Blog

Posts Tagged ‘Zecurion’

Do You Have a Data Protection Policy?

Tuesday, January 3rd, 2012

Technology is great — and Zecurion is in the business of providing industry-leading data encryption and data loss prevention solutions — but  you also need to have an established policy for data handling and data protection. Tools like Zlock, Zgate, and Zserver do an excellent job of monitoring network traffic and locking down sensitive data to ensure it isn’t compromised or exposed, but no software tool is fool proof. They are there to augment and support the policies your organization has in place. Neither policy, nor technology alone can prevent every data breach incident, but the combination of a documented data protection policy, with the right technology to support it will give you peace of mind that your data is as safe as it can be.

So, what sorts of things should your data protection policy cover?

  • A designated role responsible for maintaining the policy
  • A system for defining the classification of data based on its sensitivity or criticality
  • Provisions for conducting a risk analysis to identify where sensitive data is stored, how it is used, and where it travels to
  • Established guidelines for data handling and protection procedures for employees
  • Defined disciplinary measures for violations of the policy
  • Restrictions on physical access to the servers that store and process sensitive data
  • A plan for backing up critical and sensitive data, and ensuring that the backup data is secure
  • A system for monitoring and periodically reviewing data access to ensure it is safe
  • Define data breach incident reporting requirements and incident handling procedures
  • Establish a periodic review of the data protection policy to modify or update it as needed

This is just a baseline, but it’s a start. If you don’t have a written data protection policy that your employees are aware of you can’t expect them to follow it. Develop an effective data protection policy, then support and enforce that policy with the award-winning tools from Zecurion.

Time Is Running Out

Tuesday, December 27th, 2011

I know you are busy spending time with family, enjoying the holidays, and not even thinking about business, or protecting your data — but time is running out.

Zecurion is offering special discount pricing on our award-winning data loss prevention and encryption products through the end of the year. Is your data adequately protected? Do you have the right tools in place to enable you to exercise some control over how and where your sensitive data goes without getting in the way of productivity?

You simply purchase the one-year support agreement, and we’ll throw in the product license for free. It is an 80 percent savings off the normal price. You owe it to yourself — and the employees, customers, vendors, and others that trust you with sensitive data — to take advantage of this offer before the ball drops at midnight on December 31.

Your 2012 will be much happier if you have the peace of mind that comes with knowing your data is protected. Happy New Year!

How Much Data Are You Leaving Behind?

Sunday, December 18th, 2011

The very things that make portable storage devices convenient for storing and transporting data also make them a greater risk for loss or theft. USB thumb drives hold gigabytes of information, yet fit in your pocket. You can easily have one fall out of your pocket in a taxi or on a train, and you are unlikely to miss it if someone “liberates” one from your possession.

Security vendor Sophos recently bought a number of USB thumb drives at auction that were left behind on trains. Sophos found that two-thirds of the USB thumb drives contained malware–possibly suggesting they were intentionally “left” behind to be found and used by an unsuspecting victim. But, the 50 USB drives comprised nearly 140GB of potential lost data.

None of the USB keys was encrypted, and none of the USB keys contained any encrypted data. None. Sophos found all kinds of interesting data on the USB keys, including lists of tax deductions, minutes of an activists’ meeting, school and University assignments, autoCAD drawings of work projects, photo albums of family and friends, a CV and job application, and software and web source code.

Don’t let that be your data. Make sure you have policies and security controls in place to control what data is allowed to be stored and transported on portable storage media, and make sure your data is encrypted so it is protected even if that media is lost or stolen.

The Real “Bad Guy” Is a Simple Lack of Common Sense

Friday, December 2nd, 2011

It is convenient to think of network security and data protection in terms of “us and them”. There are good guys, and there bad guys. There are authorized users inside the network just trying to get their jobs done, and there are insidious, malicious hackers diligently trying to compromise the network and steal sensitive information. The reality is quite different.

There are, of course, attackers out there with low moral character, a lack of ethics, and too much time on their hands who will not hesitate to exploit holes and expose data if possible. However, if you review the data breaches large and small that occur on a daily basis, the vast majority have nothing to do with any attack at all. Sensitive, personal information is compromised and exposed because the authorized users entrusted with that information are often clueless–or at least careless–in how they handle it. There are school principals accidentally uploading sensitive information, employees tossing files with personal information into public trash bins, and many employees with unencrypted data on laptops, tablets, and smartphones that are easily lost or stolen. The hackers often don’t have to work very hard.

Organizations should do more to educate users and increase awareness about sensitive data, data protection policies, and proper data handling procedures. Beyond that, though, organizations should have tools in place on the endpoint systems, monitoring the flow of network traffic, and protecting data at rest on servers to ensure that a lapse in judgment doesn’t lead to a data breach.

Protecting Data Is Not a Black and White Issue

Saturday, November 26th, 2011

Data protection is more nuanced than simply allowing or denying access. The ages-old concept of group and individual permissions for file and folder access are based on the fact that one person may have no business opening a given file, while the next person may need to read and review that same file as a function of their role. This same type of control is needed when it comes to allowing data to be printed, or stored on an external drive or USB flash drive.

