Michael Mattis

In the interview with Georg Nestmann, CEO of comcrypto GmbH

In the interview with Georg Nestmann, CEO of comcrypto GmbH

comcrypto GmbH, based in Chemnitz, has been working for many years on secure email transmission. Over the past few years, they have developed a data protection-compliant and practical solution designed to ensure secure email transmission. Previous email encryption has been very complicated, yet relevant for every company and public institution. Often, multiple tools are used for different external recipients, there is a high training requirement, and complicated guidelines for employees. In practice, it is almost impossible to verify the correct implementation of the process. In an interview with Georg Nestmann, CEO of comcrypto GmbH, we therefore discuss previous complex portal solutions, the acceptance of secure email transmission, its use in different industries, and which renowned customers have already opted for such a solution.

DIGITAL FUTUREmag: Mr. Nestmann, what is your objection to unencrypted email?

Georg Nestmann: Emails almost always contain data that needs to be protected, especially emails in a corporate context. Often, these are personal data, and in many industries, very sensitive data containing, for example, trade secrets that need to be safeguarded. Cybercriminals have long identified email as a weak point and gateway into many companies and institutions. Many attack scenarios begin with a prolonged phase of spying on email communication. Encryption is a good way to make it significantly more difficult for cybercriminals. However, experience shows that encryption must above all be practical; otherwise, it won’t be used at all.

DIGITAL FUTUREmag: In which industries would you absolutely recommend email encryption?

Georg Nestmann: In every industry—and if the technology isn’t too complicated, it’s feasible. Wherever people communicate digitally via email, data is exchanged. Of course, there are differences in the sensitivity or “value” of the data. Some industries are particularly predestined for this, such as those with professional confidentiality obligations, e.g., doctors, tax consultants, or lawyers. The same applies to the social sector, where highly sensitive data about those affected is involved. But even for medium-sized companies, there are many reasons today not to send digital invoices via “postcard email”—there have already been too many cases of invoice fraud where large sums of money were transferred to incorrect accounts. To assess the different risks, there are approaches like a risk matrix in data protection. The data protection supervisory authorities have examined this for email communication and concluded that encrypted transmission of emails is mandatory even in cases of only “normal data protection risks.”

DIGITAL FUTUREmag: Statista says: Three quarters of German internet users consider it important to be able to encrypt emails so that they can only be read by the recipients. This is according to a recent survey conducted on behalf of WEB.DE and GMX. In reality, however, only 13.5 percent of respondents use end-to-end encryption. What is the reason?

Georg Nestmann: Unfortunately, wishful thinking and reality collide here. Of course, everyone would say it would be good if only the recipients—and no one else—could read my message. But end-to-end encryption is unfortunately complicated, and of course, you don’t want to burden your recipients with having to obtain a certificate or having to read messages only after entering a password. I would be interested to know what proportion of emails is actually encrypted by the aforementioned 13.5 percent of respondents—this is almost certainly even much lower. Of course, widespread end-to-end encryption would be the desirable state. But as long as we are still miles away from this state, we should first aim for a realistically achievable security level that is still worlds ahead of the level currently practiced.

DIGITAL FUTUREmag: What distinguishes your solution from previous portal solutions?

Georg Nestmann: Previous solutions assume that the transmission between email servers is inherently insecure. According to this way of thinking, security can only be achieved if the email channel itself is bypassed, i.e., the data is sent via a web portal, for example. In practice, this only happens if users consider the data important enough to impose a portal login on their counterpart, meaning that the majority of emails continue to be transmitted as “postcard emails.”

Our solution, on the other hand, is based on the fact that the transmission between email servers can indeed be secured. Data protection authorities themselves have defined clear criteria for how so-called transport encryption should be technically implemented and how the sending system must be tested to ensure that even data with high risks can be sent. This is then referred to as “qualified transport encryption.” The only challenge: Not all recipient servers yet support this process.

