Company Profile
- Company
- Federal Government
- Size
- Federal
- Industry
- Government
A federal government organization moved from manually applied protection to automated discovery and protection, and reports saving 75 to 90 percent of the time that work previously took. The same range describes the improvement in its data security. Its requirements span personal data, confidential files and legal documents, each protected differently through access control, encryption or redaction.
Background
This case study of a federal government is based on a December 2020 survey of PKWARE customers by TechValidate, a third-party research service. The profiled organization asked to have their name blinded to protect their confidentiality.
The study is a December 2020 TechValidate survey and the organization is unnamed, which is ordinary for a public body discussing its security posture. The value of the format is that the compliance drivers and the use cases are the organization’s own answers rather than a vendor’s description of them.
Challenges
The cybersecurity needs that most influenced their decision to use PKWARE solutions:
- Automation
- Unauthorized file sharing or theft
- Viruses / spyware
The compliance measures that most influenced their decision to use PKWARE solutions:
- GDPR
- PCI / DSS
- CCPA / CPRA
- TISAX
With PKWARE’s data security technology, I have confidence that we are meeting our data compliance goals. Anonymous
The three needs listed are one problem seen from three angles. Unauthorized file sharing, malware and the absence of automation all describe data that is not tracked well enough to be controlled. A file nobody has classified cannot be governed by policy, cannot be reported on, and is indistinguishable from a file that does not matter. Automation is what makes that tracking continuous rather than a point-in-time exercise.
Our Approach
This company saved 75 – 90% of time by moving from manually applied protection to PKWARE’s automated discovery and protection solution.
Use Cases
The following data types are protected with PKWARE:
- Personal data (SSNs, race, religion, minors, etc.)
- Confidential files
- Legal documents (patents, trademarks, etc.)
Data uncovered by PKWARE’s data discovery is protected with:
- Access control
- Encrypting
- Redacting
PKWARE functionality for data security is used with these additional use cases:
- Secure email with partners and customers
- DLP enhancement
- Data redaction
Three remediation methods appear because the data types are genuinely different. Access control suits a confidential file that a defined group still needs to read. Encryption suits data in transit or at rest where the content must survive intact. Redaction suits a legal document that has to be shared in part. Choosing per data type, rather than applying one method everywhere, is what keeps protection from obstructing legitimate work.
TISAX is the unusual entry in the compliance list. It is an automotive-sector assessment for information security, so its presence indicates exchange with suppliers or partners who require it, and it is a useful reminder that obligations arrive through relationships as often as through jurisdiction.
Results
The company experienced these immediate benefits following the deployment of PKWARE:
- Located and classified sensitive data
- Met audit and compliance requirements
- Improved the efficiency of a business process
- Improved protection of critical information
- Satisfied customer and/or board mandates
- Increased their data security by 75 – 90% since implementing PKWARE technology
- Saved 75 – 90% of time by moving from manually applied protection to PKWARE’s automated discovery and protection solution
Satisfying customer and board mandates sits in the same list as meeting audit requirements, and the pairing is the point. An audit establishes a floor, while a mandate reflects what the organization has committed to above it. Automated discovery serves both, because it produces the same evidence either way.
