Paid feature Heres the irony of ransomware data breach stories that gets surprisingly little attention: cybercriminals enthusiastically encrypt and steal sensitive data to extort money and yet their victims rarely bother to defend themselves using the same obviously highly effective concept.
It should be a no-brainer. If sensitive data such as IP are competently encrypted, that not only means that attackers cant access or threaten to leak it, in many cases they wont even be able to see it in the first place all encrypted data looks alike.
Ransomware is like a tap on the shoulder, telling everyone they have a problem. Its not that criminals are able to reach the data perhaps thats inevitable but that when they get there, the data is defenceless, exposed. You could even argue that ransomware wouldnt exist if encryption and data classification had been widely adopted in the Internets early days.
Historically, the calculation has always been less clear cut. Using encryption (or tokenisation) across an organisations data is seen as adding complexity, expense and imposing a rigour few beyond elite regulated industries and government departments are willing to take on. Its an issue thats not lost on Thales UKs cybersecurity specialist Romana Hamplova, and Chris Martin, IAM pre-sales solutions architect.
Ransomware targets sensitive data. But if the attackers cant see the contents of the file because of encryption, they cant see that its sensitive, agrees Hamplova. "On the other hand, there is no need to encrypt all data, only the data that qualifies as worth protecting. Just as you don't want to have exposed/unprotected all/sensitive data, you also don't want to have maximum security applied to public data because that just slows down the infrastructure.
The catch, she says, is that organisations often arent always certain where that sensitive data is in an increasingly complex world where data gets moved around, deleted, changed, and re-classified. In many cases, they dont have any easy way to identify what is and isnt sensitive. What youre left with is a form of data paralysis where organisations default back to trying to stop access to sensitive data rather than protecting the data itself.
The first job for organisations is to understand what data they have. We enable them to discover the data in both structured and unstructured format and scan those locations and find out what data is there. For instance, perhaps they want to understand what GDPR data they have, or to adhere to PCI-DSS or HIPAA, says Hamplova.
The ongoing chaos surrounding data and what to do with it was confirmed by Thaless 2021 Thales Data Threat Report, which found that three quarters of the 2,600 global IT respondents questioned werent certain where all their organisations data was located.
Less than a third said they were able to classify or categorise it according to sensitivity. Interestingly on the data protection side, despite 42 per cent saying theyd experienced a data breach within the previous 12 months, half of victims were still able to avoid making a notification to information commissioners because the stolen data had been encrypted.
In terms of near-term spending priorities, 37 per cent of respondents mentioned encryption, only one per cent less than the percentage mentioning data loss prevention. An identical 37 per cent rated tokenisation as the most effective technology for protecting data, followed by data discovery and classification at 36 per cent, with encryption seen as the most effective by 34 per cent.
Working from home has made organisations aware of the data risks they have been taking, says Martin. When people are in an office, there is an implicit amount of security. With working from home, the implied security is lost. You dont have the visibility of that person sitting in front of their computer.
Architectural changes such as cloud access exacerbate this. Whats happened in the last 18 months is that companies are protecting their VPN. But employees are using applications that are not internal, so VPN access wont necessarily control access to the applications or data. They are now separate.
Another anxiety was the burden of software complexity itself, with organisations securing themselves using a mesh of overlapping tools. For example, 40 per cent or organisations admitted to using between five and seven different key management systems, with 15 per cent putting the number at between eight and ten. Much of this headache is caused by the growing importance of diverse cloud platforms.
The companys 2021 Access Management Index uncovered a similar picture with authentication, with 34 per cent of respondents in the UK admitting that they used three or more authentication tools, with 26 per cent using three to five, and 8 per cent putting the number at more than five. That level of complexity makes management harder but also significantly raises the likelihood of misconfiguration and error.
By coincidence, just as the pandemic sent everyone scurrying to their spare rooms to work in early 2020, US super-body NIST published its first draft of SP 1800-25, which for the first time offered specific advice on coping with ransomware. This was followed in June this year with the NISTIR 8374, which related anti-ransomware strategy to the organisations risk-oriented Cybersecurity Framework, first published in 2014.
Built around the overarching Framework, everything NIST publishes these days is quickly funnelled into best practice presentations the world over. Its influence is being felt across an industry that cant pretend it hasnt been warned, agrees Martin.
