IDC Analyst Connection—Collaborate with Confidence: Encrypting Data in Use for Efficiency and Privacy
Collaborate with Confidence: Encrypting Data in Use for Efficiency and Privacy August 2025
Questions posed by: Paperclip Inc.
Answers by: Jennifer Glenn, Research Director, Security and Trust
Can you define “encryption in use” or “searchable encryption”?
Encryption is the process of changing data to an unviewable format that only a device or user with the appropriate decryption key (or keys) can read. Encryption is more commonly used (or known) for securing data at rest (e.g., stored data) or data in motion/transit (e.g., file download, email encryption). Data in use — data that is in active use for applications or collaboration — is much more challenging to encrypt. “Encryption in use” or “searchable encryption” is the ability to keep that data fully encrypted while allowing calculations on the data.
There are a few different approaches to securing data through encrypting data in use: searchable symmetric encryption (SSE), homomorphic encryption (HE), and confidential computing. Confidential computing uses a hardware-based secure environment or trusted execution enclave (TEE) to process data for a project or an application. Homomorphic encryption is a cryptographic approach designed to allow teams to perform analytics upon encrypted data without first decrypting it. Searchable symmetric encryption, while similar to homomorphic encryption, better enables users to perform on-demand operations upon encrypted data without decrypting the data set or making the data readable to unknown parties.
How are organizations currently approaching encryption and, specifically, securing data in use?
According to IDC’s March 2025 Data Security and Privacy Survey, encryption is the most widely used security technology for protecting data. The current encryption standard, the Advanced Encryption Standard (AES), has wide use and has yet to be breached. Most organizations use this type of encryption for securing stored data or data in transit. Although they can use AES to secure data in use, it is uncommon.
This may be due to a lack of awareness about how to secure data in use or confusion about how this type of encryption differs from securing stored data or data in motion. The most likely reason, however, is the disruption of available data. Encrypted data in any state requires decryption. For stored or transferred data, latency can be frustrating but doesn’t typically cause too much disruption. For data in use, however, latency during decryption can create delays and/or negatively impact the availability of required data for applications, services, or websites. There are some newer encryption technologies leveraging SSE that have reduced latency to a negligible amount, which should help with greater adoption of data in use encryption strategies.
What factors drive the need to encrypt data in use?
Several factors drive the need to encrypt data in use. One of the most notable drivers is the need to comply with a growing number of evolving data privacy and industry- or regional-specific rules. Compliance regulations, such as GDPR, require organizations to improve the confidentiality and integrity of the data they use and process. This means encrypting all data under their purview to ensure its protection in all possible ways. Other regulations, such as the Digital Operational Resilience Act (DORA) in the European Union, focus less on security and require organizations to identify and manage the availability of business-critical data instead. Effectively encrypting data in use is a solution to meeting both of these requirements, and many others. Finally, most organizations are simply struggling under the weight of their data, and this risk is not going away anytime soon with GenAI and agentic AI. As the volume of data increases, organizations’ attack surfaces become larger and more difficult to manage. We’re also seeing a general increase in cyber crime — including data theft, ransomware attacks and data manipulation — that is very costly for organizations. Data-in-use encryption offers a final layer of management and control. This limits the impact of a breach by ensuring that, in the event of a compromise, any data that is exfiltrated by malicious actors remains encrypted and — with the addition of shredding technology in some solutions — unreadable.
Who benefits from data-in-use encryption?
From an industry perspective, highly regulated organizations will benefit the most from encrypting data in use. Financial and insurance, healthcare and pharma, and government and education organizations tend to have a higher volume of sensitive or secret data, such as credit card details (PCI), Social Security numbers (PII), and sensitive health information (PHI). These organizations are also likely to rely on collaboration technologies to work with partners or suppliers on various activities, such as creating new pharmaceuticals, sharing personal or health information, or brokering financial transactions. Data-in-use encryption enables multiple organizations to work together while maintaining the integrity and security of sensitive information. From a role perspective, data-in-use encryption can benefit CIOs and CISOs, both of whom must prove adherence to privacy and industry regulations. It is an important tool for ensuring and continuously maintaining compliance with requirements. Non-security executives, such as CEOs, CFOs, and even the board of directors, should also see benefits from protecting critical data and their data supply chain while enabling efficiency and collaboration. Finally, the media drumbeat of attacks and the required breach notifications mean that customers are more aware of how organizations are using — and protecting — customer data. It becomes a question of trust between an organization and its consumers. The ability to prove that exfiltrated data remains unreadable can be instrumental in building and maintaining that trust with consumers.
Why now?
Data is money. It’s how organizations generate — or lose — revenue, growth momentum, and consumer trust. They can use data in commercial, consumer-facing, or internal applications to make informed business or strategy decisions. It is also the foundation of AI. Organizations often do not fully think through data security plans as they aggressively build AI tools. Research from IDC’s March 2025 Data Security and Privacy Survey demonstrates that businesses are increasingly prioritizing AI over security. In the same survey from 2024, 36% of respondents indicated that they felt security and AI goals were completely aligned. That percentage dropped to 29% in 2025. The challenge with this misalignment is that malicious actors use both data and AI to achieve their negative outcomes. These actors can automate attacks and rapidly compile collected information for more targeted strikes, and AI tools help create more sophisticated attack techniques that are harder to detect. Owing to the value of data and the growing amount of plaintext in-use data, executives and company boards are putting more pressure on their security teams to protect confidential information as completely as possible without sacrificing the productivity or availability of data for use. This includes addressing post-quantum computing threats to data integrity. Many organizations are opting for a zero trust approach. Although this layered defense addresses many security issues, data exfiltration continues to occur at alarming rates. Encrypting data in use provides a critical layer of defense for zero trust initiatives, making data available whenever it is needed while ensuring it is unreadable to malicious actors in case of exfiltration. In addition, modernizing encryption algorithms for data in use helps address quantum computing threats, offering data security and integrity now and in the future.