Protegrity Data Security Outlook Blog

Data Security Outlook Blog

Welcome to “Data Security Outlook,” the official Protegrity Blog


Insights from two recent conferences on data security

Posted by Ulf Mattsson, CTO on May 17, 2012

For those interested in new trends in data security breaches, new PCI DSS compliance guideline, and new cost-effective security approaches, there were great insights at the North American CACS ISACA Conference in Orlando on May 10, and at the ISACA Spring Conference 2012 in New York City on April 30th. Both the conference in Orlando Read more

Share

Posted in: Industry Events, Security Outlook

(0) Comments


Most breaches caused by a lack of data security, Verizon finds

Posted by Ulf Mattsson, CTO on April 13, 2012

The article, by Jaikumar Vijayan, appeared in Computerworld on April 9, 2012. It concluded despite rising concerns that cyber attacks are growing more and more sophisticated, hackers used relatively simple methods for 97% of data breaches in 2011, according to a report compiled by Verizon. The findings suggest that organizations are overlooking basic precautions even Read more

Share

Posted in: Breaches, Data Protection, Data Security, Security Outlook

(0) Comments


Global Payments has some explaining to do

Posted by Ulf Mattsson, CTO on April 3, 2012

I agree that “Global Payments has some explaining to do“. Global Payments said “Based on the forensic analysis to date, network monitoring and additional security measures, the company believes that this incident is contained.” I want to know what specific actions Global Payments took to improve security and how did they allow those safeguards to Read more

Share

Posted in: Breaches, Data Protection, Data Security, News & Resources, PCI DSS, Security Outlook, Tokenization

(0) Comments


Vaultless Tokenization reduces complexity

Posted by Raul Ortega, VP Chief Evangelist on March 1, 2012

Vaultless Tokenization continues to receive lots of attention from companies that have attempted to use vault-based tokenization and have failed. With Vault-based tokenization, the more data elements that are tokenized, the higher the likelihood of failure. Companies using vault-based tokenization to protect many data fields associated with Protected Health Information (PHI) or Personally Identifiable Information Read more

Share

Posted in: Security Outlook, Tokenization

(0) Comments


Why your most valuable asset is under constant attack

Posted by Ulf Mattsson, CTO on February 28, 2012

While some are trying to steal your data outright, others are hard at work creating new ways to gain access to that data through an application. They’re attacking your external applications that collect information, such as your websites, call center programs, and point-of-sales systems. They’re also after the sensitive internal systems that use and store Read more

Share

Posted in: Data Protection, Data Security, Security Outlook

(0) Comments


Data Security for Cloud Computing

Posted by Ulf Mattsson, CTO on February 27, 2012

The cloud is widely recognized as the disruptive technology that is changing the way everyone (from consumers to small businesses to large enterprises) communicates and does business. It comes as no surprise that adoption of cloud-based data storage is on the rise. A December 2010 Cisco study revealed that 52 percent of IT officials surveyed Read more

Share

Posted in: Cloud Security, Data Security, Security Outlook

(0) Comments


Differences between Vault-Based Tokenization and Vaultless Tokenization

Posted by Raul Ortega, VP Chief Evangelist on February 22, 2012

Last week, in my blog I introduced a concept called Vaultless Tokenization, and I contrasted it against Vault-Based Tokenization. In this blog, I will go into more detail and illustrate the differences. In Vault-Based Tokenization a large database table is used to create lookup pairs that associate a token with an encrypted credit card. The Read more

Share

Posted in: Security Outlook, Tokenization

(0) Comments


Cloud Contract? You better have data security!

Posted by Ulf Mattsson, CTO on February 17, 2012

Cloud Security is always a hot topic.  However when I read the article “In the Cloud, a data breach is only as bad as your contract”, I raised my eyebrows.  In the cloud, a data breach can occur because you have not taken the proper steps to secure the data.  It has very little to Read more

Share

Posted in: Cloud Security, Data Security, Security Outlook, Tokenization

(0) Comments


Vault-based Tokenization vs Vault-less Tokenization

Posted by Raul Ortega, VP Chief Evangelist on February 17, 2012

Over the last 3 months I’ve seen an increase in the number of companies that are looking to protect sensitive data with tokenization.  This isn’t a surprise in the PCI world, but these companies are attempting to protect personal information (PII) and health related information (PHI) with tokenization.  Perhaps the fact that KPMG is expected Read more

Share

Posted in: PCI DSS, Security Outlook, Tokenization

(0) Comments


When is VeriSign going to learn about Tokenization?

Posted by Ulf Mattsson, CTO on February 4, 2012

With the RSA/EMC breach still in our minds, and also some of the additional breaches that resulted from the RSA breach, including Lockheed Martin. RSA issued a vaguely worded letter about what data that was stolen. It begs the question – what does this all mean? Bottom line is it means these systems are storing Read more

Share

Posted in: Breaches, Data Protection, Data Security, Security Outlook, Tokenization

(0) Comments


« Older Entries