Industry Insights
Why Encryption Is Now a ‘Need to Have,’ Not Just a ‘Nice to Have’
Reported by betanews.com
By Linus Chang, CEO and Founder at Scram Software,
Cloud-based services are so commonplace today that it’s tempting to simply trust them with your data. After all, everyone else is using them, right? Not so fast. As the recent data debacle with Facebook and Cambridge Analytica showcased to the world, it may not be smart to assume that your sensitive information will be safe with third-party providers. The fact is that large-scale data breaches now happen routinely to corporations, governments, and individuals, and can cost organizations millions of dollars while resulting in the loss of consumer trust. And it’s not just companies that have lots to lose—everyday citizens may end up paying the biggest price when their personal or financial data gets misappropriated or misused.
The Facebook data incident came as no surprise to many security professionals, since the industry had long warned of the likelihood of something like this happening—not just with Facebook but with any third party cloud provider that you entrust with your data. Once you’ve handed over your data to a third party, however, that entity can disclose it—purposefully or accidentally, legally or illegally, with or without you knowing anything about what’s happening. Think about the number of third parties who have your personal or customer data, and it becomes clear how massive this potential problem is.
Since you can never really be sure a third party will handle your data how you want it to be handled, it’s important to take extra measures to protect against data breaches, whether you’re dealing with corporate or personal data. The best strategy is one that enables encryption on the client-side—which means that the data owner maintains control of their own key instead of giving a third party free reign over their critical data. Frankly, if you’re storing data on servers that aren’t your own, this is the one certain step you can take to ensure data privacy.
In Europe—as indicated by the new GDPR legislation that takes effect on May 25, 2018—privacy is taken very seriously. GDPR strongly advocates using encryption to protect personal data. Yet studies reveal that just a small amount of breached data—4 percent—is protected by encryption technology, which leaves the vast majority of data within easy reach of hackers. With this statistic in mind, there’s plenty of room for improving the way that companies handle data privacy where the cloud is concerned.
Expanding Protections
Security has long been a priority for many companies, but only when it comes to safeguarding certain types of information. For example, commercial intellectual property and trade secrets—like the secret sauce for a popular burger—is at the top of the totem pole in terms of asset value. Yet personal data was not historically considered to require the same level of protection.
Today, companies can no longer base their security best practices on how a breach might affect the organization alone—they must also consider the consequences for consumers or citizens whose personal data is stolen. Fortunately, the growing awareness of the importance of protecting personal data has created a mindset shift within many American corporations. As a result, more companies are widening their practices concerning data protection and privacy to include the identifying details of citizens, not just corporate data.
Why has this shift occurred? For one thing, there’s exponentially more data being stored in digital formats. Another factor is that many new forms of crime and worsening threats due to the cloud’s interconnectedness. Just think about the ease with which someone could unintentionally trigger a huge data breach—by clicking a mouse on the wrong checkbox, access controls can be suddenly misconfigured, making personal data accessible to the general public. Even an accidental data drag-and-drop can instantly copy data to inappropriate locations. And this isn’t just “what-if” scenarios—as just one example, the largest known data leak of its kind occurred when the Republican National Committee inadvertently released the personal data of 198 million American voters due to a misconfiguration snafu on an Amazon S3 server that was both unsecured and publicly accessible.
How Much Is Personal Data Worth?
It wasn’t always clear in terms of dollar value how much customer data was worth to the organization holding it. But it’s now possible to see the true price of personal data via regulatory fines. A single HIPAA violation can cost a company millions, or failure to comply with the GDPR can cost an entity up to 2 percent of their total global turnover.
Clearly, personal data has tangible value that needs to be protected the same way that a company protects its IP. Yet the level of protection that most cloud providers can offer isn’t sufficient. “In theory, the market is supposed to incentivize cloud providers to keep customer data safe,” said Dr. Toby Murray, University of Melbourne. “Yet history tells us that few organizations can truly be relied upon to have sufficient security, even when their business models depend on them remaining secure.”
Murray points to the certificate authority DigiNotar, which went out of business in 2011 after a major security breach. “Knowing that your cloud provider might go out of business if your company’s data is breached is little comfort if that breach would also cripple your own business,” concluded Murray. Dr. Vanessa Teague, who is a cryptographer at the University of Melbourne, agreed: “The incentives only work if someone finds out that their data has been breached—we don’t know how many breaches are never discovered, or never reported.”
An analogy can help visualize the distinction between using or foregoing encryption: If you park a car worth $10 million in a secure garage and hand over the key, you have some measure of protection, but you ultimately don’t maintain control of your car’s security—you’re at the mercy of the staff attendants. How much safer would you feel if you simply kept the key in your own pocket, rather than handing it over to the valet?
Layers of Security
Cryptography offers data owners the gift of privacy and control over their own files. Yet there are added benefits as well, which shouldn’t be overlooked, including data integrity and authentication. Encryption not only makes sure the data doesn’t get modified from its original form, but it also provides verification that the data in question came from a specified source, such as verifying that two sets of fingerprints haven’t been swapped. Teague noted that data is sometimes evidence, as with police cameras. “The police might not only have to keep the data private, they might also have to prove at a later date that nobody had the opportunity to tamper with it,” she said.
Another reason encryption is necessary for optimum data security is that not all data breaches are accidental. As Teague explaned: “Some occur because the entity to whom you entrusted your data could make money by reselling it, or giving others the opportunity to exploit it. She added that in the dispute between Facebook and Cambridge Analytica, the Cambridge University researcher acquired the sensitive data of millions of people with the permission of Facebook. “A cloud provider of any data might, similarly, decide to share it,” said Teague, adding that the situation becomes even more muddled if the provider thinks your data has been ‘de-identified’ before sharing it. “Although it may be very easily re-identifiable, you may have no way of knowing, and some countries are considering making it a crime for you to try to find out,” explained Teague.
There have been few options until now when it comes to data privacy in today’s world of omnipresent data breaches, but recent developments and emerging technologies are changing the equation. It’s now possible to deploy a universal file encryption system that secures data to protect against cybercrime, minimizing the chance of a breach succeeding. The system must be well designed, easy to use, and offer clear instructions for flawless implementation.
Dr. Ron Steinfeld of Monash University has been working on one such encryption system. As Steinfeld said: “Encrypting stored user information on the cloud server with a key known only to the user should significantly reduce the likelihood of such data breaches.” This is why secondary copies of data—whether backups, transfers, archives, or migrations—should always use encryption technologies. Such types of data are files, so this is simple to achieve thanks to these recent advances in file system encryption. You can also encrypt many primary copies of data, and since a growing number of web systems now compile private information and identification data, it’s becoming critical that this occurs. Clearly, given the current state of breaches and the ballooning frequency of cybercrime, encryption must now be considered a basic part of data protection rather than a frill.