Banking Institution #1

    Customer
  • Banking Institution #1
    Industry
  • Banking
    Customer Profile
  • Leading financial institution, providing commercial and consumer banking
    Challenges
  • Strong data encryption for transfer of information via tape
  • Ability to move information directly to tape in one step
    PKWARE® Solution
  • SecureZIP® for i5/OS®
    Results
  • 1Step2Tape functionality enabled data transfer, encryption, and compression in one step
  • Strong encryption for data transfer, including exchange with largest business partner

Company Background

Our client provides commercial and consumer banking at over 350 locations.

Challenges and Requirements

Wanting to avoid the risk of lost or stolen customer information and the inevitable negative publicity which follows, the bank proactively sought a method to secure their backup tape process. Every night, sensitive customer data is sent from the bank’s i5/OS midrange system, and saved to an unencrypted tape backup at an offsite disaster recovery location.

The bank wanted to ensure that if a tape was lost or stolen during transit, the data would be completely secured and virtually useless to anyone who intercepted it. In addition to basic encryption requirements, being able to move information directly to tape in one step to stay within current processing windows was a top priority.

Competitive Landscape

While our client investigated Patrick Townsend as an option, the flexibility of SecureZIP combined with the security vision and strategy PKWARE offered, made our solution the easy choice.

The Solution - SecureZIP

In addition to using SecureZIP for encrypted tape backup, the bank saw the long-term value in securely exchanging sensitive data with business partners. The bank’s mortgage division exchanges information from their i5/OS with their largest business partner. Because their partner is also a SecureZIP user, the companies began securely exchanging data as soon as the bank completed implementation, making them compliant with their partner’s encryption requirements.

Most importantly, SecureZIP 1Step2Tape functionality enabled the bank to transfer, encrypt, and compress data directly to tape in one step, preserving significant time and resources without dramatically altering their existing processes.

Banking Institution #2

    Customer
  • Banking Institution #2
    Industry
  • Financial Services
    Customer Profile
  • One of the world’s largest financial institutions, serving more than 54 million clients
    Challenges
  • SEC Compliance
  • Limit employee encryption
    capabilities based on employee job function(s)
    PKWARE® Solution
  • PKZIP® for Windows® desktop
    Results
  • SEC Compliance
  • Encryption management
    capabilities

Company Background

Our client is one of the world’s largest financial institutions, providing individual consumers, small/mid-market businesses, and large corporations a full range of banking, investing, asset management, and other financial and risk-management products and services. The company serves more than 54 million consumers and small businesses across the globe.

Challenges and Requirements

In order to be in compliance with the Securities and Exchange Commission’s (SEC) data encryption requirements, the company needed the ability to centrally manage user rights for encrypting data. Additionally, the solution had to allow them to limit employee encryption capabilities based on job function. The company also wanted a compression solution that could be centralized and was easy to manage and maintain.

Competitive Landscape

The company was using WinZip® for data compression on over 20,000 desktops throughout their organization. In 2006, WinZip engaged the company in maintenance renegotiations, wanting to tie maintenance renewal pricing to the original purchase price, timeframe, and quantities as opposed to starting with a general Enterprise agreement. This turned out to be fairly expensive and extremely complex for the company to manage, as they had purchased different licenses and quantities at various times over several years.

Faced with this kind of complexity, WinZip’s lack of key functionality, and the huge amount of desktops needing compression, the company decided to seek out a solution that would better serve their requirements.

The Solution - PKZIP

The company chose PKZIP because they felt it was easy to deploy, manage, and use cost effectively. PKZIP’s policy manager capabilities enable administrators to define how their end-users encrypt information, allowing them to turn off the encryption capability for those employees who do not need to use it.

The company also realized the value of the migration path from PKZIP to SecureZIP. They recognized that when they needed to improve their desktop security, they could upgrade the appropriate users to the more advanced security capabilities of SecureZIP without disrupting their current processes.

Another key benefit of choosing PKZIP was the ability to eventually standardize compression and security on all computing platforms. This will give the company fewer vendors to work with, contracts to manage, and systems to learn, reducing their overall cost of doing business. The company is well on their way to achieving this goal--they already use SecureZIP on their mainframes and are currently identifying a migration plan to implement SecureZIP on their desktops.

Leading European Bank Extends Encryption Solution across all Enterprise Computing Platforms

    Industry
  • Banking & Financial Services
    Customer Profile
  • Responsible for the bulk clearing of cheques and paper credits throughout Great Britain
    Challenges
  • Protecting sensitive data during movement or storage
  • Reducing data center costs and operational overhead
  • Extending the useful life of the existing IT infrastructure
    PKWARE® Solution
  • SecureZIP Server
  • SecureZIP for z/OS®
    Results
  • Protected sensitive data using persistent signing authentication and file encryption capabilities
  • Implemented a solution that works across disparate computing systems

Company Background

Our client is a division of a large international trade association for institutions that deliver payment services to customers. The bank is responsible for ensuring that all payments are secure and
reliable by handling the bulk clearing of cheques and paper credits throughout Great Britain, totaling several million cheques each day.

Our client also processes various forms of payment, including Bankers’ drafts, Building society cheques, Post orders, Warrants, Government payable orders, and Travellers’ cheques. In addition, they also manage the systems for the clearing of paper bank giro credits (credit clearing) and euro cheques (euro clearing).

Challenges and Requirements

A project was initiated in 2005 to simplify the infrastructure and reduce costs of the United Kingdom’s cheque clearing process. The scope of the project was to provide management of the electronic data related to paper cheques and credits. Each transaction is processed as an individual file transmission between each of 12 member banks. The information flows among the member banks during an end-of-day processing window that needs to accommodate millions of transactions. This results in a physical settlement to each bank the following morning based on all of the aggregate totals verified daily by the Bank of England.

Due to the fact that paper cheque usage volumes have been declining, our client needed a solution that offered predictable costs throughout the several-year term of the project. The complete desired solution needed to fulfill several requirements:, including

  • Supplying a private network provider
  • Providing a Certificate Authority (CA)
  • Enabling secure transfer
  • Providing persistent signing authentication and file encryption capabilities
  • Easy implementation for multiple outsourcers with various computing platforms

The Solution - SecureZIP Server & SecureZIP for z/OS

The project’s technical committee evaluated 38 other companies that offered "hub and spoke" solutions. Unfortunately, a hub and spoke solution would force all members banks to send their transactions to a single outsourcer that would "police" all transactions. PKWARE was the only company to advise the project team that by using SecureZIP they could eliminate the need for a hub and spoke model. By leveraging banks’ existing infrastructures, SecureZIP allows the banks to work independently on their own computing platforms, eliminating the need for a centralized outsourcer and saving millions of pounds for processing and transmission.

Each of the 12 member banks has its own IT infrastructure composed of several different computing platforms ranging from z/OS® mainframes to Windows®, UNIX®, and Linux® servers. Not only did SecureZIP eliminate the need and cost associated with a hub and spoke model, but it was able to efficiently manage the various computing environments used by member banks. This helped our client overcome future cost concerns by providing an option that allowed member banks to change their computing environments without impacting the overall cost of the solution.

In addition to addressing the flexibility and cost concerns raised by our client, SecureZIP was also able to address all of the proposed technical requirements. It offers a private network provider, Certificate Authority (CA), and enabled secure transfer of information. Further, SecureZIP easily and efficiently added digital signing capabilities to each of the millions of transactions occurring daily. And, SecureZIP can automatically translate different file formats during nightly batch processing, saving processing time and reducing operational overhead.

Using SecureZIP, our client was able to quickly address and solve critical data security needs. It not only met the immediate requirements, but will address the future needs of our client and the overall project.



Success Stories

Banking Institution #4

    Industry
  • Banking & Financial Services
    Customer Profile
  • One of the world's largest financial institutions
    Challenges
  • Protecting sensitive data to meet PCI compliance requirements
  • Securely transferring data to multiple endpoints
  • Implementing and using Public Key Infrastructure (PKI) for secure email communication
    PKWARE® Solution
  • SecureZIP® for UNIX® Server
  • SecureZIP for z/OS®
  • SecureZIP for Windows® desktop
    Results
  • Protected sensitive data sent to multiple endpoints, including email communication via seamless integration with Microsoft Outlook®
  • Met PCI DSS compliance requirements

Company Background

Our client is one of the world’s largest financial institutions, providing individual consumers, small/mid-market businesses, and large corporations a full range of banking, investing, asset management, and other financial and risk-management products and services.

Challenges and Requirements

The company needed to comply with the Payment Card Industry Data Security Standard (PCI DSS), which required them to protect credit card data as it is transmitted, processed, and/or stored, impacting several processes throughout their organization. Initially, the company set out to protect and store credit card dispute information for the PCI mandated minimum of 7 years.

This information was taking up space on their UNIX server, so the company wanted a solution that could both encrypt and compress the data. Every night, hundreds of thousands of settlement transactions containing confidential credit card information are sent to companies of all sizes. Without secure, dedicated lines set up for data transfer with smaller merchants, this confidential credit card data was sent via fax.

In an effort to secure this process, the company established an initiative to move all fax transmissions to email, electronically transferring encrypted data to multiple endpoints that would then have to decompress and decrypt the data after it was received. The data for these transactions originates on the company’s z/OS mainframe and is then transferred to an internal server before it is sent externally to merchants. The company wanted a solution that would be easy to use and cost effective, especially for their business partners.

The Solution - SecureZIP (Multiple Computing Platforms)

As soon as the company purchased SecureZIP, they quickly realized the solution could work for additional security initiatives throughout the organization. They engaged PKWARE for assistance in achieving strong enterprise security across all major computing platforms.

The company wanted to use PKI to facilitate secure email communication both internally and externally with business partners. SecureZIP was the only solution that could provide the level of functionality, customization, and ease of use required. The company also incorporated the RSA Keon Certificate Authority product as well as the PKWARE ZIP reader to round out the solution.

SecureZIP provides seamless integration with the centralized directories containing digital certificates issued by RSA. This supported the requirement for processing secure transactions without slowing the delivery of reports to their partners. PKWARE’s free ZIP reader extends the benefits of SecureZIP to the company’s large network of partners without requiring them to purchase additional software. As a result, our client is able to securely communicate with, and send information to, its partners, regardless of the their computing environment or security infrastructure.

Banking Institution #5

    Customer
  • Banking Institution #5
    Industry
  • Financial Services
    Customer Profile
  • One of the leading financial
    institutions in North America,
    providing products and
    services to more than 11
    million clients
    Challenges
  • Finding a security solution that
    would protect customer data
    both in transit and at rest
    PKWARE® Solution
  • SecureZIP® for UNIX® server
  • SecureZIP for i5/OS®
    Results
  • Strong data encryption (AES
    256-bit) solved compliance
    issues as well as saving
    significant time and resources
    resulting from compressing files before encryption

Company Background

Our client is one of the leading financial institutions in North America, providing a full range of products and services to more than 11 million individual and small business clients.

Challenges and Requirements

The company completed an internal audit resulting in the introduction of a compliance initiative requiring all customer data be secured while at rest. This meant sensitive customer data that was being stored on their UNIX servers needed to be secure, in addition to data being sent internally to their i5/OS midrange system for archival purposes.

The Solution - SecureZIP

As the company began investigating security options, they were aware of the PKWARE family of data-centric security solutions. The company reached out to PKWARE for assistance on this project.

The company’s internal compliance mandates required 96-bit encryption, but after consulting with PKWARE, they realized that in order to truly mitigate risk and ensure the security of confidential customer data, they would need to implement a solution that provided strong 256-bit encryption at a data level. The need for a strong data-centric encryption solution combined with the significant time and resource savings resulting from compressing files before encryption, caused the company to choose SecureZIP.


Banking Institution #6

    Customer
  • Banking Institution #6
    Industry
  • Banking
    Customer Profile
  • Large international bank
    providing investment banking
    services, brokerage, insurance,
    asset management, leasing,
    and factoring
    Challenges
  • Finding a compression solution
    to replace WinZip®
    PKWARE® Solution
  • PKZIP® for Windows® desktop
    Results
  • Provided a strong enterprise
    solution at a lower price
  • Policy manager allowed for
    control over which employees
    could encrypt data
  • Ability to easily upgrade to
    SecureZIP® for future data
    security concerns

Company Background

Our client is a large international bank with more than 570 domestic banking locations and over 1,000 units overseas. The bank provides a full range of financial products and services, including investment banking services, brokerage, insurance, asset management, leasing, and factoring.

Challenges and Requirements

The bank was using WinZip for desktop compression throughout their organization. When their license was due for renewal, they were dissatisfied with WinZip’s pricing policy changes. WinZip, recently acquired by Corel, had tripled prices for license quantities over 500 and wanted to charge maintenance fees equal to 18% of the product price. These changes caused the bank to release an RFP in an effort to find a more affordable and robust ZIP-based compression solution for their desktops.

The Solution - PKZIP Enterprise Edition

Several vendors responded to the RFP, including WinZip. The bank chose PKZIP Enterprise Edition from PKWARE because it exceeded their requirements, providing a better enterprise solution at a lower price. In addition, PKZIP Enterprise Edition met the bank’s current needs for encryption management with Policy Manager, which allows the ability to control which employees may encrypt data.

Most importantly, PKZIP offers a simple upgrade path to enterprise data security. The bank was beginning to recognize the importance of data security and liked having the option to upgrade to SecureZIP, which would provide them with more advanced security capabilities without disrupting current operating processes.


Educational Institution #1

    Customer
  • Educational Institution #1
    Industry
  • Education
    Customer Profile
  • One of the oldest institutions of higher education in the United States, with over 30,000 students
    Challenges
  • Finding a way to protect and securely exchange personal and academic information
    PKWARE® Solution
  • SecureZIP® for Windows® desktop
    Results
  • Data can be exchanged securely and student privacy is protected
  • Integration with Microsoft Outlook® allows secure email exchange

Company Background

Our client is one of the oldest institutions of higher education in the United States, providing both high-quality undergraduate and graduate programs in the arts, sciences, and professional fields. The university is home to nearly 5,000 full-time faculty members, and over 30,000 undergraduate and graduate students. With such a large campus population, the university wanted a way for its students and faculty to protect their data, some of which contains sensitive personal and/or academic information.

Challenges and Requirements

When the university’s IT services department initially contacted PKWARE, they were looking at various data security options. In addition to securing data exchanges amongst faculty, they wanted to also extend that same security and privacy to their students.

Competitive Landscape

A WinZip® customer at the time, the university was becoming increasingly discouraged with WinZip’s high pricing and lack of customer support.

The Solution - SecureZIP

SecureZIP was a natural choice for the university. They had a tight timeline, wanting to implement the new software by the beginning of the upcoming semester. SecureZIP could be implemented within days rather than several weeks or months with other providers.

In addition, the university wanted an easy way for incoming students, bringing their own PCs and laptops, to gain access to SecureZIP. The university was impressed with the exceptional customer support PKWARE offered. Working together with the university, PKWARE Sales and IT Services were able to develop a solution that was both cost-effective and worked within the required timeframe. Faculty immediately received copies of the SecureZIP software. A secure portal was also created, which will be maintained by university IT services—this will allow downloads of SecureZIP to be distributed to students on an as-needed basis.

Finally, the university was impressed with SecureZIP’s ability to integrate seamlessly with Microsoft Outlook® to secure email exchanges, allowing for secure data exchange throughout the university when needed.


Financial Services Provider #1

    Customer
  • Financial Services Provider #1
    Industry
  • Financial Services
    Customer Profile
  • One of the top 20 largest banks in the world, serving over 20 million consumer clients
    Challenges
  • Encrypt data being saved to tape
  • Exchanging data securely with business partners
    PKWARE® Solution
  • SecureZIP®/PartnerLink for z/OS®
    Results
  • Able to exchange data securely with business partners

Company Background

Our client is a prominent international bank, serving more than 20 million consumer clients around the world.

Challenges and Requirements

The bank had experienced a security breach when a tape containing unencrypted sensitive customer information was lost in transit to a consumer credit bureau. While they already had an encryption initiative underway, the breach accelerated the project. The bank’s immediate need was to encrypt the data being saved to tapes from their z/OS mainframe. This data was being exchanged monthly with their largest trading partner.

Competitive Landscape

Concurrent to the data breach, the bank had signed a deal to outsource their data center operations. Their outsourcing partner was currently evaluating and testing PartnerLink (powered by SecureZIP®) against IBM® software encryption solution, Encryption Facility for z/OS (EF).

After an extensive evaluation, the bank and its outsourcing partner agreed that PartnerLink was the best solution. Not only could PartnerLink meet all of their key requirements, but the solution was more cost effective than IBM’s EF and could be implemented very quickly.

The Solution - PartnerLink

PartnerLink provided the bank with a framework for exchanging data securely with partners. In addition to efficient implementation, the bank was influenced to select PartnerLink because of its acceptance from other business partners. The bank’s largest business partner was already using SecureZIP, allowing the companies to begin securely exchanging information immediately. In the future, the bank can easily extend PartnerLink to enable the secure exchange of sensitive data with other business partners, at no cost to those partners.


Financial Services Provider #2

    Customer
  • Financial Services Provider #2
    Industry
  • Financial Services
    Customer Profile
  • Leading provider of information technology solutions for community-based financial institutions
    Challenges
  • Securely transferring information via tape/backup tapes
  • Finding a solution that would integrate with current applications
    PKWARE® Solution
  • SecureZIP® for i5/OS®
    Results
  • Ability to encrypt information and store on backup tapes
  • Seamlessly integrated with HORIZON banking system application

Company Background

Our client is a leading provider of Information Technology (IT) solutions for community-based financial institutions with capabilities ranging from Core Processing to eBanking and Check Imaging to Business Intelligence. Their financial solutions enable commercial banks, credit unions, and savings institutions to optimize operational efficiencies, mitigate risks, maximize revenues, and fortify their customer or member relationships.

Challenges and Requirements

The company uses a HORIZON banking system, built to run on the IBM® i5/OS platform. The system provides financial reporting, transaction processing, and relationship management capabilities for hundreds of banks.

The company took notice of the negative publicity associated with lost or stolen tapes containing private customer data. They recognized both the need and revenue opportunity of adding functionality to their system that would enable their clients to encrypt the data being saved to backup tapes. The company began researching backup tape encryption solutions that could be integrated with HORIZON and resold as an add-on module, enabling their clients to secure backup tapes using a simple and cost-effective method.

The company was also looking for a solution they could use for their own i5/OS machine, as they exchange private customer information and account data with their clients for testing purposes when they do upgrades. They also wanted to protect proprietary data on their machines.

Competitive Landscape

The company researched SecureZIP and Patrick Townsend and found SecureZIP to be a much more robust security solution. It fit all of their internal needs, was easy to implement, and could be seamlessly integrated into their HORIZON system.

The Solution - PartnerLink

With SecureZIP, the company’s client banks, many of whom do not have their own programmers and system analysts, can select encryption options from the HORIZON systems menu. It works like any other end-of-day function, allowing them to merge the options into automated processes for end-of-day backups on their i5/OS systems. The company now has multiple instances of PKWARE products working within their operating environment, including PKZIP®, SecureZIP, and PartnerLink.



Financial Services Provider #3

    Customer
  • Financial Services Provider #3
    Industry
  • Financial Services
    Customer Profile
  • One of the nation’s leading providers of private mortgage insurance, providing products and services that help credit unions efficiently conduct business
    Challenges
  • Finding a solution that works on any computing platform
  • Ability to access encrypted data at any time
  • Support for both passphrase and PKI encryption/authentication
    PKWARE® Solution
  • PartnerLink for z/OS®
  • PartnerLink for server
    Results
  • Ability to encrypt and compress data in transit and at rest throughout the organization
  • Ability to securely exchange data with business partners, at no cost to partners
  • Maintain control over who encrypts data both internally and externally

Company Background

Our client is one of the nation’s leading providers of private mortgage insurance, serving more than 5,000 home mortgage lenders across the United States and Puerto Rico. They offer a critical component of our country’s residential mortgage finance system, protecting mortgage investors from credit losses as well as providing numerous products and services that help credit unions become more efficient and responsive to consumer needs.

