Shadow AI is already using your data. Get the complimentary Gartner® report. Read the report

Smart Encryption Key Management

PKWARE

By PKWAREProductivity Protected

Share on social media

Recent high-profile data breaches have demonstrated beyond question that network and device protection is not enough. True information security requires persistent data-level protection, so that files and folders remain secure even after they leave a company’s systems. Although many security and IT professionals have known this for years, enterprise-wide data encryption remains the exception rather than the norm. Before strong encryption can come into widespread use, a new approach to key management is needed.

Three Unappealing Options

After a breach, one fact tends to surface: the compromised data was not protected by persistent encryption, so whoever took it can use it. The question is why any organization would leave data unencrypted, and the answer is that both established approaches create problems most would rather avoid.

Option One: Passphrases

Symmetric key encryption is the oldest form of data protection and still accounts for about 80 percent of the encryption in use. Organizations choose it because it is simpler to put in place and easier for people to understand.

It has two serious drawbacks. Key strength is one: users routinely believe they have created an unbreakable passphrase, and a brute-force attack finds it anyway. Lockout is the other. When someone applies their own encryption, they hold control of that data. The file is then inaccessible to auditors, to security staff, and to data loss prevention tooling unless the user shares the key, and an employee or contractor who leaves without handing it over can lock the company out of its own data permanently.

Option Two: Public Key Infrastructure

PKI is the stronger alternative and accounts for the other 20 percent. It protects well when used correctly, and few organizations have the resources to run it across an enterprise.

The difficulties compound. Users must establish an identity through a certificate authority before they can participate, and data cannot be encrypted for anyone who has not done so. Private keys have to exist on every device a user works from, and moving them there often means email or another insecure channel. Exchanging public keys is unfamiliar work for most people. Escrow is still required so that audits and data loss prevention scans can function, and it brings its own problem of working out which keys belong to which data. A compromised certificate can be revoked, which does nothing to stop someone who already holds the key from reading what they stole. And key rotation, which long-term security requires, means replacing keys across all protected data, a job that can run for weeks or months.

Option Three: Nothing

Faced with those two, most organizations end up where they started, with no company-wide data-level protection. That carries obvious financial and legal exposure, and it creates a second problem underneath. Without a consistent policy, employees encrypt sensitive files themselves, which blocks auditors and scanners and raises the same risk of the company losing access to its own data.

The Key Management Challenge

When organizations weigh passphrases against PKI, the comparison almost always reduces to one thing: managing the keys. It is the hardest part of encrypting at enterprise scale, and it covers generation, storage, exchange, and rotation. Reliable algorithms and hash functions have existed for decades. A good answer to key management has been much slower to arrive.

For a large, complex organization, the list of things key management has to handle is long. Private keys have to be created and synchronized to every authorized device. Public keys have to be created, synchronized, and exchanged. Data has to be encryptable for parties who have published no public key at all. Access to shared data has to be added and removed without re-encrypting the data itself. Administrative functions such as IT review, audit, and data loss prevention scanning have to keep working throughout. Keys have to be rotated to limit the damage from theft or compromise. And none of it can create obstacles for the people doing their jobs.

Neither passphrases nor PKI answers all of those, and some of them survive whichever route an organization takes. That gap is the likeliest explanation for why so many organizations run without data-level protection despite understanding the risk.

Why the Cost of Doing Nothing Looks Low

There is a quieter reason as well. Companies assign a value to every physical asset they own, from mainframes to laptops to phones, and their general ledgers carry no line at all for the value of the data held on them. That absence biases decisions. A company-wide encryption programme has a visible and certain cost, while the cost of going without is undefined and the chance of a breach is unknown, so the comparison is never made on equal terms.

In this whitepaper, you will learn more about:

  • Key management challenges
  • How to bridge the gap between passphrases and PKI
  • What a Smartkey is and how to implement it for maximum benefit

Download The Whitepaper

PKWARE

PKWARE

Productivity Protected

PKWARE has been securing sensitive data for over 40 years. We’ve earned the trust of 21 of the 25 largest banks in the U.S. Our team delivers modern, data-centric security solutions organizations can rely on.