Back to Glossary

Entry · Business

Des

DES stands for Data Encryption Standard, an early and once widely used method of scrambling electronic data so that only people with the right key can read it. It protected card payments, bank transfers and other sensitive information for decades, but it is now considered too weak for modern use.

From the Money Master HQ dictionary, founded by Shihan Sheriff (FCMA, VP of Finance at Nomod, CFO at Esanjo Ventures). How these definitions are written.

What it means

Encryption turns readable information into a scrambled form, and a secret key turns it back. DES was developed in the 1970s and adopted as a US government standard, after which banks and payment companies built it into their systems.

It works on blocks of data that are 64 bits long and uses a key of 56 bits, which was considered strong at the time. For finance, DES mattered because it sat behind many everyday activities.

Cash machines, card terminals and interbank messaging all relied on it to keep personal identification numbers and account details private. Its wide adoption made it a foundation of electronic banking.

Over time, computers became so powerful that a 56-bit key could be guessed by trying every possibility, which is known as a brute force attack. Researchers demonstrated this in the late 1990s, and the standard was later withdrawn in favour of stronger methods.

A stronger variant called Triple DES, which applies the process three times, extended its life, but it has also been phased out in many settings. Today, finance teams are mostly concerned with DES in the context of legacy systems.

Older payment equipment, software or archived data may still use it, which creates a security and compliance risk. Card industry rules and auditors often require businesses to move to stronger standards such as AES (Advanced Encryption Standard).

The practical lesson is that security tools age. A control that was best practice a generation ago can become a weakness, so finance and technology teams should review what protects their data at regular intervals.

Replacing old encryption is rarely free, because it can involve new hardware, software upgrades and staff time. Budgeting for this work early is cheaper than paying for a breach or failing an audit later.

In practice

Real-world examples.

1

Example

A retailer audits its card payment terminals and finds that a batch of old devices still uses single DES to protect PIN data. The finance director budgets $120,000 to replace them before the next compliance review.

2

Example

A bank's operations team discovers that an archive of old customer files was encrypted with DES in the 1990s. It re-encrypts the archive using a modern standard and records the project in its risk register.

3

Example

A software supplier tells a client that its payroll system still supports DES for exports to an old partner system. The client's IT manager asks for the option to be switched off and inserts a clause in the contract requiring modern encryption.

Formula

Calculation

Number of possible keys = 2 ^ key length in bits DES uses a 56-bit key, so there are 2 ^ 56 = 72,057,594,037,927,936 possible keys, roughly 72 quadrillion. A modern key of 128 bits has 2 ^ 128 possible keys, which is 2 ^ 72 (about 4.7 sextillion) times more than DES. As a simple comparison, if a computer could test 1 billion keys per second, searching all DES keys would take about 72,057,594 seconds, or roughly 834 days, whereas special hardware testing trillions of keys per second can do it in far less time.

Case study

Seen in the real world.

Bluepeak Payments is a fictional payment processor used here as an illustrative example. During a routine audit, its security consultant finds that one legacy settlement system still uses DES to protect files sent to a small partner bank.

The finance director weighs a $90,000 upgrade against the potential cost of a breach, which could include fines, customer compensation and lost business. She approves the upgrade and schedules it to finish before the partner's next contract renewal, and the work is completed in six weeks.

The partner bank later cites the upgrade as a reason for extending the contract by three years. The episode becomes a short training example inside Bluepeak on why legacy controls need an owner and a review date.

Watch out

Common mistakes.

  • Assuming that anything encrypted is safe. The strength of the method and the key matters, and DES is now considered weak.
  • Believing Triple DES fixes everything. It is stronger than single DES but is also being retired in favour of newer methods.
  • Ignoring old archives and equipment. Legacy systems are where outdated encryption is most likely to hide.

Questions

People also ask.

What replaced DES?

The Advanced Encryption Standard, or AES, became the main replacement and is widely used today. It supports longer keys and is considered strong for current needs.

Why is DES relevant to finance staff?

It is part of the history of payment security and may still appear in older systems. Auditors and card industry rules expect businesses to know where outdated encryption is in use.

Is DES illegal to use?

It is not usually illegal, but many standards and contracts no longer allow it. Using it can lead to failed audits and higher breach risk.

Was this explanation helpful?

From the founder's library

Accounting Fundamentals: A Non-Finance Manager's Guide to Finance and Accounting, by Shihan Sheriff

Take it further with the book.

Build your financial confidence beyond this definition. Shihan's full-length guide, Accounting Fundamentals, takes the same plain-English approach and turns it into a complete, practical playbook for non-finance managers, business owners and students - with chapter-end quiz answers and presentation slides included.

US$2.24US$2.99

25% off with code MMHQ25, applied at checkout. Priced in USD - checkout may show the equivalent in your local currency.

View the book and save 25%

Related

Keep reading.

EncryptionCybersecurityPayment Card Industry Data Security StandardTriple DESAdvanced Encryption StandardOperational RiskData Breach
Last updated · October 8, 2026
Browse all terms →

Disclaimer

The information provided in this finance dictionary is for educational and informational purposes only. It should not be construed as financial, investment, legal, or tax advice. Always consult with a qualified professional before making any financial decisions. Money Master HQ makes no representations or warranties about the accuracy, completeness, or suitability of this information. Use of this content is at your own risk.