Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - How Encrypting Data Can Protect Sensitive Company Data
Articles

How Encrypting Data Can Protect Sensitive Company Data

ISBuzz TeamBy ISBuzz TeamMay 18, 20184 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Governance of company data has never been trickier for organisations than in today’s business world. It was not so long ago that the bulk of company data simply resided either on premise or within a company datacentre, with supervision of that data proving to be a relatively manageable task for IT teams. The widespread adoption of cloud infrastructures has halted this trend, however, with many enterprises increasingly keen on embracing the cloud to help digitally transform their businesses.

However, the distribution of corporate data across private and public stores presents a conundrum in today’s data storage landscape. Many companies are looking to embrace the flexibility and cost advantages of the cloud, whilst at the same time protecting themselves from the impact of a cyber-attack. An obvious way of meeting both of these needs is data encryption, so that even in the event of a breach or hack, resulting in customers’ data being exposed, the information itself cannot be exploited by cyber-criminals.

The GDPR perspective

 

The enforcement of GDPR has provided an additional incentive for encryption. One of the key tenets of the regulation is that it requires businesses to implement appropriate technical and organisational measures to provide protection to any user information they hold, including encryption of personal or sensitive data. Failure to do so could result in a business being fined €20 million, or 4% of its annual turnover, depending on which is higher.

Breaches occur on an ever more frequent basis and therefore relying solely on a third-party provider’s encryption is unlikely to be a robust defence if a breach occurs.

Encrypting data

 

As standard practice a company should also encrypt its own data, particularly if it is going to reside on a third-party cloud provider. Adhering to this should not add a difficult process to the organisation’s data processes, as if it is, users will just bypass it if they can. Therefore, the aim is to make it easy and transparent for the whole company to encrypt data.

Hybrid, multi-cloud solutions provide exactly this method of transparent encryption for companies, but it’s important to choose the right one. The solution should provide FIPS compliant encryption and be configured to encrypt all data for all mapped on-premises or on-cloud data.

Encryption transparency is pivotal to this process. Ecnryption is done upon upload and then un-encrypted on download, using the same solution, with users not aware that this is taking place. Therefore, in the event of a breach on a third-party provider, and resulting in access to data stored there, cybercriminals will be unable to read or decrypt the data.

Additionally, an encryption solution should integrate with a company’s existing corporate identity management solution, such as Active Directory, LDAP, SAML etc, allowing users to sign into it using their existing domain credentials (single-sign-on).

Additional security should be added over and above the identity management in the form of two-factor authentication, with users entering their single sign-on credentials but then also receiving a two-factor challenge before they can then proceed to login – which adds an essential extra layer of security. Security layers are important as they make it more difficult for attackers to create a breach and steal data.

Deployment of transparent file encryption to enforce data security and satisfy compliance regimes such as GDPR can be simple, scalable and fast with the right solution.  With high-profile security breaches seemingly occurring on a weekly basis, and with companies facing huge fines for non-compliance ahead of the GDPR deadline, introducing measures which will help encrypting data should certainly be explored by all organisations irrespective of their size. In doing so, IT teams can be safe in the knowledge that they have a final layer of protection against cyber hackers, keen to do damage to a business’s digital world, and return to benefitting from the advantages of the cloud.

[su_box title=”About Jim Liddle” style=”noise” box_color=”#336588″][short_info id=’105249′ desc=”true” all=”false”][/su_box]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}