Securing Valuable Data

Perimeter security is flawed on many levels. Not only are businesses in every industry routinely breached but this model provides the same level of security for all data, irrespective of its value. As a result, when hackers are able to access a network, identifying and extracting valuable data can take less than half a day.

Data is a business’ most valuable asset, so why are security posture treating all data the same by continuing to focus security on the perimeter?

Risk Is Everywhere

No business is immune from the risk of security breach. From power station shut-downs, couriers unable to make deliveries and car retailers having their entire network locked while customers’ personal data, including bank details, is targeted, every business is vulnerable to cyber disruption and ransomware attack. The implications are becoming ever more severe. In addition to the loss of reputation and customer trust, the fines imposed by regulators are becoming ever more punitive. 

The reality for all businesses is that no system is safe when cyber criminals have so much time on their hands - and so many tools at their disposal. Plus, of course, businesses are making it easy, with traditional perimeter-based security models failing to provide adequate protection.  

In a recent Ethical Hacking survey, the most common reason for breach of the perimeter security was ‘vulnerable configurations’; or, to put it another way, human error. And the opportunities for breach become ever greater given the scale of global communications. From IoT to the cloud and highly complex global supply chains, companies have no control over the networks that have become core to every business operation.

Businesses do, however, have control over their data. And with a duty to both the company and customer base to protect that data, it is time to adopt a data first approach to security.

Data First Security

By wrapping security around the data, a business can safeguard this vital asset irrespective of infrastructure. Whether the data is generated within the business or by a third party, whether it is crossing an internal network, travelling via SD-WAN or across a supplier’s infrastructure, by adopting Layer 4, policy-based encryption a business can ensure the data payload is protected for its entire journey.

Encrypting the data means that the company’s most valuable asset has nothing to offer a hacker: all a bad actor can see is crypto-segmented flows of data. They have no idea if the data is payroll, command and control, customer information – or just a social media update. And this is key because bad actors really don’t need much time to identify and extract valuable data.

The Ethical Hacking survey revealed it typically takes less than one hour in 16% of cases and one to two hours for 24% of cases to see what data’s in motion and decide what’s most valuable to steal for a ransomware attack.

With crypto-segmentation, bad actors can spend as long as they like within a business and still be unable to identify any valuable information.

Policy Based Approach 

The policy-based encryption model allows companies to adopt an approach founded on data value, encrypting personally identifying information (PII) such as HR, healthcare or financial data, for example. With this orchestrated, policy-based solution, a business can define a business policy around a specific data set and allow the orchestration to deliver that to the various data protection enforcement points on the network.

Furthermore, as the business’ perception of data value and risk evolves, in response to operational or regulatory change, orchestration can deliver consistent change automatically across the business.

Additionally, this encryption model allows businesses within highly regulated industries, such as utilities, to meet growing expectations that all data must be encrypted irrespective of value. This reflects the new risks created by today’s complex, multi-directional networks and the use of IoT devices such as smart meters, which create a huge attack surface. 

And, because only the payload data is encrypted, while header data remains in the clear, there is minimal disruption to network services or applications. It means the business still has full visibility of all core metrics, including analytics, and it makes troubleshooting an encrypted network easier.

Conclusion

Global regulation is accelerating the need to focus on data, not infrastructure. Not only are growing numbers of vertical markets now affected by new regulatory demands but countries around the world have built on and extended the regulations introduced in the US and EU.

With interconnected global data flows, every business and its directors are far more vulnerable, not only to fines, but also prison terms. It is, therefore, vital to stop relying on perimeter security and look closely at protecting valuable data.

Simon Pamplin is CTO at Certes Networks

You Might Also Read: 

Who Foots the Bill For A Data Breach?:

___________________________________________________________________________________________

If you like this website and use the comprehensive 6,500-plus service supplier Directory, you can get unrestricted access, including the exclusive in-depth Directors Report series, by signing up for a Premium Subscription.

  • Individual £5 per month or £50 per year. Sign Up
  • Multi-User, Corporate & Library Accounts Available on Request

Cyber Security Intelligence: Captured Organised & Accessible


 

« Webinar: Firewall-as-a-service (FWaaS)
The Virtual & Real Cybersecurity Threats In The Metaverse  »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Authentic8

Authentic8

Authentic8 transforms how organizations secure and control the use of the web with Silo, its patented cloud browser.

CYRIN

CYRIN

CYRIN® Cyber Range. Real Tools, Real Attacks, Real Scenarios. See why leading educational institutions and companies in the U.S. have begun to adopt the CYRIN® system.

ZenGRC

ZenGRC

ZenGRC - the first, easy-to-use, enterprise-grade information security solution for compliance and risk management - offers businesses efficient control tracking, testing, and enforcement.

BackupVault

BackupVault

BackupVault is a leading provider of automatic cloud backup and critical data protection against ransomware, insider attacks and hackers for businesses and organisations worldwide.

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall (and why does it matter)?

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall (and why does it matter)?

Watch this webinar to hear security experts from Amazon Web Services (AWS) and SANS break down the myths and realities of what an NGFW is, how to use one, and what it can do for your security posture.

LRQA

LRQA

LRQA are a leading global assurance provider, bringing together unrivalled expertise in certification, brand assurance, cybersecurity, inspection and training.

SecWest

SecWest

SecWest is the organizer of CanSecWest, PACSEC, originator of PWN2OWN, security auditing, and virtual engagement/training.

OSIRIS Lab - NYU Tandon

OSIRIS Lab - NYU Tandon

The Offensive Security, Incident Response & Internet Security Lab (OSIRIS) is a security research environment where students analyze and understand how attackers take advantage of real systems.

Rogue Wave Software

Rogue Wave Software

At Rogue Wave, our mission is to simplify your hardest problems, improve software quality and security, and shorten the time it takes to deliver value.

Payatu

Payatu

Payatu Technologies is a security testing and services company specialized in Software, Application and Infrastructure security assessments and deep technical security training.

Cyberlitica

Cyberlitica

Cyberlitica (formerly iPhish) provides a Workforce Threat Intelligence application that significantly augments companies’ cyber threat prevention efforts.

Modulo Security

Modulo Security

Modulo provides automated Governance, Risk, and Compliance (GRC) solutions.

Barbara IoT

Barbara IoT

Barbara is an industrial device platform specifically designed for IoT deployments.

Beosin

Beosin

Beosin is a blockchain security company providing cybersecurity services including security audits, on-chain asset investigation, threat intelligence and wallet security.

RUSCADASEC

RUSCADASEC

RUSCADASEC is an independent non-profit initiative on developing the open Russian-speaking international community of industrial cyber security/ICS/SCADA cyber security professionals.

Simply Hired

Simply Hired

Simply Hired is a job search engine that collects job listings from all over the web, including company career pages, job boards and niche job websites.

Purple Knight

Purple Knight

Purple Knight is a free Active Directory security assessment tool built and managed by an elite group of Microsoft identity experts.

Red Goat Cyber Security

Red Goat Cyber Security

Red Goat Cyber Security have created excellent, informative and interactive Social Engineering Awareness training which is suitable for all levels of staff.

Sure Valley Ventures

Sure Valley Ventures

Sure Valley Ventures is an entrepreneur led venture capital fund focused on helping software entrepreneurs grow and scale businesses that will have a global impact.

KATIM

KATIM

KATIM is a leader in the development of innovative secure communication products and solutions for governments and businesses.

Anchor Technologies Inc (ATI)

Anchor Technologies Inc (ATI)

Anchor provides a full spectrum of cybersecurity services assisting our clients with all aspects of cybersecurity risk planning, identification, management, and monitoring.