Echoworx

Echoworx Echoworx provides advanced email encryption solutions for secure business communication. Known for Echoworx is 100% email encryption focused.

Our belief when we started was the same as it is today: protecting people's privacy is the right thing to do for business and for the world. We're headquartered in North America and with offices in the US and UK. And, with over 1 million users and 5000 deployments in over 30 countries, Echoworx customizable encryption is the platform of choice for some of the world's leading brands in banking, insurance, government and healthcare.

Recipient verification in enterprise email is moving from optional to enforced.For years, verification lived with the se...
08/31/2026

Recipient verification in enterprise email is moving from optional to enforced.

For years, verification lived with the sender. Protect the message, and the recipient might open it with a password, a one-time code, or whatever the organization allowed. That flexibility helped adoption. It also left a gap between what security teams recommended and what business units actually enforced.

Regulated institutions are closing that gap. Verification is becoming a control applied by default — to specific messages, user groups, data classes, and destinations.

So the question worth asking has changed.

Not "does the service support verification?"

But whether verification can be required by policy, matched to the risk of the message, and recorded as evidence a reviewer can follow.

That distinction carries weight, because not all authentication is equal. A password, an SMS code, and a phishing-resistant authenticator offer very different assurance. Convenience methods are a floor, not a ceiling.

Handled well, secure email stops behaving like a product feature and starts behaving like a governed control: consistent enforcement, measured exceptions, and auditable proof.

Enforcement without flexibility is blunt. Flexibility without enforcement stays optional in name only. The strongest programs hold both — and treat every protected message as a promise kept, not a setting left to chance.

https://small-bizsense.com/from-optional-to-enforced-why-recipient-verification-is-becoming-an-enterprise-email-policy/

Recipient verification is moving from a user-selectable safeguard to a policy requirement. The change raises a harder question for security leaders: not whether to verify, but how to choose authentication that matches the risk. For years, encrypted email portals often treated recipient verification....

Security stacks are quietly becoming ecosystems. In regulated workflows, integration quality, auditability, and digital ...
08/28/2026

Security stacks are quietly becoming ecosystems. In regulated workflows, integration quality, auditability, and digital trust now outweigh any single platform's feature list.

The likely winner isn't the biggest suite—it's the composable one, with clear responsibilities.

https://www.xinureturns.com/cybersecurity-roundup-seven-signals-that-security-stacks-are-becoming-ecosystems/

Cybersecurity strategy is shifting away from the idea that one platform can absorb every control. Cloud services, identity systems, secure email gateways, data-loss prevention, certificate authorities, encryption services, endpoint tools and security operations all see a different part of the same t...

Something quiet has changed in how regulated institutions think about encryption.It used to be a tool you switched on. N...
08/27/2026

Something quiet has changed in how regulated institutions think about encryption.

It used to be a tool you switched on. Now, under DORA and NIS2, it's part of your governance story — the evidence you reach for when an audit lands.

Derek Christiansen, Engagement Manager at Echoworx, works directly with the world's most regulated institutions. These are the five shifts he says keep coming up — across sectors, across projects, across audit cycles. A few patterns stood out.

Legacy encryption is becoming a liability. Change control on aging on-premise hardware can stretch weeks or months — the opposite of the operational resilience regulators now expect. Cloud-native platforms close that gap. One Top 5 Canadian bank moved thousands of users onto a cloud-native foundation without a single day of disruption, feeding live audit data straight into its SIEM.

Rip-and-replace is losing favor. The safest modernization preserves what already works. Platform-agnostic encryption runs alongside existing DLP and email hygiene tools, so transitions happen on the institution's timeline — not a vendor's.

Mandatory verification is becoming the baseline. Proving that only the right recipient opened a message is shifting from optional setting to expected standard. The technical range matters, because a mandate only holds if people can actually comply.

Certificate management is where compliance is quietly won or lost. An expired certificate breaks secure communication at the worst possible moment. Automated lifecycle management removes those failure points — this is efficiency measured in resilience, not saved hours.

