Service · IT security

VPN and encryption

Encryption sounds like mathematics, but day to day it comes down to very practical questions. What happens when a field sales rep has her laptop stolen from the car? Can someone on hotel Wi-Fi read along while a colleague connects to the server? How does a law firm send a draft contract to a client without it crossing several mail servers in the clear? And who actually holds the recovery key when BitLocker suddenly demands it after a firmware update? We make sure data is protected both in transit and on the device, in a way that does not get in the way of work and never leaves anyone locked out in an emergency. That covers everything from the encrypted tunnel between head office and a branch, to remote access for home workers, to the question of how keys are stored and withdrawn when someone leaves. All configuration is carried out remotely.

BitLocker
and FileVault on every laptop
Recovery keys
held centrally, not on a scrap of paper
WireGuard or IPsec
in place of outdated protocols
Multi-factor
on every VPN login

Everything this covers

We pick the method to suit the purpose. Not every remote connection needs a full VPN, and not every document needs encrypting individually.

Settle the details with an engineer

Site links

Site-to-site tunnels between the firewalls at head office, branches and warehouse, using current ciphers and rules on which networks may reach each other.

Remote access

A VPN client with multi-factor sign-in for home and mobile workers, or access that exposes individual applications only. Old connections based on a shared key are replaced.

Disk encryption

BitLocker on Windows and FileVault on macOS, enforced through Intune, with recovery keys stored centrally. Servers holding sensitive data and external backup drives are encrypted as well.

Email encryption

TLS between mail servers as the baseline, plus Microsoft Purview message encryption or S/MIME for content that must stay protected at the recipient end.

Secure file exchange

Shares with expiry dates and passwords instead of attachments; encrypted archives only as an exception. Separate exchange areas for law firms and medical practices handling especially sensitive files.

Certificates and key handling

An overview of TLS certificates for website, mail server and VPN with their expiry dates, and automatic renewal wherever possible, so nothing lapses unnoticed.

Our working method

Encryption rarely fails on the technology; it fails on forgotten keys. That is why key management comes first with us.

01

Stocktake

Which devices are encrypted, where keys are kept, which tunnels and remote connections exist, and which protocols and certificates are in use.

02

Concept

Agreeing methods, key storage and responsibilities, including who may release a recovery key in an emergency.

03

Implementation

Encrypting devices while they stay in use, moving tunnels and remote access over during maintenance windows, and short guides for staff.

04

Proof

A report on the encryption status of every device, suitable for your insurer, a customer or your GDPR records.

An encrypted laptop turns a data breach into mere property loss. When an unencrypted device holding customer data is stolen, the question of notifying the Data Protection Authority arises quickly. If it is demonstrably encrypted and the key is safely stored, the assessment usually looks very different. The evidence comes from a report in your device management console.

Frequently asked questions

On current hardware you will hardly notice, because processors accelerate encryption in hardware. The initial encryption runs in the background while people carry on working.

Not for email, Teams and SharePoint, which are encrypted already and protected by multi-factor and conditional access. A VPN or application gateway remains necessary for terminal servers, on-premises business software or a file server in the office.

If the device is registered in Entra ID or Active Directory, the key is usually stored there. Write to support@apply.at or helpme@apply.at and we will retrieve it remotely from the admin portals. If it truly is missing, the data on that device is lost, which is why we arrange central storage beforehand.

For recipients without their own certificates, an encrypted Microsoft 365 message opened with a one-time passcode is simpler than S/MIME, as is a download link with an expiry date. We set it up so it takes your team a single click.

Encrypt what travels and what can go missing

Describe your sites, home working and devices. We will show where unencrypted data is sitting and the order in which we would protect it.

Availability
Monday to Friday, 8:00-17:00 Austrian time (CET/CEST), reply within one working day
Meetings
By video on Microsoft Teams or Google Meet

We only use cookies that are technically required: to run the website and to remember the location you picked. There are no advertising or tracking cookies. Details are in the privacy notice.