What it means
Encryption turns readable information into a scrambled form, and a secret key turns it back. DES was developed in the 1970s and adopted as a US government standard, after which banks and payment companies built it into their systems.
It works on blocks of data that are 64 bits long and uses a key of 56 bits, which was considered strong at the time. For finance, DES mattered because it sat behind many everyday activities.
Cash machines, card terminals and interbank messaging all relied on it to keep personal identification numbers and account details private. Its wide adoption made it a foundation of electronic banking.
Over time, computers became so powerful that a 56-bit key could be guessed by trying every possibility, which is known as a brute force attack. Researchers demonstrated this in the late 1990s, and the standard was later withdrawn in favour of stronger methods.
A stronger variant called Triple DES, which applies the process three times, extended its life, but it has also been phased out in many settings. Today, finance teams are mostly concerned with DES in the context of legacy systems.
Older payment equipment, software or archived data may still use it, which creates a security and compliance risk. Card industry rules and auditors often require businesses to move to stronger standards such as AES (Advanced Encryption Standard).
The practical lesson is that security tools age. A control that was best practice a generation ago can become a weakness, so finance and technology teams should review what protects their data at regular intervals.
Replacing old encryption is rarely free, because it can involve new hardware, software upgrades and staff time. Budgeting for this work early is cheaper than paying for a breach or failing an audit later.
In practice
Real-world examples.
Example
A retailer audits its card payment terminals and finds that a batch of old devices still uses single DES to protect PIN data. The finance director budgets $120,000 to replace them before the next compliance review.
Example
A bank's operations team discovers that an archive of old customer files was encrypted with DES in the 1990s. It re-encrypts the archive using a modern standard and records the project in its risk register.
Example
A software supplier tells a client that its payroll system still supports DES for exports to an old partner system. The client's IT manager asks for the option to be switched off and inserts a clause in the contract requiring modern encryption.
Formula
Calculation
Number of possible keys = 2 ^ key length in bits
DES uses a 56-bit key, so there are 2 ^ 56 = 72,057,594,037,927,936 possible keys, roughly 72 quadrillion. A modern key of 128 bits has 2 ^ 128 possible keys, which is 2 ^ 72 (about 4.7 sextillion) times more than DES. As a simple comparison, if a computer could test 1 billion keys per second, searching all DES keys would take about 72,057,594 seconds, or roughly 834 days, whereas special hardware testing trillions of keys per second can do it in far less time.Case study
Seen in the real world.
Bluepeak Payments is a fictional payment processor used here as an illustrative example. During a routine audit, its security consultant finds that one legacy settlement system still uses DES to protect files sent to a small partner bank.
The finance director weighs a $90,000 upgrade against the potential cost of a breach, which could include fines, customer compensation and lost business. She approves the upgrade and schedules it to finish before the partner's next contract renewal, and the work is completed in six weeks.
The partner bank later cites the upgrade as a reason for extending the contract by three years. The episode becomes a short training example inside Bluepeak on why legacy controls need an owner and a review date.
Watch out
Common mistakes.
- Assuming that anything encrypted is safe. The strength of the method and the key matters, and DES is now considered weak.
- Believing Triple DES fixes everything. It is stronger than single DES but is also being retired in favour of newer methods.
- Ignoring old archives and equipment. Legacy systems are where outdated encryption is most likely to hide.
Questions
People also ask.
What replaced DES?
The Advanced Encryption Standard, or AES, became the main replacement and is widely used today. It supports longer keys and is considered strong for current needs.
Why is DES relevant to finance staff?
It is part of the history of payment security and may still appear in older systems. Auditors and card industry rules expect businesses to know where outdated encryption is in use.
Is DES illegal to use?
It is not usually illegal, but many standards and contracts no longer allow it. Using it can lead to failed audits and higher breach risk.
From the founder's library

Take it further with the book.
Build your financial confidence beyond this definition. Shihan's full-length guide, Accounting Fundamentals, takes the same plain-English approach and turns it into a complete, practical playbook for non-finance managers, business owners and students - with chapter-end quiz answers and presentation slides included.
25% off with code MMHQ25, applied at checkout. Priced in USD - checkout may show the equivalent in your local currency.
View the book and save 25%Related