The significance of this is huge. We are used to regulations such as PCI-DSS and GDPR, but NIST is trying to raise the profile of ransomware. It affects the supply chain. NIST is trying to use its weight to do something about this sooner rather than later. The urgency has been raised.
Frameworks work in a different way to rules. Rules create boundaries, a narrow focus, and the risk of the infamous tick box mindset that says that if the rule has been followed, the job is done. Twenty years of cybersecurity failure says rules arent enough. It could be that frameworks encourage more nuanced, long-term thinking.
Even though companies dont necessarily have to comply with the NIST recommendations, they still like to follow it because they understand that it is best practice, says Hamplova. We have been recommending best practice for years but unless there is a third-party body like NIST it doesnt always have enough strength. Having a guideline like this can help companies to focus.
A wider challenge remains the need to translate best practice into something which can be understood and implemented under real world conditions. Thales currently offers a wide range of data protection products and technology across the cybersecurity stack, bolstered by acquisitions including Alcatel Lucents cybersecurity division (2014), Vormetric (2016), and Gemalto (2017).
The Thales portfolio covers a large proportion of the data protection stack, starting with data classification and encryption, addressed by the CipherTrust platform. This also maps to the risk assessment subsection within the NIST Frameworks Identify risk assessment category (ID.RA). A critical element of CipherTrust is its transparent encryption approach, which means it is processed automatically without manual intervention.
In our systems, encryption should always be transparent to an authorised user or application, to ensure business processes run uninterrupted comments Hamplova.
As well as file encryption, CipherTrust also allows organisations to apply and manage encryption and tokenization for applications and databases using APIs. The second layer is access control and authentication, provided by SafeNet Trusted Access, which corresponds to NISTs Protect, access control category (PR.AC). Within the context of home working, SafeNet adds a layer of security that is more reliable than naively relying on VPNs alone.
This must go beyond simply identifying the user, says Martin. Its also about the context, for example where they are located. We can geo-locate with IP address or mobile phone. If someone is doing something from the same IP address as their home, we have a greater degree of confidence about their identity. Its about taking authentication to the next level.
Both Hamplova and Martin are cautiously optimistic about the latest cybersecurity bandwagon, zero trust (ZT), which can be thought of as a software-defined perimeter. The idea is a good one assess users, credentials, or applications before allowing them access but there are still practical difficulties in implementation. It would be perverse if an attempt to reform the nave trust in credentials that has caused so many cybersecurity problems simply created new layers of complexity.
Our society innovates built on trust. When we talk of zero trust, its not about being unable to trust anything but about establishing the right element of trust and build from there, says Hamplova.
Martin agrees: Is zero trust impossible? Ultimately, you have to trust someone or something in your organisations, or externally when accepting trust certificates.
The issue of complexity remains a lurking worry with too many trust gateways being used to manage poorly integrated technologies. If authentication becomes too complex, trust becomes impossible to deliver. The Thales perspective is that the acid test for cybersecurity is whether it can protect data.
Says Hamplova: As all cybersecurity specialists know, there is no nirvana! Its always about making it harder for the cyber criminals to reach the critical data and ensuring your organisation is resilient enough to continue operating, should the worst happen.
This article is sponsored by Thales.
