While encryption would have massively reduced the outcry over the HMRC data loss and the slew of others since, it comes with its own risks, warns data protection software firm nCipher.
Geoffrey Finlay, CEO of nCipher, makes the point that, although encryption is increasingly accessible – being embedded in trusted platform modules (TPMs) or bundled, as with Microsoft’s BitLocker – the problem is what happens if the keys that lock and unlock the data are lost.
“Encryption is a powerful tool, but getting it wrong can at best result in a false sense of security and, even worse, leave data scrambled for ever – the equivalent of a corporate document shredder,” says Finlay.
He suggests that with data protection stakes high, there should be a growing demand for secure and automated encryption key management to manage the rapidly growing number of keys across multiple applications and servers. “Large organisations may literally have millions of them,” he says.
“A well-planned deployment of encryption, supported by strong key management and access controls will eliminate further HMRC, DVA and Driving Standards Agency catastrophes, and result in better protected data that is available to the right people at the right time.
“The idea of end-to-end encryption may still be a long way off but cryptography is increasingly playing a vital role as the last line of defence. Encryption and key management is now a must for all organisations with sensitive data,” says Finlay.