Skip to content

Protecting Data in Transit with Strong Encryption

By Team DTS

Data in transit is one of the most exposed elements of an organization’s information flow.

Sensitive information—including CUI, financial records, employee information, proprietary business data, and client information—may move through email, cloud platforms, remote connections, file transfers, applications, and internal or external systems. Each transmission path creates an opportunity for unauthorized access or disclosure.

Whether protecting sensitive business information or meeting NIST SP 800-171 requirements, organizations should use encryption to safeguard data as it moves between users, systems, platforms, and vendors. Encryption methods should meet recognized security standards, including NIST SP 800-171 and applicable federal requirements.

How can data in transit create cybersecurity risk?

Data in transit creates risk when sensitive information moves across networks or systems without appropriate protection. If transmissions are unencrypted or rely on outdated protocols, information may be more vulnerable to interception, unauthorized disclosure, or manipulation.

This can include:

  • Sensitive data moving between systems
  • Authentication credentials sent through insecure channels
  • File transfers using outdated protocols
  • Remote access sessions without strong encryption
  • Application traffic exposed through weak configurations
  • Legacy services that still allow plaintext transmission

Strong encryption helps protect confidentiality and integrity while information is moving. It also gives organizations a clearer way to demonstrate that transmission protections are operating as intended.

What encryption practices should organizations prioritize?

Organizations should prioritize modern, approved, and properly configured encryption methods for systems that transmit sensitive information. The goal is not only to turn on encryption, but to confirm that it is appropriate, current, and applied consistently.

Practical steps may include:

  • Using TLS 1.2 or higher where applicable
  • Disabling SSL and outdated TLS versions
  • Restricting plaintext transmission unless explicitly justified
  • Reviewing remote access and file transfer methods, email, and application pathways
  • Confirming that encryption settings align with organizational requirements
  • Using FIPS-validated cryptography when required to protect sensitive data confidentiality

Older protocols and unencrypted services can remain active because of legacy systems, inherited defaults, or incomplete configuration reviews. Removing them helps reduce the attack surface and supports stronger alignment with current cybersecurity expectations.

How should encryption settings be documented?

Encryption settings should be documented clearly enough for the organization to understand what is protected, how it is protected, and where evidence can be found.

Useful documentation may include:

  • Screenshots of encryption settings
  • Configuration files showing protocol restrictions
  • System or application settings showing approved protocols
  • Change records related to encryption updates
  • Vendor documentation for managed platforms
  • Review notes showing that settings were checked
  • Records showing where FIPS-validated cryptography is used when required

Documentation should show more than a one-time configuration. It should help demonstrate that encryption settings are reviewed, maintained, and updated when systems or security requirements change.

How often should transmission protections be reviewed?

Transmission protections should be reviewed routinely and after meaningful system changes. Even if encryption is configured correctly during implementation, software updates, platform changes, new integrations, or vendor defaults can reintroduce risk over time.

Reviews may include checking that:

  • Approved protocols remain enabled
  • Outdated protocols remain disabled
  • New systems are configured consistently
  • Exceptions are documented and approved
  • File transfer and remote access methods remain protected

Regular reviews help organizations catch configuration drift before it becomes a security or compliance issue.

What can small teams do first?

Small teams do not need to start with a complex encryption overhaul. They can start by identifying where sensitive information moves and confirming that the most important transmission paths are protected:

  • Listing the systems and tools that transmit sensitive information
  • Identifying where sensitive data may move between users, systems, vendors, or platforms
  • Confirming that remote access and file transfer methods use strong encryption
  • Disabling outdated protocols where they are no longer needed
  • Documenting approved transmission methods
  • Capturing evidence of encryption settings
  • Reviewing exceptions and removing them when they are no longer justified

This approach helps teams focus on the transmission paths that matter most instead of trying to solve every technical edge case at once.

