Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.


02:04 PM
Connect Directly

Security Pros Keys To The Kingdom Leave Encrypted Data At Risk

Survey finds that, if abused, IT pros' access to encryption keys could do some serious damage to their organizations

Talk about the insider threat: Some 40 percent of IT pros worldwide say that the way in which their firms have deployed encryption could allow them to hold their companies’ encrypted data hostage if they were to go rogue or leave the company.

One-third of the 500 IT security pros from around the globe surveyed at the InfoSecurity 2011 conference last month by Venafi say their individual familiarity and access to encryption keys could do some serious damage to their organizations if they were to refuse to relinquish them or to abuse them in any way. Some 40 percent say if they were to leave their firms, they would still have access to enough sensitive information that could hurt their organizations.

The data appears to shed light on how some enterprises are not sufficiently managing and protecting their encryption keys -- and, thus, their sensitive data.

"With all the warnings over the past few years, recent high-profile data breaches, and the financial services regulations, one would have assumed that senior-level management would already have taken steps to address key and certificate management," says Jeff Hudson, CEO at Venafi. "The survey data confirms what we've seen working with our customers and prospects, particularly in the financial services space where there's so much sensitive and regulated data. Organizations fail to address encryption key and certificate management because it's in the hands of a few IT administrators."

Hudson says the mismanagement of encryption is akin to increasing the size of the lock on your door, but leaving the key to the door out in the open. "Increasing the size of the lock on your door or business may make you feel more secure. But the reality is that if the key and lock -- no matter its size or strength -- is left on the transom, under the mat, or distributed willy-nilly out in the open, it doesn’t matter how large or strong the lock is ... the data can be easily accessed."

While 82 percent of the respondents say they use digital certificates and keys, 43 percent say they have been locked out of their encrypted data due to lost keys or departed IT security pros who held the keys.

Interestingly, 24 percent of the respondents in the survey, which was published today, say worries about lost encryption keys is keeping them from investing in encryption and digital certificate technologies.

"The reality is that the world’s Fortune-ranked organizations all utilize thousands and even hundreds of thousands of encryption keys and digital certificates across their global networks. Our research demonstrates that organizations are managing tens of thousands of certificates and encryption keys, with many not even knowing exactly how many they have in their inventories or where they are deployed," Venafi's Hudson says. "Without leveraging best practices and automated management processes, organizations will never gain complete control of their key and certificate inventories, resulting in significant security, compliance, and operational risk that invariably lead to unauthorized access and the kinds of high-profile and costly breaches both Sony and Epsilon recently experienced."

An executive summary of the report by Venafi is available for download here.

Have a comment on this story? Please click "Add Your Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message.

Kelly Jackson Higgins is the Executive Editor of Dark Reading. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Newest First  |  Oldest First  |  Threaded View
Inside the Ransomware Campaigns Targeting Exchange Servers
Kelly Sheridan, Staff Editor, Dark Reading,  4/2/2021
Beyond MITRE ATT&CK: The Case for a New Cyber Kill Chain
Rik Turner, Principal Analyst, Infrastructure Solutions, Omdia,  3/30/2021
Register for Dark Reading Newsletters
White Papers
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
PUBLISHED: 2021-04-17
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting of file capabilities on files in an underlying file system. Due to the combination of unprivileged user namespaces along with a patch carried in the Ubuntu kernel to allow unprivile...
PUBLISHED: 2021-04-17
Shiftfs, an out-of-tree stacking file system included in Ubuntu Linux kernels, did not properly handle faults occurring during copy_from_user() correctly. These could lead to either a double-free situation or memory not being freed at all. An attacker could use this to cause a denial of service (ker...
PUBLISHED: 2021-04-17
A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. We have already fixed this vulnerability in the following versions: QTS Build 20210202 and later Q...
PUBLISHED: 2021-04-17
An SQL injection vulnerability has been reported to affect QNAP NAS running Multimedia Console or the Media Streaming add-on. If exploited, the vulnerability allows remote attackers to obtain application information. QNAP has already fixed this vulnerability in the following versions of Multimedia C...
PUBLISHED: 2021-04-16
jose-node-esm-runtime is an npm package which provides a number of cryptographic functions. In versions prior to 3.11.4 the AES_CBC_HMAC_SHA2 Algorithm (A128CBC-HS256, A192CBC-HS384, A256CBC-HS512) decryption would always execute both HMAC tag verification and CBC decryption, if either failed `JWEDe...