrypt this sentence: โ€œProtect your data with encryption.โ€ If you use a 39-bit encryption key, the encrypted sentence would look like this:

โ€œEnCt210a37f599cb5b5c0db6cd47a6da0dc9b728e2f8c10a37f599cb5b5c0db6cd47asQK8W/ikwIb97tVolfr9/Jbq5NU42GJGFEU/N5j9UEuWPCZUyVAsZQisvMxl9h9IwEmS.โ€

You can send that encrypted message to someone, separately share the key, then theyโ€™re able to decrypt it and read the original sentence.

If you send an encrypted email, only the person with the encryption key can read it. If youโ€™re using an encrypted internet connection to shop online, your information and credit card number are hidden from unauthorized users, like hackers, illegal surveillance, or identity thieves. If you encrypt data before syncing it with the cloud, the cloudโ€”or anyone breaking into itโ€”canโ€™t read that data. Even iPhones are encrypted to protect their data if theyโ€™re lost or stolenโ€”something that has made headlines when organizations like the FBI or the NSA need access to them for investigations.

But encryption can be used for bad, too. Ransomware attacks are becoming more prevalent, also called denial of service (DOS) attacks that use encryption software to lock users out of their computers until they pay a fee.

Encrypting Data โ€œIn Transitโ€ vs. Data โ€œAt Restโ€

Basically, the data we encrypt is always either:

  • In transit, meaning itโ€™s moving via email, in apps, or through browsers and other web connections
  • At rest, when data is stored in databases, the cloud, computer hard drives, or mobile devices

Encrypting this data is achieved mainly through:

  1. Full disk encryption (FDE): the primary way to protect computer hard drives and the at-rest data on them. Any files saved to the disk (or an external hard drive) are automatically encrypted. There are intermediate options for disk encryption, as wellโ€“folder encryption, volume encryption, etc.โ€“that arenโ€™t quite full-disk encryption, but in between.
  2. File encryption: a way to encrypt at-rest data on a file-by-file basis so it cannot be read if intercepted. This isnโ€™t automatic, but itโ€™s beneficial because that data will stay encrypted after itโ€™s left its place of origin.
  3. End-to-end (E2E) encryption: obscures any content of messages so only senders and receivers can read it, like the early Pretty Good Privacy (PGP) email encryption software. The idea with E2E encryption is that it tackles all the vulnerabilities on the communication chain: the middle (intercepting a message during delivery), and both ends (sender and receiver). This is not just a niche offering anymore, eitherโ€”platforms like Facebook Messenger and Appleโ€™s iMessage have E2E encryption now, too.
  4. Encrypted web connections: via HTTPS, encrypted web connections use a Secure Sockets Layer (SSL) or transport layer security (TLS) protocols. With secure internet connections, weโ€™re able to have better protected communications on the web. These arenโ€™t impenetrable, but thereโ€™s less risk of exploitation. How it works: HTTPS uses SSL and TLS certificates when a browser and server communicate over the web. These are encryption keys, and when both browser and server have them, theyโ€™re authorized to access the encrypted data thatโ€™s passed between them. Itโ€™s a very basic, but very important, security measure when connecting to the web. If youโ€™ve ever seen โ€œhttpsโ€ instead of โ€œhttp,โ€ or noticed a lock in the URL bar of your browser, youโ€™re accessing a secure site.
  5. Encrypted email servers: S/MIME (Secure/Multipurpose Internet Mail Extensions) public key encryption essentially gives SMTP (simple mail transfer protocol) email servers a leg up by allowing them to send and receive encrypted messages, not just simple text messages.
  6. Pre-encrypting data thatโ€™s synced with the cloud: thereโ€™s plenty of software available that can pre-encrypt data before it even gets to the cloud, making it unreadable by the cloud or anyone who hacks into it. Note that any files still stored on the local machine arenโ€™t encrypted and are still vulnerable. This accounts only for files sent to the cloud encrypting tech.

Encryption can be simple, like secret-key, or incredibly complex, like the Advanced Encryption Standard (AES), depending on the algorithm and the length of the key. The longer the key, the more protection, but also the more processing power required to handle the encrypting and decrypting process.