Our solution nevertheless leverages the potential of qualified TLS encryption by using this technology to securely transmit every outgoing message for which qTLS protection is possible. This works for around 95 percent of emails. Only in the remaining exceptional cases, for example if the email contains a corresponding risk level, additional protection such as a password must be used. Overall, therefore, the majority of the effort is removed from the users.

DIGITAL FUTUREmag: Please explain at least roughly how the entire system works technically.

Georg Nestmann: Our system, comcrypto MXG, is integrated as an outgoing SMTP relay, i.e., as an additional mail system of the sender, into the mail processing and assumes the role of the last system involved in the mail delivery on the recipient's side. You can think of it as a digital post office. Setting up the new system is not a major task for the IT department. From then on, every outgoing email passes through the new MXG solution. The data protection or IT managers of our customers define which data protection risks the solution addresses and what should happen in each case.

The MXG then checks each outgoing email to determine how securely the transmission can be configured at the server-to-server level. For example, the strength of the available encryption algorithms of the recipient's server and the TLS certificate available there are taken into account in this evaluation, where all security parameters are checked to see whether, according to the current assessment of the BSI, sufficient security is guaranteed. If so, the transport channel is secure and the email in question can be transmitted as a "normal" email, i.e., immediately readable for users. Otherwise, the previously defined procedures are used. For example, the sender can be asked for confirmation, or the solution automatically generates a password-protected email that can be securely transmitted even over an insecure transport channel. We call this principle of automated adaptation adaptive encryption.

DIGITAL FUTUREmag: What requirements do I need to meet on my computer or server to use your tool correctly?

Georg Nestmann: There are no requirements for the actual users and their end devices. They receive and send completely normal emails via any email client. To ensure that our system can be connected, it must be possible to set a so-called "routing rule" on the existing email server so that the email server no longer sends outgoing messages itself but instead forwards them to the MXG. This is easily possible in most standard systems used in companies and public institutions.

DIGITAL FUTUREmag: From what company size does the use pay off, and is your solution also available for small and medium-sized enterprises?

Georg Nestmann: Since even in the smallest business context, data worth protecting is generated and communicated via email, the use of our solution is worthwhile from the very first mailbox. We currently have customers ranging from 1 to 15,000 employees. Our licensing model is therefore also tailored to small or micro-enterprises.

DIGITAL FUTUREmag: You particularly recommend the use of your solution for companies in the fields of healthcare, finance, housing and professional confidentiality holders. What is your experience from discussions with decision-makers and how high is their willingness to address this issue?

Georg Nestmann: The willingness to address this issue is generally higher, the more legal requirements and demands regarding IT security a company must meet. Because often it is not just data protection laws – the KRITIS regulation or regulations such as BAIT in the banking sector also require secure communication, just like, for example, an ISO 27001 certification. Occasionally, there are also existing solutions in these sectors that have been identified as too complex for users and are to be replaced. Decision-makers in these areas are fully aware of the relevance of the topic – and are often interested in simple alternatives.

DIGITAL FUTUREmag: As customers, you were able to win the Munich Security Conference. Here, real experts meet. What was the decisive argument?

Georg Nestmann: For the MSC, the security of the conferences they host and the data of the often high-ranking participants is of the utmost priority. Alongside the security aspect, the ease of use without prior training was crucial for the MSC, as new employees are frequently brought in to help organize the ongoing conferences and should not need to be specially trained to use a security tool. The combination of ease of use for employees and unquestionable security in transmission was therefore decisive in choosing MXG.

DIGITAL FUTUREmag: How complex is the implementation of your tool?

Georg Nestmann: Implementation is quick, as our tool only affects the email outgoing side. If customers operate their email servers as a cloud system, e.g. M365, the setup is completed in under 30 minutes and MXG is ready for operation. The more complex the email infrastructure, the longer it naturally takes. However, the effort is far below that of typical IT projects.

DIGITAL FUTUREmag: That sounds feasible. Thank you very much for this insightful interview.