Ask an Expert
Planning the right solution requires an understanding of your project’s security goals. Let Kingston’s experts guide you.
We notice you are currently visiting the UK site. Would you like to visit our main site instead?
Your web browser is out of date. Update your browser now for better experience on this site. https://browser-update.org/update-browser.html
Emailing, whether for personal or business purposes, is ubiquitous in our modern way of life. In the wake of the COVID pandemic, businesses rely more and more on remote meetings versus personal visits. As a result, company workers share more files with colleagues, clients, customers or other third parties (e.g. service providers, contractors, financial, legal and engineering partners). It is more important than ever that we feel secure when attaching files with sensitive information to our emails – that we can trust our sensitive data is secure with email providers that properly encrypt our messages, end-to-end.
Many people go further. Applications such as Word, Excel®, Adobe® Acrobat® and numerous others allow users to password-protect a file. This built-in encryption is intended to boost confidence that the data within will be kept secure, accessible only to the intended recipients with the correct password.
However, this confidence can be misplaced. IT departments do not routinely check outgoing emails for potential breaches of protected data, as data on its own or in cloud servers as required by laws and regulations. In many cases, a contractor with an email breach may not report it to its partners.
We must assume that our email servers, Internet providers and customer/partner servers are properly secured. There are constant stories of cloud or company data breaches, and few reports of email breaches.
Yet, in July 2023, hackers broke into US government email accounts. In January 2024, Microsoft® revealed that it was the victim of a two-month long email breach in which executives’ internal messages and attachments were stolen.
Is it still possible to feel secure with sensitive data? Consider professions that handle valuable data, such as lawyers, financial advisors, tax advisors, insurance companies and others. Password-protecting files so that they can be encrypted serves as a relief to many people but can no longer be considered a guarantee of security.

Password-protected Microsoft Excel spreadsheets of customer information, or encrypted Acrobat PDFs of legal evidence may provide peace of mind, but what can hackers do if they procure these documents?
Files like these are software encrypted on the computer, and a password gate is added to access the data. When the wrong password is entered, the file will not allow access and will stay inaccessible.
Unfortunately, these files lack protection against brute force (also known as dictionary) attacks, which involve guessing all combinations of characters that could make up a password. For example, assume a secure, complex password using three out of four character sets – uppercase, lowercase, numbers and special characters. This is the typical password type required as a best practice by IT security policies. Most commonly, complex passwords are eight characters long.
In principle, such complex passwords should take many years for a computer to guess. Password-protected files have no defences against password guessing except the randomness (or entropy) of the selected password.
Today’s computers can guess 1 billion or more passwords a second. That is a huge leap from when password-protected files were first created.
How do cybercriminals break password-protected files?
There are many free tools on the Internet to remove a password from Excel or Acrobat files. Files with special security encryption can be targeted by paid tools that attack a password-protected file with a single computer or scaled up to a thousand or more networked computers (for determined attackers seeking high-value data). Some of these powerful tools are marketed as forensic tools for law enforcement, yet they’re highly accessible – to the point that you can buy and download them with a credit card.
According to Home Security Heroes, an AI-based password cracking tool can hack the common eight-character complex password in minutes or take a maximum of seven hours. With networked computers, a brute force attack on a single password-protected file could be completed in a shorter time period.

At this point, it is clear that any transmission of sensitive data by electronic means is subject to a breach if a file is intercepted, or servers containing the file as an attachment or a file are breached. The same is also true of encrypted files stored on a cloud – any cloud – that has to rely on software encryption. If someone acquires the password-protected file, then they can subject it to brute force attacks using software that is customised to the file type.
The solution to mitigate this risk is to keep that data “off-the-grid” or air-gapped. It can be stored on a computer that is not connected to the Internet, or the data can be transmitted through a medium that is hardened against brute force password attacks. This can be cumbersome, but is a mitigation related to the value of the data – some types of breaches can cost millions of dollars and high legal costs and settlements, depending on the data that is lost. For example, a spreadsheet of customer accounts with details can be very damaging to a business when lost. A customer’s IP details used in a legal case can severely impact a company if those details are lost and sold on the dark web.
