Securing Valuable Data

Perimeter security is flawed on many levels. Not only are businesses in every industry routinely breached but this model provides the same level of security for all data, irrespective of its value. As a result, when hackers are able to access a network, identifying and extracting valuable data can take less than half a day.

Data is a business’ most valuable asset, so why are security posture treating all data the same by continuing to focus security on the perimeter?

Risk Is Everywhere

No business is immune from the risk of security breach. From power station shut-downs, couriers unable to make deliveries and car retailers having their entire network locked while customers’ personal data, including bank details, is targeted, every business is vulnerable to cyber disruption and ransomware attack. The implications are becoming ever more severe. In addition to the loss of reputation and customer trust, the fines imposed by regulators are becoming ever more punitive. 

The reality for all businesses is that no system is safe when cyber criminals have so much time on their hands - and so many tools at their disposal. Plus, of course, businesses are making it easy, with traditional perimeter-based security models failing to provide adequate protection.  

In a recent Ethical Hacking survey, the most common reason for breach of the perimeter security was ‘vulnerable configurations’; or, to put it another way, human error. And the opportunities for breach become ever greater given the scale of global communications. From IoT to the cloud and highly complex global supply chains, companies have no control over the networks that have become core to every business operation.

Businesses do, however, have control over their data. And with a duty to both the company and customer base to protect that data, it is time to adopt a data first approach to security.

Data First Security

By wrapping security around the data, a business can safeguard this vital asset irrespective of infrastructure. Whether the data is generated within the business or by a third party, whether it is crossing an internal network, travelling via SD-WAN or across a supplier’s infrastructure, by adopting Layer 4, policy-based encryption a business can ensure the data payload is protected for its entire journey.

Encrypting the data means that the company’s most valuable asset has nothing to offer a hacker: all a bad actor can see is crypto-segmented flows of data. They have no idea if the data is payroll, command and control, customer information – or just a social media update. And this is key because bad actors really don’t need much time to identify and extract valuable data.

The Ethical Hacking survey revealed it typically takes less than one hour in 16% of cases and one to two hours for 24% of cases to see what data’s in motion and decide what’s most valuable to steal for a ransomware attack.

With crypto-segmentation, bad actors can spend as long as they like within a business and still be unable to identify any valuable information.

Policy Based Approach 

The policy-based encryption model allows companies to adopt an approach founded on data value, encrypting personally identifying information (PII) such as HR, healthcare or financial data, for example. With this orchestrated, policy-based solution, a business can define a business policy around a specific data set and allow the orchestration to deliver that to the various data protection enforcement points on the network.

Furthermore, as the business’ perception of data value and risk evolves, in response to operational or regulatory change, orchestration can deliver consistent change automatically across the business.

Additionally, this encryption model allows businesses within highly regulated industries, such as utilities, to meet growing expectations that all data must be encrypted irrespective of value. This reflects the new risks created by today’s complex, multi-directional networks and the use of IoT devices such as smart meters, which create a huge attack surface. 

And, because only the payload data is encrypted, while header data remains in the clear, there is minimal disruption to network services or applications. It means the business still has full visibility of all core metrics, including analytics, and it makes troubleshooting an encrypted network easier.

Conclusion

Global regulation is accelerating the need to focus on data, not infrastructure. Not only are growing numbers of vertical markets now affected by new regulatory demands but countries around the world have built on and extended the regulations introduced in the US and EU.

With interconnected global data flows, every business and its directors are far more vulnerable, not only to fines, but also prison terms. It is, therefore, vital to stop relying on perimeter security and look closely at protecting valuable data.

Simon Pamplin is CTO at Certes Networks

You Might Also Read: 

Who Foots the Bill For A Data Breach?:

___________________________________________________________________________________________

If you like this website and use the comprehensive 6,500-plus service supplier Directory, you can get unrestricted access, including the exclusive in-depth Directors Report series, by signing up for a Premium Subscription.

  • Individual £5 per month or £50 per year. Sign Up
  • Multi-User, Corporate & Library Accounts Available on Request

Cyber Security Intelligence: Captured Organised & Accessible


 

« Webinar: Firewall-as-a-service (FWaaS)
The Virtual & Real Cybersecurity Threats In The Metaverse  »

ManageEngine
CyberSecurity Jobsite
Check Point

Directory of Suppliers

North Infosec Testing (North IT)

North Infosec Testing (North IT)

North IT (North Infosec Testing) are an award-winning provider of web, software, and application penetration testing.

Resecurity

Resecurity

Resecurity is a cybersecurity company that delivers a unified platform for endpoint protection, risk management, and cyber threat intelligence.

Practice Labs

Practice Labs

Practice Labs is an IT competency hub, where live-lab environments give access to real equipment for hands-on practice of essential cybersecurity skills.

CSI Consulting Services

CSI Consulting Services

Get Advice From The Experts: * Training * Penetration Testing * Data Governance * GDPR Compliance. Connecting you to the best in the business.

F-Secure

F-Secure

F-Secure defends enterprises and consumers against everything from opportunistic ransomware infections to advanced cyber attacks.

Fasoo

Fasoo

Fasoo provides data-centric security to protect data within the organizational perimeter and beyond by limiting access to sensitive data according to policies that cover both users and activities.

VdS

VdS

VdS is an independent safety and security testing institution. Cybersecurity services include standards, audit/assessment and certification for SMEs.

Cyber Security For Critical Assets (CS4CA)

Cyber Security For Critical Assets (CS4CA)

Cyber Security For Critical Assets is a global series of summits focusing on cyber security for critical infrastructure.

4N6

4N6

4N6 is a privately-owned firm founded with the goal of providing expert knowledge of computer forensics.

Nexthink

Nexthink

Using our solution, hundreds of IT departments effectively balance offering a productive and enjoyable end-user experience with making the right decisions to secure and transform the digital workplace

Cryptshare

Cryptshare

Cryptshare is a communication solution that enables you to share e-mails and files of any size securely.

itbox.online

itbox.online

Itbox.online offers IT solutions to ensure that your company's technologies are always available and secure as your business demands.

BrandShelter

BrandShelter

BrandShelter specializes in providing online brand protection for companies and trademark owners.

Ridge Global

Ridge Global

Ridge Global works with C-suite executives and corporate directors to build more resilient organizations through innovative preparedness, protection, response and education capabilities.

Avint

Avint

Avint delivers transformational cybersecurity solutions that help both commercial and government entities achieve mission success.

CSIR Information & Cybersecurity Research Centre

CSIR Information & Cybersecurity Research Centre

The CSIR Information & Cybersecurity Research Centre focuses on research, development, and innovation of home-grown cyber and information security.

Securonix

Securonix

Securonix delivers a next generation security analytics and operations management platform for the modern era of big data and advanced cyber threats.

Kolide

Kolide

Kolide ensures that if a device isn't secure, it can't access your apps.

UBDS Digital

UBDS Digital

UBDS Digital is your Digital Lifecycle Partner for Secure Cloud Transformation.

Harmonia Holdings Group

Harmonia Holdings Group

Harmonia Holdings Group was born in 2006 with the vision to bring innovation and change to the federal IT sector.

WiseBee

WiseBee

WiseBee is an AI-driven cybersecurity platform that functions as your on-demand, autonomous security team.