Insights provided by the DTS Cybersecurity Team

References

  • Defense Federal Acquisition Regulation Supplement, 48 C.F.R. § 252.204-7012 (2020). Safeguarding covered defense information and cyber incident reporting. https://www.acquisition.gov/dfars
  • Department of Defense. (2014). Department of Defense Instruction 8500.01: Cybersecurity (Change 1, 2019). Office of the Chief Information Officer. https://www.esd.whs.mil
  • National Institute of Standards and Technology. (2020). Protecting controlled unclassified information in nonfederal systems and organizations (NIST Special Publication 800-171 Revision 2). U.S. Department of Commerce. https://doi.org/10.6028/NIST.SP.800-171r2
  • National Institute of Standards and Technology. (2020). Assessing security requirements for controlled unclassified information (NIST Special Publication 800-171A). U.S. Department of Commerce. https://doi.org/10.6028/NIST.SP.800-171A
  • Office of the Under Secretary of Defense for Acquisition & Sustainment. (2020–2024). Cybersecurity Maturity Model Certification (CMMC) Program Documentation. U.S. Department of Defense. https://dodcio.defense.gov/CMMC

About DTS

Share this Article
More Insights
  • Controlling Removable Media for CMMC-Aligned Security
    Team DTS June 26, 2026

    Removable media introduces unique risks related to data loss, malware, and unauthorized data transfer. Federal frameworks such as NIST SP 800-171 and DoD cybersecurity…

  • Securing Network and Remote Access Pathways for CMMC-Aligned Security
    Team DTS June 15, 2026

    Remote access and network boundaries are critical components of a compliant and secure environment. DoD and NIST guidance require organizations to restrict remote connections,…

  • Baseline Safeguards for a Cross-Framework Security Foundation
    Team DTS April 27, 2026

    Organizations often operate under multiple frameworks, including NIST Cybersecurity Framework, NIST 800-171, ISO 27001, and SOC 2. While each uses different terminology, their foundational safeguards share…

  • Enforcing Authorized User and Device Controls for CMMC-Aligned Security
    Team DTS April 15, 2026

    Controlling who can access systems and what devices they use is one of the most fundamental principles in federal cybersecurity standards. NIST SP 800-171,…

  • Establishing an Operating Rhythm for Security Excellence
    Team DTS March 26, 2026

    Security is not a one-time project. Federal guidance and industry frameworks consistently reinforce that the effectiveness of security controls depends on continuous operation. A…

  • Building an Organized Evidence Kit for a Strong and Defensible Security Program
    Team DTS March 17, 2026

    A security program is only as strong as its ability to demonstrate outcomes. Federal frameworks such as NIST SP 800-171 and the CMMC assessment…

  • Scope What Matters: Building a Focused and Sustainable Security Program
    Team DTS February 23, 2026

    A security program becomes repeatable only when it focuses on the systems and processes that truly matter. Federal guidance such as NIST SP 800-171…

  • Information Governance and CUI: Establishing Structure for CMMC Compliance
    Team DTS February 18, 2026

    February is recognized as Information Governance Month, with February 19 marking Global Information Governance Day. For organizations supporting federal contracts, information governance defines how…

  • 8 Essential Data Privacy Practices for Federal Contractors
    Team DTS January 27, 2026

    A clear, actionable guide to protecting sensitive information and preparing for evolving privacy expectations Introduction Data Privacy Week arrives at a time when organizations…

  • Strengthening Identity Integrity and MFA Controls to Prevent Credential Theft
    Team DTS December 4, 2025

    Identity is the core of modern cybersecurity. Federal frameworks, including NIST SP 800-171 and CMMC, consistently emphasize maintaining traceable, unique identities and enforcing multi-factor…

  • A Practical Starting Point for CMMC Readiness
    Jamie Repesh November 24, 2025

    CMMC requirements are now being incorporated into Department of Defense (the Department) contracts following the November 10 effective date of DFARS 252.204-7021. With the…

  • Reducing Cybersecurity Risk In 2025: Consider A Supply Chain Strategy
    Edward Tuorinsky February 7, 2025

    DTS CEO, Edward Tuorinsky, shares his insights with Forbes Business Council, on reducing cybersecurity risk in 2025: consider a supply chain strategy. Despite increased…