Continued here:
If cybercriminals cant see data because its encrypted, they have nothing to steal - The Register
- WhatsApp overhauling status tab with encrypted Snapchat Stories-like feature - 9 to 5 Mac [Last Updated On: February 21st, 2017] [Originally Added On: February 21st, 2017]
- GOP demands inquiry into EPA use of encrypted messaging apps - CNET [Last Updated On: February 21st, 2017] [Originally Added On: February 21st, 2017]
- Encryption Apps Help White House Staffers Leakand Maybe Break the Law - WIRED [Last Updated On: February 21st, 2017] [Originally Added On: February 21st, 2017]
- World Wide Web Creator Calls for Internet Decentralization & Encryption - The Data Center Journal [Last Updated On: February 21st, 2017] [Originally Added On: February 21st, 2017]
- What It Means to Have an 'Adult' Conversation on Encryption - Pacific Standard [Last Updated On: February 21st, 2017] [Originally Added On: February 21st, 2017]
- Confide in me! Encryption app leaks sensitive info from Washington DC - SC Magazine UK [Last Updated On: February 21st, 2017] [Originally Added On: February 21st, 2017]
- Gmail v7.2 Prepares to Add Support for S/MIME Enhanced Encryption - XDA Developers (blog) [Last Updated On: February 26th, 2017] [Originally Added On: February 26th, 2017]
- Top 6 Data Encryption Solutions - The Merkle [Last Updated On: February 26th, 2017] [Originally Added On: February 26th, 2017]
- Your Guide to the Encryption Debate - Consumer Reports - ConsumerReports.org [Last Updated On: February 26th, 2017] [Originally Added On: February 26th, 2017]
- Google helps put aging SHA-1 encryption out to pasture - Engadget [Last Updated On: February 26th, 2017] [Originally Added On: February 26th, 2017]
- Decipher your Encryption Challenges - Infosecurity Magazine [Last Updated On: February 28th, 2017] [Originally Added On: February 28th, 2017]
- How the Politics of Encryption Affects Government Adoption - Freedom to Tinker [Last Updated On: February 28th, 2017] [Originally Added On: February 28th, 2017]
- How Encryption Makes Your Sensitive Cloud-Based Data an Asset, Not a Liability - Security Intelligence (blog) [Last Updated On: February 28th, 2017] [Originally Added On: February 28th, 2017]
- Set up VMware VM Encryption for hypervisor-level security - TechTarget [Last Updated On: February 28th, 2017] [Originally Added On: February 28th, 2017]
- How The Media Are Using Encryption Tools To Collect Anonymous Tips - NPR [Last Updated On: February 28th, 2017] [Originally Added On: February 28th, 2017]
- Encryption patent that roiled Newegg is dead on appeal | Ars Technica - Ars Technica [Last Updated On: February 28th, 2017] [Originally Added On: February 28th, 2017]
- Research proposes 'full-journey' email encryption - The Stack [Last Updated On: March 1st, 2017] [Originally Added On: March 1st, 2017]
- Database-as-a-service platform introduces encryption-at-rest - BetaNews [Last Updated On: March 1st, 2017] [Originally Added On: March 1st, 2017]
- Encrypted Messaging Service 'Signal' Adds Video Call Option - Top Tech News [Last Updated On: March 2nd, 2017] [Originally Added On: March 2nd, 2017]
- Germany, France lobby hard for terror-busting encryption backdoors ... - The Register [Last Updated On: March 2nd, 2017] [Originally Added On: March 2nd, 2017]
- How to Send Encrypted Nudes, a Guide for the Discerning Lover - Inverse [Last Updated On: March 2nd, 2017] [Originally Added On: March 2nd, 2017]
- Ironclad Encryption Corporation Announces New Ticker Symbol OTCQB: IRNC - Yahoo Finance [Last Updated On: March 2nd, 2017] [Originally Added On: March 2nd, 2017]
- The Best Email Encryption Software of 2017 | Top Ten Reviews [Last Updated On: March 2nd, 2017] [Originally Added On: March 2nd, 2017]
- No, you shouldn't delete Signal or other encrypted apps - TechCrunch [Last Updated On: March 11th, 2017] [Originally Added On: March 11th, 2017]
- Best encryption software: Top 5 - Computer Business Review [Last Updated On: March 11th, 2017] [Originally Added On: March 11th, 2017]
- Encryption Backdoors, Vault 7, and the Jurassic Park Rule of Internet Security - Just Security [Last Updated On: March 11th, 2017] [Originally Added On: March 11th, 2017]