There is an inexpensive solution for mobile data that does just that – hardware-encrypted USB drives or SSDs. They have a self-contained, hardware-based security ecosystem that guards against password attacks and uses always-on AES-256 bit encryption that, in itself, is not known to have been compromised. It is important to source such storage devices from known and trusted manufacturers as inexpensive drives sold online may not properly implement password security or encryption.
A hardware-encrypted USB drive or external SSD, such as a Kingston IronKey drive, is not your typical USB or SSD. It is engineered from the ground up as a data protection device – using specialised controllers with security as the primary design goal. Such drives can provide enterprise-grade security and military-grade security (which adds a FIPS 140-3 Level 3 certification by NIST, the US government agency that creates AES-256 bit encryption and that sets the standards for US government agencies). Kingston has also been designing and manufacturing hardware-encrypted drives for over 20 years for enterprises and governments worldwide.
All accesses to an IronKey drive are routed through the secure microprocessor. To allow access to the data, the secure microprocessor requires either a valid password or a PIN for keypad drives. The secure microprocessor keeps a count of invalid password retries (if you have ever had a mobile phone reset on you, you know how it works). IronKey drives allow multiple passwords: Admin, User and One-Time Reset. If One-Time Reset or User passwords are entered incorrectly 10 times in a row, the drive will lock the passwords. If the primary Admin password is entered incorrectly 10 times in a row, the secure microprocessor will enter data self-destruct mode – it will execute a crypto-erase of all encryption parameters, format the data storage and reset the drive to factory state. At this point, the data previously stored on the drive is lost forever. This is the defence against most attacks that you want for your sensitive data.
Unfortunately, electronic transmission of password-protected files by email or posting on a cloud server can lead to data breaches as the files themselves cannot be protected using today’s AI and computer technologies. The best security requires that mobile data be transported physically in your possession – in your pocket or in your bag. Then, it can be shared with the other party. Or, you can send the drive to your customer/partner and tell them how to access the data. The drive can be left with them to keep the data secure and off the grid. IronKey external SSDs with capacities of up to 8TB can provide strong security for a range of professionals, from law firms all the way to providers of medical or financial services.
Many manufacturers no longer email key intellectual property documents and details. Instead, they send IronKey drives to others (often in different countries) and follow up with instructions on accessing the data. IronKey drives allow the Admin role to set a global read-only mode, which prevents any alteration of the files when a User password accesses them.
IronKey drives follow the best practices of the CIA Triad and are an inexpensive insurance to keep your sensitive data secure and protected to the best extent commercially possible. In the end, it is all about the perceived value of your information.
Was this helpful?
Planning the right solution requires an understanding of your project’s security goals. Let Kingston’s experts guide you.
Encrypted USB flash drives keep your private data safe but how do they work?
For creatives that produce content for high-profile clients, encrypted storage can secure your important files and help you fulfil your security responsibilities.
Whether you’re working on your own or collaborating with important clients from around the world, encrypted storage can secure your important files and help you fulfill your security responsibilities.
No products match your current filter selection. Try adjusting your filters to explore more options.
Looking for improved data security & need to know what is encryption? Kingston covers the basics.
Discover how encrypted USB drives protect your data, and which type fits your needs.
Hardware, not software-based password protection, is the best way to protect files and drives.
Secure important personal and private information on a PC with a hardware-encrypted SSD.
Most IronKey and Kingston secure USB flash drives are FIPS 140-2 Certified.
A look at how companies manage their systems when cloud computing is unavailable.
Your guide to EU data sovereignty, risks, and secure data storage strategies.
Learn the right way to protect data and prepare it for safe reuse or recycling.
Breaches remain a major threat. Explore the need for comprehensive cybersecurity measures.
Here is a list of USB security features to consider for data protection.
Learn what the 3-2-1 data backup method is and why it is your best defence against ransomware.
Learn data security best practices with Dr. Vynckier, and the importance of offline backups.
David Clarke covers encryption, super user safeguards, vulnerability management, and training.
Learn how Kingston IronKey's solutions helped EgoMind enhance their data security hygiene.
Built for disparate purposes, client SSDs and enterprise SSDs have different properties.
We discuss NIS2 and DORA, and how organisations can turn compliance into an opportunity.
We discuss the shifts in how organisations are storing and encrypting sensitive data.
Learn how Kingston IronKey hardware-encrypted solutions supports NIS2 Directive compliance.
