Multi-cloud use and compliance requirements shape encryption strategy

Encryption with public cloud services experienced double digit growth.

  • 6 years ago Posted in
Thales has published the results of its 2018 Global Encryption Trends Study. The report, based on independent research by the Ponemon Institute and sponsored by Thales, reflects some of the changes and challenges organisations are experiencing in a world marked by widespread cloud deployments, use of multiple public cloud providers and new regulations such as the EU General Data Protection Regulation (GDPR).

 

Click to Tweet: #Encryption in public #cloud services sees double digit growth, according to new @thalesesecurity report https://bit.ly/2uAPMPi

 

This year, 43% of respondents report that their organisation has an encryption strategy applied consistently across their enterprise. This strategy is leveraged to protect sensitive data against cyber criminals, help organisations address complex compliance requirements, and guard against human error.  Encryption, which is achieved with software or hardware tools such as hardware security modules (HSMs), is often coupled with best practice-based key management. Encryption is also playing an increasingly large role in protecting the enormous adoption of organisations deploying to the cloud.

 

Among the findings:

·         84% of respondents either use the cloud for sensitive/non-sensitive applications and data today, or will do so in the next 12-24 months

·         61% of respondents are using more than one public cloud provider, and 71% plan to in the next two years

·         39% encrypt in public cloud services (such as Amazon Web Services, Microsoft Azure and Google Cloud), a number that has risen 11% since last year’s report

·         Overall HSM use grew to 41% -- the highest level ever. The most common use cases for HSMs are SSL/TLS and application level encryption, with 20% of respondents reporting that they use HSMs with blockchain applications

·         49% of enterprises are either partially or extensively deploying encryption of IoT data on IoT devices and platforms

This year’s statistics are encouraging, but the report does show areas of challenge. Data discovery rates as the top data encryption planning/execution challenge by 67% of respondents, a number that is 8% higher than 2017. Respondents from the UK, Germany, the US and France have the most challenges, which likely points to activities associated with preparation and compliance of data privacy regulations such as GDPR which comes into effect in May this year.

 

When considering the majority of organisations polled are using more than one public cloud provider, the report also raises questions about how organisations are enforcing consistent encryption and key management policies across multiple cloud vendors. Securing data in a multi-cloud environment can be especially problematic for organisations seeking compliance, particularly if they are attempting to instantiate a single organisational policy using different native tools from multiple cloud providers.  Not surprisingly, policy enforcement is second only to performance as a most valued feature of encryption solutions in this year’s study.

 

Dr. Larry Ponemon, chairman and founder of The Ponemon Institute, says:

“While enterprises are rightfully encrypting cloud-based data, 42% of organisations indicate they will only use keys for cloud-based data-at-rest encryption that they control themselves. Similarly, organisations that use HSMs in conjunction with public cloud-based applications prefer to own and operate those HSMs on-premises. These findings tell us control over the cloud is highly important to companies increasingly under pressure from data security threats and compliance requirements.”

Research shows ‘game needs to be changed,’ with security innovation years behind that of the...
Node4 has released its Mid-Market IT Priorities Report 2021. The independent report reveals that...
Atos has launched Atos OneCloud Sovereign Shield, a set of solutions, methodologies, and...
New distribution agreement set to bolster Westcon-Comstor’s Zero Trust offering in more markets...
Research from Avast has found that employees in almost a third (31%) of Small and Medium...
This year, over half of MSPs or their end customers have been attacked by ransomware but only 53%...
Trend Micro has published new research revealing that 90% of IT decision makers claim their...
Cyber consultants call on businesses to act now, or risk budgets shrinking further in ‘real...