Back to Explore
๐Ÿ›ก๏ธ

IT & Cyber Audit

Data Encryption Coverage

Encryption at rest and in transit is the most demonstrable POPIA safeguard โ€” coverage gaps turn a lost device into a reportable breach.

๐Ÿ“– 6 min read๐ŸŽฏ Intermediateโœ๏ธ Updated 2026

Why encryption coverage is a measurable POPIA control

POPIA's Section 19 requires a responsible party to secure the integrity and confidentiality of personal information using appropriate technical measures, and encryption at rest and in transit is the most demonstrable of these. Gaps โ€” an unencrypted laptop, a database without transparent encryption, an uncontrolled USB drive โ€” are exactly the weaknesses that turn a lost device into a reportable security compromise under Section 22. AuditPro Core measures encryption coverage across databases, endpoints and removable media holding personal data so that the responsible party can show, rather than assert, that reasonable safeguards are in place.

The Numbers

AuditPro Core renders this view from your tenant's live, tamper-evident records. The figures below are illustrative sample data.

Endpoints encrypted

86%

โ–ฒ 11%

Databases at rest

73%

Unencrypted PII stores

12

TLS-enforced services

91%

Encryption coverage by asset type

Unencrypted PII stores

Data storeRecordsOwner
Legacy HR archive41200HR
Citizen complaints DB28800Comms
Bursary applications9600Skills

Figures shown are illustrative sample data for demonstration. AuditPro Core renders these views from your own tenant's live, tamper-evident records.

At rest versus in transit

Data must be protected both where it is stored and while it moves across networks. Encrypting one without the other leaves a real exposure that attackers and lost-device scenarios will find.

The endpoint and removable-media gap

Servers are often encrypted while laptops and USB media are not, yet those are the assets that physically leave the building. Full-disk encryption and controlled removable media close the most common breach vector.

Coverage as a percentage, not a yes/no

Encryption is meaningful only as proportion of the personal-information estate actually covered. Knowing that 80% of databases are encrypted is a control metric; a blanket policy statement is not.

Key management underpins it all

Encryption is only as strong as the protection of its keys. Poor key custody or hard-coded keys can render encryption cosmetic, so key management is part of the control, not an afterthought.

How AuditPro Core Bridges the Gap

  • Coverage measurement: the platform quantifies encryption across databases, endpoints and removable media holding personal data as a tracked percentage.
  • Gap exception workflow: unencrypted assets in scope are raised for remediation with an owner and due date.
  • Breach-readiness evidence: coverage status provides the demonstrable Section 19 safeguard record needed if a Section 22 notification arises.
  • Continuous monitoring: newly provisioned or non-compliant assets are detected as coverage drifts rather than at annual review.

Key Takeaways

  • POPIA Section 19 expects demonstrable safeguards โ€” measured coverage is that evidence.
  • Laptops and USB media are the assets that leave the building; encrypt them first.
  • Track encryption as a percentage of the estate, not a policy statement.
  • Without sound key management, encryption can be cosmetic.

See This on Your Own Data

AuditPro Core renders this dashboard from your tenant's live, tamper-evident records โ€” every figure traceable to source.