Challenges and Requirements

The provider works very closely with their banking partners and, as a result, was subject to audits. Therefore, they began looking for the best method to protect their sensitive customer data. The provider identified the major areas of concern for data encryption including data at rest (stored on their local disk subsystem in their mainframe) and data in transit (via tapes and electronically) as it is exchanged both internally and externally with their extended network of partners and customers.

Competitive Landscape

The provider had PGP® deployed for limited data encryption, but because the PGP solution only encrypted one file at a time, it increased their processing times and overhead. In order to broadly deploy PGP, all of the provider’s partners would be forced to purchase a licensed copy of the same installation of PGP, creating a significant cost to those partners. The provider recognized this limitation and instead sought a solution from PKWARE.

PKWARE worked with the provider to establish how data moved within their organization. The investigation uncovered data security vulnerabilities, confirming the specific need for a data security solution that was both easily deployed and cost effective.

The Solution - PartnerLink

The provider concluded that the SecureZIP product family was the best solution to address their data security requirements. They deployed SecureZIP/PartnerLink on their mainframe to facilitate secure information exchange with their partners and they also deployed SecureZIP for server to the main application gateway FTP server. SecureZIP for server will allow the provider to encrypt and compress data that is in transit and at rest throughout their organization.

PartnerLink for z/OS will secure the data backbone of the company. By encrypting data at its source in the mainframe, a number of benefits can be derived including secure data transmission and secure data storage/tape processing. PartnerLink will allow the provider to seamlessly exchange information securely with their partners. In addition, the software is free to partners, easy to setup and deploy.



Financial Services Provider #4

    Customer
  • Financial Services Provider #4
    Industry
  • Financial Services
    Customer Profile
  • Global payment and financial services company, providing global payment services through a network of over 125,000 agent locations
    Challenges
  • Securely exchanging data via FTP
  • Retaining compression capabilities while adding a cross-platform security solution
    PKWARE® Solution
  • SecureZIP® for Linux® server
    Results
  • Cross-platform compatibility as well as command line functionality for use with Linux servers
  • Ability to securely exchange information with largest business partner

Company Background

Our client is a global payment and financial services company, conducting business in two primary segments. One segment provides money transfer services, money orders, and bill payment services to consumers. The other segment provides financial institutions with payment processing services, primarily official check outsourcing services and money orders for sale to their customers. Overall, the company provides consumers and businesses with these global payment services through a network of over 125,000 agent locations.

Challenges and Requirements

The company transfers customer financial data to banking institutions and agents daily via FTP. Previously, they were using WinZip® on the desktop to encrypt transactions carrying customer account numbers during transmission.

When the company decided to migrate their FTP servers to a Linux environment, they realized they would have to find a new encryption solution because WinZip does not operate on a Linux platform.

Because the company sends data to thousands of customers, it was critical to retain the ability to use compression. Another key requirement was cross-platform interoperability. The solution also had to be non-invasive, easy to use, and cost effective for the recipient.

Competitive Landscape

The company considered both PGP® and SecureZIP, but quickly found that PGP could not meet their requirement for cross-platform interoperability.

The Solution - SecureZIP

SecureZIP not only enables cross platform interoperability, but is also easy to use and offers command line functionality for use with the company’s Linux servers. In addition, the company’s largest business partner, a SecureZIP user, highly recommended the product. SecureZIP met all of the company’s initial requirements and made exchanging information with their largest business partner even easier.


Financial Services Provider #5

    Customer
  • Financial Services Provider #5
    Industry
  • Financial Services
    Customer Profile
  • Leading provider of investment management, asset and fund administration, as well as fiduciary and banking solutions
    Challenges
  • Compressing data to save storage space, bandwidth, and transfer times
  • Finding a solution that was interoperable across multiple platforms
    PKWARE® Solution
  • SecureZIP® for z/OS®
    Results
  • Compression solution with added security, allowing for secure and efficient transfer of data
  • Complete interoperability across all operating platforms
  • Provided LPAR licensing

Company Background

Our client is a leading provider of investment management, asset and fund administration, as well as fiduciary and banking solutions for corporations, institutions, and individuals worldwide.

Challenges and Requirements

The company’s world-wide technology group provides technical services for all business units within the company. A particular business unit was transferring information from a mainframe via CD to their customers. They wanted to add compression to their process to save storage space.

The business unit reached out to the technology group with requirement specifications for assistance in finding the right solution. The key requirement was finding a solution that would be interoperable across all platforms to ensure every customer could access the data. The company also wanted to find a solution that would provide LPAR licensing.

The Solution - SecureZIP

When the company first contacted PKWARE, they inquired about PKZIP. After further internal discussions, they came to realize the importance of adding security to their processes to ensure the sensitive information being transferred remained protected. While they considered implementing a secure pipe infrastructure, they chose SecureZIP because it could quickly and easily provide both the compression and security the company needed without disrupting their existing process or requiring additional infrastructure investments.

Since SecureZIP is built on the ZIP file format, the de-facto standard in compression, the solution is completely interoperable and can be easily transported. In addition, PKWARE could provide LPAR licensing. The company’s world-wide technology group moved forward with SecureZIP as it met and exceeded all of their requirements and expectations.


Financial Services Provider #6

    Customer
  • Financial Services Provider #6
    Industry
  • Financial Services
    Customer Profile
  • One of the nation’s largest diversified financial services organizations, providing retail and business banking
    Challenges
  • Securely exchanging data with business partners via tape
    PKWARE® Solution
  • PartnerLink for z/OS®
    Results
  • Cost-effective and cross-platform solution
  • Easy and fast deployment
  • Long-term value—can use to secure FTP transfers in the future

Company Background

Our client is one of the nation’s largest diversified financial services organizations, providing retail and business banking as well as specialized services for corporations and government entities.

Challenges and Requirements

After witnessing the negative publicity surrounding data breaches as a result of lost or stolen tapes, the company decided to ensure that information they were sending from their mainframe to business partners via tape was encrypted. Although the company uses secure FTP transfer for most of their data transmissions, some partners prefer to exchange information via tape.

The company was sending 50-100 tapes containing sensitive customer information to these business partners each month via UPS, FedEx, and other carriers. They needed a solution that would allow them to secure their sensitive data prior to its transfer to tape without imposing a significant cost to partners.

Competitive Landscape

The company investigated Megacryption®, PGP®, and PKWARE’s PartnerLink.

The Solution - PartnerLink

PartnerLink proved to be easy to use, cost effective, and provided cross-platform interoperability, which meant regardless of what platform the company’s partners were running, PartnerLink would work. Additionally, the company knew that deploying PartnerLink would be easy due to the excellent customer support they had received during their initial search for a security solution. The company also liked the long-term value PartnerLink provided, such as its ability to secure FTP in the future.


Customer Success Story

Global Financial Services Provider Meets all Data Security Needs with Single Solution

    Industry
  • Financial Services
    Customer Profile
  • Provides credit and debit card clearing and settlement services at over one million locations
    Challenges
  • Meeting data security compliance standards and requirements, including PCI DSS
  • Protecting sensitive data sent via email attachments, as well as information transferred to external locations on portable media devices
    PKWARE® Solution
  • SecureZIP® for Windows® desktop
  • SecureZIP for Windows server
    Results
  • Met PCI DSS compliance requirements
  • Protected sensitive data transferred on portable media
  • Leveraged policy manager functionality to enforce new encryption policies
  • Extended useful life of existing IT infrastructure by seamlessly integrating with existing PKI environment

Company Background

Our client provides credit/debit card clearing and settlement services, handling millions of transactions daily at more than a million locations worldwide.

Challenges and Requirements

The company was required to comply with the Payment Card Inudstry Data Security Standard (PCI DSS), which mandates all credit cardholder data be protected as it is transmitted, processed, and/or stored. Enforced by major credit card companies in response to the overwhelming occurrences of data theft, PCI DSS requires any company handling credit card data to comply or face monetary fines. Our client was being audited by several business partners. During the audit process, it became apparent that they needed to address the issue of data security.

The company was transmitting credit card information that originated on their Windows server throughout the company via email attachments, as well as burning data to CD for backup storage. Not wanting to risk non-compliance, they began searching for a data security solution that would enable encryption and be easy to deploy and use.

The Solution - SecureZIP

Although the company considered PGP®, they chose SecureZIP because it was able to meet all of their requirements while also providing a more robust solution. SecureZIP offered policy manager functionality for use on the company’s Windows desktops. Using policy manager, IT administrators can centrally configure encryption settings according to internal organizational policies. This allows the company to extend their data security policies, regardless of the number of endpoints or computing environments involved in the exchange. The company recognized SecureZIP would allow them to effectively protect data at the file level, making it impossible for anyone except authorized personnel to access it. By centrally configuring security settings, it also made it easier for employees to ensure they were adhering to internal data security policies, limiting their resistance to a new solution.

SecureZIP was deployed in less than a week and is now being used on Windows server and desktop environments. SecureZIP’s seamless integration with our client’s existing PKI environment was also an added benefit because the company had wanted to use their Windows servers to produce X.509 digital certificates. Digital certificates are housed in an active directory and can easily be accessed by users via Outlook.

Success Story

Global Financial Services Provider Secures External Information Exchange, at No Cost to Partners

    Industry
  • Banking & Financial Services
    Customer Profile
  • Leading global financial services provider with locations in the United Kingdom, Europe, United States, and Asia
    Challenges
  • Protecting sensitive data during movement or storage
  • Exchanging data securely with external business partners
  • Extending the organization's internal data security policies to external business partners
    PKWARE Solution
  • SecureZIP PartnerLinkTM
    Results
  • Protected sensitive information exchanged with external partners, at no cost to partners
  • Improved operational efficiencies due to seamless integration with existing applications and computing platforms

Company Background

Our client is one of the world's leading financial services providers. In addition to its strong presence in the United Kingdom, the company has offices in Europe, the United States, and Asia. Our client works with over 1,500 partners throughout the world and operates several hundred individual branch locations.

Challenges and Requirements

The company offers a Windows®-based application to external financial advisors, trust managers, brokers, and other third-party business partners, through which they place transactions (buy and sell securities, stocks, bonds, mutual funds, etc.). The application transmits files over public networks to a central UNIX® server, which then executes the transactions through various trading systems. After the transactions clear, the server returns confirmation to the appropriate partner’s application.

As our client was preparing for a new release of this system, adding new features and functionality, their Data Security & Compliance Committee determined that the data being exchanged was sensitive in nature. Therefore, strong data protection was needed to meet internal standards and policies.

The company was very familiar with PKWARE as they were already using PKZIP® for compression and file management in their data center to improve operational efficiencies and overall workflow. In addition, several other organizations within the banking and financial services industry had begun using SecureZIP® by PKWARE for data security.

The Solution - SecureZIP PartnerLink

The company was looking for a cost-effective way to securely exchange sensitive data with their external business partners - a method that, when implemented, would expand with their business over time. SecureZIP PartnerLink was a natural choice based on its ability to seamlessly integrate with existing applications, allowing daily operations with external partners to continue without interruption. The fact that the company was already utilizing PKZIP for compression and file management made the upgrade that much easier, achieving complete deployment of the solution within a matter of weeks.

SecureZIP PartnerLink ensures sensitive information remains protected both at rest at the point of origin or destination, and during transit. Our client can distribute an unlimited number of SecureZIP Partner licenses, at no cost to their partners, increasing partner acceptance and adoption of the software. Being a “no cost” solution furthered partner acceptance and eased the adoption process. And, the company can extend their security policies, regardless of the number of endpoints or computer environments involved in the exchange. This assures our client that the solution will grow with their organization as new partners are added.

The Policy Manager functionality of SecureZIP PartnerLink allows administrators to centrally configure encryption settings according to internal policies. This allows the company to extend their data security policies, regardless of the number of endpoints or computer environments involved in the exchange. Our client can now effectively protect the data at the file level, making it impossible for anyone except authorized personnel to access it, whether the data is at rest or in transit being exchanged with partners.

In addition, while SecureZIP PartnerLink allows for encryption of data exchanged with partners, it also provides for the use of an unlimited number of contingency keys which can be added to any encrypted .zip file created on any platform. These contingency keys provide access to the encrypted archives should the primary key or passphrase be lost or compromised. And, SecureZIP PartnerLink supports the use of PKI certificates that comply through the X.509 certificate standard and passwords or passphrases can be added in conjunction with digital certificates.

In the end, our client was able to preserve their corporate brand and avoided the liability risk of sensitive information being lost or stolen. By strongly protecting their information, they eliminated exposing confidential financial and personal information of a large number of influential customers and business partners. Using SecureZIP PartnerLink, the company was also able to secure this information in a cost-effective manner and with minimal technical integration efforts.

Financial Services Provider #9

    Customer
  • Financial Services Provider #9
    Industry
  • Financial Services
    Customer Profile
  • Full-service financial institution providing inventory financing, retail loans, leasing programs, and customer credit applications
    Challenges
  • GLBA compliance
  • Enforcing strong security quickly, easily, and cost-effectively
    PKWARE® Solution
  • SecureZIP® for Windows® desktop
    Results
  • GLBA compliance
  • Extended free ZIP reader to partners, enabling secure communication
  • Ensured that files transferred between employees and with partners are secure

Company Background

Our client is one of the 10 largest banks in the United States, operating thousands of branch locations, home mortgage stores, and other offices. A specific division of the bank operates as a full-service financial institution that serves automobile companies and new car dealers, handling financing, retail loans, leasing programs, and customer credit applications.

Challenges and Requirements

The bank instituted a comprehensive plan to protect all personal customer information, in part to comply with GLBA (Gramm-Leach Bliley Act) requirements, which mandate confidentiality of client information. The corporate compliance guidelines were extensive and extended to information stored on hard drives and in transit, including communications with external customers, prospects, and vendors.

The division needed a solution that would enable them to meet corporate mandates and enable strong security quickly, easily, and most importantly, cost-effectively. They had tough security requirements to meet with limited resources and an aggressive deployment schedule. In addition, the chosen solution had to work within the existing infrastructure of an extensive external network of clients and partners. Therefore, the solution needed to be user-friendly and easy for customers to adopt.

The Solution - SecureZIP

The division chose SecureZIP to meet their security requirements and was deployed throughout the organization in less than a week. SecureZIP helped the division gain regulatory compliance, along with the added ROI benefits of reducing file size through compression—even after information was strongly encrypted.

To solve their need for increased security among partners, the division is leveraging the free ZIP Reader by PKWARE to enable secure communication. The reader enables partners to decrypt files, regardless of their IT infrastructures. Using the free ZIP Reader, customers don’t have to purchase a security product in order to open secure files.

Using SecureZIP, the division is now able to ensure that files transferred between employees within the organization, and with external partners and other third parties, are secure. PKWARE enabled the division to quickly achieve enterprise-class security through data-centric security.

Financial Services Provider #10

    Customer
  • Financial Services Provider #10
    Industry
  • Financial Services
    Customer Profile
  • Leading provider of IT solutions for community-based financial institutions
    Challenges
  • Securely exchanging information with a wide range of business partners
  • Ability to create encrypted tapes, CDs, and email attachments
    PKWARE® Solution
  • SecureZIP® / PartnerLink for z/OS®
  • SecureZIP / PartnerLink for UNIX® Server
    Results
  • Ability to securely exchange information with business partners at no cost to partners
  • No user training required--fast and easy deployment that accelerated partner acceptance

Company Background

Our client is a leading provider of core financial institution processing, card issuer and transaction processing services, and mortgage loan processing for financial institutions, retailers, mortgage lenders, and real estate professionals. The company processes information for 7,800 financial institutions and over 100,000 retailers in more than 60 countries worldwide.

Challenges and Requirements

The company wanted to ensure that their confidential customer information was not compromised by theft, loss, or interception while in transit. They needed a security solution to support the full range of technical capabilities that their partners represented. The company’s partners ranged from small to large in size and transaction volume. Each site had various levels of technical experience; in fact, several of the smaller partners did not have access to secure leased lines.

Considering their wide range of partners, the company began looking for a solution that could handle the disparate mix of partners and provide a solution that would be easy to deploy in each operating environment. In addition, the solution had to offer multi-platform capabilities and the ability to create encrypted tapes, CDs, and email attachments. Many partners already used other encryption products, but the company wanted one standard to ease the operational process burden. This meant it was also extremely important that the solution be reasonably priced for their business partners.

Competitive Landscape

The company conducted an extensive evaluation of PGP®, Megacryption®, and PKWARE. They chose PartnerLink, an extension of SecureZIP, over the competition due to its flexibility, ease of use, and multi-platform capabilities.

The Solution - SecureZIP / PartnerLink

PartnerLink clearly provided the lowest risk, highest performance, and the easiest integration and support options for the company’s existing infrastructure. It was offered at no cost to their business partners which quickly resulted in partner acceptance, easing the adoption process.

The company had been using PKWARE’s cross-platform solutions for years to streamline data storage and transfer, giving them additional confidence in the PartnerLink solution. They now use PartnerLink with over 200 endpoints on a variety of computing platforms including mainframes and UNIX servers.

The company is able to efficiently protect their data with strong encryption, making it virtually impossible for anyone except authorized parties to access files whether the data is at rest or being exchanged with partners.

Financial Services Provider #11

    Customer
  • Financial Services Provider #11
    Industry
  • Financial Services
    Customer Profile
  • One of the largest banking and financial services organizations in the world
  • Partners with leading retailers to provide a broad range of products, flexible programs, and CRM capabilities
    Challenges
  • PCI compliance
  • Securely exchanging data with business partners
  • Finding a solution that complements existing operations and computing platforms
    PKWARE® Solution
  • SecureZIP® for z/OS®
    Results
  • Interoperable across all computing platforms
  • Met PCI compliance requirements

Company Background

As one of the largest banking and financial services organizations in the world, our client works through an international network linked by advanced technology to provide a comprehensive range of financial services.

Its merchant services division partners with leading retailers to provide a broad range of products, flexible programs, and strong CRM capabilities to help retailers drive sales, profits, and customer loyalty.

Challenges and Requirements

The company’s merchant services division was looking for a solution to protect confidential customer data while complying with PCI requirements, in addition to mitigating the increasing risk of having their data lost or stolen. As one of the largest processors of credit card clearing transactions in the world, the merchant services division constantly exchanges information between business partners.

The bank realized that they needed a data security solution that would secure the data itself in order to ensure their information was protected regardless of where it was in transfer or storage. They were also hoping to implement a solution that would complement existing operations and operate seamlessly with all of their computing platforms.

The Solution - SecureZIP / PartnerLink

After a rigorous evaluation of several security products, the bank chose to implement the data-centric technology of SecureZIP on their z/OS Mainframe. SecureZIP was the natural choice for the bank as it is completely scalable and interoperable. It is also easy to deploy, support, and maintain and did not pose a risk to operational efficiencies.


Success Story

Leading Financial Services Provider Protects Data on over 380,000 Desktops, Achieves Enterprise-Wide Data Security with a Single Solution

    Industry
  • Financial Services
    Customer Profile
  • Financial services company, holding more than 200 million customer accounts in over 100 countries
    Challenges
  • Protecting sensitive data placed on removable media, such as CDs, USB drives, and tapes
  • Meeting data security standards and compliance requirements, specifically SEC compliance
  • Maintaining control of encryption use within the organization
  • Applying data security across multiple operating platforms
    PKWARE® Solution
  • SecureZIP® for Windows® desktop, i5/OS®, and Windows, Linux®, UNIX® servers
    Results
  • Protected sensitive data placed on multiple forms of removable media using strong encryption
  • Met SEC compliance requirements
  • Controlled the use of encryption within the organization via policy manager

Company Background

Our client is a major American financial services company whose products include those within consumer, corporate, and investment banking, as well as global wealth management, investment research, and private equity. The company holds over 200 million customer accounts in more than 100 countries.

