Data Protection in the Cloud – Whose Problem Is It Really?

Richard Moulds, Vice President Product Management and Strategy, Thales e-Security
Using cloud computing is like climbing a mountain – the higher you go the harder it is to climb. Moving mundane tasks to the cloud is easy, but for security centric applications the move is harder to make and for those involving regulated data the day may never come. That’s a shame because it’s in just these areas where the strongest economic incentives for moving to the cloud lie. The question is, who is best placed to establish the appropriate security in order to make this particular mountain easier to climb? Should cloud users plan on a “Bring Your Own Security” approach where they assume that the cloud is essentially an untrusted environment where they must wrap their own security around their applications and data, or should cloud providers be responsible for providing appropriate protection as part of a trusted cloud platform where users can feel safe and do what they do best – build applications? This presentation will address the tradeoffs as well as provide practical guidance regarding data protection approaches in a cloud environment.
May 23 2012
46 mins
Data Protection in the Cloud – Whose Problem Is It Really?
More from this community:

IT Security

Webinars and videos

  • Live and recorded (2605)
  • Upcoming (175)
  • Date
  • Rating
  • Views
  • There has been a lot of press lately on the escalating cyber threats especially from China. A panel of security experts and practitioners will discuss focus on how this press coverage has changed how organizations think about these cyber threats and what countermeasures they need or plan to implement to address escalating crimes, espionage, or warfare cyber risks.
  • More and more organizations are exploring the ramifications of Big Data on their enterprises. Deployments of Smart Meters to better manage the electric grid, Industrial Control Systems (ICS) across a variety of sectors, and the promise of always on and always connected systems are pushing organizations to gather more data than previously imagined. What are the implications from a privacy and intellectual property perspective and how can we as security professionals provide a level of control and risk management over the coming wave of The Internet of Things? Join (ISC)2 and Capella University on May 23, 2013 at 1:00pm Eastern for a discussion on these important concerns.
  • How do you monitor and assess performance in the cloud? Do you need more visibility and control over your managed cloud environments? Learn how HOSTING 360° Report™ delivers a level of visibility to cloud performance that has historically been unavailable to cloud customers. Aggregating key performance and operational data in a concise and usable format provides full visibility into the availability, performance, recovery, security and capacity (AppRisk™) of HOSTING’s cloud services.
  • The explosion of social media in recent years means that there are millions of users or ‘fans’ to reach and add to your customer base. While there are clear benefits to end-users and the organizations that accept their social identities for account creation and authentication, there are important risk factors that have to be considered as well.

    Please join CA and ISACA for this webinar, where we will review the pros and cons of social media login and Bring Your Own Identity (BYOI), and provide guidance and best practices based on real use cases to help guide organizations to a model that meets their risk profile.
  • BYOD is inevitable and unstoppable. Maybe even uncontrollable and unmanageable. But is it the real issue? We seem to be very interested in mobile device management and security risks and data breaches, as, of course, we should be. But, isn’t the real issue the fact that traditional IT is fast becoming irrelevant. Nearly all of us use our personal devices for work and have multiple personal clouds full of data – personal and business. Today’s users believe that they need traditional IT less than before. Crowdsourcing is replacing the Service Desk while Web self-service is replacing live people. But, there’s more to running IT than mobile device buzz words and doom & gloom blogs and tweets. Check out this webinar with CA Technologies & Pink Elephant to find out what’s really happening and what IT can do to embrace this new world. 1 PriSM CPD.
  • For the IT employer utilizing contingent or contract worker(s) services there are best practices and considerations that need to be made in order to protect yourself and your employees.

    - Do you know how to discuss pay rates, increases or bonuses?
    - Do you know how to deal with full-time employment queries, how to properly deal with timecards or forms?
    - How do you deal with punctuality, attendance, dress code etc?
    - What do you do when you want to terminate or suspend a contingent worker?

    These are the common questions we receive and we will provide tangible tools and information that can help protect you as an employer.
  • For the IT employer utilizing contingent or contract worker(s) services there are best practices and considerations that need to be made in order to protect yourself and your employees.

    - Do you know how to discuss pay rates, increases or bonuses?
    - Do you know how to deal with full-time employment queries, how to properly deal with timecards or forms?
    - How do you deal with punctuality, attendance, dress code etc?
    - What do you do when you want to terminate or suspend a contingent worker?

