Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Perimeter

5/23/2011
02:04 PM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

Security Pros Keys To The Kingdom Leave Encrypted Data At Risk

Survey finds that, if abused, IT pros' access to encryption keys could do some serious damage to their organizations

Talk about the insider threat: Some 40 percent of IT pros worldwide say that the way in which their firms have deployed encryption could allow them to hold their companies’ encrypted data hostage if they were to go rogue or leave the company.

One-third of the 500 IT security pros from around the globe surveyed at the InfoSecurity 2011 conference last month by Venafi say their individual familiarity and access to encryption keys could do some serious damage to their organizations if they were to refuse to relinquish them or to abuse them in any way. Some 40 percent say if they were to leave their firms, they would still have access to enough sensitive information that could hurt their organizations.

The data appears to shed light on how some enterprises are not sufficiently managing and protecting their encryption keys -- and, thus, their sensitive data.

"With all the warnings over the past few years, recent high-profile data breaches, and the financial services regulations, one would have assumed that senior-level management would already have taken steps to address key and certificate management," says Jeff Hudson, CEO at Venafi. "The survey data confirms what we've seen working with our customers and prospects, particularly in the financial services space where there's so much sensitive and regulated data. Organizations fail to address encryption key and certificate management because it's in the hands of a few IT administrators."

Hudson says the mismanagement of encryption is akin to increasing the size of the lock on your door, but leaving the key to the door out in the open. "Increasing the size of the lock on your door or business may make you feel more secure. But the reality is that if the key and lock -- no matter its size or strength -- is left on the transom, under the mat, or distributed willy-nilly out in the open, it doesn’t matter how large or strong the lock is ... the data can be easily accessed."

While 82 percent of the respondents say they use digital certificates and keys, 43 percent say they have been locked out of their encrypted data due to lost keys or departed IT security pros who held the keys.

Interestingly, 24 percent of the respondents in the survey, which was published today, say worries about lost encryption keys is keeping them from investing in encryption and digital certificate technologies.

"The reality is that the world’s Fortune-ranked organizations all utilize thousands and even hundreds of thousands of encryption keys and digital certificates across their global networks. Our research demonstrates that organizations are managing tens of thousands of certificates and encryption keys, with many not even knowing exactly how many they have in their inventories or where they are deployed," Venafi's Hudson says. "Without leveraging best practices and automated management processes, organizations will never gain complete control of their key and certificate inventories, resulting in significant security, compliance, and operational risk that invariably lead to unauthorized access and the kinds of high-profile and costly breaches both Sony and Epsilon recently experienced."

An executive summary of the report by Venafi is available for download here.

Have a comment on this story? Please click "Add Your Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message.

Kelly Jackson Higgins is the Executive Editor of Dark Reading. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
COVID-19: Latest Security News & Commentary
Dark Reading Staff 5/27/2020
10 iOS Security Tips to Lock Down Your iPhone
Kelly Sheridan, Staff Editor, Dark Reading,  5/22/2020
How an Industry Consortium Can Reinvent Security Solution Testing
Henry Harrison, Co-founder & Chief Technology Officer, Garrison,  5/21/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
How Cybersecurity Incident Response Programs Work (and Why Some Don't)
This Tech Digest takes a look at the vital role cybersecurity incident response (IR) plays in managing cyber-risk within organizations. Download the Tech Digest today to find out how well-planned IR programs can detect intrusions, contain breaches, and help an organization restore normal operations.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-13632
PUBLISHED: 2020-05-27
ext/fts3/fts3_snippet.c in SQLite before 3.32.0 has a NULL pointer dereference via a crafted matchinfo() query.
CVE-2020-13253
PUBLISHED: 2020-05-27
sd_wp_addr in hw/sd/sd.c in QEMU 4.2.0 uses an unvalidated address, which leads to an out-of-bounds read during sdhci_write() operations. A guest OS user can crash the QEMU process.
CVE-2020-13630
PUBLISHED: 2020-05-27
ext/fts3/fts3.c in SQLite before 3.32.0 has a use-after-free in fts3EvalNextRow, related to the snippet feature.
CVE-2020-13631
PUBLISHED: 2020-05-27
SQLite before 3.32.0 allows a virtual table to be renamed to the name of one of its shadow tables, related to alter.c and build.c.
CVE-2020-4226
PUBLISHED: 2020-05-27
IBM MobileFirst Platform Foundation 8.0.0.0 stores highly sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 175207.