- That Encrypted Chat App the White House Liked? Full of Holes - WIRED [Last Updated On: March 11th, 2017] [Originally Added On: March 11th, 2017]
- What the CIA WikiLeaks Dump Tells Us: Encryption Works - New York Times [Last Updated On: March 11th, 2017] [Originally Added On: March 11th, 2017]
- Snake-Oil Alert Encryption Does Not Prevent Mass-Snooping - Center for Research on Globalization [Last Updated On: March 11th, 2017] [Originally Added On: March 11th, 2017]
- Customer Letter - Apple [Last Updated On: March 11th, 2017] [Originally Added On: March 11th, 2017]
- Don't Let WikiLeaks Scare You Off of Signal and Other Encrypted Chat Apps - WIRED [Last Updated On: March 12th, 2017] [Originally Added On: March 12th, 2017]
- BT to offer customers encryption service for data - Capacity Media (registration) [Last Updated On: March 12th, 2017] [Originally Added On: March 12th, 2017]
- Encryption - technet.microsoft.com [Last Updated On: March 12th, 2017] [Originally Added On: March 12th, 2017]
- Use FileVault to encrypt the startup disk on ... - Apple Support [Last Updated On: March 12th, 2017] [Originally Added On: March 12th, 2017]
- Viber launches secret chats to go beyond encryption - SlashGear [Last Updated On: March 13th, 2017] [Originally Added On: March 13th, 2017]
- Zix wins 5-vendor email encryption shootout - Network World [Last Updated On: March 13th, 2017] [Originally Added On: March 13th, 2017]
- A lesson from the CIA WikiLeaks dump: Encryption works - The Seattle Times [Last Updated On: March 13th, 2017] [Originally Added On: March 13th, 2017]
- What the CIA WikiLeaks Dump Tells Us: Encryption Works - NewsFactor Network [Last Updated On: March 18th, 2017] [Originally Added On: March 18th, 2017]
- Panicked Secret Service Says It Lost Encrypted Laptop But It's Fine, Everything's Fine - Gizmodo [Last Updated On: March 18th, 2017] [Originally Added On: March 18th, 2017]
- Google Cloud adds new customer-supplied encryption key partners ... - ZDNet [Last Updated On: March 18th, 2017] [Originally Added On: March 18th, 2017]
- Preseeding Full Disk Encryption - Linux Journal [Last Updated On: March 18th, 2017] [Originally Added On: March 18th, 2017]
- Bypassing encryption: 'Lawful hacking' is the next frontier of law enforcement technology - Boston Business Journal [Last Updated On: March 18th, 2017] [Originally Added On: March 18th, 2017]
- SecurityBrief NZ - Gemalto introduces on-prem encryption key solution for 'highly regulated' organisations - SecurityBrief NZ [Last Updated On: March 21st, 2017] [Originally Added On: March 21st, 2017]
- 'Always Be Concerned': US Court Slaps Down Fifth Amendment Defense of Encryption - Sputnik International [Last Updated On: March 21st, 2017] [Originally Added On: March 21st, 2017]
- Quantum Key System Uses Unbreakable Light-Based Encryption to Secure Data - Photonics.com [Last Updated On: March 21st, 2017] [Originally Added On: March 21st, 2017]
- Wikileaks Only Told You Half The Story -- Why Encryption Matters More Than Ever - Forbes [Last Updated On: March 21st, 2017] [Originally Added On: March 21st, 2017]
- EPA Sued For Withholding Info On Encrypted Text Messages | The ... - Daily Caller [Last Updated On: March 22nd, 2017] [Originally Added On: March 22nd, 2017]
- Opinion Data encryption efforts ramp up in face of growing security threats - Information Management [Last Updated On: March 22nd, 2017] [Originally Added On: March 22nd, 2017]
- Bypassing encryption: Lawful hacking is the next frontier of law enforcement technology - Salon [Last Updated On: March 22nd, 2017] [Originally Added On: March 22nd, 2017]
- NeuVector Announces Container Visualization, Encryption, and Security Solution for NGINX Plus - DABCC.com [Last Updated On: March 23rd, 2017] [Originally Added On: March 23rd, 2017]
- Is encryption one of the required HIPAA implementation specifications? - TechTarget [Last Updated On: March 23rd, 2017] [Originally Added On: March 23rd, 2017]
- Paper Spells Out Tech, Legal Options for Encryption Workarounds - Threatpost [Last Updated On: March 23rd, 2017] [Originally Added On: March 23rd, 2017]