Challenges and Requirements

When the company initially contacted PKWARE, they were looking for a solution that would
address three major security issues:

1) A corporate-wide initiative had been put in place requiring that all data stored on removable media be encrypted. This included CDs and USB drives at the desktop level and cartridge tapes and CDs being used in conjunction with servers.

2) A division within the company that advises corporations on mergers and acquisitions, as well as issuing and selling securities, was facing compliance issues with SEC regulations. SEC regulators must have access to information at all times. Frequently, passphrases were being used to secure information; if a passphrase was forgotten, the SEC could not access the data. In addition, unregulated use of encryption meant that information could potentially be sent outside the corporate perimeter without the company’s knowledge.

3) The company was looking to deploy a single security solution across all desktops within the organization, totaling over 380,000 units.

Competitive Landscape

A current WinZip® user, our client was struggling with the lack of administrative capabilities the product offered for controlling employee encryption functions. The company considered several other IT security vendors, including Tumbleweed®, Patrick Townsend®, and PGP® for server.

The Solution - SecureZIP Enterprise Edition

The company purchased SecureZIP Enterprise Edition for i5/OS and Windows desktop, as well as for Windows, UNIX, and Linux servers. SecureZIP provided a single solution that met all of their requirements. Information placed on all forms of removable media is protected, satisfying a corporate-wide security initiative. Using the policy manager function of SecureZIP allowed IT administrators to centrally configure and control which employees were and were not able to encrypt information.

In addition, because the company uses passphrases to encrypt sensitive data, the contingency key functionality of SecureZIP proved to be an invaluable tool. It ensured that data could be accessed at any time, even if a passphrase was lost or stolen, a critical factor when considering SEC regulations. While using contingency key allowed data to be accessed at any time, the company also wanted to increase the complexity of the passphrases they were using for encryption. SecureZIP offers passphrase hardening, which allowed IT administrators to set regulations on factors that increased passphrase strength, such as length of the passphrase and special character requirements.

Finally, our client was pleased to discover that SecureZIP provided them with one solution that was compatible across all computing platforms. The company was in the process of executing an organization-wide desktop refresh, looking for a single solution that would meet their needs, on over 380,000 desktops. SecureZIP provided a single solution, providing both encryption and compression needs, allowing the company to replace WinZip and others and use one universal product throughout the organization.


Success Story

Federal Government Agency Secures Sensitive Information Exchanged with External Business Partners, at No Cost to Partners

    Industry
  • Federal Government
    Customer Profile
  • Federal agency under Department of Health and Human Services
  • Provides guidance for the administration of health care financing programs and policies
  • Implements insurance reform provisions of HIPAA
    Challenges
  • Meeting data security standards and compliance requirements, including FIPS 140-2 and OMB M-06-16
  • Securely exchanging data with external business partners
    PKWARE® Solution
  • SecureZIP PartnerLink™ for z/OS®
  • SecureZIP PartnerLink for Windows® desktop
    Results
  • Secured information exchange with external business partners, at no cost to partners
  • Met FIPS 140-2 and OMB M-06-16 compliance requirements

Company Background

A Federal agency under the Department of Health and Human Services (HHS) provides direction and technical guidance for the administration of the Federal effort to plan, develop, manage, and evaluate health care financing programs and policies. Along with the Departments of Labor and Treasury, the agency also implements the insurance reform provisions of the Health Insurance Portability and Accountability Act of 1996 (HIPAA).

Challenges and Requirements

Our client is in possession of vast amounts of medical data and patient records for each person enrolled in the Medicare program, spanning a time frame of several years. As a result of data security standards and requirements, such as OMB M-06-16 and FIPS 140-2, it was absolutely critical that they find a solution that would comply with these mandates and allow them to continue exchanging sensitive data with numerous external business partners.

Each month, the agency transmits thousands of tapes/CDs containing sensitive Personally Identifiable Information (PII) to hundreds of endpoints, including research labs, universities, large business partners, and other government agencies. Data is placed on a tape or burned onto a CD directly from the mainframe and sent to partners with operating platforms ranging from z/OS® mainframes to Windows® desktops.

Our client faced two major challenges when trying to send sensitive data to partners: 1) many of the institutions they are sending data to do not have an IT support staff; and 2) they do not have the funding to purchase a decryption tool.

Due to the mixture of platforms and end-user expertise, it was essential that the recipient community react favorably to the chosen solution and adapt it into their processes. The agency required a cost-effective solution that could take the disparate mix of partners and IT environments into account and extend a solution that would be easy to deploy and use. The solution also required the secure, efficient exchange of critical business information with little to no interruption at the origin or endpoint(s).

The Solution - SecureZIP PartnerLink

SecureZIP PartnerLink was deployed at three data centers on multiple mainframes and on multiple open systems environments (UNIX®, O/S®, and Windows). It provided the lowest risk, highest performance, and the easiest integration and support options for the agency’s existing infrastructure, allowing daily operations with partners to continue without interruption.

SecureZIP PartnerLink allows the agency to distribute an unlimited number of SecureZIP Partner licenses, at no cost to their partners. Being a “no cost” solution furthered partner acceptance and eased the adoption process. The agency can now effectively protect the data at the file level, making it impossible for anyone except authorized personnel to access, whether the data is at rest or in transit. And, they are able to extend their security policies, regardless of the number of endpoints or computer environments involved in the exchange.

In addition to meeting the agency’s critical need of securely exchanging data with external business partners, SecureZIP also met each of their other requirements. Because SecureZIP is transport independent, it is capable of encrypting data onto mainframe tapes as well as other forms of data movement (i.e. CD, DVD). SecureZIP will create the encrypted .zip archives that then can be transferred to the media of choice via the standard method of writing.

The agency was also looking for a solution that would utilize the mainframe encryption coprocessor as well as support the AES encryption standard. SecureZIP provides a cross-platform security solution that offers encryption, digital signing, and authentication, both outside and within the IBM® hardware cryptographic environments. It also supports the AES encryption standard.

While SecureZIP allows for encryption of data exchanged with partners, it also provides for the use of an unlimited number of contingency keys which can be added to any encrypted .zip file created on any platform. These contingency keys provide access to the encrypted archives should the primary key or passphrase be lost or compromised. SecureZIP supports the use of PKI certificates that comply with the X.509 certificate standard; and, passwords or passphrases can be added in conjunction with digital certificates.

SecureZIP PartnerLink provided the agency with a solution that met all of their requirements and eliminated the exposure risk of exchanging sensitive information with external business partners. They are extremely pleased that not only are they exchanging information securely with current partners, but SecureZIP PartnerLink allows them to extend the same solution to new partners as they are added.

Federal Government Agency #2

    Customer
  • Federal Government Agency #2
    Industry
  • Federal Government
    Customer Profile
  • Data center for the government’s largest finance and accounting operation
    Challenges
  • Finding a solution that could meet organizational requirements and meet a tight deployment schedule
  • Encryption information saved to tape for secure transfer
    PKWARE® Solution
  • SecureZIP® for z/OS®
    Results
  • Compression of data before transmission up to 95%, increasing efficiency
  • Automatic translation from ASCII to EBCDIC during decompression and extraction processes

Company Background

Our client serves as the data center for the world’s largest finance and accounting operation, serving all branches of the military. They outsource the generation of W-2s for military personnel to a third party, requiring batch transfers of sensitive employee information annually.

Challenges and Requirements

With increased regulatory pressure surrounding the need to secure employee information, the process the organization was using to transfer sensitive employee information to their third party processor, needed to be more secure. The employee information was being saved from their z/OS mainframe to tape, and was then transferred via courier. This posed a major concern as the tapes were at serious risk of being lost or stolen. The organization recognized that encryption was the best solution to ensure the data was protected during transmission and began researching options.

The Solution - SecureZIP

The organization was looking for a solution that was easy and quick to implement and provided the best value for their requirements. They originally went to IBM® and Computer Associates for direction. The solutions they recommended were too expensive, complex, and would require too much time to test, implement, and deploy. As the organization continued to look for an encryption solution, they reached out to Gartner analysts for recommendations. Gartner directed them to SecureZIP which would allow the organization to meet their security requirements and expedite their processes. The third party company that exchanges information with the organization was already using PKZIP on their server, which allowed for use of SecureZIP with passphrase encryption.

Federal Government Agency #3

    Customer
  • Federal Government Agency #3
    Industry
  • Federal Government
    Customer Profile
  • Federal Government agency established to regulate civilian use of nuclear materials
    Challenges
  • FISMA compliance mandates for data security
  • FIPS 140-2 compliance mandates
    PKWARE® Solution
  • SecureZIP® for Windows® desktop
    Results
  • Policy manager function allows administrators to define how users apply encryption
  • Met FIPS 140-2 and FISMA compliance requirements

Company Background

Our client is an independent Federal Government agency established to regulate civilian use of nuclear materials. Over 3,000 employees work to support the agency’s primary mission of protecting public health and safety, as well as protecting the environment from the effects of radiation from nuclear materials, reactors, and waste facilities.

Challenges and Requirements

The agency handles various types of sensitive information, including intellectual property, employee information, and other proprietary information that is not intended for public release. This information is being exchanged both internally across desktops and externally with other partners.

The agency was required to meet the Federal Information Security Management Act (FISMA) compliance mandates for data security. This required them to develop, document, and implement an agency-wide program to provide information security for the information and information systems that support the operations and assets of the agency. In addition to FISMA compliance, they also needed a solution that was FIPS 140-2 compliant, supported secure file shredding, and could be administered centrally to enforce compliance.

Competitive Landscape

The agency was already using WinZip®, but could not consider using it to meet their security requirements. WinZip does not have any administrative capabilities, which was extremely important to the agency.

Government agencies are required to evaluate a minimum of 3 alternative solutions. Therefore, the agency also reviewed PGP®, Sigaba®, File Assurity®, and Tumbleweed®. SecureZIP was chosen because it fulfilled both the agency’s compression and encryption requirements, and also because SecureZIP was the only product that could assist with FIPS 140-2 compliance.

The Solution - SecureZIP

Using SecureZIP’s policy manager, system administrators can define how end-users apply encryption, allowing the agency to maintain control over its employees. To help meet the stringent security standards imposed on governmental agencies, PKWARE developed a special version of SecureZIP for the agency, which incorporates a FIPS 140-2 compliant encryption engine from RSA® Security.

SecureZIP also enables the use of Verisign certificates, another important requirement. The agency deployed SecureZIP on 1,800 desktops throughout the organization, including stand-alone regional locations, in one month.

Federal Government Agency #4

    Customer
  • Federal Government Agency #4
    Industry
  • Federal Government
    Customer Profile
  • One of the nation’s oldest federal law enforcement agencies
  • Operates the Witness Security Program
  • Protects the federal judiciary and transports federal prisoners
    Challenges
  • Data encryption guaranteeing security on portable media
  • Cross-platform interoperability
  • Finding a solution that would support future security upgrades
    PKWARE® Solution
  • SecureZIP for Windows® Desktop
    Results
  • Cross-Platform interoperability allowed security across the infrastructure
  • Strong data encryption allowed for security on portable media
  • On the GSA schedule, allowing for immediate deployment

Company Background

This Law Enforcement Agency is one of the nation’s oldest and most versatile. It occupies a uniquely central position in the federal courts and is involved in virtually every federal law enforcement initiative. It is responsible for more than half of all arrests of federal fugitives, protecting the federal judiciary, operating the Witness Security Program, and transporting federal prisoners. This Law Enforcement Agency has been presidentially appointed and direct the activities of 94 districts—one for each federal judicial district.

Challenges and Requirements

The Law Enforcement Agency needs to have access to sensitive criminal and investigative data at all times. With over 6,500 desktop users in the field, the Law Enforcement Agency wanted to ensure that their data was secure regardless of the device it was stored on or where it was sent.

The Law Enforcement Agency realized they needed an encryption solution to address their security requirements for removable media, specifically USB drives and laptops--the tools field agents use to store and access data. The solution had to support cross-platform interoperability and include the ability to upgrade to PKI. While the Law Enforcement Agency has not yet deployed PKI, they are strongly considering it and wanted a solution that would provide the best value today while supporting future security upgrades.

Competitive Landscape

The Law Enforcement Agency was using WinZip® for desktop compression, but recognized that WinZip was not a viable option for data security because it does not offer strong encryption or administrative policy support for contingency keys. Since most agents were using removable media to store sensitive information, they also looked at PointSec media encryption for mobile devices, but found it extremely expensive to deploy.

The Solution - SecureZIP

SecureZIP was chosen as the best solution. SecureZIP offers strong data encryption that is interoperable across all major computing platforms and security infrastructures. In addition, it is also on the GSA schedule, which allowed the Law Enforcement Agency to expedite their purchasing process and begin securing data in the field almost immediately.

Federal Government Agency #5

    Customer
  • Federal Government Agency #5
    Industry
  • Federal Government
    Customer Profile
  • Large Federal Government agency providing reliable and cost-effective IT solutions to achieve mission performance delivery for its extended agencies
    Challenges
  • Compliance with OMB Mandate 06-16 for removable media
    PKWARE® Solution
  • PartnerLink/SecureZIP® for z/OS®
    Results
  • AES 256-bit encryption ensured compliance with OMB Mandate 06-16

Company Background

Our client is a large Federal Government agency providing reliable and cost-effective Information Technology (IT) solutions to achieve effective mission performance delivery for its extended agencies.

Challenges and Requirements

The agency transfers data from a z/OS mainframe to tape and then physically sends the tape to the IRS and other federal agencies. When a tape was lost in transit, the agency knew they needed a security solution that was easy to use and quick to deploy.

The agency had to comply with the OMB Mandate 06-16, which required that sensitive data being transferred to removable media be protected via encryption. The agency required AES 256-bit encryption, the strongest form of encryption available, to secure government data.

The Solution - SecureZIP

The agency researched several security options, but in the end, they felt PKWARE offered the strongest solution. SecureZIP could be deployed easily, fit seamlessly into existing processes, and it met the AES 256-bit encryption requirement.

The agency purchased SecureZIP for z/OS in order to encrypt data before being transferred to tape. They were able to apply the solution with minimal disruption to their current processes and ensure the highest level of security for customer private data, while still fulfilling OMB Mandate 06-16 requirements.

Federal Government Agency #6

    Customer
  • Federal Government Agency #6
    Industry
  • Federal Government
    Customer Profile
  • Federal data center providing cost- effective IT solutions to support the needs of customers within the federal sector
    Challenges
  • Securely exchanging data, both in transit and at rest
  • Finding a solution that could support multiple computing platforms
  • Compression and encryption of data for faster processing
    PKWARE® Solution
  • SecureZIP® for z/OS®
    Results
  • Interoperable solution that provided strong encryption of data, both in transit and at rest

Company Background

Our client is a recognized, award-winning Federal Government IT Center responsible for administering benefits to Veterans and their families.


As a fee-for-service organization, this data center provides cost-effective IT enterprise solutions to support the information technology needs of its customers within the Federal sector. Their offerings include a full complement of technical solutions, including platform hosting services, total information assurance, customer business continuity, data conversation and interfacing, configuration management, and application administration.

Challenges and Requirements

The data center provides processing services to various government and military agencies and was transferring large files containing Personally Identifiable Information (PII) from their z/OS® mainframe to multiple Federal Government agencies nightly.


Although the data center had a secure pipe (SSL), they wanted to ensure that the data was fully protected once it left the pipe, while awaiting retrieval. As the data waits to be retrieved by other federal agencies, it rests at the perimeter of the system and still must be protected.

The data center wanted a solution that could encrypt data at the file level and also support multiple computing platforms.

The Solution - SecureZIP for z/OS

The data center researched several security options but, in the end, they felt PKWARE® offered the strongest solution. SecureZIP's ability to protect the sensitive data - as it rests on the perimeter of the system - ensured that only intended federal employees had access to the confidential information. The agency took a step toward preventing confiscation of this data at rest by encrypting it - at the file level and applying the highest level of security to this PII.


SecureZIP's ability to provide data security at rest and in transit, as well as interoperability across all major computing platforms, were key factors in the data center's decision. And, because ZIP technology continues to be a recognized brand in the marketplace, they knew they were using a stable, reliable, and proven application.

Federal Government Agency #7

    Customer
  • Federal Government Agency #7
    Industry
  • Federal Government
    Customer Profile
  • A major ministry within the Canadian Government that enforces various provincial laws and assists municipal police forces as needed
    Challenges
  • Implementing a data security solution allowing the secure exchange of sensitive criminal data with other law enforcement agencies Finding a cost-effective solution that would fit within the budget and be easily and efficiently deployed
    PKWARE® Solution
  • SecureZIP® for z/OS®
    Results
  • Solution fit well into the current operating environment without requiring implementation of large changes
  • Cross-platform capability allowed for secure data exchange with other ministries regardless of other software or platforms being used

Company Background

Our client is a ministry within the Canadian Government that is responsible for enforcing provincial laws, some municipal bylaws, and the criminal code. The ministry also assists municipal police forces when needed.

Challenges and Requirements

As a result of the many public data breaches occurring both domestically and internationally, the ministry recognized an immediate need for increased data security. They needed to securely exchange sensitive criminal data with other ministries and law enforcement agencies.

When the ministry contacted PKWARE, they were looking for a security solution to be deployed on their z/OS mainframe that would fit within their budget and be installed easily and efficiently.

The Solution - SecureZIP

Other ministries within the Canadian Government were using PKWARE products and SecureZIP came highly recommended to our client. After an initial testing period, they were impressed with the functionality and the ease of use the product provided for their employees. SecureZIP also fit well within their current operating environment and did not require any large changes in order to implement.

The relationship that other ministries had established with PKWARE further eased the SecureZIP adoption process by allowing for ease with contracts and licensing. In addition, SecureZIP’s cross-platform compatibility allowed our client to securely exchange data with other ministries regardless of their operating platforms or other types of software being used.

Success Story

Federal Government Agency Secures Email Exchange, Meets Data Security Standards & Compliance Requirements

    Industry
  • Federal Government
    Customer Profile
  • Responsible for the safety of civil aviation
    Challenges
  • Protecting sensitive information sent via email and/or email attachments
  • Meeting data security standards and compliance requirements, including FISMA
  • Finding a cost-effective solution that would fit within the budget and be easily and efficiently deployed
    PKWARE® Solution
  • SecureZIP® for Windows® desktop
    Results
  • Protected sensitive information exchanged via email using Lotus Notes
  • Met compliance requirements (FISMA, OMB M-0408, and others)
  • Maintained control of data by centrally- controlled encryption policies
  • Integrated with current operating environment without requiring implementation of large infrastructure changes

Company Background

Our client is a Federal Government agency responsible for the safety of civil aviation. The agency maintains various responsibilities, including: regulation of civil aviation to promote safety; development of civil aeronautics; research and development of the National Airspace System; and regulation of U.S. commercial space transportation. The agency is divided into several individual offices.

Challenges and Requirements

An audit was performed within the agency to identify instances where Personally Identifiable Information (PII) may be exposed. Two offices within our client agency took a proactive stance and concluded that they needed additional security around information that is exchanged daily via email and email attachments. They began searching for a solution that would allow them to encrypt sensitive information exchanged via email and, if possible, a solution that would also allow them to access encrypted information for purposes of audit and/or data recovery.

The agency uses Lotus Notes for desktop email communication. While encryption capabilities are built into the program for secure exchange between Lotus Notes users, the agency needed a solution that would integrate with the application and also allow for secure external email exchange. In addition, with office employees located across the country, it was imperative that the solution be quick to deploy and easy to integrate within the daily workflow.

When searching for a security solution, the agency needed to ensure the solution would meet the requirements outlined in their statement of work for encryption software. These requirements included:

  • Compliance with Federal Information Security Management Act (FISMA) of 2002 for mandatory use of FIPS 140-2 compliant technology
  • Compliance with Information Technology Management Reform Act of 1996, Public Law 104-106 to use Validated Cryptographic Modules
  • Compliance with OMB Memo M-0408, Maximizing Use of SmartBuy and Avoiding Duplication of Agency Activities with the President’s 24 E-Gov Initiatives GSA Advantage purchase

Competitive Landscape

The agency was already using WinZip® for desktop compression, but soon recognized that it was not a viable option for data security because it did not offer strong encryption or administrative policy support for contingency keys. WinZip also could not meet several of the compliance requirements, specifically FIPS-140.

