All Articles

Professional Services · September 2026

Who controls your encryption keys in the cloud

If you store business files or databases in the cloud, you probably assume they are encrypted. But who holds the key, and does that matter for your business?

If you store business files or databases in the cloud, you probably assume they are encrypted. The harder question is who controls the encryption keys. Can the cloud provider see your data? Can you lose access if a key gets deleted? For most Ontario businesses, the default settings work fine. But if you handle sensitive client information or need to meet compliance standards, understanding your options now will save confusion later.

The practical difference between provider-managed and customer-managed keys

Cloud platforms typically offer two ways to encrypt your data. The first is provider-managed keys. The platform creates and stores the encryption keys for you. Your files are encrypted automatically, you do not need to do anything, and the service stays available. The second option is customer-managed keys. You create the key, you decide who can use it, and you can disable or delete it whenever you want.

Provider-managed keys are easier. Customer-managed keys give you more control, but that control comes with responsibility. If you disable the key, your application stops working. If you delete it, your data becomes unrecoverable. For most businesses that are not under regulatory scrutiny, the simpler option is the better one.

Can the cloud provider read your data

This is one of the most common questions we hear from business owners moving files or databases to the cloud. The short answer is no. The encryption keys used by AWS KMS are stored in hardware security modules that are designed so no one, including AWS employees, can retrieve your plain text keys from the service. The modules themselves are validated under FIPS 140-2, which is a government security standard.

If you need an even higher level of separation, AWS CloudHSM lets you generate and use encryption keys in hardware you control. AWS staff have limited access to monitor the health of the module and take encrypted backups, but they cannot export or use your keys. That level of isolation is usually only necessary if you are under strict regulatory requirements or handling extremely sensitive data.

What bringing your own key actually means

Some businesses believe that generating their own encryption key material outside the cloud and importing it makes their data more secure. It does not. Once the key is imported, it is protected and used in the same way that a platform-generated key is. What it does give you is the ability to meet a compliance requirement that says you must generate and store a copy of master keys outside the cloud.

Most businesses find it much easier to let the platform generate and manage key material. The security level is identical, and you avoid the operational burden of tracking external copies. If you do not have a specific regulatory obligation, there is no practical security benefit to bringing your own key.

Key rotation happens automatically

One of the worries people have is whether encryption keys need to be rotated, and whether that means downtime or complicated migration work. AWS automatically rotates customer-managed keys once every year. You do not have to do anything, and your applications keep running. If you import your own key material, you can rotate it manually as often as you need to.

This is one area where cloud platforms make security easier. On-premises systems often require manual key rotation, which gets delayed or forgotten. In the cloud, it is automatic by default.

What this means for your business on Monday

If you are already storing files or running databases in the cloud, check whether encryption is turned on. In most cases, it is enabled by default. If you are using Microsoft 365, Azure, or AWS, your data is likely encrypted with provider-managed keys already. That is enough for most businesses.

If you handle health records, financial data, or other regulated information, ask your IT provider whether customer-managed keys or a hardware security module would help you meet compliance requirements. The answer depends on the specific regulation, not on your industry. A law firm with client privilege concerns and a medical clinic with patient privacy obligations may need different approaches.

If you are not under regulatory pressure and your current setup is working, you probably do not need to change anything. Encryption is already protecting your data. The question is whether you need more control over the keys, and for most Ontario businesses, the answer is no.

Sources

Talk to us about cloud security

Get started today

Have an IT Question?

Our team is ready to help, whether you need advice on cybersecurity, cloud strategy, or AI readiness.