Audit readiness is becoming a standing posture rather than a scramble. One Irish commercial bank saw a 63% increase in encryption adoption under DORA and GDPR — growth driven by trust in the platform, not a mandate. Every message logged, every policy trigger recorded, every delivery state captured.

Underpinning all of it: independent proof. SOC 2, PCI DSS, and FSQS registration are the credibility markers compliance teams, security architects, and procurement reviewers look for before they say yes.

Read across the five, and one theme holds. Encryption is no longer a standalone tool. It's strategic infrastructure — woven into compliance, resilience, and digital trust. The institutions modernizing now are the ones who won't be caught explaining a gap later.

"Our communications are secure."In DACH, that sentence no longer clears the bar.Under DORA and NIS2, regulators don't wa...
08/06/2026

"Our communications are secure."
In DACH, that sentence no longer clears the bar.

Under DORA and NIS2, regulators don't want to hear that your controls exist. They want you to prove it — with auditable records, jurisdiction-aware data residency, and consistent policy across every message and every reply.

That's a real shift. Encryption used to be treated as a tool you bolted on. Now, governed secure communication is infrastructure — built into cloud transformation from day one, not patched in after the audit finds the gap.

So today we're proud to share this: Echoworx and NTT DATA Deutschland are partnering to deliver governed secure communications across Germany, Austria, and Switzerland — as one integrated ecosystem.

• NTT DATA brings enterprise-grade systems integration — that makes modernization succeed at scale.
• Echoworx brings the cloud-native governance layer — policy-driven encryption, automated certificate lifecycle management, full reply-chain control.

We're making our joint debut at it-sa Expo & Congress this October — and couldn't be more excited to show what "proof, not promises" actually looks like in practice.

Full announcement in the comments. 👇

Some news just feels good to share.Echoworx has officially joined FS-ISAC as an Affiliate Member.It's a step that reflec...
07/23/2026

Some news just feels good to share.
Echoworx has officially joined FS-ISAC as an Affiliate Member.
It's a step that reflects who we are — and who we want to keep becoming.

For years, we've built our work around one conviction: protecting sensitive data in financial services isn't something any organization can accomplish from the outside looking in. It takes proximity. It takes trust. And it takes the kind of structured, ongoing knowledge exchange that FS-ISAC has been enabling across the financial sector for decades.

The threats that keep security leaders awake aren't static. They're adaptive, cross-border, and increasingly shaped by AI. So is the regulatory pressure — DORA, NIS2, and the broader compliance landscape are raising the bar for what "secure" actually means when data moves between organizations. That's the environment our customers operate in every day. And it's exactly the environment that demands more than point solutions. It demands community.

Our focus at Echoworx has always been on the part of that challenge that often gets overlooked: securing regulated external communication — the messages, statements, and documents that cross organizational and jurisdictional lines, and where a failure carries real consequences for real people.

Joining FS-ISAC brings us closer to the institutions, leaders, and conversations shaping how the financial sector defends itself — not just today, but over the long term. We're here to learn, to contribute what we know, and to be a more useful partner to every organization that puts its trust in us.

To the FS-ISAC community — we're honored to be part of it.

For regulated institutions, compliance stopped being a checkbox a while ago. DORA, NIS2, and GDPR raised the bar on what...
07/16/2026

For regulated institutions, compliance stopped being a checkbox a while ago.

DORA, NIS2, and GDPR raised the bar on what "secure" has to prove — audit readiness, data sovereignty, control you can actually demonstrate.

Here's the part that doesn't always make the headlines: the institutions living with those expectations every day are the ones shaping what gets built to meet them.

That's the story behind the latest Echoworx releases. The new features didn't start on a roadmap. They started as requests from compliance and risk teams navigating the same pressures you are:

• Encryption that holds up under audit, not just in theory.
• Data sovereignty handled by design, across jurisdictions.
• Oversight and control that fit how regulated teams actually work.

None of it invented in a vacuum. All of it a response to what peers facing the same requirements asked for.

Maybe that's the quiet sign encryption has grown up — it's shaped less by what a vendor imagines and more by what regulated institutions need to prove.

