85 percent of US organizations hit by one or more data breaches within the last twelve months

July 14, 2009 · Filed Under Security Software, Software News · Comment 

Latest Research from The Ponemon Institute Shows Data Protection is Part of Overall Enterprise Risk Management Strategy

PGP Corporation, a global leader in enterprise data protection, announced the results from The Ponemon Institute’s fourth annual study on encryption usage in the enterprise – The 2009 Annual Study: U.S. Enterprise Encryption Trends. This year’s study surveyed 997 IT and security practitioners and identifies the trends in enterprise encryption planning strategies, budgeting and spending, deployment methodologies and impact on data breach incidents. While 78 percent of organizations have an encryption strategy in place and are moving toward a more consistent approach to data protection, data breaches continue to rise across the board. 85 percent of survey respondents experienced at least one data breach in the last 12 months, consistent with 84 percent in 2008, and the number of companies experiencing more than 5 data breaches in one year rose to 22 percent, up from 13 percent last year. For the first time, fifty-eight percent of the respondents reported that data protection is a very important part of their overall risk management. Additionally, as organizations increasingly rely on mobile technology and PDAs as their primary computing platform, 26 percent indicate they encrypt a smartphone or PDA most of the time, 51 percent said they never do.

“In our fourth year of conducting this study, we are consistently breaking new ground in identifying new data protection trends to help enterprises as they assess their risk posture,” said Dr. Larry Ponemon, chairman and founder of The Ponemon Institute. “Organizations are looking for more complete solutions that can protect their data wherever it may reside. The focus for 2010 needs to be on applying a strategic approach to data security across the enterprise.”

The following list summarizes key findings from the study that included nearly 1000 U.S.-based enterprise IT leaders, analysts and executives:

  • Data protection is an important part of an organization’s risk management efforts. For the first time, Ponemon asked how data protection relates to an organization’s risk management efforts. Fifty-eight percent report that is a very important part of risk management and 22 percent say it is an important part.
  • Encryption of data on mobile data-bearing devices used by employees is very important or important. More than 59 percent of respondents say it is very important or important to encrypt employees’ mobile devices – a sign that organizations recognize that valuable data is more mobile than ever.
  • More than 70% have fully executed or just launched data encryption strategy in their organization. Once again data encryption strategies are being implemented across a majority of the respondent participants. The majority of organizations, 78 percent, have some type of encryption strategy, up from 74 percent in 2008 and from 66 percent in 2007.
  • Data Breaches continue to be a huge problem: Eighty-five percent of organizations surveyed had had at least 1 data breach in the last 12 months, demonstrating that there is no let up in breaches as this is consistent with 84 percent sited in the 2008 report. Companies suffering more than 5 data breaches rose to 22 percent in 2009 up from 13 percent in 2008.
  • Encryption is mostly used to mitigate data breaches and comply with privacy and data protection regulations. In addition, there was an increase in the percentage of respondents who reported that encryption is also important to preserving brand and reputation.
  • The percentage of organizations using the platform approach to managing encryption solutions has increased. Additionally, 76 percent would strongly recommend or recommend the platform-based approach if it reduced the cost of acquiring, deploying and managing encryption applications.

“This year’s research clearly demonstrates that compliance, breaches and brand damage are driving companies to deploy more data protection solutions,” said Phillip Dunkelberger, president and CEO of PGP Corporation. “The risk migration goal is clear; take a more strategic approach to protect your data – at rest, in motion and in use.”

The 2009 Annual Study: UK Enterprise Encryption Trends was released last week and reports in Germany and Australia will be released in the coming months.

For more information or to receive a copy of this study, visit: http://www.encryptionreports.com/

Source: PGP Corporation

Mobile Armor is Awarded the Highest FIPS 140-2 Validation for Security Software

April 18, 2009 · Filed Under Security Software, Software News · Comment 

Mobile Armor releases ground breaking cross platform validated Cryptographic Module for Data at Rest Encryption and Data Leakage Prevention

Mobile Armor, Inc., the leader in mobile data protection for the U.S. Government and recipient of the largest single award for Data at Rest Encryption, announces an update to its Federal Information Processing Standards (FIPS) 140-2 validation. Mobile Armor’s Cryptographic Module v3.5 has been validated at FIPS 140-2 Level 2 through the Cryptographic Module Validation Program (CMVP).

The CMVP is a cooperative partnership between the U.S. National Institute of Standards and Technology (NIST) and the Communications Security Establishment (CSE) of the Canadian government to ensure that sensitive information remains secure. The FIPS 140-2 validation assures that military, government agencies and commercial organizations are acquiring products that meet or exceed the stringent objectives set for securing confidential and sensitive data.

“Encryption of data on laptops, smartphones, USB keys and hard drives, where information is the most vulnerable, is essential to any organization’s data protection plan,” said Chand Vyas, Chairman and CEO at Mobile Armor. “Our Enterprise Mobile Data Security Platform continues to provide leading edge data security solutions for the Government, Healthcare, Financial Services, Education and any other type of organization or agency that handles sensitive data.”

This Mobile Armor release is a cross platform validated Cryptographic Module for Data at Rest Encryption and Data Leakage Prevention validated at Level 2 under the FIPS 140-2 certification. This specific validation is unique in its functionality of protecting cross platform clients and securing the Mobile Armor unified management platform, PolicyServer, with the same Level 2 module.

“The Mobile Armor Cryptographic Module v3.5 is a snap-in update to the existing Mobile Armor Data Protection Suite. With this modular ability, Mobile Armor is able to provide FIPS 140-2 Level 2 security across all of the Enterprise Mobile Data Security Platform,” Vyas added.

“Mobile Armor provides the highest level of cryptographic validations available in the Data at Rest protection market. Our comprehensive security management console is not only the most extensive in the market, supporting both hardware and software, but it also has the broadest support of client platforms including: Windows Vista, Windows XP, Windows Mobile, Linux, and Mac OS X. This new FIPS validation further reinforces Mobile Armor as the leading provider of mobile data protection,” said Mobile Armor CTO, Bryan Glancey.

Mobile Armor

Mobile Armor is an innovator and a visionary leader in data protection technology, headquartered in St. Louis, Missouri. Mobile Armor is an American company that provides domestically developed trusted data security solutions to commercial and government organizations. Notable customers include the U.S. Army, U.S. Navy, civilian agencies and customers in healthcare and financial services verticals. Mobile Armor offers a solution that provides centralized management of all mobile devices, including desktops, laptops, PDAs, smartphones, and removable drives (including thumb drives). The company is a recipient of the coveted DoD Data at Rest Tiger Team award for its data encryption products. Mobile Armor technology is certified to meet the standards and guidelines for security set by the National Institute of Standards and Technology (NIST). Additional information regarding Mobile Armor can be found at www.mobilearmor.com.

« Previous Page