That's two different points through from a company perspective. The first is whether you're compliant with well-defined local regulations for the jurisdictions you are within, as well as any industry specific regulations you're under (think Finance). For example, the specific regulations for employee email are substantially different in the UK, Germany and USA.
The point you're making is whether 'state actors' can get into your documents or email. It's a different order of magnitude issue. First, as a company you're going to comply with whatever the law is in the jurisdiction. Second, if you're being attacked by a state actor then you've got major issues. And for many businesses even considering protecting against that wouldn't make sense from a cost vs risk perspective.
Comments
That's two different points through from a company perspective. The first is whether you're compliant with well-defined local regulations for the jurisdictions you are within, as well as any industry specific regulations you're under (think Finance). For example, the specific regulations for employee email are substantially different in the UK, Germany and USA.
The point you're making is whether 'state actors' can get into your documents or email. It's a different order of magnitude issue. First, as a company you're going to comply with whatever the law is in the jurisdiction. Second, if you're being attacked by a state actor then you've got major issues. And for many businesses even considering protecting against that wouldn't make sense from a cost vs risk perspective.