    These are the common questions we receive and we will provide tangible tools and information that can help protect you as an employer.
  • By 2014, 60% of global companies are expected to pilot, deploy or expand their BYOD programs (RainKing). As BYOD has become a fixture in the workplace, with 72% of employees clamoring to have their personal devices work-enabled, the IT industry has watched as the familiar “perimeter" model has become untenable. Data is going to more places, and ending up on a wider variety of devices, than ever before. A new model for protecting data has become a necessity. Organizations have tried to do so in a multitude of ways: extending policies to cover mobile devices, monitoring usage, MDM solutions, and even NAC; all have been methods used to try and create the most stable environment for mobile technology. Let Integralis security expert Mike Gabriel explain how to best balance mobile productivity and security in this Security Talks installment.

    Why Attend?

    1.Discover how your peers are trying to protect mobile data.
    2.See how the perimeter is being sculpted (or not) by the IT industry.
    3.Find out what the future holds for BYOD in the workplace.
  • Over the years true MSPs have had to work diligently to differentiate themselves from companies that are at best, not true MSPs and at worst, are shady fly-by-night operators. This is where the Unified Certification Standard or (UCS) for Cloud & Managed Service Providers comes in.

    The UCS was created by a team of dedicated MSPs to address the shortfalls of existing standards like ISO 27001, ITIL, CoBIT, SSAE 16, which were never intended for managed services organizations and offered little in the way of consumer protection.

    CASE IN POINT: Many MSPs do NOT fail because of technical deficiencies, but due to financial risk. Because of this, customers have very little insight into the service provider's business practices and financial strengths and capabilities.

    Attend this webcast and you will hear from real MSP executives on how the UCS certification and audit has helped them to:

    - Win new business
    - Provide needed transparency to customers
    - Achieve compliance objectives
    - Quickly develop trust with customers and prospects
    - Provide documentation on how those MSPs deliver their services
    - And much more...

    Both Cloud and Managed Service Providers should attend this webcast and at least begin to follow the standards necessary to achieve managed services and cloud computing excellence.
  • Doug Turner, CEO of Mantis Technology Group, talks about how his team built Pulse Analytics, a sentiment analysis solution using text analytics tool running on SAP HANA One. Hear how his team strengthened the capabilities of this solution while simplifying their data architecture by replacing 20 servers with only 1 SAP HANA One instance.
  • Channel
  • Channel profile
Up Down
  • Simplifying DNSSEC - Managing DNSSEC Has Never Been Simpler Recorded: Mar 27 2013 50 mins
    Join BlueCat and Thales for a solution webinar on how you can better protect your sensitive data with DNS security extensions (DNSSEC). The Domain Name System (DNS) is what allows you to connect to anything and anyone on the Internet. Yet for all its business criticality, most organizations don’t properly secure it. DNSSEC provides a trust relationship within DNS that protects your organization from falling prey to attacks or attempts to steal your – or your customers’ – data.

    Managing DNSSEC security keys has traditionally been complex, costly and time consuming, but it doesn’t need to be. BlueCat combines the ultra-high security of the Thales nShield Connect HSM with the simplicity of our IP Address Management (IPAM) platform to deliver the simplest and most secure solution available for managing DNSSEC. Learn what to look for in a DNSSEC solution and why some of the most demanding and secure organizations in the world trust BlueCat to securely manage their networks.
  • Encryption as a Barometer – What’s Your Security Posture? Recorded: Mar 12 2013 61 mins
    Global Encryption Trends Report: Encryption usage is an indicator of a strong security posture. Is your organization ready? Organizations that deploy encryption extensively throughout the enterprise as opposed to limiting its use to a specific purpose are more aware of threats to sensitive and confidential information and spend more
    on IT security.

    The Ponemon Institute and Thales e-Security are pleased to present the findings of the 2012 Global Encryption Trends Study. Ponemon surveyed 4,205 business and IT managers in the United
    States, United Kingdom, Germany, France, Australia, Japan and Brazil. The purpose of this
    research was to examine how the use of encryption has evolved over eight years and its impact of this technology on the security posture of organizations. Join us to learn more and find out how you can determine the barometer of your company’s overall security posture!
  • Understanding and Selecting a Key Management Solution Recorded: Feb 5 2013 63 mins
    Organizations that are expanding their use of encryption technology for data protection are increasingly turning their attention to developing an overarching enterprise key management strategy. However, the complexities of meeting current needs while trying to account for future requirements and evolving virtualization and cloud computing initiatives can easily cause confusion and frustration. This webinar, the second in a two-part series from Securosis and Thales e-Security focused on key management, explains deployment options, describes important technology and management features, and includes a practical checklist to use when selecting a key management solution to best fit the needs of specific projects and environments.
  • Data Protection in the Cloud – Whose problem is it really? Recorded: Dec 12 2012 45 mins
    Using cloud computing is like climbing a mountain – the higher you go the harder it is to climb. Moving mundane tasks to the cloud is easy, but for security centric applications the move is harder to make and for those involving regulated data the day may never come. That’s a shame because it’s in just these areas where the strongest economic incentives for moving to the cloud lie. The question is, who is best placed to establish the appropriate security in order to make this particular mountain easier to climb? Should cloud users plan on a “Bring Your Own Security” approach where they assume that the cloud is essentially an untrusted environment where they must wrap their own security around their applications and data, or should cloud providers be responsible for providing appropriate protection as part of a trusted cloud platform where users can feel safe and do what they do best – build applications? This presentation will address the tradeoffs as well as provide practical guidance regarding data protection approaches in a cloud environment.
  • Assessing a PKI Against Today’s Changing Requirements - Helping Ensure a Strong Recorded: Oct 24 2012 62 mins
    Thales PKI Webinar: The suitability and trustworthiness of a PKI must be regularly assessed as more higher value applications increasingly depend on it. As the demands on previously deployed PKIs change, consultants and PKI implementers can play a valuable role by examining usage, applications, and data to ensure the appropriate levels of assurance are in place. With the backdrop of well-known attacks on sensitive data, as well as technology advances, implementers must consider critical security factors including:

