The
Rise of the Data Breach
Recent
analysis of data breaches shows that they
have become an epidemic - to the point where
the frequency and magnitude can be predicted
(see white paper on 'Data
Breach Prediction Analysis'):
- The chances of one
or more data breaches that expose 1M+ records
in the next year is a virtual certainty:
99.9999%
- We will likely see
1 or 2 data breaches in the next year that
expose 10M+ records – equivalent to 5%
of US adult population
- We will probably see
about 14 data breaches in the next year
that expose 1M+ records – 1 in 200 citizens
The big question is -
how can companies protect information about
customers and employees, and ensure, that
if it does fall into the hands of criminals
that no fraud can be committed.
How
to Reduce the Risks
The industry at large is
demanding end-to-end protection of data to
provide information security on a continuous
basis. Unfortunately, many encryption technologies
simply do not address the threat to data
over its full lifecycle. Data does not stay
at rest for long, so simply protecting the
containers or pipes leaves gaps that can
be and will be exploited.
Fortunately, Voltage Security
is replacing these outdated encryption approaches,
thereby enabling you - the global enterprise
- to protect information end-to-end across
any legacy or contemporary IT system, at
any scale, and with short implementation
at 1/5th of the time of alternative solutions
while also providing high value business
ROI of typically less than 12 months. Voltage
Security achieves these results with its
innovative technologies backed by over 25
years of cryptographic research - Identity-Based
Encryption™ and Format-Preserving Encryption™. |
|
|
New security to combat data protection risks
Organizations today have significant pressures
to safeguard their customers most sensitive data - the dangers
of identity theft, regulations such as PCI DSS (Payment Card
Industry Data Security Standard) or the new Identity Theft
Red Flags regulation, and development environments or outsourced
environments where customer identity data may be exposed.
Voltage SecureData™ enables companies to simply
and rapidly protect the data itself, without the need for major
changes to their applications, databases or business processes.
Based on a revolutionary technology called Format-Preserving
Encryption™ (FPE), Voltage SecureData encrypts data in databases
and applications while retaining the format of the original
structured information. FPE
is a mode of standard AES, recognized by NIST.
Standard encryption methods alter the original
format of data, producing a different output. For example –
a 16 digit credit card number encrypted with AES produces a
long alphanumeric string, with FPE mode AES- the encrypted
credit card number that looks and feels the same as a regular
credit card without sacrificing strength, and without any additional
data storage. By maintaining the format of the data being encrypted,
database schema changes are zero and application changes minimized
– in many cases 1-2 line of code total. This means that whole
systems can be rapidly protected in just days at significantly
reduced cost.

Using Format-Preserving Encryption (FPE),
Voltage SecureData maintains data format and eliminates
business process changes.
Protect your customers from Identity
Theft
By encrypting identity information such as credit card numbers,
bank account numbers, social security numbers with FPE, criminals
will be unable to compromise customer identities in the event
of a data breach
Fast compliance with PCI, Identity
Theft Red Flag and other regulations
By using the FPE approach with Voltage SecureData, it is possible
to rapidly enable compliance - in fact on average 5 times faster
than traditional techniques
Reduce risks with outsourced environments
By safeguarding your data with FPE and Voltage SecureData,
the risks of unintentional exposure of sensitive data is
dramatically reduced
Enable developer access to production
data
By masking or de-identifying your production data for use by
developers in test and QA environments, you ca continue to
get the best results from your developers without compromising
the safety of sensitive information
Voltage SecureData leverages FPE to deliver a comprehensive
solution for data protection that offers data de-identification,
data masking, and data redaction services that does not require
costly and time-consuming data schema and data format changes
in existing systems. Voltage SecureData enables enterprises
to ensure sensitive data is protected as it is collected, used,
stored, and distributed to less controlled environments (e.g.
test and development) regardless of infrastructure or application
format requirements. |
|