Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Data Protection

Google Workspace Gets Client-Side Encryption in Gmail

Google on Friday announced the beta availability of client-side encryption in Gmail for some of its Google Workspace customers.

Google on Friday announced the beta availability of client-side encryption in Gmail for some of its Google Workspace customers.

The feature is meant to improve the confidentiality of emails when they rest on Google’s servers, by applying encryption to the email body and attachments while providing Workspace customers with control over the encryption keys and the identity service used to access the keys.

“Google Workspace already uses the latest cryptographic standards to encrypt all data at rest and in transit between our facilities. Client-side encryption helps strengthen the confidentiality of your data while helping to address a broad range of data sovereignty and compliance needs,” Google announced.

The internet giant previously enabled client-side encryption for Workspace Enterprise Plus, Education Plus, and Education Standard customers, for services such as Google Drive, Docs, Sheets, Slides, Meet, and Calendar (beta).

Client-side encryption in Gmail

Now, client-side encryption is also available for Gmail, and those interested in trying it can apply for beta access until January 20, 2023.

To get started, administrators first need to complete a few steps to prepare accounts for the beta. While off by default, the client-side encryption can then be enabled from the admin console.

Once the feature is enabled, end-users can add it to their messages by clicking on a lock icon and selecting additional encryption. Composing messages and adding attachments will work as usual, Google says.

The internet giant has published several resources to help Google Workspace administrators set up and learn more about client-side encryption.

Advertisement. Scroll to continue reading.

Business Starter, Business Standard, Business Plus, Education Fundamentals, Enterprise Essentials, Frontline, Nonprofits, Workspace Essentials, legacy G Suite Basic and Business customers, and users with personal Google accounts are not receiving client-side encryption in Gmail yet.

Related: New Identity Verification Feature Boosts Google Workspace Protections

Related: Google Workspace Now Warns Admins of Sensitive Changes

Related: Google Fights Phishing With Updated Workspace Notifications

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Cody Barrow has been appointed as CEO of threat intelligence company EclecticIQ.

Shay Mowlem has been named CMO of runtime and application security company Contrast Security.

Attack detection firm Vectra AI has appointed Jeff Reed to the newly created role of Chief Product Officer.

More People On The Move

Expert Insights

Related Content

Application Security

Cycode, a startup that provides solutions for protecting software source code, emerged from stealth mode on Tuesday with $4.6 million in seed funding.

Data Protection

The cryptopocalypse is the point at which quantum computing becomes powerful enough to use Shor’s algorithm to crack PKI encryption.

Artificial Intelligence

The CRYSTALS-Kyber public-key encryption and key encapsulation mechanism recommended by NIST for post-quantum cryptography has been broken using AI combined with side channel attacks.

Cloud Security

Cloud security researcher warns that stolen Microsoft signing key was more powerful and not limited to Outlook.com and Exchange Online.

Compliance

The three primary drivers for cyber regulations are voter privacy, the economy, and national security – with the complication that the first is often...

Compliance

Government agencies in the United States have made progress in the implementation of the DMARC standard in response to a Department of Homeland Security...

Email Security

Many Fortune 500, FTSE 100 and ASX 100 companies have failed to properly implement the DMARC standard, exposing their customers and partners to phishing...

Data Protection

While quantum-based attacks are still in the future, organizations must think about how to defend data in transit when encryption no longer works.