    . Growing industryand government regulatory compliance requirements
    . Today’s increased threat environment and sophistication of attacks
    . Supported applications and the sensitivity of the data they process
    . Expanded use of a PKI to support mobility and cloud computing
    . Transition to longer RSA key lengths and alternative algorithms

    Join our webcast to learn how to create awareness of the critical need to assess PKIs in the face of new developments, and to ensure they can still do the job. This informative Microsoft PKI implementers session will provide you:

    . A security blueprint to create awareness in this critical security matter
    . A framework to examine PKI needs against required assurance levels
    . A set of best practices to develop action plans to strengthen their PKIs
    . Information about how Thales nShield hardware security modules (HSMs) can enhance the assurance level of Microsoft PKIs
  • Pragmatic Key Management for Data Encryption Recorded: Oct 18 2012 59 mins
    Securosis/Thales e-Security Webinar: Over the years, key management has developed a dubious reputation – in a large part due to numerous crypto-enabled products failing to meet enterprise requirements for full lifecycle key management and few being genuinely easy to use. Fortunately, new techniques and tools remove much of the historical pain of key management, setting the stage for better experiences with mature technologies like encryption and PKI as well as a host of new and innovative applications.

    In this webinar, Securosis and Thales review encryption and key management basics, outline the four primary key management strategies, show how they map to typical enterprise use cases, and review how to choose a strategy that best fits your organization today while preparing you for tomorrow’s needs.
  • Encryption in the Cloud - Thales/Ponemon Recorded: Sep 25 2012 60 mins
    This Cloud focused webinar is based on the Ponemon research that considers how encryption is used to ensure sensitive or confidential data is kept safe and secure when transferred to external-based cloud service providers. Together, Thales & Ponemon discuss important findings that demonstrate the relationship between encryption and the preservation of a strong security posture in the cloud environment. Based on the research, organizations with a relatively strong security posture are more likely to transfer sensitive or confidential information to the cloud. We'll cover high-level questions asked and issues sought by this research including:

    . What percent of organizations currently transfer sensitive or confidential data to external cloud-based services?
    . Who is most responsible for protecting sensitive or confidential data transferred to an external cloud-based service provider? Is it the cloud provider, the cloud consumer or is it a shared responsibility?
    . Do organizations have the ability to safeguard sensitive or confidential data before or after it is transferred to the cloud?
    . Do respondents believe their cloud providers have the ability to safeguard sensitive or confidential data within the cloud?
    . In the eyes of respondents, does the adoption of cloud services impact their organization’s security posture?
    . Where is encryption applied to protect data that is transferred to the cloud?
    . Do organizations fully comprehend or even have visibility of the steps or measures taken by the cloud provider to protect sensitive or confidential data?
    . Who manages encryption keys when sensitive and confidential data is transferred to the cloud?
  • Appliance Key Management Advantages for IBM Storage Encryption Recorded: Jul 12 2012 39 mins
    How can you be sure you can recover your data, long-term, ensure that keys are protected from theft, and limit access to all but legitimate users? Key management is the foundation to deploying encryption successfully.
    During this webinar Thales e-Security and IBM will discuss:
    • The importance of key management for effective encryption solutions
    • Determining environmental readiness and solution qualifying criteria
    • Six critical requirements of a robust key management system
    • A best of breed approach: IBM software in a security-hardened appliance

