Shadow AI is already using your data. Get the complimentary Gartner® report. Read the report

Safeguarding Data During Cloud Migration

PKWARE

By PKWAREProductivity Protected

Share on social media

Download

The cloud promises countless ways to realize operational and bottom-line benefits when an organization migrates physically hosted IT operations to a virtual environment. Although data is safe once inside the cloud, large-scale data movement can incur risk of exposure for sensitive data.

Mitigating risks requires users to take extra care when transferring and storing highly sensitive data. While cloud service providers guarantee data will be safe once in the cloud, organizations are responsible for ensuring data is protected in transit. PK Protect plays a vital role in cloud strategy by automatically scanning and acting on all migrations to keep data safe.

Download this solution overview to learn more about how PK Protect supports cloud migration.

The Risk Is in the Movement, Not the Destination

Cloud providers secure what they host, and data is generally safe once it has arrived. The exposure sits in the migration itself, where large volumes of sensitive data move between environments with different controls at either end.

Under the shared responsibility model the provider secures the platform and the customer secures the data, which means protection in transit is entirely the organization’s obligation.

Know What You Have Before You Move It

A migration is the one moment when the whole estate is examined at once, which makes it the best opportunity an organization gets to find out what it holds.

Review what is actually moving, in what format, and what access each type requires. Data and applications that are no longer needed should not be migrated at all. Leaving them behind reduces the bill and the risk in the same decision.

Decide What Should Not Go

Some data cannot reside in the cloud, whether through regulation, contract or internal policy. That determination has to be made per data element rather than per system, and then held to, because the exceptions are what create the incidents.

Any point at which personal information enters a new environment is a point where the migration needs to be controlled rather than assumed.

Naming and Mapping in the New Environment

Two practices make the destination governable. Data elements need clear names in database tables or a central index, and those elements need clear mapping to where they now live.

Without both, the organization arrives in the cloud with an estate it cannot describe, and the first subject access request or audit becomes an archaeology exercise.

Aggregation Changes What Something Is

Individually harmless elements can combine into something regulated. A postcode is not personal data; a postcode with a date of birth and a gender frequently identifies a person.

Migration is where that combination happens most often, because data from separate systems lands in the same repository for the first time. Recognizing when elements come together to represent a higher degree of sensitivity is part of planning the move, not a review to run afterwards.

Keep Scanning After the Migration

Automatic scanning of every migration, with action taken according to policy, is what keeps the answer current as workloads continue to move. A single pre-migration inventory describes the estate on one day, and cloud estates do not stay still for long.

What Arrives Protected Stays Protected

The sequence is what decides the outcome. Data protected before it leaves the source arrives in the cloud already protected, and there is no interval during which an unprotected copy sits somewhere the organization has not finished configuring.

Protecting after arrival means the first state of that data in its new home was the unprotected one. That is the state an auditor will ask about, and it is the state a misconfigured bucket exposes.

PKWARE

PKWARE

Productivity Protected

PKWARE has been securing sensitive data for over 40 years. We’ve earned the trust of 21 of the 25 largest banks in the U.S. Our team delivers modern, data-centric security solutions organizations can rely on.