The Solution - SecureZIP for Windows desktop

Strong encryption for secure email exchange. SecureZIP offered the agency strong data file encryption that met their initial goal of implementing a security solution compatible with their Lotus Notes email application. The offices can now encrypt and securely exchange sensitive information via email and/or email attachments with all external endpoints.

Access data for audit/recovery purposes. Contingency key functionality ensures that data can be accessed at any time, even if a passphrase used for encryption is lost or stolen. The agency can recover any data encrypted using SecureZIP, which is especially important in the instance of an agency audit.

Centrally control encryption capabilities. Policy manager, another capability of SecureZIP, grants the agency the ability to set security protocols so they automatically become part of the workflow. In some cases, users are unaware that files are being secured because SecureZIP works “in the background,” encrypting and decrypting files without requiring any user interaction. Using policy manager, administrators can centrally control encryption standards, configuring and securing protocols. Every time an employee or affiliate creates a SecureZIP file, the user is locked into encrypting the file according to the agency’s settings.

Fast and easy deployment. SecureZIP also provides a solution that is easy to use and deploy within the current work environment. It allows the agency to send sensitive data freely within the organization as it is protected from the originating source, in transit, and remains protected when it reaches its destination.

Federal Government Agency #12

    Customer
  • Federal Government Agency #12
    Industry
  • United States Federal Government
    Customer Profile
  • Program office located within the
    Department of Defense Health
    System
  • Offers specialized support in managing the healthcare of active military members, retirees, and family members
    Challenges
  • Standardizing the process for
    file compression and processing
    throughout the organization
  • Reducing operational overhead &
    network bandwidth
    PKWARE® Solution
  • PKZIP® Enterprise Edition for Server
    Results
  • Reduced operational overhead
    and network bandwidth, while also increasing operational efficiencies
  • Easy and rapid deployment
    throughout the organization
  • Use of the defacto .zip compression standard allowed for easy crossplatform support

Company Background

Our client, a program office within the Department of Defense (DoD) Health System, provides decision support information to those managing the delivery of healthcare. They are responsible for making multi-level healthcare management information available to the necessary parties. They receive, validate, edit, process, aggregate, and integrate all data resulting from the healthcare of military members, including active duty members, retirees, and their families.

Challenges and Requirements

The organization is expanding rapidly and needed to find a solution that would be quick and easy to deploy, while meeting their data processing needs. Data is required to be sent through two specific applications where it then goes through a perimeter inspection process before being sent to various proxy server locations.

Currently, a large amount of network bandwidth is being used to transmit these large files, as well as significant man-hours spent waiting to transmit the files. The organization wanted a single solution that would standardize and automate their file transfer and processing protocol. Reducing operational overhead and network bandwidth was essential.

The Solution - PKZIP Enterprise Edition

When the organization contacated PKWARE, they were faced with needing to quickly implement a solution that would easily fit within their existing infrastructure, while meeting their data processing needs. Other areas within the organization were already using PKZIP for data compression, so it made sense to continue to expand the use of a single product throughout the organization.

Using PKZIP, files can be zipped for transfer through the applications, and remain in their zipped format as they go through the inspection process before making their way to proxy server locations. Inspected, zipped files are forwarded from the proxy servers where the data can then be unzipped and processed. By using an automated process, the organization is now saving considerable overhead in network bandwidth and is also reducing the man-hours required to transmit the files.

After data is processed, it can be sent easily to a Military Data Repository (MDR). Using the defacto .zip standard for compression ensures that the data can be seamlessly transferred across multiple computing platforms within the organization.


State Government Agency #1

    Customer
  • State Government Agency #1
    Industry
  • State Government
    Customer Profile
  • State Government agency that collects tax revenues and administers tax laws
    Challenges
  • Migrating from Legacy system to Windows server environment
  • Securely transferring data from server to server
  • Finding a solution that allowed use of digital certificates and supported AES encryption
    PKWARE® Solution
  • SecureZIP® for Windows® Server
    Results
  • Ability to enforce certificate-based encryption
  • Easy and rapid deployment without requiring user training

Company Background

Our client is a State Government agency that collects tax revenues and administers tax laws. The agency ensures voluntary compliance with tax laws through public education and by providing assistance to taxpayers in filing tax returns and paying taxes. Additionally, the agency has the authority to initiate collection of unpaid taxes and apply enforcement measures when necessary.

Challenges and Requirements

The agency wanted to migrate from a Legacy system to a Windows server environment. They needed to securely transfer financial and taxpayer data files that move internally from server to server. The agency was required to follow guidelines in order to protect sensitive taxpayer information via AES encryption, so they needed to find a solution that would support that directive. They also wanted to have the ability to use digital certificates for authentication purposes.

Competitive Landscape

In order to meet these challenges, the agency considered two potential solutions: WinZip® and SecureZIP. WinZip was disqualified because they were unable to support the use of digital certificates, a key requirement. After a thorough evaluation of SecureZIP, the agency selected SecureZIP Enterprise Edition.

The Solution - SecureZIP Enterprise Edition

The agency chose SecureZIP Enterprise Edition because of its ability to enable certificate-based encryption. Due to SecureZIP’s ease of use and the technical support provided by PKWARE, no user training was required. The agency was able to deploy SecureZIP within hours, providing minimal distraction to daily operations.


Success Story

State Government Agency Secures External Data Exchange at No Cost to Business Partners

    Industry
  • State Government
    Customer Profile
  • Collects local and state tax revenue used for state-funded programs
  • Provides IT services critical to daily operation of many state agencies
    Challenges
  • Exchanging data securely with external business partners via FTP
  • Implementing a solution that would work across multiple computing platforms and accommodate varying IT infrastructures
    PKWARE® Solution
  • SecureZIP PartnerLink
    Results
  • Securely exchanged data via FTP with external business partners, at no cost to partners
  • Met government data security requirement of AES 256-bit encryption

Company Background

Our client is a state government agency that serves as the Chief Financial Officer for their state, collecting billions of dollars each year in state and local tax revenue used for state-funded programs. As a fee-based service bureau, the Agency also provides Information Technology (IT) services critical to the daily operation of many of their individual state agencies. In addition, the Agency regulates the state’s alcohol, tobacco, and motor fuel industries and serves as a member of many state boards and commissions.

Challenges and Requirements

Our client does a great deal of business with external business partners, including state and local government agencies, as well as corporations. They required a data security solution that would support varying transaction volumes and frequencies, but, at the same time, could address a broad range of technical capabilities that their business partners represented.

The Agency’s external business partners are varied, ranging from large financial institutions with significant IT resources to small state and local government agencies with limited IT resources and technical capabilities. Due to the mixture of computing platforms and end-user IT expertise, it was essential that the recipient community react favorably to the Agency’s security directive and adapt it into their processes.

Our client also needed a cost-effective solution that would take the disparate mix of business partners and IT environments into account and extend a solution that would be easy to deploy and use. In addition, the solution had to address the bidirectional secure transfer of data files via FTP that offered the flexibility to scale to multiple platforms without changing the existing infrastructure. The solution required the secure, efficient exchange of critical business information with little to no interruption at the origin or endpoint(s).

The Solution - SecureZIP PartnerLink

The Agency was already using PKZIP by PKWARE on their mainframe. Upgrading to SecureZIP PartnerLink was simple. SecureZIP PartnerLink provided the lowest risk, highest performance, and the easiest integration and support options for their existing infrastructure, allowing daily operations to continue without interruption.

SecureZIP PartnerLink allows the Agency to distribute an unlimited number of SecureZIP Partner licenses, at no cost, to their partners. Being a “no cost” solution furthered partner acceptance and eased the adoption process. The Agency can extend their security policies, regardless of the number of endpoints or computing environments involved in the exchange.

Our client is now effectively protecting data at the file level, making it impossible for anyone except authorized personnel to access it, whether the data is at rest or in transit being exchanged via FTP. SecureZIP PartnerLink provides a cross-platform security solution that offers encryption, digital signing, and authentication. It also supports the AES encryption standard, meeting the Agency’s other technical requirement of AES 256-bit encryption.

As a “no cost” solution, implementing SecureZIP PartnerLink furthered business partner acceptance and eased the adoption process. In the end, our client eliminated the risk of exposing sensitive information being exchanged with external business partners by implementing a solution that accommodated current partners with the added ability to scale to meet the Agency’s future needs as new partners are added.


State Government Agency #3

    Customer
  • State Government Agency #3
    Industry
  • State Government
    Customer Profile
  • Largest pension system in the US
  • 170,000 members
    Challenges
  • Securely transferring information via tape
  • Strong data encryption
    PKWARE® Solution
  • SecureZIP for i5/OS®
    Results
  • Ability to secure data on back- up tapes
  • Reduced overall time required for back-up processes

Company Background

Our client is one of the largest pension systems in the United States, administering a basic Qualified Pension Plan as well as the largest unified Section 403(b) Tax-Deferred Annuity Program in the country. The agency serves more than 170,000 retirees and beneficiaries.

Challenges and Requirements

The agency was transferring sensitive member information to backup tapes “in the clear,” leaving the data completely vulnerable. While the agency had not experienced a breach themselves, data breach headlines regarding tape loss/theft were major drivers in their decision to initiate an encryption project.

To ensure that their confidential data was secure, the agency performed an internal data classification project, via which they pinpointed 39 specific libraries that contained sensitive information that they wanted to encrypt.

Competitive Landscape

The agency evaluated both Patrick Townsend and SecureZIP to provide an encryption solution for their tape backups.

The Solution - SecureZIP

SecureZIP was chosen because it offered a more comprehensive product with more functionality, flexibility, and configuration options. In addition, several agency employees had used PKZIP® at previous jobs and liked the concept of using a familiar tool. The agency was able to deploy SecureZIP in a couple weeks. Not only did SecureZIP meet the agency’s need for backup tape encryption, they were also able to reduce the overall time required for the backup process by 10%, saving both time and resources.


Success Story

State Government Agency Dramatically Reduces IT
Security Spending

    Industry
  • State Government
    Customer Profile
  • Agency charged with implementing public school laws and State Board of Education policies and procedures
    Challenges
  • Securing Personally Identifiable Information (PII)
  • Exchanging sensitive data securely and more efficiently amongst all counties within the state
  • Finding a cost-effective solution that would meet agency requirements and be deployed within a short timeframe
    PKWARE® Solution
  • SecureZIP PartnerLink™ for i5/OS® and Linux®
    Results
  • Experienced significant cost savings by allowing the replacement of private SNA network as a license is only required for “hub” machines
  • Secured sensitive data both in storage and transit

Company Background

Our client is a state government agency charged with implementing the State’s public school laws, as well as the State Board of Education’s policies and procedures. The Agency is composed of hundreds of positions that work to provide leadership and service to all local public school districts across the state within the areas of instruction, finance, technology, and personnel support.

Challenges and Requirements

The Agency oversees all public schools within the state and is in possession of Personally Indentifiable Information (PII), including home addresses, phone numbers, and social security numbers. Since the Agency is responsible for formalizing the education standards state-wide, secure communication exchange is required between the state and individual counties.

When the agency contacted PKWARE, they were looking for a solution that would replace their current private SNA Network. The cost of maintaining the private SNA Network was thousands of dollars each month, an extremely expensive solution. It was essential to find a new solution that would be both cost-effective and could be deployed within a short time frame, prior to moving from the SNA Network to a public network.

It was also critical that the Agency find a solution that would allow them to continue exchanging massive amounts of sensitive data with their external business partners, totaling over 100 different counties across the state. First and foremost, however, the data needed to be secure before moving to a public network containing multiple operating platforms.

Competitive Landscape

The Agency researched nuBridges® as another possible security solution. However, nuBridges, a point-to-point solution provider required that each end-point be licensed individually. While nuBridges would solve infrastructure issues, they would be costly to implement and did not offer additional features, such as the scalability that was critical to the Agency.

The Solution - SecureZIP PartnerLink

SecureZIP PartnerLink was a natural choice for our client. It was be deployed on their i5/OS midrange system and Linux server, providing them lowest risk, highest performance, and the easiest integration and support options for their existing and new infrastructure.

The “hub and spoke” design of SecureZIP PartnerLink allows information to be distributed from the central location, or “hub,” directly to the various end-points. Rather than transport security models, where only the transmission layer is secure, SecureZIP PartnerLink allows the data to be secure both in transit and at rest. SecureZIP PartnerLink allows our client to purchase a single solution that eliminated the high costs they were currently experiencing with the SNA Network.

SecureZIP PartnerLink also allows the Agency to distribute an unlimited number of SecureZIP Partner licenses, at no cost to their partners, furthering its cost-effectiveness. The Agency was able to deploy SecureZIP PartnerLink within a couple of weeks, eliminating their high monthly costs while providing a data security solution that ensured easy, efficient, and secure exchange of data with multiple end-points.


Success Story

Leading Healthcare Organization Protects Sensitive Data, Meets HIPAA Compliance Requirements

    Industry
  • Healthcare
    Customer Profile
  • Healthcare organization with a network of over 3,400 physicians
  • Provides additional services such as home care and hospice services
    Challenges
  • Meeting data security standards and compliance requirements, specifically HIPAA compliance
    PKWARE® Solution
  • SecureZIP® for z/OS®
    Results
  • Met HIPAA compliance requirements
  • Protected sensitive information exchanged via FTP with business partners

Company Background

Our client, a large healthcare organization, has become a nationally recognized leader in efforts to improve the quality of healthcare. The organization’s array of additional services include community clinics in partnership with local medical schools, home care and hospice services, QuickCare clinics, and others.

Challenges and Requirements

Our client needed a secure, reliable enterprise solution for data exchange that offered strong encryption in order to meet HIPAA regulations. The organization had recently undertook an effort to digitize most of its records to ensure HIPAA compliance, reduce its reliance on tape backups, and, most importantly, make sure its patients had the most current records available when visiting an affiliated facility. It also needed to be able to securely exchange large volumes of Personally Identifiable Information (PII), including patient health records, from its mainframe computers to business partners and suppliers.

Competitive Landscape

The organization wanted to ensure that if their information was intercepted in transmission, it could not be accessed. Simultaneously, due to the size of the files being transmitted, they needed a way to compress them. To address this issue, they explored several data encryption options, including PGP® and SecureZIP. The organization had to make sure the chosen solution would work in its heterogeneous computing environment. So, rather than having to find an encryption utility for each individual platform, they wanted one product that could handle all of their compression and encryption needs from a centralized IBM® z/OS system.

The Solution - SecureZIP

The organization selected SecureZIP for z/OS to enable strong encryption. This allowed them to send information via FTP to their partners directly from the data center, saving time and money. SecureZIP provided straight-forward implementation and its interoperability meant it could be implemented on platforms throughout the organization. Now, the organization has a centralized tool that allows users of other servers to FTP their files to their z/OS mainframe and have them compressed, encrypted, and transmitted.

Healthcare Organization #2

    Customer
  • Healthcare Organization #2
    Industry
  • Healthcare
    Customer Profile
  • Global pharmaceutical company producing consumer and animal health products, serving more than 120 countries
    Challenges
  • Securing information on laptops and other forms of portable media
  • Exchanging data securely regardless of transmission method
  • Finding a solution that would enable desktop email encryption
  • Compliance with Japanese and European Union legislation
    PKWARE® Solution
  • SecureZIP® for Windows® desktop
  • SecureZIP for UNIX® server
    Results
  • Encryption for data stored on portable media
  • Passphrase encryption allowing secure exchange of email
  • Secure transfer of information using data-centric security

Company Background

Our client is a global pharmaceutical company, producing some of the most well-known consumer and animal health products. By collaborating with a complex network of partners, the company discovers, develops, manufactures, and markets advanced drug therapies to hospitals, doctors, and consumers.

Challenges and Requirements

Because the company operates globally, they had several key data security issues within their organization. The company has employees using laptops to access sensitive data, such as patient health information, research findings, and other intellectual property. They also have employees working in lesser developed areas in the world where the risk of laptop theft is very high. The company was very concerned with the loss or misuse of information resulting from the potential theft of laptops and removable media devices containing trade secrets. They needed to ensure their research and client information was secure regardless of where the laptop or other removable media resided.

In order to facilitate collaboration with all of its entities, the company sends data via CDs, tapes, disk arrays, and FTP to other company locations around the world. They needed a way to secure that data regardless of the transmission method. Operating on a global scale, they encountered multiple government security mandates, the most restrictive in Japan and Europe.

The Japanese government requires any company operating in Japan to utilize passphrase encryption to protect all sensitive employee and customer data that is sent attached to emails. This resulted in a need for the company to acquire a solution that would enable desktop email encryption for their subsidiary in Japan.

The European Union’s “safe harbor” laws were developed to assure EU companies that the organizations they share information with provide adequate data protection. Organizations in the United States who wish to comply with the safe harbor framework must protect personal information from loss, misuse, and unauthorized access, disclosure, alteration, and destruction. This enables the companies to confidently and securely exchange information without experiencing interruptions or delays.

The Solution - SecureZIP

Utilizing a combination of SecureZIP for Windows desktop and UNIX, the company was able to solve each of their data security issues easily and in a cost-effective manner. SecureZIP for Windows desktop enables them to encrypt sensitive data when it is stored on laptops rather than encrypting the entire hard drive. SecureZIP’s data-centric technology protects the data itself, so even if the laptop is lost of stolen, the data is protected.

SecureZIP also enables the company to meet Japanese government’s data security requirements and EU’s safe harbor laws. Although Japan had originally standardized on WinZip®, they chose SecureZIP as an alternative because it enables passphrase-based encryption for email attachments. To comply with EU’s safe harbor laws, the company leverages SecureZIP for Windows desktop combined with SecureZIP for UNIX. They are able to encrypt all of the information they are sending to their European locations utilizing existing data transfer and processing methods.


Healthcare Organization #3

    Customer
  • Healthcare Organization #3
    Industry
  • Healthcare
    Customer Profile
  • One of the nation’s largest health benefits companies, in terms of commercial membership, serving more than 34 million members nationwide
    Challenges
  • Finding a solution to reduce transmission time of weekly data
    PKWARE® Solution
  • PKZIP® for z/OS®
  • PKZIP for UNIX® server
    Results
  • Large file size support allows for compression of all files, decreasing transmission times significantly
  • Interoperable solution ensured data could be easily transferred across platforms

Company Background

Our client is one of the nation’s largest health benefits companies, in terms of commercial membership, serving approximately 34 million medical members nationwide. The company provides health benefit solutions through a wide range of health care plans and related services, as well as specialty products including life and disability insurance benefits, pharmacy benefit management, flexible spending accounts, and others.

Challenges and Requirements

Every week 2-3 million files, each over 20 GB in size, are sent from the company’s mainframe to UNIX server. These files contain pharmacy data, including claim information, prescription details, and individual policy numbers for various health plans. The company was in need of a solution that would significantly reduce the amount of time it took to transmit all of their weekly data from the mainframe to servers.

The Solution - PKZIP Enterprise Edition

PKZIP Enterprise Edition provided the company with enhanced file support--the capacity to handle much larger file sizes while decreasing transmission times significantly. “With PKZIP Enterprise Edition, we are now able to compress file batches to half of their original size, which is much more manageable for our ETL server. We are also experiencing wall-clock savings as a result of the increased compression,” said an Application Developer for the company.

The company is also pleased with PKZIP’s interoperability across all major computing platforms, ensuring that data can be easily transmitted from the mainframe to their UNIX servers.

In addition, the company was extremely satisfied with the customer and technical support they received from PKWARE. “They were very responsive and answered all of my questions during the deployment process,” said the Application Developer. Overall, the upgrade was fast and easy, deploying within a matter of days and provided the solution that fit their immediate need.