    Whether yours is a small enterprise looking for a reliable point solution, or a global organization with a large investment in centralized IT services, this presentation will inform you on how today’s solutions provide the right fit to accelerate adoption and plan for future growth.
  • O crescimento da Criptografia na Protecao de Dados Recorded: Jun 27 2012 28 mins
    Veja como as organizações brasileiras estão aumentando o uso da criptografia para atender aos novos regulamentos e aos ataques cibernéticos. Pesquisa multi-nacional da Thales conclui que a criptografia e o uso de chaves criptográficas tem se tornado questões estratégicas de negócios para abordar os regulamentos de segurança e gerenciar os riscos
  • Data Protection in the Cloud – Whose Problem Is It Really? Recorded: May 23 2012 46 mins
    Using cloud computing is like climbing a mountain – the higher you go the harder it is to climb. Moving mundane tasks to the cloud is easy, but for security centric applications the move is harder to make and for those involving regulated data the day may never come. That’s a shame because it’s in just these areas where the strongest economic incentives for moving to the cloud lie. The question is, who is best placed to establish the appropriate security in order to make this particular mountain easier to climb? Should cloud users plan on a “Bring Your Own Security” approach where they assume that the cloud is essentially an untrusted environment where they must wrap their own security around their applications and data, or should cloud providers be responsible for providing appropriate protection as part of a trusted cloud platform where users can feel safe and do what they do best – build applications? This presentation will address the tradeoffs as well as provide practical guidance regarding data protection approaches in a cloud environment.
  • Increasing Encryption Deployment- Response to Compliance & Cyber Attacks Recorded: Apr 26 2012 41 mins
    Thales e-Security and Ponemon Institute have partnered within the security community to identify and understand the trends that shape the market. This webinar will examine the usage of encryption and how it has been evolving. Having recently completed the “2011 Enterprise Encryption Trends Report” that focuses on compliance pressures and cyber-attacks targeting sensitive data that is leading IT organizations to alter their encryption strategies, this webinar will provide insight from surveyed I.T. workers across various job functions. You'll hear how they're leveraging encryption technology in order to protect their critical information assets. Since compliance laws differ around the world, encryption trends tend to vary greatly in various markets. Are your assets being fully protected?

    Join Thales e-Security and guest speaker Larry Ponemon to learn more about this exciting webinar topic on April 26, 2012 at 2:00 pm EST!
  • How High Assurance Code Signing Can Make You a Hero Recorded: Apr 24 2012 42 mins
    Advanced persistent threats (APTs) like Stuxnet and Duqu have caused many software-producing organizations to re-examine their code signing operations – specifically the security of private signing keys that underpin the integrity of the entire process. What many don’t realize is that they can both increase the assurance level of their code signing AND simplify and automate their code signing workflows at the same time!

    Join Thales security expert Peter DiToro on April 24, 2012 at 2:00pm EST for an informative session where you will learn how to:
    • Provide high assurance protection for private code signing keys and digital signature operations
    • Automate and simplify code signing workflows in multi-workstation environments
    • Apply cryptographic best practices to significantly reduce the risk of malicious software alteration and protect your brand.
  • Ensuring Sustainable Compliance in a Changing Regulatory Environment - Oracle Recorded: Apr 19 2012 44 mins
    Thales e-Security and Oracle will discuss database security solutions levering encryption and key management for users of Oracle 11g R2. You'll learn about the "standards of due care" and why HSMs (hardware security modules) play an important role in meeting compliance and auditing requirements.
  • Database Encryption for Government- High Assurance and Compliance Recorded: Mar 22 2012 41 mins
    Thales and Microsoft will discuss high assurance database encryption for Government Microsoft SQL Server users. Learn how to:
    • Enhance the security of your Microsoft SQL database using built-in TDE and the extensible key management feature
    • Achieve operational ease with centralized key management in a scalable manner across multiple databases
    • Simplify regulatory compliance by protecting critical master keys in certified hardware with advanced separation of duties capabilities
  • Database Encryption for Financial Services - High Assurance and Compliance Recorded: Mar 15 2012 40 mins
    Thales and Microsoft will discuss high assurance database encryption for Microsoft SQL Server users in the financial services industry. Learn how to:
    • Enhance the security of your Microsoft SQL database using built-in TDE and the extensible key management feature
    • Achieve operational ease with centralized key management in a scalable manner across multiple databases
    • Simplify regulatory compliance by protecting critical master keys in certified hardware with advanced separation of duties capabilities
Encryption and Key Management Solutions
Solutions to help companies meet compliance and protect the security of your most sensitive data leveraging encryption and key management.

Embed in website or blog

Successfully added emails: 0
Remove all
  • Title: Data Protection in the Cloud – Whose Problem Is It Really?
  • Live at: May 23 2012 5:00 pm
  • Presented by: Richard Moulds, Vice President Product Management and Strategy, Thales e-Security
  • From:
Your email has been sent.
or close
You must be logged in to email this