Cyber Security
Encryption isn't the end of the security conversation
Encryption protects information as it moves, but people still need to see, hear and use it. Good SME security also considers the device, the room and what happens after data is decrypted.
7 min read — Altitude IT Security Team
Encryption is essential. It protects information from being read while it travels or sits in storage, provided it is implemented and used properly. But a person cannot listen to an encrypted Teams call or read an encrypted document without the information eventually being presented in a usable form.
That transition—from protected data to sound, text or a picture on a screen—is where endpoint and physical security enter the conversation. It is also the useful context for recent security research on headphone audio. The research is unusual and technically interesting; it is not a reason to assume that someone is routinely intercepting meetings from outside an SME's office.
What the headphone research did—and did not—show
Researchers presented Injected and Leaked: Actively Inducing Side-Channel Leakage Using Electromagnetic Injection and Hardware Nonlinearity at USENIX Security 2026. They demonstrated recovering audio played through wired and wireless headphones by transmitting an RF signal and measuring leakage created by nonlinear analogue components. The researchers report demonstrations at distances of up to 30 metres and in through-wall scenarios.
This was not a crack of the call's encryption, a Bluetooth exploit or a way to read ordinary network traffic. It was a specialised physical side-channel experiment: the information had already been converted by endpoint hardware into an analogue signal. The headline distance is an experimental maximum, not a normal operating range or evidence that this is a likely attack against a typical small business.
We first looked at the underlying research in IT Club's explanation of electromagnetic leakage from headphones. For an SME, the more useful takeaway is broader: protecting data in transit does not remove the need to protect the systems and places where people use it.
Protected data eventually becomes useful information
A confidential conversation may be encrypted while travelling over the internet, then emerge as audio from headphones or a speaker. A document may be encrypted in storage, then appear on an unlocked laptop screen. A spreadsheet may be printed. A support call may be audible to people nearby. None of that makes encryption pointless. It means encryption is one control in a chain, not a force field around every copy and every human who handles the information.
More ordinary exposures can include:
- An unlocked laptop left open in a meeting room or reception area.
- A screen showing payroll, a client record or a password reset visible through a window or to a visitor.
- A confidential call taken on public transport or in a shared workspace.
- Printed documents left by a shared printer or placed in general waste.
- Meeting-room microphones, cameras or conferencing accounts that remain available after a call.
- A compromised or unsupported endpoint where an attacker can see information after a user opens it.
These examples do not all have the same likelihood or consequence. The point is to ask what information is exposed, who could reach it and what practical control would reduce the risk.
Fix the common routes before the exotic ones
For most SMEs, the immediate security work is still much more familiar than electromagnetic interception: phishing, stolen credentials, accounts without effective multi-factor authentication, unsupported or unpatched devices, excessive user access and backups that have not been tested. An unusual research result should improve understanding, not reorder priorities by headline value.
The UK's Cyber Essentials scheme is a useful baseline because it focuses on five technical controls intended to prevent common internet-based threats: firewalls, secure configuration, user access control, malware protection and security updates. It is not a guarantee against every threat, and it does not replace physical security or good information handling. It does help keep the basics ahead of the rare edge case.
Start with identity and endpoints: require MFA where available, remove accounts that no longer need access, apply security updates, use supported devices and make sure endpoint protection is active. Confirm that backups cover important business data and that someone has tested a restore. These controls address risks that are both more likely and more consequential for most small organisations.
Then protect the places where sensitive information is used
For financial, legal, health or commercially sensitive information, proportionate extra measures may be justified. Hold discussions in rooms where they cannot be overheard. Lock screens when people step away. Position displays thoughtfully. Collect confidential print jobs directly and dispose of them securely. Use approved meeting-room equipment and review who can start or share a recording.
Bluetooth devices, microphones and cameras should be managed as part of the wider device picture: know which equipment is approved, keep its software supported, use sensible network access and remove equipment that no longer has a business purpose. This is basic asset and access management, not a special countermeasure to the headphone experiment.
If a business has unusually sensitive information or a specific threat model, document that context and decide whether additional physical or technical controls are proportionate. Do not buy shielding products or change your meeting practices simply because a paper demonstrated an uncommon attack under laboratory conditions. Ask what an attacker would need, what information is at stake and whether a more common weakness deserves attention first.
A practical security check
- List where important information is opened, discussed, printed and stored—not only where it is transmitted.
- Check MFA, access rights, device updates, malware protection and backup recovery before investing in unusual controls.
- Review meeting-room microphones, cameras, shared displays and recording permissions.
- Set expectations for confidential calls and screen use in public or shared spaces.
- Apply stronger physical controls only where the information and realistic risk justify them.
Good cybersecurity is not about defending against every theoretically possible attack. It is about understanding your information, your realistic risks and applying controls in proportion. An independent Cyber Essentials readiness review or security review can help identify what should be addressed now and what can reasonably wait. For a wider prioritisation approach, see our cybersecurity roadmap guidance.