Success Story

Healthcare System Protects Data Sent Via Portable Media, Email, and FTP with a Single Solution

    Industry
  • Healthcare
    Customer Profile
  • Organizational division within one of the largest publicly funded healthcare systems in the United Kingdom
    Challenges
  • Protecting sensitive data being sent via portable media, email, and FTP
  • Ensuring strong passphrases meeting specific requirements are being used to secure data
    PKWARE® Solution
  • SecureZIP® for Windows® desktop Enterprise Edition
    Results
  • Protected sensitive data sent inside and outside the organization via portable media, email, and FTP using strong encryption
  • Enforced data security according to organizational policies and best practices
  • Ensured access to data at any time for audit or recovery purposes
  • Integrated with Microsoft Office®; eased use of product amongst employees

Company Background

Our client is an organizational division of one of the largest publicly funded healthcare systems in the United Kingdom. Since Her Majesty’s Revenue and Customs data loss in 2007 affected 25 million individuals, the organization has been proactive in protecting their sensitive information, taking steps to encrypt Patient Identification Information (PII) and maintain compliance with European Union Privacy Laws.

Challenges and Requirements

Considering the vast amounts of sensitive data the organization handles, they first and foremost required a solution that would meet the AES 256-bit encryption standard. The solution needed be easily deployed on thousands of desktops, providing strong data encryption for transfer of sensitive information via portable media, email, and FTP.

One requirement was the ability to enforce the use of strong passphrases so the encrypted data could not be easily accessed. Using SecureZIP, IT administrators can centrally configure passphrase strength and apply organizational policies and best practices.

It was also imperative that the organization find a solution that could be deployed within a very tight time frame. In addition to rapid deployment, ease of use was extremely important—they needed a solution that would be scalable across multiple operating environments and infrastructures.

Competitive Landscape

A current WinZip® user, the organization soon realized the benefits that SecureZIP could offer over their current utility. SecureZIP offered both the compression capabilities and AES encryption WinZip was currently providing; however, unlike WinZip, SecureZIP also was able to provide:

  • User Policy Management. The ability to push out policies enforcing or restricting the use of compression, encryption, passwords, certificates, and digital signing.
  • Password Hardening. The ability to establish rules regarding the minimum and maximum length of passwords as well as the strength of the password.
  • Contingency Key. The ability to recover encrypted data for audit or recovery purposes.
  • Cross-Platform Interoperability. SecureZIP is interoperable across all major computing platforms, including desktop, server, midrange, and mainframe environments.

The Solution - SecureZIP

The organization was introduced to SecureZIP Enterprise Edition. SecureZIP integrates with Microsoft Office, providing a solution that allowed for secure data storage with the click of a button. Since ease of use was a requirement, this provided an easy way for all employees, internally and externally, to secure information.

SecureZIP’s integration with Microsoft Outlook® provides the option for secure information exchange via email. With SecureZIP, information can also be sent securely via Outlook directly from Office applications, making the secure exchange of information even easier.

The contingency key functionality of SecureZIP allowed the organization to access encrypted data for audit or recovery purposes, a factor that became a necessity very early in the decision-making process. In addition, passphrase encryption allowed them to transfer data securely via e-mail, FTP, CD, and other forms of portable media. Data is protected, even if intercepted in transit, protecting the organization from a data loss similar to that of Her Majesty’s Revenue and Customs.

SecureZIP met and exceeded the organization’s initial goals, providing strong encryption for data transfer and storage, an easy-to-use solution for all employees, as well as rapid deployment and adoptability.

Insurance Provider #1

    Customer
  • Insurance Provider #1
    Industry
  • Insurance
    Customer Profile
  • Leading provider of property/casualty, life, and specialty insurance
    Challenges
  • Data compression capabilities
  • Standardizing data exchange processes Finding a cost-effective solution
    PKWARE® Solution
  • PKZIP® for Server
    Results
  • Cross-platform compatibility, ensuring use across all machines
  • Effective and efficient deployment imposing minimal cost

Company Background

Our client is one of the world’s largest insurance and financial services providers, with operations across the globe. Domestically, the company is known as a leading provider of property/casualty, life, and specialty insurance to commercial, institutional, and individual customers. Internationally, the company provides reinsurance, life insurance and retirement services, asset management, and financial services.

Challenges and Requirements

When the company contacted PKWARE, they were sending bulk data from 25 different endpoints globally through a main FTP server, and then outward to various machines. The company was searching for a standardized way of handling their data, while also providing a compression solution.

The Solution - PKZIP

The company chose PKZIP due to its low cost, flexibility, and simplicity of the solution. Because PKZIP automatically integrates with FTP, the company was able to eliminate the need to integrate compression into a multi-step process. PKZIP is also compatible across all major computing platforms, which ensured it could be used with other machines that were receiving data after it passed through the FTP server. The company was able to deploy the solution quickly and reduced administrative costs. PKZIP provided the effective and efficient solution they were seeking.


Insurance Provider #2

    Customer
  • Insurance Provider #2
    Industry
  • Insurance
    Customer Profile
  • Helps small- to mid-sized businesses afford better insurance coverage
    Challenges
  • Finding a solution that supported AS400 passphrase encryption
    PKWARE® Solution
  • SecureZIP® for i5/OS® Midrange
    Results
  • Ability to encrypt and save information on portable media
  • Ability to send information securely via email attachments

Company Background

Our client is a leading provider of workers’ compensation insurance, established to help small- to mid-sized businesses facing rising insurance costs to better afford coverage.

Challenges and Requirements

The company’s legal department was generating legal briefs containing sensitive claim information in hard copy and then filing them away for storage. This was not efficient and took up a lot of physical space throughout the office.

The company began storing their information in electronic format for increased efficiency. They began utilizing a Websphere application on their i5/OS midrange system that enabled their distributed legal team to centrally generate files. They then wanted to take those documents and convert them to PDF and encrypt them with AS400 passphrase encryption to ensure the data was secure.

Competitive Landscape

The company initially looked to their core system software provider for the security they required, but they were unable to offer the required encryption capabilities. They then consulted with Gartner analysts who suggested SecureZIP. Patrick Townsend was the other option considered. After evaluating both solutions, the company selected SecureZIP because it provided more features and a higher level of functionality, including the ability to compress files.

The Solution - SecureZIP

With SecureZIP, the company can now encrypt the sensitive PDF files generated on their i5/OS systems. These secured files can then be saved to CD, DVD, and/or backup tapes for long-term storage. SecureZIP also enables the ability to send the information securely via email attachments from their i5/OS machines to other parts of the company, including legal firms outside of their corporate network.


Insurance Provider #3

    Customer
  • Insurance Provider #3
    Industry
  • Insurance
    Customer Profile
  • Provides healthcare to nearly 2 million people
  • Provides nearly 200,000 Medicare recipients with supplemental coverage
    Challenges
  • Securely exchanging data with business partners
    PKWARE® Solution
  • SecureZIP® for UNIX® server
    Results
  • Ability to exchange information securely with business partners, as well as exchange information securely between operating systems on-site

Company Background

Our client provides healthcare to nearly 2 million people across the Midwest. Company products include PPO, POS, indemnity plans, as well as vision care, dental, life, managed drug plans, and disability insurance. The company also provides nearly 200,000 Medicare recipients with supplemental coverage.

Challenges and Requirements

The company was providing confidential patient health information to insurance brokers of all sizes and recognized that they needed to enable secure data transfer with select business partners. While they already had secure communications set up with larger brokers, they also needed a secure, cost-effective method to transmit the data to smaller brokers. The data they needed to secure originated on their UNIX server and was sent to an automated files transfer department for uploading to a web server. The insurance brokers then downloaded the information onto their desktops.

Competitive Landscape

The company initially looked to their core system software provider for the security they required, but they were unable to offer the required encryption capabilities. They then consulted with Gartner analysts who suggested SecureZIP. Patrick Townsend was the other option considered. After evaluating both solutions, the company selected SecureZIP because it provided more features and a higher level of functionality, including the ability to compress files.

The Solution - SecureZIP

SecureZIP met the company’s requirements by providing them an interoperable, cost- effective solution. With SecureZIP, data is encrypted on their server, ensuring the information is protected throughout the entire transfer process. The recipient easily unzips and decrypts the data on their desktops using PKWARE’s free ZIP Reader.

When the company purchased SecureZIP, they had one server running multiple environments. Two years later, they began migrating the server environments to multiple physical servers. They needed to mirror the SecureZIP solution in their development, pre-production, and production environments, expanding the solution even further. This proved to be a simple implementation due to SecureZIP's scalability, meeting the company’s growing data security needs.



Success Story

IT Service Consultant Increases Data Transfer Efficiency by Compressing Data Up to 95%

    Industry
  • IT Services
    Customer Profile
  • Provides solutions that enable companies to profit from the use of advanced technology
    Challenges
  • Processing large volumes of information within a tight time window
  • Transmitting and processing data originating from multiple data centers
    PKWARE® Solution
  • PKZIP® for z/OS® Enterprise Edition
    Results
  • Increased operational efficiency; reduced file size up to 98% to speed up data transfer processes
  • Completed transmissions within allotted window; automatically translated from ASCII to EBCDIC during decompression and extraction processes

Company Background

Our client is an IT services consulting firm and leading provider of solutions that enable companies to maximize their use of advanced technology. The firm assisted a government agency in selecting software and oversaw their ability to process information more quickly and easily, in an effort to increase operational efficiencies.

Challenges and Requirements

The volume of data being handled by the government agency’s operating system is immense. In addition to managing over six million claims per week, the agency also keeps two years of claim details in an active database. Maintaining these active claims allows for evaluation and validation of new claims within seconds.

The three-terabyte DB2 mainframe database application feeds into a data warehouse critical to the overall operations of the organization. Monthly and weekly updates from the central data warehouse are distributed to data marts maintained on-site at five remote locations. The source data for each data mart update is moved from the database and into the z/OS environment for transmission management.

Each update can fill as many as four 20-gigabyte IBM® 3590 tape cartridges. That data must be transmitted via FTP within a 12-hour operational window. Even with high speed OC3 connections, transmitting as much as 80 gigabytes of data to each of the five endpoints within the required time frame proved impossible.

The Solution - PKZIP Enterprise Edition

The consulting firm turned to PKZIP for z/OS Enterprise Edition to compress data before distributing it to the various data marts. The agency’s update application now takes the data written to tape cartridges and compresses them with PKZIP before transmission. Ultimately, the consulting firm chose PKZIP because of the outstanding results it delivered when used in other projects.

The agency also incorporates critical information from third party providers. An update from a provider frequently includes as many as 160 files compressed and contained in a single ZIP archive each month. This is then written to CD and sent to the consulting firm. There, the ZIP archive is transferred to the mainframe where PKZIP automatically translates the data format from ASCII to EBCDIC during the decompression and extraction process.

“PKZIP compresses the data at least 75% and frequently as high as 90-95%,” according to an Operations Analyst. “Consequently, data mart updates that may have been as large as 80 gigabytes are compressed to as little as 4 gigabytes. We wouldn’t be able to complete transmissions within the operational window without the use of PKZIP. It works with the original ASCII-oriented file names and renames them to a Data Set Name (DSN) appropriate for the mainframe during extraction - it has good flexibility.”


IT Services Provider #2

    Customer
  • IT Services Provider #2
    Industry
  • IT Services
    Customer Profile
  • Provides mailing solutions and helps companies manage their mailing requirements
    Challenges
  • Secure data transfer via portable media (tape)
  • PCI compliance imposed by credit card processing partners
    PKWARE® Solution
  • SecureZIP® for z/OS®
    Results
  • Met PCI compliance requirements
  • Ensured secure transfer of information via tape and/or FTP

Company Background

Our client is an IT services company providing comprehensive mailing solutions to help companies manage their mailing requirements. Their services integrate software, hardware, and communication, offering a full-service solution to help customers with their mailing needs.

Challenges and Requirements

The company handles the printing, fulfillment, and shipping of credit card billing for a large chain of retail department stores. The customer information required to generate bills was being sent via tape through standard, unsecured FTP from the retailer’s z/OS mainframe to the company’s UNIX® server.

The retailer began using SecureZIP to encrypt their sensitive data both at rest and in transit. Although their original reason for purchasing SecureZIP was to comply with PCI mandates imposed by their credit card processing partners, they soon recognized the value in extending SecureZIP to other areas. The IT services company was one of the partners the retailer engaged to use SecureZIP in order to secure data transmissions wherever possible.

The Solution - SecureZIP

The IT services company looked into implementing SecureZIP in their environment. After evaluating both SecureZIP and their data transfer process, they decided to purchase SecureZIP for their z/OS mainframe so communications with their retailer partner would be secure whether the data was transferred via FTP or tape.

After implementing SecureZIP, the company was able to secure data transfer via portable media and also met PCI requirements that were being imposed by credit card processing partners of some of their largest clients.




IT Services Provider #3

    Customer
  • IT Services Provider #3
    Industry
  • IT Services
    Customer Profile
  • World Leader in collection and distribution of airline fare data
    Challenges
  • Securing the exchange of data between multiple endpoints
  • Cross-Platform compatibility
  • Maintaining transfer times using data compression
    PKWARE® Solution
  • SecureZIP® for z/OS®
    Results
  • Ability to securely exchange data between multiple endpoints
  • Fast deployment which required no additional training of employees or business partners

Company Background

Our client is a world leader in the collection and distribution of airline fare and fare-related data. The company acts as a data clearing house and processing agent serving more than 500 carriers. They collect and process data relating to flight reservations and purchase transactions. This information is then passed back to global distribution systems and computer reservation systems, providing a single source of fare related data.

Challenges and Requirements

The company processes up to 1 million fare changes daily using a variety of delivery mechanisms ranging from ad hoc transfer to automated batch transfer. They also receive data from business partners via FTP. They needed a solution that would work seamlessly with all operating environments and add security to their operations, while retaining transfer times and the simplicity of transfers from their mainframe data center.

The Solution - SecureZIP

PKWARE was the only provider that could meet all of the company’s needs, including cross-platform compatibility, easy exchange of secure information with business partners, and the ability to deploy a solution without requiring extensive training of employees or partners. The company also maintained transfer times using data compression and was able to deploy SecureZIP in a couple of hours without a change to operations and without requiring training for employees or business partners.




Success Story

Leading IT Services Provider Protects Sensitive Information without Sacrificing Operational Efficiencies

    Industry
  • IT Services
    Customer Profile
  • Provides information processing and computer software services to a wide variety of service industries
    Challenges
  • Protecting sensitive data being sent via tape without sacrificing operational efficiencies
  • Securely exchanging information with external business partners across multiple operating platforms
  • Meeting data security compliance standards and requirements, including PCI DSS
    PKWARE® Solution
  • SecureZIP® for z/OS®
  • SecureZIP® for Windows® desktop
  • SecureZIP® for i5/OS®
  • SecureZIP® for UNIX® server
    Results
  • Secured sensitive data exchanged with external business partners across multiple operating platforms
  • Increased operational efficiencies by compressing and encrypting data for secure exchange
  • Immediate deployment of a fully functional solution across multiple operating systems within the organization

Company Background

Our client is a global provider of sophisticated information processing and computer software services and products to the financial services, communication, healthcare, and other major service industries.

Challenges and Requirements

The company exchanges sensitive financial information with their business partners, representing some of the largest mutual fund companies in the world. The majority of this information is sent via tape from the company’s mainframe to business partners. Our client specifically wanted to use key encryption at the X.509 standard to protect the sensitive information being exchanged.

The ability to deploy a security solution quickly and easily was a top concern--the need to protect tapes being sent to external business partners had become a number one priority. In addition, the company was looking for a solution that would securely transfer data and be compatible with all operating platforms.

Due to the financial data that the company handles, they were also facing the requirement of complying with PCI mandates.

The Solution - SecureZIP

When the company initially contacted PKWARE, they were only concerned with launching SecureZIP on their z/OS mainframe. However, after experiencing the scalability of the solution, the company decided to deploy SecureZIP on their i5/OS, UNIX server, and desktops running Windows. By purchasing SecureZIP for several operating platforms, they are able to use the solution as a standard within the company; or, they can also standardize the solution to specifically meet evolving business needs.

SecureZIP met all of the company’s needs, including the ability to encrypt sensitive data using the X.509 standard, allowing for the secure transfer of tapes with business partners. SecureZIP was launched throughout the organization and provided security across multiple operating platforms.

An unexpected added benefit the company received from their purchase of SecureZIP was that it helped differentiate them from their competition. SecureZIP could be extended to their business partners at no cost and still enable the secure exchange of data.

Success Stories

Leading IT Services Provider Secures External Data Exchange, Reduces Overall Data Center Costs

    Industry
  • IT Services
    Customer Profile
  • Provides resources to customers to help them succeed in the brokerage industry
    Challenges
  • Exchanging data securely with external business partners
  • Reducing data center costs and operational overhead; increasing operational efficiencies
    PKWARE® Solution
  • SecureZIP® for Windows® desktop Enterprise Edition
  • SecureZIP for z/OS® Enterprise Edition
  • SecureZIP PartnerLink™ for Windows® desktop
  • SecureZIP PartnerLink for z/OS®
    Results
  • Encrypted sensitive data to ensure it remains protected during transit, even if intercepted or received at the wrong endpoint
  • Increased operational efficiencies on the mainframe using application integration functionality

Company Background

Our client is one of the largest securities and data processing firms in the country. The company provides customers with the knowledge and tools needed to succeed in the brokerage industry, focusing specifically on computer processing expertise to provide practical solutions designed to fit customer needs.

Challenges and Requirements

In their current operating environment, the company was using a method of secure FTP to transfer information from the mainframes within their data center. They realized that data leaving their facility was vulnerable and could end up unprotected in the wrong location. Secure FTP did not provide the protection they needed.

The company went to work looking for a security solution that would ensure that data being transferred would remain protected while in transit and as it arrived at each respective endpoint. Information is sent out from the data center’s mainframes, as well as by employees within the organization from their desktops. Since our client is responsible for processing data for large global organizations, having unencrypted information intercepted in transit had the potential to create a great deal of damage for all parties involved.

In addition to a data encryption solution, the company was also looking for a way to provide strong security while also increasing operational efficiencies within the data center—ideally they wanted a solution that would not only provide them with encryption, but also a way that they could save time and resources while achieving that data security.

The Solution - SecureZIP Enterprise Edition & SecureZIP PartnerLink

The company realized that SecureZIP Enterprise Edition and SecureZIP PartnerLink would solve their security issues, and therefore purchased the product for their desktops and mainframes. This enabled them to send encrypted data to external customers from either operating platform, ensuring information remained protected at all times. Employees could encrypt data easily and exchange information securely from their desktops throughout the organization. The company brand was protected, as well as all data being sent from their organization to large business partners and internal resources alike.

The Application Integration feature of SecureZIP for z/OS® provided our client the ability to stream data directly into, or out of, a secure ZIP container, improving operating efficiencies within the data center while ensuring data remained protected, without ever staging it to disk. Extensive testing of this feature has shown elapsed processing times reduced by up to 600% and CPU clock times reduced by up to 60%.

IT Services Provider #6

    Customer
  • IT Services Provider #6
    Industry
  • IT Services Provider
    Customer Profile
  • One of the nations largest communications services providers
  • Provides cable television, high-speed Internet, and voice & long-distance telephone services
  • Over 6 million customers and 22,000 employees across the United States
    Challenges
  • Moving very large files exceeding 4GB for month-end invoicing
  • Finding a solution that could be quickly and easily deployed to avoid loss of revenue
    PKWARE® Solution
  • SecureZIP® Enterprise Edition for IBM i®
    Results
  • Data is efficiently transferred for month-end invoicing, avoiding loss of corporate revenue
  • Personally Identifiable Information (PII) is now encrypted during transfer, protecting against loss or theft

Company Background

Our client is a full-service, facilities-based provider of communications solutions for commercial customers, with more than 6 million customers and over 22,000 employees. In addition to cable television, the company also provides high-speed Internet, voice and long distance services (including wireless services) over its own nationwide IP network, and data and video transport services for small- to large-sized businesses.

