Most often, the word “encryption” brings to mind decryption keys and complex processes. Those processes create friction for the end users who need access to data. Because of that friction, businesses commonly use alternate forms of encryption, such as disk encryption, to meet business or compliance requirements. Disk encryption protects information stored on a disk drive—an external hard drive, a laptop, or even enterprise storage. It does that by blocking access to the drive without the proper password or authentication credentials.
Disk encryption is effective, but on its own it is simply not enough. In the past, encryption was often too heavy or too resource intensive for extremely high transaction volumes. Health insurers, card processors, and healthcare clearinghouses all run at that scale. For them, transaction volume and low latency requirements sat so far at odds that data-level encryption was not a great option. Therefore encrypting a disk, a storage area network, or network-attached storage remains a great security control in those environments. However, it is no longer good enough as the only encryption solution in play.
The Reality of the Physical Risk
Organizations often tie encrypt and decrypt mechanisms to role-based access controls. An authentication, authorization, and accounting service such as Active Directory governs those controls. As a result, only permitted roles reach the data store and the decrypted data. Meanwhile the service encrypts data at rest and protects the keys. So if someone did gain access to the data store or the physical disks, the data would be worthless.
Physical obtainment of a disk or drive still matters when you develop your security programs. However, companies must also ask whether this addresses a perceived risk or an actual one. Physical tampering with disks is possible, but the risk is quite minimal in professional data centers. These facilities often have impressive—albeit imperfect—physical security controls that minimize access to the actual hardware. Someone can also take a disk out for destruction and compromise it that way. The risk and the impact are therefore real. Even so, physical security measures are not protecting the data at rest the way many organizations believe.
Cracking Credentials
According to a study by Dark Reading, phishing causes over 50 percent of the data breaches across surveyed responders. Criminals commonly use phishing to obtain sensitive information and compromise an organization or an individual. In today’s decentralized and often borderless world of access and connectivity, organizations use credentialed access to protect themselves from unauthorized parties. Once stolen, those credentials are keys to the castle.
When Stolen Credentials Are Enough
If other factors of authentication are not in place, an attacker needs nothing more. The same is true when the compromise starts inside the organization, in an area that requires no authentication. In either case the attacker simply appears to be an authorized user of the system. Password spraying attacks take previously compromised credentials, which criminals already hold, and try them on other environments. Many individuals reuse passwords or choose easily guessable ones. Therefore credentials alone often cannot protect your organization from the outside world.
When Attackers Hunt for Credentials Instead
Let’s say an attacker uses a malicious link or download, or exploits a vulnerability, and gains access without credentials. Hunting for credentials within many environments is not a difficult task. Misconfigurations that make those credentials easy to find are common. For example, insecure protocols such as SMB or NetBIOS can make access as easy as sitting quietly on a system and listening. Alternatively, the attacker executes a script downloaded from the internet. In a security mature organization, some of those issues may not exist or may not be exploitable. But consider what happens when the attacker spawns a fake login page on a workstation. The page looks just like the traditional Windows login. Instead of authenticating anyone, it takes the password and dumps it somewhere the attacker can reach.
All of this proves that credentials are simply not enough anymore. Disk encryption typically and traditionally relies on user permissions and access to decide who can decrypt the data on the disk. Considering how easy it is to steal credentials today, are credentials still valid keys for unlocking sensitive data? As a long time security practitioner, I have never been a fan of relying solely on disk encryption. It too often creates a false sense of security.
Enhancing Protection with Targeted Encryption
Encrypting the data itself is key to mitigating these issues. The encryption mechanisms must not connect directly to authentication credentials. Can your encryption architecture vet decryption requests for who the individual is, where they are, and what type of data it is? This is a very difficult task. However, it ultimately addresses the risk far more widely and more effectively than disk encryption alone.
With disk encryption, mapping data types to what is encrypted and where would be a huge lift. Disk encryption performs encryption on the disk itself. Therefore the data typically needs parsing into partitions and isolating first, then encrypting. How do you perform these tasks when your data is co-mingled? The same question applies when different roles require different views of the same data set.
Encryption at the element or column level, across structured and unstructured data, greatly reduces reliance on disk encryption. In conjunction with masking, it meets compliance and security program requirements to protect data. More targeted encryption automatically considers what data elements are present, along with the user’s role. That combination is a top consideration for maturing these operations across the entire enterprise.
Secure Files and Data with PKWARE
Targeted encryption begins with complete administrative control. Automated protection such as data encryption, part of the PK Protect data discovery and protection solution suite, helps organizations define granular enterprise data protection policies. It also protects sensitive data at the element level wherever it is stored.
PK Protect gives businesses the power to encrypt sensitive data in files and databases, as well as data that is moving between them. Only those with properly approved access hold the decryption capabilities. Options include persistent file and email encryption, format-preserving encryption, dynamic data encryption, and transparent data encryption. Therefore PK Protect builds on existing disk encryption solutions to keep your data protected however it is accessed and used, all without impacting how you do business.
Learn how PK Protect can automatically protect your organization’s most sensitive data. Get a free personalized demo here.