Kingston IronKey has hardware options to protect small and medium businesses against cybercrime.
FIPS 140-3 Level 3 is certified by the world-leading agency NIST as the apex of encryption.
Questions to ask when seeking the right SSD for your organisation’s data center.
Our infographic showcases the differences between software and hardware-based encryption.
2023 has been a year full of challenges and innovations. But what will 2024 bring?
Learn about two methods that give SMBs superior resilience vs ransomware: encryption and backups.
In this whitepaper, we explain how to enforce a DLP strategy, while allowing USB drive use.
Enterprise-grade and military-grade digital security: two high standards with different requirements.
Learn how hardware encryption can protect a travelling lawyer’s confidentiality with secure file storage.
How is pen testing ensuring Kingston IronKey USB drives lead the way in trusted data security?
Hardware encrypted Kingston IronKey drives protects organisations’ data on the move.
Bring your own device (BYOD) policy is tricky for employers. How to balance security & convenience?
How do encrypted drives improve cybersecurity and compliance for finance companies? Kingston explains.
DLP offers tools for network admins to protect sensitive data from cybercrime and negligence.
A look at how the requirement for data encryption can be key to any organisation's security strategy.
How can we bolster network security with remote working and international travel so common now?
Invest in encrypted drives so you do not incur expensive legal fees if they are lost or stolen.
Discover why national security agencies trust Kingston IronKey to protect their data.
A company’s IT specialists should be expected to add data security to the PCs of remote workers.
Kingston’s three key practices for robust DLP for businesses that handle sensitive data.
You can read and write to an encrypted USB flash drive with an iPad or iPhone with the right adaptor. Here’s how.
Learn why hardware encryption beats software encryption for law firm data protection.
A brief explaining the purpose and types of data security software available.
Passphrases are superior to complex passwords for keeping data secure, with many powerful benefits.
HIPAA requires healthcare organisations to keep patient data safe at all times, including in transit.
This requires encryption of sensitive data, appointing a Security Officer, cyber security programmes and policy adoption.
Kingston IronKey encrypted USBs are a security consideration for organisations of all sizes.
We compare unencrypted and encrypted USB drives and explain how to keep data secure!
Learn how Kingston IronKey is protecting the intellectual property with customisation.
Discover why Kingston IronKey is the go-to solution for protecting financial services data.
Learn how Kingston IronKey is securing the military operations’ data.
How can you get your organisation to use encrypted drives and make them part of your security policy? Here are some tips.
Learn how Kingston IronKey is protecting telecoms industry's data using encryption.
Encryption is an incredibly helpful option for creatives to protect their clients’ important files.
Kingston IronKey encrypted USBs: a small but important part of any organisation’s security strategy.
Kingston IronKey can help mitigate data loss due to the rise in lost electronic devices.
In this eBook, we explore how Encrypted USB drives have become a key tool in keeping data secure.
How to use your IronKey Vault Privacy 80 External SSD: set password, connecting to a PC and more.
Organisations are considering data security options to protect against private mobile data breaches.
Discover how Kingston IronKey is protecting the sensitive data of the finance sector.
Here is how Kingston IronKey helped protect the sensitive data of the Energy industry.
We explore our KingstonCognate experts’ thoughts on cyberthreats and cybersecurity challenges.
Protecting data on the move with superior hardware-based Advanced Encryption Standard (AES) 256.
Users can disable software-based encryption, which can lead to legal fees if the drive is lost.
We explore Tomasz Surdyk's thoughts on how all entities can stay secure in the digitised world.
Don’t plug any USB drives into your computer if you don’t know exactly where they came from.
What we learned from Kingston’s experts and tech influencers on work-from-home enablement Twitter chat.
There are benefits to using both cloud storage and hardware-based encryption.
We explore the top 12 tips small and medium size enterprises can take to enhance cybersecurity.
We’ve examined several factors using unique research to identify what may impact markets globally in 2022.
2021 has been a year full of challenges and innovations. But what will 2022 bring?
Prof Sally Eaves shares her thoughts on the SME cybersecurity landscape and the need for education & support.
Bill Mew shares his thoughts how the largest security challenges need commitment from the boardroom.
Rob May shares his thoughts on how close we are to edge computing and the security it requires.