Challenges and Requirements

When our client approached us, they were currently using PKZIP to compress data for month-end invoicing. The amount of data being processed each month had grown to exceed the 4GB limit that their current PKZIP application could process. In order for the company to send out their monthly invoices and, in turn, generate revenue, they needed to find a new compression solution as soon as possible.

The Solution - SecureZIP Enterprise Edition

Our client had a compelling reason to purchase from PKWARE--to solve the immediate problem of compressing huge amounts of data. However, they discovered they could add security capabilities as well by using SecureZIP Enterprise Edition.

SecureZIP puts our client “ahead of the curve” in terms of encryption capabilities. In their current working environment, there are no regulations or official requirements regarding data security, but the company was eager to begin following a best business practice and protect their customer information. SecureZIP now compresses and encrypts data for month-end invoices that contain large amounts of Personally Identifiable Information (PII) including customer names, addresses, and phone numbers. The company not only solved the immediate problem, they also maximized ROI while increasing their role as a customer service leader by ensuring that all customer data is being handled as efficiently and securely as possible.




Manufacturer #1

    Customer
  • Manufacturer #1
    Industry
  • Consumer Electronics
    Customer Profile
  • Leading international supplier in consumer electronics industry
    Challenges
  • Finding a solution that provides digital signature capabilities
    PKWARE® Solution
  • SecureZIP® for i5/OS®
  • SecureZIP for Windows® desktop
    Results
  • Digital signature capabilities
  • Email integration in the desktop environment
  • Data encryption and added security

Company Background

Our client is a leading international supplier and value-added service provider in the consumer electronics industry. The company conducts business through subsidiaries and other markets in mobile and consumer electronics, domestically and internationally. They also function as an Original Equipment Manufacturer (OEM) supplier to a wide variety of customers, through several distinct distribution channels.

Challenges and Requirements

The company was moving to a paperless environment and needed to integrate digital signature capabilities into their processes in order to manage the receipt and approval of internal documents. Moving to a paperless environment primarily impacted data coming off their i5/OS machine. They had large spool files that needed to be reviewed, approved, and digitally signed-off on. They also required a solution for their Windows desktops in order to achieve a similar review and sign-off process.

The Solution - SecureZIP

The company was already familiar with PKWARE and was confident in our solutions as a result of our experience and longevity in the marketplace. Although the company’s primary need was digital signature capabilities, they also recognized the benefits of data encryption and the added security it would provide. The company purchased SecureZIP for Windows desktop and i5/OS midrange system.

The company leveraged Verisign as the certificate authority to facilitate digital signing at PKWARE’s recommendation. They also appreciated SecureZIP’s email integration capabilities provided in the desktop environment, and, most importantly, the ability to place many digitally signed files into a single secure container, in both the i5/OS and Windows desktop environments.




Manufacturer #2

    Customer
  • Manufacturer #2
    Industry
  • Manufacturing
    Customer Profile
  • Manufacturer of desktops, notebooks, PCs, displays, storage drives, and IT services
  • Largest PC manufacturer in China
    Challenges
  • Securely exchanging data with business partners, primarily an international shipping company
    PKWARE® Solution
  • SecureZIP® for UNIX® server
    Results
  • Ability to exchange information securely with business partners, as well as exchange information securely between operating systems on-site
  • Fast deployment with minimal interruption of current processes

Company Background

Our client's product line-up includes desktop and notebook PCs, displays, storage drives, and IT services. They are also one of the largest PC manufacturers in China. Although China remains the company's primary market, after a major acquisition, they become one of the top ten PC providers in the world.

When the shipping company began using SecureZIP in their environment to secure their data, they requested that their business partner purchase SecureZIP as well so the companies could enable secure data communication.

Challenges and Requirements

The company uses a leading international shipping company to send consumer purchases to the appropriate customer, requiring them to exchange personal customer information with the carrier. The data was sent between UNIX servers.

When the shipping company began using SecureZIP in their environment to secure their data, they requested that their business partner purchase SecureZIP as well so the companies could enable secure data communication.

The Solution - SecureZIP

The company quickly realized the value in securing all sensitive customer data being exchanged with business partners. SecureZIP is also quick to deploy and easy to use, resulting in minimal interruption of current processes. And, since SecureZIP is a cost-effective solution, the decision was an easy one. The two companies are now encrypting the data they exchange, ensuring sensitive customer information is protected throughout the entire exchange process.




Manufacturer #3

    Customer
  • Manufacturer #3
    Industry
  • Manufacturing/Consumer Goods
    Customer Profile
  • One of the world’s largest food and beverage companies
    Challenges
  • Finding a new data compression solution to replace WinZip®
  • Finding a solution that would grow and be compatible with future security needs
    PKWARE® Solution
  • PKZIP® for Windows® desktop
    Results
  • Simple, low-cost, flexible solution
  • Solution that will grow with the enterprise and allow for security upgrades
  • Policy Manager allows for control over which employees encrypt data

Company Background

Our client is one of the world’s largest food and beverage companies in the world. With factories or operations in almost every country, the company is a world leader in coffee distribution, and is also one of the world’s largest bottled water and baby food makers.

Challenges and Requirements

The company was using WinZip for desktop data compression, but when WinZip was acquired by Corel and began aggressively changing their licensing policies, they were forced to deal with increased, ongoing operational costs. As a direct result, they decided to look at alternative compression tools to replace WinZip on 140,000 desktops throughout the organization.

The company had an aggressive time window to implement an alternative compression tool, so they sought a solution that could be installed quickly. While compression was the current requirement, the company's security group was hoping for a solution that would be compatible with future security needs as well. Ideally, the chosen solution would even offer an upgrade path to security.

The Solution - PKZIP

The company evaluated PKZIP and Power Archiver. They ultimately chose PKZIP due to its low cost, flexibility, and simplicity of implementation. The ability to upgrade to enterprise data security via SecureZIP was a key driver. They also liked the policy manager functionality, which gives them a central tool for managing the solution, including which employees have the ability to encrypt data.




Manufacturer #4

    Customer
  • Manufacturer #4
    Industry
  • Consumer Goods
    Customer Profile
  • One of the nation’s largest manufacturers of trusted household brands
    Challenges
  • Strong encryption to protect sensitive information
  • Compliance with several government regulations
  • Cross-platform compatibility
    PKWARE® Solution
  • SecureZIP® for HP-UX® Server
  • SecureZIP for z/OS®
  • SecureZIP for Windows® desktop and server
    Results
  • Cost-effective cross-platform solution
  • Ability to encrypt sensitive information and send securely via email
  • Compression of email attachments to conserve bandwidth and storage space

Company Background

Our client is a consumer company with one of the largest and strongest portfolios of trusted household brands. The company is as strong internationally as it is domestically, with employees located in 81 countries.

Challenges and Requirements

The employee services division of the company manages all of the internal HR, payroll, training, and travel expense systems globally for all employees. Historically, the company outsourced some or all of its HR functions.

As increasingly more employee data was being sent to third-party providers, it became clear that a standard encryption solution was needed to protect sensitive information and ensure the company remained in compliance with various government regulations. However, many of the encryption solutions being used internally were not versatile enough to work across different computing platforms. These systems were also often incompatible with the wide variety of systems run by third-party vendors. The company needed a solution that was not proprietary to a single provider.

Competitive Landscape

The company’s information services division looked at several encryption solutions, including WinZip® and PGP®. They also researched best practices with Gartner analysts before deciding on SecureZIP. SecureZIP was the only solution that met all three of their primary requirements: 1) it provided industry-standard encryption; 2) it was a public standards-based solution; and 3) it was capable of being deployed across all required platforms (Windows, HP-UX, and IBM® zSeries®). SecureZIP also supported the company’s future aspirations of implementing PKI because it supports certificate-based encryption and digital signing.

The Solution - SecureZIP

SecureZIP has enabled the HR department to exchange encrypted email attachments with other departments, remote offices, and third-party providers quickly and easily. By adding SecureZIP to the server environment, PDF reports queried from the SAP database are now encrypted. An added benefit for the company is that SecureZIP also compresses attachments by up to 95 percent, conserving bandwidth and storage space. For special projects, such as mergers and acquisitions, when large volumes of employee data are exchanged, the company is now sending encrypted files, rather than copying the personal information of employees onto a CD to be hand-delivered. The new process is both more efficient and more secure.




Success Story

Manufacturer Meets SOX Requirements with Strong Encryption, while also Increasing Operational Efficiencies

    Industry
  • Manufacturing
    Customer Profile
  • Provider of industrial automation power control and information systems and services
    Challenges
  • Meeting data security compliance standards and requirements, including SOX
  • Reducing data center costs and operational overhead; finding a cost-effective solution
    PKWARE® Solution
  • SecureZIP® for z/OS®
    Results
  • Use of strong encryption met SOX compliance requirements
  • Increased operational efficiencies by conserving time and bandwidth and minimally impacting processing and system utilization

Company Background

Our client is a provider of industrial automation power, control, and information systems and services. The company operates domestically and internationally, including a Partner Network of thousands of regional and global specialists in distribution, system integration, and product referencing.

Challenges and Requirements

After conducting an internal audit, the company determined that they could be facing substantial fines for non-compliance with SOX requirements as a result of HR data that was being sent to a
third-party provider. The Personally Identifiable Information (PII) that required encryption was being sent to the provider from the company’s mainframe.

One of the company’s key requirements was the ability to add encryption without impacting other business processes and system utilization. The company was also concerned about the cost to upgrade their bandwidth to handle the new traffic. They estimated that this upgrade could cost as much as $24,000 more each month to conduct the nightly transfer of information.

The Solution - SecureZIP

Our client's goal was to research, implement, and test SecureZIP in their environment in one month. The company chose SecureZIP because of its cross-platform interoperability and because they could initiate it in both automated and interactive environments. SecureZIP provided the ability to securely transfer files from PCs to UNIX boxes to mainframes.

The company also selected SecureZIP because it offered the shortest time to implementation and the best system performance. Using SecureZIP, the company is able to provide strong encryption to meet SOX requirements while minimally impacting processing times through the use of data compression. SecureZIP enables them to send 9 DB files compressed from 1GB to 200MB nightly, saving both time and bandwidth.


Success Story

Leading Manufacturer Merges Compression and Encryption, Reducing File Transmission Time by 50%

    Industry
  • Manufacturing
    Customer Profile
  • One of the largest private forest landholders in North America
    Challenges
  • Reducing data center costs and operational overhead
  • Extending the useful life of the existing IT infrastructure
    PKWARE® Solution
  • SecureZIP® for i5/OS®
    Results
  • Improved operational efficiencies by merging compression and encryption, greatly reducing processing times
  • Overall, daily file transmission times were cut in half

Company Background

Our client is one of the largest private forest landholders in North America. The company owns or manages over 1 million acres of forestland and runs saw mills, molding, millwork, and window and fiber product factories. In addition, our client is also an electronic co-generation company.

Challenges and Requirements

The company runs its business applications on two iSeries machines. Backup requirements consist of daily object mirroring from the production box to the development machine for potential disaster recovery via FTP over a T1 line. Backup requirements also include nightly tape backups of sensitive employee data (Peronally Identifiable Information such as Social Security numbers, payroll information, etc.) for off-site storage. Processing times for backups was a continuous challenge for the company, and, as data volume increased, it was becoming more difficult to meet the times required for the processing window.

The Solution - SecureZIP

Our client needed a solution that would facilitate a more efficient backup process and protect confidential data. SecureZIP fit this need perfectly. Using SecureZIP, the company could merge encryption and compression into one process, keeping CPU consumption to a minimum. It enabled them to save iSeries data directly into a ZIP archive without creating SAVF files first, allowing them to connect to their development box over the network instead of via a T1 line.

SecureZIP’s unique ability to combine the compression, encryption, and SAVF file creation steps was vital in solving the company’s backup time crunch. Not only did using SecureZIP ensure their confidential data was protected, the compression feature meant there were smaller files to encrypt, speeding up distribution significantly. The company is now able to transmit files nightly via FTP from the production to development system in half the time the process previously took.

Retailer #1

    Customer
  • Retailer #1
    Industry
  • Retail
    Customer Profile
  • Leading auto parts retailer operating over 3,000 stores
    Challenges
  • PCI Compliance with an immediate deadline
  • Digital certificate and signature capabilities
    PKWARE® Solution
  • SecureZIP® for i5/OS®
    Results
  • Met deadline enforced by PCI (10-day deployment)
  • Able to encrypt using digital certificates and signatures

Company Background

Our client is a leader in the auto parts retail industry, operating more than 3,000 stores in the United States, Puerto Rico, and the Virgin Islands. In addition to retail stores, the retailer does business with commercial customers as well.

Challenges and Requirements

Transactional credit card data is collected on behalf of customers at the retail locations. The information is then sent to corporate headquarters for processing on their i5/OS midrange system. As a retailer, the company was required to meet PCI compliance requirements, with a rapidly approaching deadline.

Needing to implement a solution in 10 days, the retailer needed to quickly find and install a data security solution. They also wanted the ability to use an encryption product that could utilize digital certificates and signatures for authentication purposes.

The Solution - SecureZIP

SecureZIP allowed the retailer to compress their data while adding security to their existing processes. SecureZIP was also cost effective and could be purchased and implemented to meet their 10-day deployment time frame. Additionally, SecureZIP allowed the retailer to utilize digital certificates and signatures, enhancing and accelerating business growth.



Success Story

National Discount Retailer Meets Compliance Requirements, while Improving Operational Efficiencies by 75%

    Industry
  • Retail
    Customer Profile
  • One of the largest discount retailers in the United States
  • Over 175 locations
    Challenges
  • Meeting PCI DSS compliance requirements
  • Securely and efficiently transferring sensitive data across multiple computing platforms
    PKWARE® Solution
  • SecureZIP for z/OS
  • SecureZIP for UNIX Server
    Results
  • Increased operational efficiencies; reduced transfer times by 75%
  • Streamlined operations by seamlessly transferring data across multiple computing platforms
  • Exceeded PCI DSS compliance requirements

Company Background

Our client is a national retailer with more than 175 locations across the United States. They are committed to providing their customers with high quality merchandise at competitively low prices. Their extensive selection of products, including groceries, electronics, apparel, and accessories, as well as health and beauty items, ensures a one-stop shopping experience for their customers.

The retailer experienced a breach in security involving credit and debit card information. Affecting thousands of transactions. The breach raised questions about the company’s ability to protect confidential customer information. After assessing the problem, the Federal Trade Commission (FTC) determined that the retailer’s security measures were not adequate. The FTC advised the company to implement a data security solution that complied with the Payment Card Industry Data Security Standard (PCI DSS).

Challenges and Requirements

Each day, stores in the retail chain send purchase transactions from the past 24 hours to a DB2 database on the z/OS mainframe located at corporate headquarters. The transaction data for each 24-hour period is put into batch files and encrypted. It remains in storage for a number of days until all transactions are closed. Once closed, the batch files are sent to an AIX server, where the information is decrypted and stripped of all sensitive customer data. The sensitive data is then deleted and the remaining non-sensitive data is moved to an Oracle data warehouse for storage.

To evaluate its data security needs and advise the company on its purchase, the retailer engaged a consulting firm and the expertise of a supply chain analyst.

Competitive Landscape

The retailer was advised to compare SecureZIP and PGP® . A detailed comparison showed that PGP was unable to work across all computing platforms within the retailer’s environment. And while PGP was able to encrypt files, it could not provide the file management capabilities the retailer required (e.g., recognition of file attributes, EBCDIC/ASCII conversion).

In addition, although PGP does compress data, its compression format is not based on the .ZIP file format and therefore could only compress files up to 50%; consequently, SecureZIP could achieve a 98% compression rate.

After the detailed comparison was complete, the supply chain analyst termed SecureZIP the “slam dunk” solution. “SecureZIP is an elegant solution for the z/OS environment because it encrypts, compresses, and manages many kinds of files--all in a single application across many platforms. PGP cannot compete with the overall value and ease of PKWARE’s application.”

The Solution - SecureZIP

SecureZIP’s performance and reputation for helping organizations comply with PCI DSS assures potential users that their data will be protected in transit and in storage. In addition to securing data, SecureZIP effortlessly streamlined operations and increased the retailer’s productivity by:

  • Working seamlessly across platforms, including mainframe and midrange systems, servers, and desktops. In this case, SecureZIP easily transferred data from the z/OS mainframe to an IBM AIX server.
  • Compressing, encrypting, and providing file management in a single process, improving operational efficiencies and conserving valuable resources.
  • Simplifying operational procedures. SecureZIP supports both digital certificate- and passphrase-based encryption, while providing scalability to fit the organization’s infrastructure.
  • Dramatically accelerating processing time. Before purchasing SecureZIP, the retailer did not use a compression product. Using SecureZIP, they were able to reduce transfer time between its mainframe and servers by 75%.


  • As an overall assessment, the supply chain analyst told the retailer, “...that this was a slam dunk--SecureZIP was far and away the product that fit their need. It was going to deliver the security they needed, true enough, but as a solution its advantages extended beyond security. SecureZIP’s other features would vastly improve the client’s processing efficiency at a lower cost. At that point, the retailer hadn’t expected a security solution to accelerate productivity. But I knew that SecureZIP was going to boost processing efficiencies in a number of ways.”

Success Story

Leading Retailer Secures External Information Exchange, at No Cost to Business Partners

    Industry
  • Retail
    Customer Profile
  • One of the United State’s top 20 retailers
  • Over 850 locations nationwide
    Challenges
  • Securely exchanging data with external business partners
  • Meeting PCI DSS compliance requirements
    PKWARE® Solution
  • SecureZIP PartnerLink™ for z/OS®
    Results
  • Securely exchanged information with external business partners
  • Increased operational efficiencies within the data center
  • Achieved interoperability across all computing platforms within the organization

Company Background

Our client is one of the nation’s top 20 retailers, with over 850 locations.

Challenges and Requirements

The retailer was facing increasing pressure to comply with increased PCI DSS regulations, especially when exchanging information with business partners. The retailer recognized the need to find a data encryption solution—one that would conserve resources and allow them to create an archive directly out of an application, thereby significantly reducing file encryption, compression, and transfer time.

The Solution - SecureZIP PartnerLink

Although the retailer investigated other data security solutions, SecureZIP/PartnerLink quickly proved to be the solution to the retailer’s data security concerns—it was easy to use and support, and maintained superior functionality and encryption capabilities. PartnerLink, an extension of SecureZIP, also solved the issue of securely exchanging sensitive data with over 200 business partners.

PartnerLink extends the retailer’s security policies to external partners by complementing existing infrastructures and security environments, making bidirectional exchange of data an easy task. PartnerLink is provided to business partners at no cost.

The Application Integration feature of SecureZIP provided the retailer the ability to stream data directly into, or out of, a secure Zip container, improving operating efficiencies and ensuring data remained protected, without ever staging it to disk. Application Integration ensured that the retailer would no longer have to risk writing data to temporary files for exchange, providing increased compliance with PCI DSS mandates. SecureZIP also dramatically increased operational efficiencies- -testing of SecureZIP has shown elapsed processing times reduced by up to 90% and CPU second utilization reduced by up to 60%.

SecureZIP's performance and reputation for helping organizations comply with PCI DSS assures potential users that their data will be protected in transit and in storage. In addition to securing data, SecureZIP effortlessly streamlines and increases productivity. SecureZIP also works seamlessly across platforms, including mainframes and midrange systems, servers, and desktops. It also simplifies operations procedures by supporting both PKI and non-PKI implementations, while providing scalability to fit the organization’s infrastructure.