The full context is in the blog — read it here → https://echoworx.com/blog/from-scrambled-to-provable-encryption-grows-up/

Well, that was a blur. ✈️One week. Two countries. More coffees than we can count.We went from New York energy to German ...
06/25/2026

Well, that was a blur. ✈️

One week. Two countries. More coffees than we can count.

We went from New York energy to German hospitality, and honestly? Our team is still catching its breath (and possibly still digesting all that good food 🍽️).

Here's what made it special:
• The familiar faces who feel more like old friends than partners
• The new connections that started over dinner and somehow turned into late-night, big-idea conversations
• The reminder that a handshake, a laugh, and a shared meal still beat any video call

We talked. We learned. We ate well. We may have had a drink or two 🥂

And through all of it, the same thing kept hitting us: the best part of this work isn't the slides or the agendas. It's the people. The ones who show up, lean in, and actually make this industry fun to be part of.

To everyone who shared a table, a story, or a "let's grab five minutes" with us — thank you. You made the miles worth it.

Now, time to recover before the next round of boarding passes 😄
Where should we land next? 🌍

Most AI roadmaps accelerate the systems that generate sensitive information. Far fewer modernize the controls that prote...
06/24/2026

Most AI roadmaps accelerate the systems that generate sensitive information. Far fewer modernize the controls that protect it once it leaves the building.

For CISOs and enterprise architects: is outbound communication security entering your cloud and AI architecture conversations early, or arriving after the gap is already visible?

Artificial intelligence is changing the speed of enterprise work. Documents are reviewed faster. Internal knowledge is surfaced more quickly. Customer ...

Amsterdam, we're on our way. Our team is heading to the FS-ISAC EMEA Summit, and honestly? We can't wait. There's nothin...
06/12/2026

Amsterdam, we're on our way. Our team is heading to the FS-ISAC EMEA Summit, and honestly? We can't wait.

There's nothing like swapping ideas in person, and at The Hague!

We're kicking things off at the Welcome Reception, we're a sponsor.

If you'll be there, be sure to say hello to Chris and Rosario - we'd love to connect.

See you in Amsterdam 🇳🇱


https://www.fsisac.com/events/2026-emea-summit

06/05/2026

Encrypted email is a compliance control. Most institutions still govern it like a back-office utility.

Most banks have modernized their inbound security stack. Almost none have done the same for what leaves the building.

That asymmetry is now a governance problem.

DORA doesn't prescribe an encryption platform. But it does raise the bar on what "dependable" looks like at scale — and secure external communication is one of the areas that fails that test most quietly.

When certificate renewals depend on manual intervention, operational risk is predictable, not hypothetical. When users route around friction, the control still exists on paper. It just doesn't function.

For regulated institutions pursuing cloud-native modernization, AI-enabled operating models, and tighter audit readiness, that gap is no longer acceptable.

Three questions that belong in the resilience conversation:
→ Can every regulated external communication be traced, governed, and demonstrated to auditors?
→ Does your secure communication architecture align with your 2026–2027 cloud and efficiency mandates?
→ If your encryption infrastructure requires manual administration at scale, is it actually a control — or a liability?

These are not IT questions. They belong in the same room as DORA readiness, third-party risk reviews, and data sovereignty frameworks.

Echoworx works with the world's most regulated institutions to make secure external communication auditable, cloud-native, and operationally sound — not a bottleneck inside the modernization programs you're already funding.

The full argument is in the article. Worth a read if you're navigating any of the above.

Read → https://www.finextra.com/blogposting/31940/why-banks-are-reassessing-legacy-email-encryption-as-dora-ai-and-cloud-modernization-converge

What's your institution treating as the biggest friction point in secure external communication right now?

Address

4101 Yonge Street
North York, ON
M2P1N6

Opening Hours

Monday 9am - 5pm
Tuesday 9am - 5pm
Wednesday 9am - 5pm
Thursday 9am - 5pm
Friday 9am - 5pm

Telephone

+18007358916

Alerts

Be the first to know and let us send you an email when Echoworx posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Contact The Business

Send a message to Echoworx:

Shortcuts

Share