sb-nz logo
Story image

Micro Focus: How to reduce the cost of data security

10 May 2019

No information technology process is free.

There is always a cost; if not to the service consumer, then most definitely to the service provider. Data protection in the form of either encryption or tokenisation is no exception.

When these technologies are added to an existing IT process, costs go up, according to Micro Focus.

These can be direct costs, in the form of acquiring more equipment or software licences or spending more on operational costs, such as power and staff.

Or the costs can be indirect, for example, taking more time to complete an IT process as data protection is CPU-intensive.

While each data protection operation takes microseconds, in a large organisation protecting petabytes of data, these all add up.

Micro Focus Australia and New Zealand enterprise security platforms director George Atrash says,  “The question then becomes how organisations can mitigate these direct and indirect costs. The answer is by reducing the number of times a data protection IT process needs to run.

“This can be done by protecting data at the application level, avoiding decryption when possible, and reducing the life cycle key management cost.”

One of the benefits of protecting data at the application level is protection can be applied only once. Persistent and pervasive data benefits most from application-level protection as the data need not be protected and re-identified when it moves throughout the enterprise.

This avoids security gaps, as well as the cost of repeated protect/unprotect cycles.

So, while application-level data protection may cost more during deployment, this method has lower operational cost.

Atrash says, “This means that one method of reducing cost and increasing overall system performance is avoiding unnecessary protection.

“The second method is to avoid unnecessary re-identification, decryption, or de-tokenisation whenever possible.”

Data protection is a function with an inverse: protect something and get exactly one unique output. Re-identify that output and always receive the original input.

The relational integrity is maintained and relational algebra on the protected data can be performed without spending the cost or time to first re-identify that data.

The ability to avoid re-identification can be taken further via the concept of partial protection.

Partial protection avoids the cost and increases performance beyond that of full protection by removing data sensitivity while still allowing more types of authorised use. 

The third method that can be used to reduce cost and increase performance is employing stateless key management.

Encryption requires the use of a security key for every different access policy.

And, there are often thousands of granular access policies running within an enterprise.

Stateless key managers generate encryption keys for authenticated users on demand.

If a user needs a key that protected data 10 years ago, a stateless key manager has no trouble delivering that key today.

And, stateless key managers do not have an upper limit on the number of keys that may be in use at any point in time.

If an enterprise needs 10 million keys to protect its Internet of Things, a stateless key manager can handle the load.

And a stateless key manager integrates with existing directory authentication services, avoiding the need for dedicated staff.

Atrash adds, “Organisations should keep in mind that judicious use of data security does reduce its cost and increase its performance.

"Avoiding re-identification, employing partial protection, and focusing on key management cost of ownership are long-term methods for efficient implementation of a data security practice.”

Story image
COVID-19-themed threats, Powershell malware continue surge
“The world—and enterprises—adjusted amidst pandemic restrictions and sustained remote work challenges, while security threats continued to evolve in complexity and increase in volume."More
Story image
AvePoint brings Salesforce Cloud Backup to channel partners
The product adds to the AvePoint suite of trusted Cloud Backup for Microsoft 365 and Dynamics 365 to provide managed service providers with backup and restore capabilities across multiple, popular SaaS providers.More
Story image
Imperva unveils new data security platform built for cloud
"The cloud has revolutionised IT, offering organisations a strategic opportunity to rapidly pursue new market initiatives and adapt their operations in the face of new business challenges."More
Story image
Kroll completes Redscan acquisition, expands cyber risk portfolio
With the addition of Redscan and its extended detection and response (XDR) enabled security operations centre (SOC) platform, Kroll expands its Kroll Responder capabilities to support a wider array of cloud and on-premise telemetry sources.More
Story image
Over a third of New Zealanders fell victim to cybercrime in the last year
"As we connected to the internet for everything from work and school to entertainment, social connection and even groceries, cybercriminals took advantage and launched coordinated attacks and convincing scams."More
Story image
Video: 10 Minute IT Jams - SonicWall VP on the cybersecurity lessons learned from the last 12 months
This is our seventh IT Jam with SonicWall, the cybersecurity company specialising in firewall, network security, cloud security and more.More