Well over half of IT professionals within large corporations were sure that the government was snooping on their data
– even before the PRISM news hit the wires
Cupertino, CA & London – July 26, 2013 – Voltage Security®, the world leader in data-centric security, today announced results of an industry survey in which 62% of senior-level IT and security respondents said that they thought the government snoops on their corporate data, without their knowledge, while it resides in the cloud. (The study was conducted by Voltage Security at Infosecurity Europe in April 2013 with over 300 IT professionals.)
Over half of respondents in the survey work for large enterprise organizations employing more than 5,000 people, representing financial services, retail, healthcare and insurance industries. These results indicate the critical need to protect sensitive information from exposure, regardless of whether the exposure is caused by a malicious act, an inadvertent slip, a surveillance operation or a failure of protective controls or processes.
“Any sensitive information, including financials, customer and employee data or intellectual property needs to be protected across the entire lifecycle of that data. Any loss or exposure of that data can result in compliance or regulatory fines, loss of brand and reputation and, as the recent NSA events further validate, a loss of privacy around how we communicate and the content of those communications,” said Dave Anderson, Voltage Senior Director.
An organization’s data protection strategy must include proactive data protection controls, which enables the ability to supervise and manage how underlying data levels are secured through encryption, tokenization and data masking, as well as how secured data can be used across the organization while still ensuring compliance.
The focus on securing sensitive data, while maintaining regulatory compliance, is becoming even stronger as a result of the surveillance activities over the last few weeks. People are growing stronger in their beliefs that security, privacy and compliance are not just a tactical, “check the box” activity that they have to do, but rather is a strategic process that adds tremendous value in their ability to securely communicate at all levels.
“Supervisory data protection controls can deliver and maintain compliance with sanctioned government regulations, and avoid any unnecessary ad-hoc snooping and surveillance activities”, said Anderson.
Privacy and security can be effectively balanced with regulatory compliance as part of a comprehensive data protection program. The ability to “de-identify” information, either through encryption, tokenization or data masking capabilities, provide very effective mechanisms to secure sensitive data, how that data is communicated, used and managed. This strategy inherently provides an underlying foundation for data privacy as well, ensuring that not just the data level itself is secure, but also that the information can only be accessed and used by authorized users and the specific intended recipients. In this case, privacy and security become much aligned and users and organizations now have the ability to secure any sensitive data, while ensuring communications and use of that data can remain private.
As more organizations leverage the cloud for data processing and analytics, security and privacy become the core requirement across these initiatives. The only way to provide the necessary levels of security to guard against data loss, either through surveillance, a malicious attack, or an inadvertent disclosure, is through a data-centric security program.
“We believe that this approach, which can protect sensitive data across the entire data lifecycle, can allow companies to leverage the benefits of cloud adoption, and ensure their sensitive data is protected from any prying eyes. This approach can completely change the negative view of 62% of companies regarding the security of their data in the cloud,” concluded Anderson.