Write your diary digitally with a password protected, cloud backup solution.
The pandemic has increased internet traffic, which has placed importance on the role of data centers.
The use of DLP software, VPNs, Encrypted SSDs and USBs, will help mitigate some risks of remote working.
Cameron Crandall of Kingston helps you decide if you should move to your server storage to NVMe SSDs.
There are many advantages to using a dedicated hardware encryption processor in USB flash drives.
What will 2021 bring in Tech and trends? What do our KingstonCognate members and industry experts predicting for the future?
Cyber security and data privacy are everyone’s responsibility. What are the key considerations?
Learn why the future of business depends on SSD-enabled SDS, and how SSD fits into a Software Defined Storage Solutions.
Kingston & Matrix42 partnered to give optimal endpoint security solution in multiple sectors to mitigate risks.
The importance of organisations to consider Revenue, Profit & Risk as equal in organisations to ensure they mitigate data security & cyber security risks. Read this article from Industry Expert, Bill Mew & he will provide you with an insight on this topic.
What do industry experts think has changed since the introduction of GDPR?
Data centres should be using server SSDs. There are many benefits over client drives and costs have come down.
NVMe is now the standard protocol for SSDs to empower data centres and enterprise environments.
Cloud and on-premise data centre managers can learn a lot from supercomputing.
SDS hasn’t lived up to its hype but now that NVMe is more affordable, the commodity hardware is ready to deliver.
Choosing the right SSD for your server is important since server SSDs are optimized to perform at a predictable latency level while client (desktop/laptop) SSDs are not. These difference result in better uptime and less lag for critical apps and services.
To work from home you need a good workspace for your PC, the right conferencing gear, and a secure connection.
What strategies can organisations use to best secure customers data in a post-GDPR world with the ever-evolving nature of cyber security threats? Kingston pooled the knowledge of some of the UK’s most experienced commentators in cyber security to discuss how data protection has changed since the introduction of GDPR.
This whitepaper demonstrates how using Kingston Technology’s Data Centre DC500 SSDs can reduce your overall capital and licence costs by 39%.
Data Center 500 Series SSDs (DC500R / DC500M) – Consistency, predictability of Latency (response time) and IOPS (I/Os Per Second) performance.
You already know that remote working is a business enabler. But the challenges posed to your network security and compliance with GDPR are too big to ignore.
How to enable and disable Microsoft’s BitLocker eDrive feature to leverage hardware encryption on your Kingston SSD.
The recent WannaCry ransomware made global headlines infecting and alerting everyone from government, healthcare, communication providers, automotive companies to corporations and the general public of their vulnerabilities.
Some of Kingston and IronKey's Secure USB Flash drives are powered by partners, licensed technology, or services.
256-bit AES hardware-based XTS block cipher mode encryption is used in DT 4000G2 and DTVP 3.0.
Kingston datacenter SSDs provide excellent resiliency to protect sensitive data in OLTP workloads.
HPC can require massive amounts of data. SSDs consume a fraction of the power of their spinning disk.
End-to-End Data Protection protects customer’s data as soon as it is transferred by the host system to the SSD, and then from the SSD to the host computer. All Kingston SSDs incorporate this protection.
This program offers the options most frequently requested by customers, including serial numbering, dual password and custom logos. With a minimum order of 50 pieces, the programme delivers precisely what your organisation needs.
Everyday working life has changed radically and so have traditional ways of working: thanks to mobile storage media, we can access our data practically at any time from any location, and can work on our data wherever we are.
Heathrow Airport in London (30 October 2017) uses unencrypted USB drives for its non-cloud storage. Unfortunately, it was not standardized on encrypted USB drives.
Linus breaks down hardware encryption making sure your files are safe and secure, especially when you're on the go. Make sure your portable storage is also safe and encrypted with Kingston Encrypted USB drives.
Storage can be the most challenging component for VDI performance.
Testing is a cornerstone of our commitment to deliver the most reliable products on the market. We perform rigorous tests on all of our products during each stage of production. These tests ensure quality control throughout the entire manufacturing process.
NVMe (Non-Volatile Memory Express) is a communications interface and driver that defines a command set and feature set for PCIe-based SSDs with the goals of increased and efficient performance and interoperability on a broad range of enterprise and client systems.