Shadow AI is already using your data. Get the complimentary Gartner® report. Read the report

Fortune 250 Financial Group

PKWARE

By PKWAREProductivity Protected

Share on social media

Company Profile

Company
Fortune 250 Financial Group
Size
Medium Enterprise
Industry
Financial Services

A Fortune 250 financial group running multiple insurance and investment businesses through subsidiaries needed to find sensitive data across six database platforms and AWS, in development as well as production, to support a cloud-first strategy. PK Protect began with discovery, then added monitoring and masking for Oracle and SQL Server, with scan results feeding a single Postgres repository so the whole estate could be reviewed in one place.

Background

This customer, who operates multiple insurance and investment management businesses through subsidiary companies, needed scanning for sensitive data on both Development and Production environments, including AWS sources, to support their new Cloud first strategy.

Subsidiary structure is the complication that is easy to overlook. Each business brings its own systems, its own database conventions and often its own history of acquisitions, so a group of this shape does not have one data estate but several that have to be reported on as one. A cloud-first strategy adds AWS to that picture without removing anything already in it.

Challenges

Primary use case was to support PCI DSS compliance across multiple platforms—including Oracle, SQL Server, DB2 LUW (DB2-MF), MySQL, Informix, and Sybase—for classification purposes and to identify the repositories that are deemed sensitive.

Scanning development as well as production is the decision that distinguishes this programme. Development environments are routinely refreshed from production, which means they hold real data under weaker controls and rarely appear in a compliance inventory at all. Six database platforms then multiply the problem, because each stores and exposes data differently and a scanner has to speak all of them to give one answer.

Use Cases

The financial group deployed PK Protect to scan AWS sources for sensitive data. The initiative began with discovery before adding on monitoring and masking capabilities for Oracle and SQL Server. The PKWARE team developed a report that would send directly to the Postgres repository, extracting all database scans into one spreadsheet for easy oversight.

Consolidating results into one repository is what turns scanning into oversight. Six platforms scanned separately produce six answers in six formats, and reconciling them by hand is the work that gets postponed when time is short. A single extract makes the estate reviewable in one pass, which is the prerequisite for acting on what the scans actually found.

Our Approach

PK Protect enabled the customer to reduce the load of creating and running manual jobs and creating connections so they could perform incremental scanning of AWS sources.

Download PDF

Results

PK Protect enabled the customer to reduce the load of creating and running manual jobs and creating connections so they could perform incremental scanning of AWS sources. Based on this success, future plans include expansion to cover Informix, Mongo DB, and Cassandra, as well as mask Flat Files and standardize reporting.

Incremental scanning is the change that makes this sustainable. A full scan of every source is expensive enough that it runs on a schedule, which leaves gaps between runs in which new data arrives unexamined. Scanning only what has changed can run often enough to keep pace. The planned extension to MongoDB, Cassandra and flat files follows the same logic, since the platforms adopted most recently are usually the ones holding the newest data.

PKWARE

PKWARE

Productivity Protected

PKWARE has been securing sensitive data for over 40 years. We’ve earned the trust of 21 of the 25 largest banks in the U.S. Our team delivers modern, data-centric security solutions organizations can rely on.