Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - Overcoming Data Residency Issues
News & Analysis

Overcoming Data Residency Issues

ISBuzz TeamBy ISBuzz TeamOctober 18, 2013Updated:July 3, 20246 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Voltage Logo
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Dave Anderson, Senior Director, Voltage Security, explains how organisations can overcome a common barrier to cloud computing adoption

The benefits of adopting cloud technologies have been widely reported, and are commonly understood. However, the decision to adopt a cloud strategy brings with it many questions and concerns about jurisdictional and regulatory control over the privacy and protection of sensitive data. For instance, data residency and sovereignty requirements often insist that certain types of sensitive and private data are stored where the government will have legal jurisdiction over it. More often than not, this means within its borders. But the cloud allows providers to possibly store, process or back-up data across several global locations, as well as allowing organisations to freely move data outside of national borders.  So, how does this impact compliance to data residency requirements?

Addressing data residency, protection and privacy concerns requires an understanding of both international and domestic regulations. Companies that do business in Europe must understand the implications of regulations such as the European Data Protection Law, as well as local data mandates. The EU’s Data Protection Directive is an example of this, as it prohibits personal data that can be linked to an individual from moving outside the EU, sometimes even outside of a specific country’s borders.  Data residency is also particularly concerning for multi-nationals that have offices all over the world, covering several jurisdictions.

It’s no wonder people are confused.  In fact, in a survey we conducted of nearly 300 IT professionals, 60% admitted that concerns over data residency kept them from putting data in the cloud.  A possible reason for this hesitation is that a staggering 48% of survey respondents said that they didn’t know which countries their data resided in once in the cloud, leading to uncertainty when it comes to complying with regulations.  While 70% of people surveyed said that they were aware of data residency requirements or laws, an alarming 30% did not know and 23% believed they didn’t abide by them- attesting to the fact that these jurisdictional issues are proving a serious stumbling block for organisations that wish to store or process data in the cloud.

And as protecting data becomes an increasingly onerous task, due largely to the fact that every new approach to security is eventually met with an even more sophisticated attack from cyber criminals, it can become time consuming and expensive.  Therefore, questions regarding privacy and compliance must be addressed as data moves to the cloud: Which information can and cannot be collected? Where and how can data can be stored and transmitted? Which security practices must be applied? What to do in the event of a data breach?

In order to stay ahead of the dynamic security and data residency regulations and to leverage the current market trends around cloud, many organisations are adopting strategies such as having data centres in all the countries they operate in as a of way keeping data confined within legal boundaries. However, this is woefully inadequate, as the data can still be accessed from anywhere in the world, while still not addressing data residency compliance. Not to mention the skyrocketing costs and overheads involved with housing multi data centres.

Another approach is to try and protect data by a single gateway process. The issue with this approach, however, is the impossible latency issues. As an example, companies have tried database-oriented tokenisation strategies; however this, and other single gateway approaches, are really a step backward as they create a need to sync vast data repositories across long path networks.

So how do CISOs avoid falling foul of legislation when considering the myriad of complex rules and regulations governing how data is used, stored or moved?

To remove any risk or doubt of non-compliance altogether, and stay ahead of security and data residency regulations in order to be able to take full advantage of cloud computing, organisations must employ a strategy that secures data directly at the source, rather than trying to implement point technologies to corral the data within a defined boundary.  This ‘data-centric’ approach means that information is protected, whether through encryption, tokenisation or data masking, and therefore remains completely secured from the moment it is created throughout the entire data lifecycle.  Even as the data moves into and across a cloud environment, it remains in a protected state and not “in the clear”.  This means that data can now be securely moved into and throughout the cloud, while remaining in compliance with data residency and privacy requirements.

The simplest way to ensure compliance is to obfuscate data as it is captured, rendering it useless to cyber criminals and unreadable to outsiders, regardless of where it lives.  Any sensitive information, including financials, customer and employee data or intellectual property, needs to be protected across the entire lifecycle and wherever it goes. Any loss or exposure of that data can result in compliance or regulatory fines, loss of brand reputation and a loss of privacy.

However, to be effective, businesses must keep it simple and consistent. A successful data-centric security approach can be applied to any type of data, and deployed across corporate systems, and does not require the deployment of multiple point solutions which are difficult to integrate and still leave security gaps as data moves across and outside of the organisation . These criteria are vital, and relevant to all solutions, whether mainframes or mobile technologies, and regardless of whether they are deployed on-premise or on-demand.

There are five critical data protection requirements that any company should consider:

– Organisations must build security policies around the technologies they use. Individual, point solutions are generally insufficient to meet a company’s unique security requirements, and don’t allow organisations to secure sensitive information while at-rest and in-transit.

– Businesses must recognise the reality of data lifecycle. Data travels across and outside of an organisation, across borders and geographies to users internal and external to the organisation.  This reality requires a data protection program that supports the needs of how the business is using information today.

– Data protection solutions need to be scalable to meet business and IT requirements and architected to match the growth of the business and its data.

– Simpler is better. The adoption and use of the technology can’t be too complex for the user, otherwise the technology won’t be utilised across the enterprise and risks will increase.  A data protection program that is too complex, or lacks usability, will not be fully and readily adopted across an enterprise, which could leave sensitive data exposed and the company at risk.

– IT environments today are heterogeneous, with new technologies working alongside legacy systems. Data protection solutions need to work with all data types, both structured and unstructured, across the entire IT infrastructure, without the need for extensive and complex re-engineering of systems and applications that manage sensitive information.

By adopting a data-centric security strategy, companies can be confident in migrating to the cloud and leverage the associated business benefits, while removing any uncertainty around compliance with data residency and privacy requirements.

www.voltage.com

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}