- Encryption debate needs to be nuanced, says FBI's Comey - TechTarget [Last Updated On: March 25th, 2017] [Originally Added On: March 25th, 2017]
- Comey Renews Debate Over Encryption - 550 KTSA [Last Updated On: March 25th, 2017] [Originally Added On: March 25th, 2017]
- UK minister says encryption on messaging services is unacceptable - Reuters [Last Updated On: March 28th, 2017] [Originally Added On: March 28th, 2017]
- The why and how of encrypting files on your Android smartphone - Phoenix Sun [Last Updated On: March 28th, 2017] [Originally Added On: March 28th, 2017]
- UK targets WhatsApp encryption after London attack - Yahoo News [Last Updated On: March 28th, 2017] [Originally Added On: March 28th, 2017]
- Critical flaw alert! Stop using JSON encryption | InfoWorld - InfoWorld [Last Updated On: March 28th, 2017] [Originally Added On: March 28th, 2017]
- SecureMyEmail is email encryption for everyone - TechRepublic - TechRepublic [Last Updated On: March 28th, 2017] [Originally Added On: March 28th, 2017]
- Apple iOS 10.3 will introduce encryption which makes it MORE difficult for cops and spooks to crack into ISIS nuts ... - The Sun [Last Updated On: March 29th, 2017] [Originally Added On: March 29th, 2017]
- How to Analyze An Encryption Access Proposal - Freedom to Tinker [Last Updated On: March 29th, 2017] [Originally Added On: March 29th, 2017]
- Questions for the FBI on Encryption Mandates - Freedom to Tinker [Last Updated On: March 29th, 2017] [Originally Added On: March 29th, 2017]
- Justice Department anti-terror chief keeps pressing on encryption - Politico (blog) [Last Updated On: March 29th, 2017] [Originally Added On: March 29th, 2017]
- UK government can force encryption removal, but fears losing, experts say - The Guardian [Last Updated On: March 29th, 2017] [Originally Added On: March 29th, 2017]
- Encryption FAQs [Last Updated On: March 29th, 2017] [Originally Added On: March 29th, 2017]
- Why isn't US military email protected by standard encryption tech? - Naked Security [Last Updated On: April 9th, 2017] [Originally Added On: April 9th, 2017]
- How have ARM TrustZone flaws affected Android encryption? - TechTarget [Last Updated On: April 9th, 2017] [Originally Added On: April 9th, 2017]
- Keeping the enterprise secure in the age of mass encryption - Information Age [Last Updated On: April 9th, 2017] [Originally Added On: April 9th, 2017]
- Lack of encryption led to Dallas siren hack - WFAA [Last Updated On: April 12th, 2017] [Originally Added On: April 12th, 2017]
- Internet Society tells G20 nations: The web must be fully encrypted - The Register [Last Updated On: April 12th, 2017] [Originally Added On: April 12th, 2017]
- Make Encryption Ubiquitous, Says Internet Society - Infosecurity ... - Infosecurity Magazine [Last Updated On: April 12th, 2017] [Originally Added On: April 12th, 2017]
- Can we encrypt the web while giving governments a backdoor to snoop? - SC Magazine UK [Last Updated On: April 12th, 2017] [Originally Added On: April 12th, 2017]
- Why we need to encrypt everything - InfoWorld [Last Updated On: April 12th, 2017] [Originally Added On: April 12th, 2017]
- Hacked Dallas sirens get extra encryption to fend off future attacks - Computerworld [Last Updated On: April 12th, 2017] [Originally Added On: April 12th, 2017]
- SHA-1 Encryption Has Been Broken: Now What? - Forbes [Last Updated On: April 14th, 2017] [Originally Added On: April 14th, 2017]
- Hewlett Packard Enterprise touts encryption tool for federal clients - The Hill [Last Updated On: April 14th, 2017] [Originally Added On: April 14th, 2017]
- Encryption on the Rise in Age of Cloud - Infosecurity Magazine - Infosecurity Magazine [Last Updated On: April 14th, 2017] [Originally Added On: April 14th, 2017]
- Lawmaker Pushes Bill That Requires Encryption by Pennsylvania State Employees - Government Technology [Last Updated On: April 14th, 2017] [Originally Added On: April 14th, 2017]
- Disk encryption - Wikipedia [Last Updated On: April 14th, 2017] [Originally Added On: April 14th, 2017]
- The apps to use if you want to keep your messages private - Recode [Last Updated On: April 15th, 2017] [Originally Added On: April 15th, 2017]