Success Story

Leading International Retailer Meets Multiple Data Security Compliance Requirements with a Single Solution

    Industry
  • Retail
    Customer Profile
  • Leading international specialty retailer offering clothing, accessories, and personal care products
  • Operates over 3,000 stores and outlets globally
    Challenges
  • Meeting data security compliance standards and requirements, including PCI DSS & California Information Practices Bill
  • Extending the useful life of the existing IT infrastructure; adopt to rapidly changing environments
    PKWARE® Solution
  • SecureZIP® for z/OS®
  • SecureZIP for UNIX® server
  • SecureZIP for Windows® desktop
    Results
  • Met PCI DSS and California Information Practices Bill compliance requirements, as well as others including HIPAA
  • Flexible solution that incorporated the anticipated implementation of a PKI environment

Company Background

Our client is a leading international specialty retailer offering clothing, accessories, and personal care products for men, women, and children. Operating under the retailer are multiple brand names with over 3,000 stores and outlets globally.

Challenges and Requirements

Our client anticipated being affected by a variety of compliance initiatives, including PCI and private state laws that require companies to disclose any security breach to those affected by it. Wanting to avoid a breach and the negative publicity associated with it, the retailer took a proactive approach to data security and began planning, researching, and budgeting a security initiative a year in advance.

The retailer recognized that their primary challenge was to secure their outbound financial and customer data. This data originated on their z/OS machines, UNIX servers, and desktops, so they needed a multi-platform solution that would support all of their computing environments. They needed a solution that was scalable, able to adapt to changing environments and compliance mandates, and had a strong presence in the marketplace. Overall, they wanted a long-term solution that would grow with their organization and meet both current and future security requirements.

Competitive Landscape

The retailer had PGP® installed on about 10% of their servers, but had experienced issues associated with cost and licensing complexity. In addition to PGP, they considered a wide variety of security solutions, including MegaCrypt, IBM MQ, SSL, SMIME/SecureContent/Via Seal, and EFS.

The Solution - SecureZIP

The retailer chose SecureZIP, a data-centric solution, because it met all of their requirements. They were also very familiar with RSA and their relationship with PKWARE. The retailer implemented SecureZIP for z/OS, UNIX Server, and Windows desktop. The retailer liked the scalability and flexibility SecureZIP offered their multi-platform enterprise. SecureZIP provided a solution that could incorporate their anticipated implementation of a PKI environment, making SecureZIP’s support for public key encryption extremely valuable. In addition to using SecureZIP for their business data, they recognized that they could use SecureZIP for other data security requirements including securing HR information to meet HIPAA compliance.

Retailer #5

    Customer
  • Retailer #5
    Industry
  • Retail
    Customer Profile
  • Chain of retail drug stores providing pharmacy services with over 1000 stores
    Challenges
  • Securely exchanging data between multiple servers
  • Finding a solution compatible with current software applications
    PKWARE® Solution
  • SecureZIP® for Windows® server
    Results
  • Interoperability with current software applications
  • Ability to transition to digital certificate-based encryption

Company Background

Our client is a licensor of over 1,000 full-service retail drug stores. The retail locations provide prescription pharmacy services, over-the-counter medications, health and beauty aids, cosmetics, and other everyday household products.

Challenges and Requirements

The retailer recognized the need to encrypt sensitive customer cardholder data and employee information, securing that data at rest and in transit between their three Windows servers. They formed a security review committee to investigate the data security options available. Current users of XCEED Zip for their compression needs, it was critical that their choice be compatible with the current software. Additionally, the new product needed to work across all operating platforms.

The Solution - SecureZIP

Due to the interoperability, flexibility, and multi-platform offerings PKWARE solutions provide, SecureZIP came across as the clear choice for the retailer. SecureZIP offered the interoperability they were looking for, seamlessly integrating with XCEED Zip.

SecureZIP’s ability to use AES or 3DES encryption also contributed to the decision. Currently, the retailer uses passphrase-based encryption; however, they have been looking into using digital certificate-based encryption. They were pleased that SecureZIP granted them a long-term solution, allowing the ability to begin utilizing both options when needed, without having to purchase additional software or alter current applications.

Overall, SecureZIP exceeded the retailer’s expectations, providing them with a data security solution that not only offered the flexibility and interoperability they were looking for, but also supplies options for future data security advancements.


Retailer #6

    Customer
  • Retailer #6
    Industry
  • Retail
    Customer Profile
  • One of America’s largest retailers with over 1,000 locations in the United States and Puerto Rico
    Challenges
  • Secure sensitive data, including customer information
    PKWARE® Solution
  • PKZIP® & SecureZIP® for Windows® desktop
  • PKZIP® & SecureZIP® for Windows server
    Results
  • Met the needs for file storage expansion, compression, and security
  • Allowed for future security upgrades
  • Satisfied PCI compliance requirements

Company Background

Our client is one of America’s largest retailers, operating over 1,000 locations in the United States and Puerto Rico. The retailer also provides one of the largest apparel and home furnishing sites on the Internet and operates one of the nation’s largest general merchandise catalog businesses.

Challenges and Requirements

The retailer was in need of additional space to store inventory information and customer transactions, as well as employee and customer data. This data is sent from regional store servers to a mainframe at their corporate headquarters. Data is then sent back to the store servers prior to the start of the next business day.

The retailer also wanted to secure sensitive data being sent via email from various desktops in the organization. The retailer required a solution that would provide increased storage capacity for information on store servers. They also needed to ensure desktop files were encrypted to protect sensitive customer data being exchanged internally and externally via email. Like most retailers, our client was very cost-conscious and therefore needed a solution that would meet their security needs and be relatively inexpensive.

Due to the interoperability, ease of implementation, and multi-platform offerings PKWARE solutions provided, the retailer chose a combination of PKZIP and SecureZIP for their operating environment. The first priority was to upgrade store servers to the most recent version of PKZIP so the company could process over 4 gigabytes of information. The retailer also decided to upgrade 10,000 desktops at their corporate headquarters to SecureZIP.

Competitive Landscape

While searching for the right product to support their upgraded servers and encrypt sensitive data, the retailer considered the WinZip® Command Line, but chose PKWARE solutions because they offered more robust functionality at a better price.

The Solution - SecureZIP and PKZIP

Overall, PKWARE met the retailer’s need for file storage expansion, data compression and encryption, security, and cost-effectiveness. PKWARE solutions also offered the opportunity for future upgrades. Our client was in vendor-consolidation mode and PKWARE’s ability to offer comprehensive solutions on all major platforms provided increased cost savings and convenience.

By selecting SecureZIP, the retailer also satisfied PCI Compliance requirements.


Retailer #7

    Customer
  • Retailer #7
    Industry
  • Retail
    Customer Profile
  • One of the largest department stores in the world, with over 850 stores
    Challenges
  • Finding a data encryption solution that would work internally and externally with business partners
  • PCI compliance
    PKWARE® Solution
  • SecureZIP® / PartnerLink for z/OS®
    Results
  • Ability to exchange information securely with business partners
  • Application Integration improved operating efficiencies and ensured data remained protected without having to stage it to disk
  • Reduced processing times by up to 90%

Company Background

Our client operates a chain of premier department stores, operating over 850 stores throughout the world.

Challenges and Requirements

After several data breaches were discussed in the news, the retailer recognized the need to find a data encryption solution. They immediately chose SecureZIP, as it was easy to use and support and maintained superior functionality and encryption capabilities. They also recognized the value SecureZIP could provide as they transferred data to their other business partners.

The retailer was also facing stringent PCI requirements. Looking specifically at encryption methods for their billing processes, the retailer wanted to conserve resources, a solution that would allow them to create an archive directly out of an application, thereby significantly reducing file encryption, compression, and transfer time.

In addition, the retailer needed a solution that would allow them to exchange information securely with over 200 business partners ranging from small private organizations to large enterprises.

The Solution - SecureZIP Enterprise Edition / PartnerLink

PKWARE engineering and support teams quickly identified SecureZIP Enterprise Edition as the perfect solution. The retailer tested SecureZIP Enterprise Edition and determined the software met and exceeded their requirements.

The Application Integration feature provides the ability for the retailer to stream data directly into, or out of, a secure Zip container, improving operating efficiencies and ensuring data remains protected, without ever staging it to disk. This feature, along with PKWARE’s world-class technical support and rapid deployment, made SecureZIP the only choice for this retailer.


Consulting Services #1

    Customer
  • Retailer #8
    Industry
  • Consulting Services
    Customer Profile
  • Provides human resources and consulting services to more than 3,000 large and mid-size companies worldwide
    Challenges
  • Securing sensitive data, including PII (Personally Identifiable Information) in transit
  • Mitigating risk associated with transferring PII
  • Incorporating a security solution that would provide control over sensitive data throughout the organization
    PKWARE® Solution
    Results
  • Sensitive data, including PII, is now protected as it is exchanged with business partners and clients
  • Mitigated risk associated with transmitting PII while also providing a solution that was trusted amongst business partners
  • Contingency key ensured the organization maintained control over data being encrypted by employees

Company Background

Our client provides human resources and consulting services for more than 3,000 large and midsize companies across the globe. They work with clients to develop and implement HR business strategies covering the following areas: retirement, financial, and health management; compensation and total rewards; and performance, talent, and change management.

Challenges and Requirements

Working as a human resources consulting firm, our client is in possession of large amounts of PII (Personally Identifiable Information) such as names, addresses, social security numbers, etc. Several clients and business partners requested that data be sent in an encrypted format to protect it while in transit. At the time, the company did not have a security policy in place and knew that it was necessary in order to continue to protect PII and maintain a trusted relationship with business partners and clients.

When the company contacted PKWARE, they were looking for a solution that would first and foremost secure data in transit and mitigate the risk associated with transmitting PII. They were committed to implementing a process that would improve their approach to data security and ensure that trusted relationships were established with all clients and business partners.

Another critical factor for our client was implementing a security solution that would provide control over the data being transmitted and encrypted throughout the organization. With offices around the world, it was necessary to be able to access data at any time.

The Solution - PKZIP for i5/OS

The company decided that SecureZIP for Windows desktop met all of their security requirements and could be quickly and easily deployed on their 27,000 desktops. SecureZIP allows documents containing PII to be encrypted and then sent to various clients, simultaneously establishing trusted relationships and mitigating risk.

When end-users are given the ability to encrypt sensitive data, it must remain accessible to the organization at all times. SecureZIPs contingency key feature allows the company to access encrypted data at any time for audit or data recovery purposes.

As a former PKZIP user, our client had experience with the reliability of PKWARE products. Not only was the company able to completely deploy SecureZIP within their required timeframe, but they were also impressed with the fact that deployment did not disrupt exciting processes and workflows.

Success Story

Consulting Firm Reduces Operational Overhead, Replaces Four Individual Products with a Single Solution

    Industry
  • Consulting Services
    Customer Profile
  • One of the world’s largest consulting services firms
  • Offers specialized expertise in the areas of compliance, risk, reputation, liability, performance, finance, and information
    Challenges
  • Standardizing the process for decompressing files from 14 different file types
  • Reducing operational overhead by finding a single solution to replace four applications currently in place
    PKWARE® Solution
  • PKZIP® Standard Toolkit
    Results
  • Data compressed using several different compression algorithms can now be decompressed with one product
  • Reduced operational overhead by replacing four individual products with a single solution

Company Background

Our client helps organizations confront critical legal, financial, and reputational issues. They offer specialized expertise in five separate areas that operate as a coordinated whole, including corporate finance, economic consulting, forensic and litigation consulting, strategic
communications, and technology. The company also provides investigative services to companies confronted with problems such as fraud in order to assist them in legal defense or pursuit of recoveries.

Challenges and Requirements

Our client was looking for a way to reduce operational overhead and standardize current decompression processes with a single solution. They sought an application that could be
embedded within an existing technology used by the organization.

The company did not have a standardized method of processing the multitude of file types they handle daily—totaling 14 different types. Using four separate products (Polarzip, Winrar, Omnizip, and Dynazip) to achieve a single task was proving to be time consuming and cumbersome. The company wanted to streamline their application and reduce overhead by finding a single solution to handle all of their file types, making their processing easier and more efficient.

The company also had other requirements that needed to be met by the chosen product, including the ability to:

  • Extract files from Zip, Rar, Tar, Gz, and Jar archives while preserving the original file paths
  • Correctly identify a corrupt archive file
  • Correctly identify an empty archive file
  • Correctly identify a password-protected archive file
  • Communicate when it can partially extract an archive because it has encountered archive corruption during extraction or long path exceptions while preserving folder structure
  • Extract an archive that contains Unicode in the folder path or file name
  • Preserve the last modified date after extraction if the archive preserved the last modified date of the compressed files


The company also had a list of additional benefits they felt would enhance the usability of the product, especially for future projects. These benefits included the ability to:

  • Extract files from Lzh and Lza archives while preserving original file paths
  • Communicate when it can partially extract an archive because it is out of storage space or part of a spanned volume
  • Run extraction for multiple archives in parallel
  • Return a list of extracted files and their paths
  • Preserve the creation date after extraction if the archive preserved the creation date of the compressed files

Competitive Landscape

In addition to PKZIP, the company also investigated 7-Zip as a possible solution. 7-Zip was not able to process all of the possible types of compressed files that our client receives and fell short on meeting the other requirements as well.

As an open source community, 7-Zip does not provide customer support. Since accessing data is critical to business, the need for technical/customer support was an obvious benefit to implementing PKZIP. Once again, PKZIP came out on top as a result of the customer service and technical support provided by PKWARE.

The Solution - PKZIP Standard Toolkit

Our client found that they could replace all four of their current products by implementing the PKZIP Standard Toolkit within their application. This solved their immediate need to find a single solution to replace the four currently in use. In addition, PKZIP met the technical requirements outlined at the onset of the project.

The flexibility of the PKZIP solution to fit into the company’s current and future technical requirements was another primary reason the product was selected. Not only would PKZIP meet the “must-have” requirements, it met all of the “nice to have” requirements for future projects.

Consulting Services #3

    Customer
  • Consulting Services #3
    Industry
  • Consulting Services
    Customer Profile
  • Consulting firm specializing in data and document conversions brought about by corporate acquisitions or hardware/software upgrades to newer technologies
  • Supports a global customer base in government, banking, insurance, banking, financial services, utilities, oil & gas, retail, and telecommunications
    Challenges
  • Securely transferring over 50 Terabytes of converted data to a major bank customer
    PKWARE® Solution
  • SecureZIP® Enterprise Edition for Server
    Results
  • Ability to quickly encrypt and securely transfer over 50 Terabytes of data to a prominent customer

Company Background

D3MC works extensively with various financial services organizations. One such organization hired D3MC to handle a project involving the consolidation of a Check Archive system from an acquired bank into their own. This project had to be finished in 6 months and involved a total of 150 Terabytes of data including 6.6 billion check images and 144 SQL databases. D3MC needed to convert these check images and index metadata into a new file format for delivery back to the customer for ingestion into their own Check Archive system.

Since the resulting 55 TB of converted data would contain sensitive financial information, as well as Personally Identifiable Information (PII) about the bank’s customers, it was imperative the data be encrypted before going back to the customer.

Competitive Landscape

During D3MC’s research process, they investigated both PGP® and WinZip® as potential solutions, but SecureZIP included more beneficial features and was more cost-effective. D3MC also needed a solution that would be configurable within their organization and be implemented quickly to begin handling large amounts of data. In addition, D3MC writes a lot of conversion software that is database driven - SecureZIP allowed them to update their database about the success or failure of the encryption process for each file.

The Solution - SecureZIP Enterprise Edition

All 150 TB of data was sent to D3MC on tape and moved from tape to disk for conversion. The data was then run through D3MC’s proprietary conversion process utilizing 25 of D3MC’s servers where it was transformed into a proprietary file format. All conversion work was done at D3MC’s secure facility in Houston, Texas and was performed only using D3MC’s hardware, proprietary software, and personnel. Neither the customer’s source nor target archive applications were required and the entire conversion process was performed using D3MC’s off-line process saving the customer money and time.

SecureZIP Enterprise Edition easily and efficiently met all of D3MC’s needs. D3MC was able to create a fully audited encryption solution utilizing SQL Server’s Integration Services. This allowed D3MC to have a completely audited conversion process. This solution queries the database, finds the files to be encrypted on disk and then encrypts them using SecureZIP. Encryption is performed on a file by file basis with each file about a half Gigabyte in size. In all, SecureZIP encrypted over 50 TB of information.

While SecureZIP encrypts massive amounts of information for D3MC, it also allows a database driven process to handle the encryption in order to monitor the encryption success and throughput rate. Using just 2 single Quad-Core servers to perform the file encryption using SecureZIP, D3MC was able to encrypt over 50 TB of data in just 2 weeks. D3MC is looking to expand their use of SecureZIP with additional clients and projects in the future.


Federal Government Agency #9

    Customer
  • Federal Government Agency #9
    Industry
  • United States Government
    Customer Profile
  • Established in 1966
  • One of the largest Medicare contractors in the country
    Challenges
  • Securely exchanging email with endpoints outside of the agency perimeter
  • Deploying a solution that would meet a host of compliance requirements
  • Finding a cost-effective solution that would fit within the budget and be easily and efficiently deployed
    PKWARE® Solution
  • SecureZIP® Enterprise Edition for Windows® desktop
    Results
  • Compliance with FIPS 140-2 allows the ability to encrypt email attachments exchanged with major business partners
  • Policy manager function allows administrators to define how users apply encryption
  • Contingency key allows the ability to centrally administer encryption policies throughout the organization

Company Background

Since 1966, our client has served as one of the largest Medicare contractors in the country, now serving over 200,000 providers and suppliers. Medicare coverage provided by the contractor is extended to more than 24.5 million people in 26 states and 5 U.S. territories. Our client has efficient operational, financial, and human resources across the United States, positioning them as a national leader in Medicare.

Challenges and Requirements

The contractor exchanges large amounts of PHI (Personal Health Information) with their major business partner. In the past, the partner maintained strict rules about securely exchanging documents between organizations; this required that all documents be sent via mail or courier. Recently, the partner announced that documents could be exchanged electronically via email attachment, if the attachments were encrypted using a FIPS 140-2 compliant security solution (the solution also needed to comply with HSPD-12 Government Mandate).

In addition to meeting business partner requirements for the secure exchange of email attachments, the contractor wanted to be able to set and apply encryption capabilities from one central location rather than dispersing the responsibility throughout the organization.

The contractor was already using WinZip® for desktop compression, but they recognized that it was not a viable option for data security because it did not offer strong encryption or administrative policy support for contingency keys. WinZip also could not meet several of the compliance requirements, specifically FIPS-140.

The Solution - SecureZIP Enterprise Edition for Windows desktop

SecureZIP offers our client strong data file encryption while meeting FIPS compliance requirements established by their business partner. This meets their initial goal of a security solution that allows them to begin exchanging documents electronically, saving both time and money throughout the organization.

Contingency key functionality ensures that data can be accessed at any time, even if a passphrase used for encryption is lost or stolen. The contractor can recover any data encrypted using SecureZIP, which is especially important in the instance of an agency audit.

Policy manager, another capability of SecureZIP, grants the contractor the ability to set security protocols so they automatically become part of the workflow. In some cases, users are unaware that files are being secured because SecureZIP works “in the background,” encrypting and decrypting files without requiring any user interaction. Using policy manager, administrators can centrally control encryption standards, configuring and securing protocols. Every time an employee or affiliate creates a SecureZIP file, the user is locked into encrypting the file according to the agency’s settings.

SecureZIP also provides a solution that is easy to use and deploy within the current work environment. Our client was pleased with how easily SecureZIP integrated with their Microsoft Outlook® email environment and that the solution was interoperable across all computing platforms within their organization.



Success Story

Retailer Improves Operational Efficiencies & Overall Cash Flow Using ZIP Compression

    Industry
  • Retail
    Customer Profile
  • Fortune 500 company providing various services to residential & commercial customers
  • Thousands of locations throughout the United States
    Challenges
  • Reducing data center costs and operational overhead associated with moving large quantities of data wirelessly
  • Increasing operational efficiencies by streamlining the ability to send route information to various service representatives
    PKWARE® Solution
  • PKZIP® for i5/OS®
    Results
  • Increased operational efficiencies by using ZIP compression to easily send infromation to portable handheld devices despite a small transfer pipe
  • Improved cash flow due to accelerated accounts receivable

Company Background

Our client is a Fortune 500 company that provides various services to residential and commercial customers through a network of thousands of locations and franchised licenses. Services of the company include lawn care services, pest control, home cleaning, and home inspection.

