Skip to main content
Anniversary Image Gallery

Encryption is the key

8 min read0 views
Sharefin

Amitabh Jacob
Channel Director, INdia & SAARC
Symantec

 

In not so distant past, it was an easy proposition to keep corporate data protected by keeping it within an established perimeter protected by established access controls and passwords. With the prolifertaion in smartphones and tablets that model has been blown apart. Added to this, file sharing services which empowers users with accessibility and usability is adding to the concerns of information security managers. These are not trends that organizations can ignore at their disadvantage. They urgently need solutions to help secure confidential data and limit access.  This is where encryption comes into play. 

Encryption is essentially insurance for loss or theft of a device containing sensitive information; both encryption software as well as insurance are bought with the hope that we’ll never truly need it. When businesses lose a device containing data, such as the personally identifying information of their customers,  the business  (in many countries & sectors)  is required to disclose the loss and notify all parties who may be affected.  Needless to say, this can be time-consuming and costly and damages a company’s reputation.  “It’s therefore important to deploy encryption for intellectual property or other confidential information irrespective of the device or platform - desktops, laptops, data tapes, servers, removable media or the cloud,”  says Amitabh Jacob, Channel Director, India & SAARC, Symantec.

Symantec has a complete range of encryption solutions that address the needs of all customer segments from the largest enterprises and government organizations to small businesses and individuals. “Symantec thus enables organizations to deliver data protection and further provide standards-based technology, centralized policy management, compliance-based reporting, and universal management for the encryption products,” says Amitabh. 

 

Srinivas Tadigadapa
Director, Enterprise Sales,
Intel South Asia 
Rajesh Awasthi
Director Telecom & Cloud Service Provider
NetApp
Kartik Shahani
Country Manager,
RSA India
Sunija Rishi
Co Founder and CMO at
Nevales Networks
Neeraj Mediratta
CEO, Ace Data
Devices Pvt. Ltd

BYOD and Encryption

The popularity of BYOD is increasing fast This is because businesses are in the process of allowing employees to bring their personally owned computers, smartphones, and tablets into the workplace and access corporate applications. The advent of BYOD has allowed application availability anytime, from anywhere, and helps business slash procurement costs.

However, the increasing popularity of these devices will create several problems for IT departments as they attempt to mitigate risk, and this signals a tough future for PC and laptop manufacturers. When it comes to BYOD, one of the most overriding threats is the loss and theft of these devices. 

In order to address the balance between usability and security, organizations are taking a variety of steps.  Apart from the vulnerability of the devices, the sensitive company data residing on these devices is also at risk. Here, encryption software can play a part in mitigating risks.  

Vishak Raman, Senior Regional Director, Fortinet India & SAARC, Fortinet, says, “BYOD provides a variety of advantages to organizations, ranging from improved productivity to increased ROI for IT departments. However, a BYOD environment also lacks many of the traditional security controls that organizations have relied on to secure their data, leaving gaps in their data and device protection strategy.” 

Most of the security threats plaguing BYOD are also common in mobility. There is a need on the part of the companies to encrypt data at the device level. Companies should also ensure that the user is not allowed to override it. 

 

Mobile Security 

Mobile devices continue to outgrow PCs as preferred primary computing devices.  According to Gartner, by 2016, at least 50% of enterprise email users will rely primarily on a browser, tablet or mobile client, instead of a desktop client.

This new mobile environment means higher security risks, as inherently unsecured mobile devices carry increasingly more business-critical information. Applications are playing a key role, offering more capabilities. While the opportunities mobile presents are significant and mobile has become an enterprise requirement, there are a number of challenges clients face like compliance with corporate policy, development and deployment of mobile applications with secure connectivity to corporate infrastructure. 

Most of the security threats plaguing BYOD are also common in mobility. Like personally owned devices, those issued by the organisations are also vulnerable to theft or loss. There is a need on the part of the companies to encrypt data at the device level. Companies should also ensure that the user is not allowed to override it. 

Vishak says, “Finally, the mobile client itself is at risk from attack when off the home network.  Fortinet secures mobile clients – laptops, smartphones, and tablets – protecting end users while they are travelling or simply working from outside the office.  Fortinet has solutions aimed at the e ndpoint itself that allow for protection of mobile devices and encrypted communications from any location, ensuring that users are communicating securely from wherever they are located.”

In particular, our FortiOS5.0 operating system released in late 2012 is a milestone in helping us provide mobile security to enterprises. 

