Thursday, September 3, 2009

WhoHooo! BitArmor recognized in the latest Magic Quadrant!

Apologize for getting a bit excited - BitArmor is named in the 2009 Gartner Magic Quadrant for Mobile Data Protection! The full report can be read from the Gartner website. Our release about this recognition can be read from our website.

In this blog, I usually talk about my thoughts on the industry, evolution of security etc and I don't blog much about our product and the company. However, this I do think is a good excuse to do so :) It is good to be recognized by leading security analysts as John Girard and Eric Ouellet!

The report highlights our unique information-centric security approach to protecting data. It also talks about our No-Breach Guarantee. And one phrase I like is "far advanced" - as a way to describe our technology. Nice!

Being information-centric in our approach to data protection makes us a bit different from the other vendors in the document - most of them protect mobile devices. Because of our Smart Tag technology, BitArmor is able to protect the data itself at all times - thus the protected data can move to a laptop, USB device, via email as attachments or via FTP. It can also move from a file share to a data center server to a backup tape and still remain protected. From this perspective, we are truly fulfilling the real "Mobile Data Protection". I think the naming of this Magic Quadrant report is a bit ahead of its times!

However, as it stands now, most people associate data protection with "mobile devices" - i.e. protecting the devices that the data rests on (laptops, USBs, phones etc). And possibly for good reason - there were no good enough or usable enough technologies that could truly protect the data itself and that too persistently. Until now, of course!

I do think the Mobile Data Protection Magic quadrant will evolve more towards a data or information-centric approach in the coming years. Looking forward to our footprint trending, nay jumping, up and to the right!

Wednesday, September 2, 2009

Another case for information-centric security

The more I read about how criminals are breaching the perimeter and getting access to sensitive data in an organization, the more I am convinced an information-centirc approach is the only way to go.

Case in point is the recent article from Information Week - 5 Security Lessons from Real World Breaches. Fun stuff!! Here is a short excerpt from one attack the article describes - the conclusion..

"...The attackers used the compromised server as their home base. They deployed tools and scanners and spent several months meticulously mapping the network without being detected. Once they found the systems that contained the data that they were looking for, they simply copied the information, put it into a Zip file, and moved it out."

Emphasis above is mine - basically compromised a server and then copied data out. This data-at-rest protection being perceived as the end-all, is making me frustrated. If this data were protected using an information-centric approach - i.e. protect the data and keep it protected at all times (at rest and in motion), this would have been much harder. All the criminals would have gotten is encrypted data.

I am also looking at the 5 guidelines/conclusions from the report and besides a short mention of layered security and isolation, there is not much emphasis on data protection. I think the authors are missing the point. You can never have enough perimeter security - IDF/IPF, anti-malware works only to a certain extent.

You need to recognize that data is the critical asset,not the network or the server. Protect the data, damn it!!

New HIPAA breach laws taking effect

More rules and more rules... The HHS has issued final guidelines on breach notification requirements for organizations under the HIPAA law. They take effect Sept 23rd... Just in time for the G20 summit?

Maybe not. However, the reality is that organizations are having to now deal with a bevy of such requirements and the bigger problem is not in complying with basic standards, but ensuring the lowest common denominator (or in this case the strictest rules) are being met...

Saturday, August 29, 2009

Encrypted is not a boolean variable


Let's face it, encryption is a new thing, and you have to
keep things simple so people can understand it.

But it frustrates me that most of the talk about
encryption technology, law, policy, compliance, etc is
always in terms of "encrypted" vs "unencrypted". Yeah,
all your data should be encrypted. But that's the beginning
of the discussion, not the end. Encryption is easy.
Protecting data is hard.

Once you use strong encryption to protect your data, you
have real security. That sounds great, but the flipside is
that your company's security policy is probably a pile of
paper in a drawer that no one reads or updates, and does
not correspond to reality. How do you organize your data,
backup your data, share your data, manage your data ...
frankly, how do you USE your data in an encrypted
world? Encryption is coming. You need to think about it
now. Do your homework. If you don't, you'll be paying for
your lack of preparation for years.

-Tim

BTW this blog post is encrypted with no less than three
proprietary encryption algorithms (ROT-13^2,
XOR-0x00, and CAESAR-26, among others) and therefore
cannot be read by anyone. "encrypted == true" !

Friday, August 28, 2009

Bernanke hit by ID breach

Did the thief think he could cash into the billions that the Fed chief oversees :) Or maybe he was looking for a bailout himself!

Will this put some fire under the administration to think seriously about national laws for breach? Always seems to happen when something hits close to home and personally...

Interesting news, nontheless...

Monday, August 24, 2009

Dirty secrets and the non-existent perimeter

The perimeter is dead - long live the perimeter (the new perimeter, that is). Which obviously is the data.

I am also intrigued by an article by Joshua Corman from IBM, in CIO magazine, that discusses this. Check out Dirty Secret #3. "There is no perimeter". I love it. Mostly because it is true. And for some small selfish reasons as well... :)

Here is what he says - very eloquently, I might add..

"We need to define what the perimeter is," he said. "The endpoint is the perimeter, the user is the perimeter. It's more likely that the business process is the perimeter, or the information itself is the perimeter, too. If you design your security controls with no base assumption of a perimeter, when you have one you are more secure. The mistake we tend to make is, if we put the controls at the perimeter, then we will be fine. For many threats, we couldn't be more wrong."

The bold emphasis above in mine - and not from Joshua. But I do it to illustrate my point (which I put forth in a recent blog on the benefits of an information-centric security approach as well). Security professionals need to move beyond the perimeter and thinking that has dominated for the past 30-40 years and recognize the world is different now.

For heaven's sake, the internet that allows for rapid dissemination of data and collaboration is already a teenager! Why do we still protect this environment with stuff built for the 70's?

Sunday, August 23, 2009

Benefits of information-centric security

For a while I have been meaning to write a short article on what I think information-centric security is - so here goes.

Organizations have focused on securing sensitive data by protecting the infrastructure that hosts the data. This could be implemented by hosting the servers inside a data center, using firewalls and similar perimeter protection techniques to prevent external attackers, encrypting whole drives or encrypting networks. I think of these as protecting data by proxy - i.e. protect the network to protect the data, protect the perimeter to protect the data, protect the device to protect the data.

Information-centric security is the concept of focusing the protection on the data itself as opposed to the device – protection that stays with the data while at rest and while in motion. Access controls and other policies are embedded in data and follow it wherever it goes - thus enforcing these policies at the data level, regardless of where the data is.

This approach has several advantages:

  • Continuous protection: Data always remains protected since it does not get decrypted as it moves - this has performance benefits as well as security benefits
  • Device independence: Data can be protected regardless of the devices it rests on or travels between. For eg, it data moves to a USB device, to a backup tape, it still remains protected. No need to deploy a USB protection solution or a backup tape solution separately.
  • Enabling secure collaboration: Since the data remains persistently protected, you can share it better - the proper access controls of who can access the data remain with the data itself! Therefore data can be self-defending. No need to provide access to networks, file shares etc to share data.
  • Lower costs and complexity: all this comes down to much lower costs and complexity - no need to have multiple device or network centric products protecting data and that too by proxy..
I think the world is moving to such a method of protecting data - the old ways are untenable in today's world of exploding data and the requirements to share and collaborate.