Tech users are at serious risk when it comes to the digital society, according to the 2017 Thales Data Threat Report, Advanced Technology Edition published by Thales and analyst firm 451 Research. Based on a survey of over 1,100 senior security executives around the world, the new report on security best practices shows that awareness of the risks is progressively increasing. Importantly, the research suggests that growing numbers of adopters of advanced technologies are embracing encryption — an area where Thales's world leadership in data protection could prove critically important.
According to the report, 93% of respondents will use sensitive data in an advanced technology environments this year. These include cloud computing, Software as a Service (SaaS), the Internet of Things (IoT) and new developments such as container technology. A majority of those respondents (63%) also believe their organizations are deploying these technologies ahead of having appropriate data security solutions in place.
Fears about cloud decreasing, SaaS usage increasing
While concerns about data security in cloud environments remains high, they’ve dropped off since last year. In 2016, 70% of respondents voiced worries about security breaches from attacks targeting cloud service providers (CSPs); in 2017, 59% expressed fears. The second biggest concern, cited by 57% of respondents, is ‘shared infrastructure vulnerabilities’, followed by ‘lack of control over the location of data’ (55%). On the SaaS side, 57% of respondents report they are leveraging sensitive data in SaaS environments – up from 53% in 2016. When it comes to SaaS insecurities, respondents are most fearful about online storage (60%), online backup (56%), and online accounting (54%).
Most major cloud providers have larger staffs of highly trained security professionals than any enterprise, and their scalability and redundancy can provide protection from the kinds of DDOS attacks that can plague on-premises workloads," says Garrett Bekker, principal analyst for Information Security at 451 Research. "Perhaps as a result of the recognition of these public cloud security realities, security concerns overall for public cloud are waning.
Big data and IoT: big hype, big security threat?
Big data is a big topic of conversation – so it might be unsurprising to learn 47% of respondents are using sensitive data in big data environments. When it comes to security, respondents cite their top fear as ‘sensitive data everywhere’ (46%), followed by ‘security of reports’ (44%) and ‘privileged user access’ (36%).
IoT adoption is even higher, with 85% of respondents taking advantage of IoT technology and 31% using sensitive data within IoT environments. Despite IoT’s popularity, and despite the personal or critical nature of many IoT tools (medical and fitness devices; video cameras and security systems; power meters), only 32% of respondents report being ‘very concerned’ about their data. When pressed about their top fears, 36% of respondents cited ‘protecting the sensitive data IoT generates’, followed by ‘identifying sensitive data’ (30%) and ‘privacy concerns’ (25%).
Containers: the new (risky?) technology on the block
Although less than five years old, container environments have proven exceptionally popular. Eighty-seven percent of respondents have plans to use containers this year, with 40% already in production deployment. But similar to the emerging IoT environment (and owing to their relative immaturity), there remains a lack of enterprise-grade security controls in most container environments. Security is cited as the number one barrier to container adoption by 47%, followed by ‘unauthorized container access’ (43%), ‘malware spread between containers’ (39%), and ‘privacy violations resulting from shared resources (36%)’.
Encryption: the security strategy of choice for advanced technologies
While advanced technologies show great promise and business benefits, they are relatively young and in some cases, untested. Understanding this risk, respondents are gravitating towards a proven security control – encryption. According to the report, 60% of respondents would increase their cloud deployments if CSPs offered data encryption in the cloud with enterprise key control. Data encryption (56%) and digital birth certificates with encryption technology (55%) are also listed as the two most popular security options for IoT deployments. Rounding out the list is containers, with 54% of respondents citing encryption as the number one security control necessary for increasing container adoption.
The digital world we live in, which encompasses everything from cloud to big data and the IoT, demands an evolution of IT security measures," says Peter Galvin, VP of strategy, Thales e-Security. "The traditional methods aren’t robust enough to combat today’s complicated threat landscape. Fortunately, adopters of advanced technologies are getting the message – as evidenced by the number of respondents expressing an interest in or embracing encryption. Putting an ‘encrypt everything’ strategy into practice will go a very long way towards protecting these powerful, yet vulnerable, environments.
Organizations interested in both taking advantage of advanced technologies and keeping data secure should strongly consider:
Deploying security tool sets that offer services-based deployments, platforms and automation
Discovering and classifying the location of sensitive data within cloud, SaaS, big data, IoT and container environments
Leveraging encryption and Bring Your Own Key (BYOK) technologies for all advanced technologies