Challenges and Requirements

Our client performs services at various residential and commercial locations. Information pertaining to various service locations needs to be given to drivers before they can begin their route of services each day. Before contacting PKWARE, the company maintained large maps at each truck station that displayed all of the stops for each driver; they would gather the information they needed and independently run their daily routes.

A recent purchase of handheld devices now allows the company to electronically provide route information to its drivers. The use of these handheld devices maximizes efficiency, as a central corporate location can add, delete, and update routes as needed. While the addition of handheld scanning devices was going to help streamline operations, the company soon encountered problems efficiently moving large amounts of data from their central corporate location to the handheld units.

The Solution - PKZIP for i5/OS

Our client found that PKZIP for i5/OS solved the issues they were experiencing with moving large quantities of data. The data center sends information wirelessly to thousands of drivers who each have a handheld device. Due to the wireless transit of information, a lot of data is being sent over a small pipe – ZIP compression was able to solve the problem. Using PKZIP, the data center leverages the software on their AS/400 to compress the routes and stops for the various drivers. The zip files are sent wirelessly to the drivers who receive them on their handheld devices.

When in the field, various representatives can also send back information to the central data center. For example, one of the company’s franchises has over 800 field representatives that use the handheld devices across a three state region. A representative can gather information at a specific service call location and then send it back to the data center, compressed, where it can be uploaded to the AS/400, decompressed, and logged for future use.

Our client is seeing immediate positive results from implementing PKZIP. The process of sending route information to drivers has been streamlined, eliminating missed calls and allowing for cancellations to reach drivers with enough time to react and reorganize their routes. Ultimately, the use of PKZIP for i5/OS has maximized efficiency by allowing for more stops per day per driver. In addition, increasing the ease and speed with which information can be returned to the central location allows for faster billing, invoicing, and processing; this, combined with a reduction in error, has improved overall business and increased company profits.


Success Story

Consulting Firm Adds Strong Data Security, Conserves Valuable Data Center Resources

    Industry
  • Consulting Services
    Customer Profile
  • Provides consulting services in the areas of security, data center transformation and outsourcing, enduser outsourcing, and application modernization outsourcing
    Challenges
  • Protecting sensitive information sent from z/OS mainframe to various destination platforms
  • Protecting sensitive information placed on removable media, including CD
  • Ensuring data remains protected during all steps of the transfer process, including on originating and destination platforms
  • Meeting FIPS 140-2 compliance requirements
    PKWARE® Solution
  • SecureZIP® for z/OS®
    Results
  • Protected sensitive data by using strong encryption before transfer, ensuring it remains protected in transit and on the destination platform
  • Increased operational efficiencies by using ZIP compression to save wall clock time and CPU resources
  • Met FIPS 140-2 compliance requirements

Company Background

Our client is an IT services consulting firm and leading provider of solutions that enable companies to maximize their use of advanced technology. The firm assisted a government agency in selecting software and oversaw their ability to process information more quickly and easily, in an effort to increase operational efficiencies.

Challenges and Requirements

The firm’s z/OS mainframe (260 MIPS) is located at their data center in New Jersey; each night the company needs to put several files, each over 10 GB in size, on CD so they can be transferred to various Federal agencies. When the company first contacted PKWARE, they had two immediate needs: 1) to compress large files stored on CD that are sent each night to various Federal agencies; and 2) encrypt the information being transferred in compliance with FIPS 140-2 requirements.

In addition to their immediate needs, they were also hoping to benefit from a data security solution that would encrypt data at the source on the mainframe and be able to transfer it securely to end points such as Windows® desktops. They wanted to ensure the data remained protected during all steps of the transfer process, at rest on originating and destination platforms, as well as in transit.

The Solution - SecureZIP for z/OS

Our client’s data center managers and system programmers agreed that SecureZIP for z/OS would meet their immediate requirements, as well as provide a stable and easy-to-use solution to meet other organizational needs.

Using SecureZIP for z/OS, the firm was able to meet their immediate needs of large file support and complying with FIPS 140-2 requirements; but they were able to leverage the solution even further. Using SecureZIP for z/OS, our client has now streamlined their process for compression and sending large files, mitigating risks associated with client data breaches.

The data-centric security approach allows them to stream sensitive data freely within the organization as it is protected from the originating source, in transit, and remains protected when it reaches its destination. For example, information is now encrypted on the z/OS mainframe and can be sent to any destination platform (servers, desktop, etc.) where it remains encrypted until it is ready to be placed on CD. That information can also be easily transferred in an encrypted format to CD when needed, meaning at no time is data left vulnerable and unprotected. In addition, the use of efficient ZIP compression has increased the efficiency of daily processing, requiring less wall clock time and CPU utilization.


Success Story

One of the Largest U.S. Healthcare Providers Meets HIPAA Compliance Requirements, Improves Service Level Delivery

    Industry
  • Healthcare
    Customer Profile
  • One of the largest healthcare providers in the United States
    Challenges
  • Transmitting an increasing amount of data during nightly and monthly batch processing
  • Meeting data security standards and compliance requirements, specifically HIPAA compliance
  • Protecting sensitive information during movement or storage
    PKWARE® Solution
  • SecureZIP® for Windows® desktop Enterprise Edition
    Results
  • Transferred data efficiently during nightly and monthly batch processing
  • Protected sensitive data against loss and/or theft during transfer, using strong encryption
  • Met HIPAA compliance requirements

Company Background

Our client is a non-profit teaching hospital and regional referral center offering full-service hospitals as well as specialty medical and surgical care. The organization also consists of rehabilitation and psychiatric hospitals, as well as a Level II trauma center.

Challenges and Requirements

Each night, our client transfers large batches of Personally Identifiable Information (PII), including patient and procedure information, to partners such as collections companies, market research organizations, and government reporting agencies. When the organization approached PKWARE, they were using PKZIP to compress data for nightly and monthly batch processing; the amount of data being processed had grown considerably since the initial implementation of the product. As a result, they were looking to reduce AS/400 resource utilization and increase the speed of large file transfers.

In addition, recent highly publicized data breaches, as well as required compliance with the Health Insurance Portability and Accountability Act (HIPAA) and other regulations, prompted our client to begin their search for a data security solution that would protect patient and employee information being transferred.

The Solution - SecureZIP

Our client’s history with PKWARE and its products made the selection of SecureZIP an easy one. The product’s reliability and ease of use also played a large role in the organization’s decision. “We haven’t had a single problem with it,” said the organization’s AS/400 Operations Manager & Security Officer.

By leveraging the ZIP compression standard, SecureZIP allows our client to reduce the steps and complexity associated with data encryption by integrating directly into their current FTP process. Faster batch processing transfers to partners frees bandwidth and disk space. In addition, partner acceptance of ZIP as a standard, regardless of computing platform, emphasized the product’s ease of use and rapid adoption.

SecureZIP’s encryption capabilities helped the organization meet the compliance requirements outlined by HIPAA. Adding security to their data exchange processes protects our client’s reputation and brand, as well as ensuring they do not fall victim to a data breach similar to those recently publicized.

Using SecureZIP, the organization now automatically compresses and encrypts data for nightly and monthly batch processing; this provides the ability to compress multiple files at once and also provides end-to-end encryption of sensitive files. In addition, the organization not only solved their immediate requirements, but they also now have the ability to compress and encrypt their backup files for off-site storage, which lowers costs associated with media and expensive “white glove” transport methods.


Success Story

Federal Government Agency Adds Encryption to External Data Exchange without Compromising SLAs

    Industry
  • United States Government
    Customer Profile
  • Administers social insurance program for a national employment group
    Challenges
  • Exchanging data securely and costeffectively with outside partners
  • Meeting data security compliance standards and requirements, specifically FIPS 140-2 and OMB M-06-16
    PKWARE® Solution
  • SecureZIP PartnerLink
    Results
  • Ability to securely exchange data with
    an unlimited number of partners, at
    no cost to partners
  • Met compliance requirements for
    FIPS 140-2 and OMB M-06-16
  • Combination of compression and
    encryption allowed the addition of
    data security without compromising
    SLAs

Agency Background

Created in 1935, our client is an independent agency within the executive branch of the Federal Government. Their primary function is to administer a social insurance program for one of our nation's largest employment groups. Our client is headquartered in Chicago, IL with field offices throughout the country.

Challenges and Requirements

In 2009, our client underwent an IT security audit in support of established FISMA guidelines; they were cited for deficiencies in access controls surrounding IT security. Specifically, they were found deficient in not adequately encrypting sensitive Personally Identifiable Information (PII) and Personal Health Information (PHI). The Agency took a proactive stance and, not wanting to face a failing compliance grade or fall victim to a data breach, began researching data security solutions that best fit their agency's needs.

Due to the large amounts of PII and PHI that our client handles, they are required to comply with OMB M-06-16 and FIPS 140-2 requirements. It was critical to find a data security solution that could ensure they were in compliance with these initiatives. The Agency also exchanges sensitive information with their external partners, including numerous regional offices and State agencies. The data is placed on tape cartridges (up to 800 MB per tape) and sent, unencrypted, via courier to the off site locations. In addition, tapes are used for off site back-up storage; 24 TB of unencrypted mainframe data and 16 TB of unencrypted server data is stored.

Since our client works with several external partners, it was important to choose a data security solution that would promote secure data exchange with external partners in a cost-effective manner. The chosen solution needed to easily integrate into the Agency's current workflows and processes and also required the secure, efficient exchange of critical business information.

The Agency provided PKWARE an overview of the additional requirements they were seeking in an encryption solution, which included the ability to:

  • Encrypt data being pushed to tape and
    EFT on mainframe and AIX servers
  • Meet FIPS 140-2 and OMB M-06-16
    compliance requirements
  • Meet 508 compliance requirements (EIT
    Accessibility Certification)
  • Offer 24/7 technical support for the
    Agency and its partners
  • Support the secure bi-directional exchange of
    data with all trading partners
  • Support the ability to write/read from legacy
    magnetic tape cartridge formats to include
    3490/3590/3592

The Solution - SecureZIP PartnerLink

SecureZIP PartnerLink was the clear choice, meeting all of the Agency's requirements while also providing additional value not originally sought at the onset of the project. SecureZIP PartnerLink, which is deployed on the Agency's mainframe (SecureZIP is also deployed on several AIX servers), provided the lowest risk, highest performance, and easiest integration and support options for their existing infrastructure. Daily operations with partners were able to continue without interruption.

SecureZIP PartnerLink also allows the Agency to distribute an unlimited number of SecureZIP Partner licenses, at no cost, to their partners. Being a "no cost" solution furthered partner acceptance and eased the adoption process. Our client is now effectively protecting the data at the file level, making it impossible for anyone except authorized personnel to access it, whether the data on tape in transit via courier or in storage at an off site facility. And, they can extend their security policies, regardless of the number of endpoints or computer environments involved in the exchange.

In addition to meeting our client's critical need to securely exchange data with external partners, SecureZIP PartnerLink also met each of their other requirements. Due to its use of strong encryption and ability to run in "FIPS mode," SecureZIP PartnerLink ensured that compliance requirements with FIPS 140-2 and OMB M-06-16 were met. Also, because SecureZIP PartnerLink is transport independent, it is capable of sending encrypted data via Electronic File Transfer (EFT), as well as encrypting data onto mainframe tapes. Although the Agency is not currently using SecureZIP PartnerLink for EFT, it offers them a flexible solution that can grow with the organization's data management and security needs.

Due to the fact that our client's initiative was data security driven, they had concerns about what adding encryption would do to their SLAs. Traditionally, adding encryption to a data exchange or back-up process results in additional required time to write data to tape. However, because SecureZIP PartnerLink combines zip compression with strong encryption, they were able to reduce the size of files before encryption, ensuring they continued to meet their SLAs.

PKWARE also alleviated the Agency's concerns by ensuring they could not only receive 24/7 technical support, but professional expertise regarding industry best practices and how to best leverage SecureZIP PartnerLink within their mainframe environment. PKWARE assisted the Agency each step of the way through set-up, implementation, and ongoing support. Seen as an expert within the industry, PKWARE also provided on site personnel during implementation and assisted them in leveraging ICSF on the mainframe to further maximize their investment.

In the end, our client eliminated the exposure risk of sensitive personal information by implementing a solution that allowed them to securely exchange data with partners. Much like other major government agencies such as the Centers for Medicare and Medicaid (CMS), our client has been able to add strong data protection to daily operations and improve operational efficiencies without additional cost or overhead. Not only have they solved their initial problems and met immediate requirements, but SecureZIP PartnerLink provides the flexible solution that will continue to grow with their organization and address future issues without requiring other products, services, or vendors.

Success Story

Leading Financial Services Provider Protects Data Exchanged
with Multiple Endpoints, Secures Email Communication

    Industry
  • Banking & Financial Services
    Customer Profile
  • One of the world's largest financial institutions
    Challenges
  • Protecting sensitive data to meet PCI compliance requirements
  • Securely transferring data to multiple endpoints
  • Implementing and using Public Key Infrastructure (PKI) for secure email communication
    PKWARE® Solution
  • SecureZIP for UNIX Server
  • SecureZIP for z/OS
  • SecureZIP for Windows desktop
    Results
  • Protected sensitive data sent to multiple endpoints, including email communication via seamless integration with Microsoft Outlook
  • Met PCI DSS compliance requirements

Company Background

Our client is one of the world's largest financial institutions, providing individual consumers, small/ mid-market businesses, and large corporations a full range of banking, investing, asset management, and other financial and risk-management products and services.

Challenges and Requirements

The company needed to comply with the Payment Card Industry Data Security Standard (PCI DSS), which required them to protect credit card data as it is transmitted, processed, and/or stored, impacting several processes throughout their organization. Initially, the company set out to protect and store credit card dispute information for the PCI mandated minimum of 7 years.

This information was taking up space on their UNIX server, so the company wanted a solution that could both encrypt and compress the data. Every night, hundreds of thousands of settlement transactions containing confidential credit card information are sent to companies of all sizes. Without secure, dedicated lines set up for data transfer with smaller merchants, this confidential credit card data was sent via fax.

In an effort to secure this process, the company established an initiative to move all fax transmissions to email, electronically transferring encrypted data to multiple endpoints that would then have to decompress and decrypt the data after it was received. The data for these transactions originates on the company's z/OS mainframe and is then transferred to an internal server before it is sent externally to merchants. The company wanted a solution that would be easy to use and cost effective, especially for their business partners.

The Solution - SecureZIP (Multiple Computing Platforms)

As soon as the company purchased SecureZIP, they quickly realized the solution could work for additional security initiatives throughout the organization. They engaged PKWARE for assistance in achieving strong enterprise security across all major computing platforms.

The company wanted to use PKI to facilitate secure email communication both internally and externally with business partners. SecureZIP was the only solution that could provide the level of functionality, customization, and ease of use required. The company also incorporated the RSA Keon Certificate Authority product as well as the PKWARE ZIP reader to round out the solution.

SecureZIP provides seamless integration with the centralized directories containing digital certificates issued by RSA. This supported the requirement for processing secure transactions without slowing the delivery of reports to their partners. PKWARE's free ZIP reader extends the benefits of SecureZIP to the company's large network of partners without requiring them to purchase additional software. As a result, our client is able to securely communicate with, and send information to, its partners, regardless of the their computing environment or security infrastructure.

Success Story

Title Institute for Social and Economic Research secures sensitive research data while achieving compliance and reducing complexity

    Industry
  • Banking & Financial Services
    Customer Profile
  • One of the world's largest financial institutions
    Challenges
  • Protecting sensitive data to meet PCI compliance requirements
  • Securely transferring data to multiple endpoints
  • Implementing and using Public Key Infrastructure (PKI) for secure email communication
    PKWARE® Solution
  • SecureZIP for UNIX Server
  • SecureZIP for z/OS
  • SecureZIP for Windows desktop
    Results
  • Protected sensitive data sent to multiple endpoints, including email communication via seamless integration with Microsoft Outlook
  • Met PCI DSS compliance requirements

Overview

The Institute for Social and Economic Research (ISER) at the University of Essex specializes in the production and analysis of longitudinal data – evidence which tracks changes in the lives of the same people over time. ISER research makes a major contribution to the to the University of Essex’s top research ranking. Using longitudinal studies such as the British Household Panel Survey and its successor, Understanding Society, researchers at ISER focus primarily on the life-course of the individual and the changing nature of society. Their research makes a crucial contribution not just to the academic literature on these subjects, but to the decisions that are made by practitioners and policy makers around the world.

Business Goals

The ISER’s business goals are centered on securing sensitive research data. Understanding Society studies the socio-economic circumstances and attitudes of 100,000 individuals in 40,000 British households. The study also captures biomedical data on 20,000 participants and places it alongside rich social histories, helping weigh the extent to which peoples’ environment influences their health. Because of the sensitive nature of the data handled, security must be a part of the ISER business model. A breach or leakage of sensitive data would be disastrous to their reputation.

The ISER works closely with government departments who require compliance with FIPS 140-2. In addition, the ISER must comply with the Data Protection Act in Europe and the UK; however it didn’t want to compromise the productivity of its researchers and employees in the process of securing data to meet compliance.

Challenges

Sensitive Research Data Exposure
As the ISER prepares the raw data for release; they apply quality control measures and make the data anonymous. The UK Data Archive, the United Kingdom’s largest collection of digital research data in the social sciences and humanities, then distributes the data to the research community. While anonymity removes the risk of exposure in the main datasets that are distributed, the risk of exposure is higher in specialized datasets that are released under more stringent conditions. Over time, the ISER built a significant pool of respondents for Understanding Society who trusted them to use their information in a certain way. The reputation of the research was on the line. ISER needed to protect sensitive data from the outside.

Compliance
FIPS 140-2 requires government agencies and organizations that exchange sensitive information with those agencies use cryptographic-based security systems to protect sensitive information. The Data Protection Act has similar encryption requirements. Collaboration with government partners would cease if the ISER couldn’t prove FIPS compliance. ISER needed a solution that supports the various industry and government security regulations.

Complexity
The ISER researchers did not want their daily workflow to be disrupted by added encryption processes. In order to reduce complexity, any added security measures needed to be streamlined into the everyday workflow of ISER researchers and employees.

PKWARE Satisfies the Need

Secure Movement of Data
Data is securely shared within the ISER and externally with The UK Data Archive. With SecureZIP for Windows® Desktop, ISER researchers will be able to encrypt sensitive data saved on internal systems, and shared externally via email and portable media like USB drives. Strong encryption using X.509 digital certificates and/or passphrases allows the ISER flexibility in encryption options. SecureZIP provides an advantage to the ISER because it integrates into their policy framework. Administrators can easily set and enforce encryption use to align with internal governance.

Compliance
With SecureZIP, the ISER will be compliant with FIPS 140-2 and the Data Protection Act. SecureZIP strongly encrypts the data itself rather than the storage device so data remains protected even if placed on removable media that is lost or stolen during transit.

Streamlined Solution
SecureZIP was a straightforward solution. It was easy to standardize on SecureZIP as the encryption format for the movement of sensitive research data. Integration with Outlook® and Microsoft® Office helped to streamline the use of encryption. Researchers will be able to easily save documents containing sensitive data in alignment with ISER encryption requirements.

Results

The ISER will be able to tell their funders that they are using FIPS compliant encryption, making it easier to receive research grants. When the rollout to SecureZIP is complete, the ISER expects its researchers will easily be compliant with complex regulations that they may not necessarily understand because encryption functionality is integrated into the Microsoft Office tools they already use.

Resources » Datasheets
Security
State Government
  • State Government Agency Secures External Data Exchange at No Cost to Business Partners
    Read Story
    »
    View PDF »