A few types of encryption to know include:

  • Secret-key algorithms: Also known as symmetric algorithms, or private-key, this algorithm uses the same key for encryption and decryption. This is a touch more vulnerable because anyone who gets a hold of that one key can read anything you encrypt. Also, passing that secret key over internet or network connections makes it more vulnerable to theft.
  • Public-key algorithms: These are also known as asymmetric algorithms. With public-key encryption, there are two different, related encryption keysโ€”one for encryption, and one for decryption. The public key is how the information is sent to you, and the private key decodes it (much like having a secure lock box on your front porch that a delivery person can put a package in, then only you can access that package with your private key). The benefit here is the key isnโ€™t subject to being sent over insecure networks, but it does require more computer processing power so itโ€™s a bit slower.
  • Block ciphers: Like the Triple Data Encryption Standard (DES), or 3DES, these encrypt data a block at a time. Triple DES uses three keys and is a pretty great encryption option for financial institutions that need to protect sensitive information.
  • Stream ciphers: A symmetric algorithm, it uses a keystream, a series of randomized numbers, to encrypt plaintext one character at a time. Rabbit, W7, and RC4 are popular stream ciphers.
  • Elliptic curve cryptography: A form of public-key encryption, it can be practically unbreakable for normal computers, or โ€œhard.โ€ This is security industry speak for technology thatโ€™s not completely unbreakable, but is generally accepted to be up to best standards.
  • Blockchain cryptography: Blockchain technology is essentially a type of distributed database, best known as the basis for Bitcoin, that uses cryptography to safely store data about financial transactions. Blockchain cryptography is a form of โ€œcryptocurrency,โ€ using public-key encryption, and itโ€™s valuable in its ability to provide direct, trustworthy and fraud-proof transactions between users on a peer-to-peer network. Because blockchain databases are distributed, theyโ€™re more resilient in the face of a DOS attack, so more companies are exploring this.

A few popular algorithms include:

  • Advanced Encryption Standard (AES): A block cipher, this is pretty much the gold standard, per the U.S. Government. It offers 128-, 192-, and 256-bit encryption, the last two reserved for instances that require extra-strength protection.
  • RSA: This asymmetric algorithm uses paired keys and is pretty standard for encrypting information sent over the internet, although itโ€™s been through some issues of getting broken, which have then been resolved.
  • IDEA (International Data Encryption Algorithm): This block cipher with a 128-bit key has a great track record for not being broken.
  • Signal Protocol: This open-source encryption protocol is used for asynchronous messaging, like email.
  • Blowfish and Twofish: Both of these block ciphers are free to use and popular among e-commerce platforms for protecting payment information. They were created by the same person and offer symmetric encryption with keys varying in bit length. Twofish is the successor and offers longer encryption keys.
  • Ring Learning With Errors or Ring-LWE: This protocol ramps up elliptic curves by adding in a new type of encryption that might be unbreakable by quantum computers.

What is key management and why is it important?

Key management is another important aspect of encryption. Keys are how all of that encrypted data becomes readable, so how you handle them is just as sensitive as the data itself.

Many businesses worry about this aspect of encryptionโ€”after all, if you lose an encryption key, you lose access to your data, too. Thatโ€™s why key management dictates how keys are stored (and shared) so prying eyes canโ€™t get a hold of them, making your entire encryption schema moot.

  • Diffie-Hellman key exchange: This secure way for people to create a key allows them to share secure information. This method is also touted as โ€œperfect forward secrecy,โ€ meaning that theoretically, at no point in the future can messages get encrypted with a Diffie-Hellman key be decrypted.
  • Double Ratchet algorithm: Based on the above, the Double Ratchet algorithm is a key management algorithm used in end-to-end encryption of instant messaging, like the Signal messaging app.

This article just scratches the surface of the art and science of encryption, but hopefully, it gives you enough basic understanding of this important security technology. If youโ€™re considering enlisting the help of a data security expert, youโ€™re in luck: there are plenty of IT services and IT security freelancers (as well as cyber security consultants) on Upwork with expertise in encryption who are able to consult with you on an encryption strategy thatโ€™s best for you and your data.