Encryption in the Cloud

For many organizations cloud computing is the way out for their IT woes. It has taken a centre stage in the technology world. Cloud computing has gained momentum, and its growth is really impressive. Cloud computing infrastructure is elastic, scalable, highly available and accessible, but is it safe? There are certainly concerns and pain points such as network encryption in third party environments, address and topology control, and connectivity need to be addressed from the enterprise and business application perspective. 

With cloud computing becoming preferred choice of the business more so in uncertain economic landscape, these are hey-days for the cyber villains who find cloud as greener pastures for making money by hacking cloud infrastructure. 

Srinivas Tadigadapa, Director, Enterprise Sales, Intel South Asia says, “Today we are witnessing aggressive deployment  for cloud in the APAC region, Cloud users will begin to demand standardized, open, interoperable platforms for cloud computing. As businesses begin to rely on the cloud for general business operation, the demand for unrestricted use - bringing data in and out of the cloud – is increasing."

Rajesh Awasthi, Director Telecom & Cloud Service Provider, NetApp India, says “Since we are primarily a storage and data management company, which is where customers keep their data be it enterprise data or business applications they are hosting, their concerns are two-fold basically. 

As part of infrastructure, one of the things which they want from us from security perspective is that their data should be secure when it is in play (at rest). And when the data is on the move, they should also be secure when they are in the move. When it is stored in the disk drives of the storage system it should be secure. Here NetApp supports encrypted disk drive so the data that get stored on encrypted disk drive is safe. Only those people who are authorized can have access these data. When it comes to data in motion, for SAN Access we have a technology which we license to one of our partners, called Brocade who encrypt the data." 

Neeraj Mediratta- CEO, Ace Data Devices Pvt. Ltd, says, “Our cloud solution is fully secure with FIPS certified AES 256 bit encryption before moving the data out of the customer’s network. This helps us ensure that data is secure. The encryption keys are defined by the customer’s system administrator. Apart from these key software features, our environment is protected with firewalls, security tools and anti-virus tools being updated regularly to ensure that the data is safe.”

Over the past year, we have seen a steady growth of cloud adoption in India. Almost all IT vendors in India have already made their presence felt in the market with their cloud offerings. Even global players operating in India have tailored their cloud offerings to suit the domestic market. Cloud has been successful in India for multiple reasons. One of the most significant reasons is the demand from global companies, which is met by the IT industry in India. The micro, small, and medium businesses, which tend to be budget-constrained when it comes to hiring information technology (IT) professionals and building IT infrastructure, find cloud computing beneficial in bringing down the cost of ownership. Productivity gains and cost savings are other factors driving adoption of cloud in India.

“While market is still maturing to cloud, in India, Security is one of the key deterrents for the industry to adopt cloud,” says Kartik Shahani, Country Manager, RSA India. 

According to Symantec’s recent ‘Avoiding the Hidden Costs of Cloud 2013 Survey’, Indian organizations are widely migrating to the cloud to gain competitive advantages around speed, agility and flexibility. According to the survey, there is an increasing complexity and the proliferation of "rogue clouds" - business groups implementing public cloud applications that are not managed by the company's IT infrastructure. The survey found that nearly two-thirds organizations have lost cloud data (60 percent of enterprises and 70 percent of SMBs), and most (80 percent) have experienced recovery failures. 

In short, performance and security are the two major concerns that rankles the client’s minds when it comes to the cloud. In many cases cloud security encryption issues have been successfully addressed. 

“Encryption is now embedded across many Quantum solutions and it is done on the fly without sacrificing performance. Quantum's solutions have built-in encryption including the ability to do on the fly encryption or encryption at rest, whichever the customer prefers.” says Jim Simon, Senior Director of Marketing Quantum Asia-Pacific.

A major trend is expansion of cloud computing. Owing to cloud the benefits, enterprises of every scale are beginning to adopt cloud services and SaaS at a greater rate. This trend presents a big challenge for network security, as traffic can go around traditional points of inspection. Additionally, as the number of applications available in the cloud grows, policy controls for web applications and cloud services will also need to evolve. “Amplified adoption of cloud-based computing is impacting the way security is consumed. The overall scenario will lead to more managed security service providers through cloud delivery. More on the way is expected, such as data-loss prevention, encryption, and authentication as technologies are aimed to support cloud computing mature," says Sunija Rishi, Co Founder and CMO at Nevales Networks. The market is shifting to more integrated systems and ecosystems and swiftly drifting away from loose varied approaches. 

edit@varindia.com