Encryption and key management at heart of great infosec say Thales

We spoke with Richard Moulds, the vice president of product strategy at Thales e-Security, at the recent RSA Conference held in San Francisco about the role of encryption in a number of different security issues.

“Everyone thinks encryption is a single thing but of course it’s not. It’s a basket of 25 different technologies,” says Moulds. “Encrypting a thumb-drive or someone’s laptop or a web connection or a backup tape or database or file-system are all completely different. To say we’re doing encryption isn’t really good enough”.

Thales released their tenth annual Global Encryption and Key Management Trends Study this week. Among the key findings were that the biggest challenge in planning and executing a data encryption strategy is discovering where sensitive data resides in the organization. Support for cloud and on-premise deployment is one of the most important features of an encryption solution and management of keys and certificates is painful because of no clear ownership and systems are isolated and fragmented.

Looking back at Peter Gutmann’s presentation at AusCERT last year - where he said "No matter how strong the crypto was, or how large the keys were, the attackers walked around it" - it’s clear the challenges surrounding the deployment of encryption remain.

Deploying encryption in a cohesive, organisation-wide manner remains a significant challenge.

“There are still two opposing trends. There’s the trend of it becoming embedded, a native capability in a system, which is about trying to make it easier. But then there’s the trend of it moving up the stack. I can encrypt a network or a file-system but anybody above that doesn’t really know that encryption is even applied”.

This is where access rights to data become important. While data might be encrypted when in-flight of at rest, once a user with appropriate rights accesses the data, the encryption becomes irrelevant.

“Why bother trying to steal the key when you can just fake the identity of a person that legitimately has access to the file? Encrypting stuff is easy. Figuring out who can decrypt it is the challenge”.

One way organisations can improve when it comes to data security, says Moulds, is to consider applying the principals of PCI/DSS to data more generally and not just credit cards. Citing the recent Anthem breach, he suggested the healthcare industry could significantly improve its security standards it of it adopted PCI/DSS on healthcare data.

With the shift to the cloud now marching forward, encryption has becoming an increasingly important element of the security discussion.

“You don’t want to be leaving valuable things, not just keys, even your application code in the open. It’s a data at rest problem,” says Moulds.

One of the challenges is even when you leave the cloud and erase your data, you can’t be certain the data is completely gone.

“Being confident you’ve not left any remnants when you leave, even if you leave temporarily – passwords, keys, sensitive data should be encrypted”.

Read more: Talking ’bout my generation – the next wave of infosec

Even though there are third party and integrated solutions for encryption of data stored on cloud services, the issue of key management still remains.

“At the end of the day, if a cloud provider has the keys, how do you know the provider won’t hand the keys over if those pesky Americans show up and demand that they do so,” he asked.

Thales has been working with Microsoft on key management within Azure and recently launched their BYOK, Bring your own Key, Deployment Package that enables businesses to generate and transfer their own keys to Azure. Although some cloud providers offer Hardware Security Modules, or HSMs, as part of their service, Thales’ nShield® Hardware Security Module (HSM) can manage keys on-premise that can then be used with Azure. This means the encrypted data and keys are stored in completely separate enviornments.

This works with the recently launched Key Vault service that uses hardware, rather than software, for key management.

Join the CSO newsletter!

Error: Please check your email address.

Tags peter gutmannGlobal Encryption#RSACPCI/DSSencryptionCSO AustraliaRSA ConferenceauscertinfosecPCI/DSSThales e-SecurityRichard Mouldskey management

More about e-SecurityMicrosoftRSA

Show Comments

Featured Whitepapers

Editor's Recommendations

Solution Centres

Stories by Anthony Caruana

Latest Videos

  • 150x50

    CSO Webinar: Will your data protection strategy be enough when disaster strikes?

    Speakers: - Paul O’Connor, Engagement leader - Performance Audit Group, Victorian Auditor-General’s Office (VAGO) - Nigel Phair, Managing Director, Centre for Internet Safety - Joshua Stenhouse, Technical Evangelist, Zerto - Anthony Caruana, CSO MC & Moderator

    Play Video

  • 150x50

    CSO Webinar: The Human Factor - Your people are your biggest security weakness

    ​Speakers: David Lacey, Researcher and former CISO Royal Mail David Turner - Global Risk Management Expert Mark Guntrip - Group Manager, Email Protection, Proofpoint

    Play Video

  • 150x50

    CSO Webinar: Current ransomware defences are failing – but machine learning can drive a more proactive solution

    Speakers • Ty Miller, Director, Threat Intelligence • Mark Gregory, Leader, Network Engineering Research Group, RMIT • Jeff Lanza, Retired FBI Agent (USA) • Andy Solterbeck, VP Asia Pacific, Cylance • David Braue, CSO MC/Moderator What to expect: ​Hear from industry experts on the local and global ransomware threat landscape. Explore a new approach to dealing with ransomware using machine-learning techniques and by thinking about the problem in a fundamentally different way. Apply techniques for gathering insight into ransomware behaviour and find out what elements must go into a truly effective ransomware defence. Get a first-hand look at how ransomware actually works in practice, and how machine-learning techniques can pick up on its activities long before your employees do.

    Play Video

  • 150x50

    CSO Webinar: Get real about metadata to avoid a false sense of security

    Speakers: • Anthony Caruana – CSO MC and moderator • Ian Farquhar, Worldwide Virtual Security Team Lead, Gigamon • John Lindsay, Former CTO, iiNet • Skeeve Stevens, Futurist, Future Sumo • David Vaile - Vice chair of APF, Co-Convenor of the Cyberspace Law And Policy Community, UNSW Law Faculty This webinar covers: - A 101 on metadata - what it is and how to use it - Insight into a typical attack, what happens and what we would find when looking into the metadata - How to collect metadata, use this to detect attacks and get greater insight into how you can use this to protect your organisation - Learn how much raw data and metadata to retain and how long for - Get a reality check on how you're using your metadata and if this is enough to secure your organisation

    Play Video

  • 150x50

    CSO Webinar: How banking trojans work and how you can stop them

    CSO Webinar: How banking trojans work and how you can stop them Featuring: • John Baird, Director of Global Technology Production, Deutsche Bank • Samantha Macleod, GM Cyber Security, ME Bank • Sherrod DeGrippo, Director of Emerging Threats, Proofpoint (USA)

    Play Video

More videos

Blog Posts

Market Place