Company Profile
- Company
- Fortune Global 500 Insurance and Investment Company
- Size
- Fortune 500
- Industry
- Financial Services
An insurance and investment company serving customers in more than 40 countries needed identifiable elements removed from its data without making that data useless for reporting. Manual review of thousands of columns could not keep pace. PK Protect was installed and running in under three hours, applied through APIs inside existing workflows rather than as a separate system the organization had to design around.
Background
This anonymous Fortune Global 500 and Fortune 500 insurance and investment company is based in the US with customers in more than 40 additional countries. With an organization culture that is doggedly determined to protect private and sensitive data at all costs, the organization needed a solution that would immediately and automatically identify data going in and data going out to free up their data scientists for other vital tasks.
The phrase that matters is data going in and data going out. Protection applied only at rest leaves every exchange unexamined, and an insurer exchanges constantly with brokers, reinsurers, regulators and claims partners. Identifying data in both directions is what makes the control continuous rather than periodic.
Challenges
In dealing with so much sensitive data day in and day out, the business wanted a solution that could take the identifiable element(s) out of the data while still leaving the data in a usable state for reporting and analysis. Manual review of thousands of data columns was unsustainable; the team required the ability to easily identify data with a reasonable level of confidence.
With the APIs and narrow focus of identifiability and protection, PK Protect suits our needs very well without requiring extensive design and architecture.Product Owner, Data Management
Thousands of columns is a scale problem, but confidence is the harder one. A judgement made by hand cannot be repeated or audited, and the same column may be assessed differently twice. Consistent automated identification produces a result the organization can rely on across teams rather than one that depends on who performed the review.
Our Approach
PK Protect takes identifiable elements out of data while still leaving it in a usable state for reporting and analysis.
Use Cases
The search for the right solution led a product owner in data management to PK Protect. PKWARE’s data discovery and remediation solution checked all the boxes. “The fact that it’s consistently applied as long as we do what we’re supposed to do with standardization; the fact that we can use that for matching to let people do what they need to do; the fact that we can decrypt data so it doesn’t have to continually be extracted or kept under lock and key—all of this was alluring to our team,” said the product owner.
PK Protect comes easily installable via APIs, extending its usability as an engine for the organization. “I can put it into workflows and don’t have to work extensively to build it in,” the product owner remarked. “With the APIs and narrow focus of identifiability and protection, PK Protect suits our needs very well without requiring extensive design and architecture.”
Installation through APIs is what kept the footprint small. A tool that has to be designed into an architecture competes with the projects already in it, while one that drops into an existing workflow does not. Reversible protection matters for the same reason: data that can be decrypted in place does not have to be extracted repeatedly or held under separate controls.
Results
The organization has already experienced impressive time-to-value, installing and implementing PK Protect in under three hours. As awareness of the solution spreads across the organization, data governance teams are lining up to have their data scanned and protected. “They want to see it and use it,” the product owner said. “They want the freedom to work with their data without worry.”
The organization is finalizing integrations with Informatica before releasing full PK Protect access.
Under three hours to install is a time-to-value figure rather than a performance one, and the follow-on is the more telling part. Governance teams asking to have their data scanned indicates protection being treated as an enabler rather than an obstruction, which is what the organization set out to achieve.