Because protecting data is not a black and white issue, the solution needs to be more flexible than simply blocking or allowing access. Zecurion’s Zlock gives IT admins the ability to apply fine-tuned controls that prevent the unauthorized copying and storing of data without impeding legitimate, authorized use of removable media at the same time. Just as one person may have no business opening a file that another person needs to do their job, one person may have no legitimate business purpose for storing data on removable media, while the next person may need that capability to perform their job function. A solution that simply locks down USB ports is like killing a housefly with a hand grenade, and applies too broadly to provide functional data protection.

Zlock takes it a step farther, though. Jim may have a business need to store sensitive data on a removable drive, but you don’t need to grant blanket permission to Jim. You can still set up controls in Zlock that let Jim store data on a USB flash drive, but only if the data is encrypted. In fact, IT admins can configure Zlock to only allow Jim to store data on a specific brand of company-issued flash drives, or even a specific hardware ID of an individual USB flash drive issued to Jim. That way, data is protected, and the flow of sensitive data is controlled, but Jim is still able to do his job without having to jump through any additional hurdles.

Now, through the end of 2011, you can get Zecurion Zlock for 80% off.

Zecurion Wins 2011 Golden Bridge Awards in Two Categories

Tuesday, August 16th, 2011

NEW YORK, NY–(Marketwire – Aug 16, 2011) – Zecurion has earned the prestigious Golden Bridge Awards titles for its Zlock and Zgate DLP (data loss prevention) products. The coveted annual Golden Bridge Awards program encompasses the world’s best in organizational performance, products and services, executives and management teams, women in business and the professions, innovations, case studies, product management, public relations and marketing campaigns and customer satisfaction programs from every major industry in the world.

Zgate 3.0 was recognized as the most innovative product in the Information Leak Prevention category, and Zlock 3.0 was awarded most innovative product in the Data Protection category. Zgate and Zlock are a formidable combination designed to keep sensitive information from being leaked, exposed, or compromised.

More than 40 judges from a broad spectrum of industry voices from around the world participated and their average scores determined the 2011 Golden Bridge Business Awards winners. The winners were announced during the awards dinner and presentation on August 10, 2011 in New York attended by the finalists, industry leaders, and judges.

“It’s an honor to be named a winner by Golden Bridge Awards for this esteemed industry and peer business award,” said Alexey Raevsky, founder and CEO of Zecurion. “These awards are a testament to Zecurion’s innovative approach and commitment to helping customers protect data and prevent information leaks without impeding productivity.”

For more information, click here to see the full press release.

Zecurion Finalist for Three Product Innovation Awards

Friday, August 5th, 2011

Zecurion Inc., a data loss prevention (DLP) leader that protects businesses against insider threats, announces that its three core products are all finalists for innovation in the 3rd Annual 2011 Golden Bridge Awards program.

Zgate 3.0 is a finalist in the Information Leak Prevention category. Zgate is a network perimeter DLP solution that monitors all outbound traffic to ensure that confidential or sensitive data don’t get leaked across your network.

Zserver Suite is a finalist in the Encryption Key Management category. Zserver Storage secures and protects confidential information at the processing and storage level on corporate servers. The Zserver Enterprise Key Management Server (EKMS) minimizes administrative overhead for encryption by generating, storing, managing, and automatically loading encryption keys across the enterprise.

Zlock 3.0 is the sole finalist for the Data Protection innovation award. Zlock is an endpoint security DLP solution that provides IT admins the ability to secure, monitor, and control computer ports and external devices to enforce data security policies and prevent exposure of sensitive data.

The 3rd Annual 2011 Golden Bridge Awards ceremony will be held in New York on August 15, 2011.

Prevent Network Data Leaks with Zgate

Sunday, July 10th, 2011

Your private and confidential data faces a real and growing danger of being leaked and exposed to the general public. Email, webmail, social networking, instant messaging, and other online channels provide ample opportunity for sensitive information to be compromised–whether intentionally or through honest error.

You need a gatekeeper–a tool that can monitor all of the various outbound network traffic and online communications to identify sensitive information and prevent it from leaving the network. Zgate is the tool you need, and an important part of Zecurion’s DLP (data loss prevention) solution.

With Zgate, data leaks are almost impossible. Zgate uses hybrid content analysis–combining digital fingerprints, Bayesian methods, and heuristic detection–to filter outbound traffic and detect confidential data with unmatched precision. Emails, social network posts, and other network communications with Social Security numbers, birth dates, and other sensitive information are detected to prevent it from leaving the network and being exposed.

Zgate also archives outbound data, providing you an opportunity for retrospective or forensic analysis. Zgate archives can help you understand which users are sending out sensitive data, what sensitive information is being shared or exposed, and where that data is heading. The Zgate archives can help you fine tune your data protection policies to prevent exposure of sensitive data.

The best part about Zgate is that it is the most cost-effective DLP solution when it comes to initial investment and deployment costs. Zgate offers a DLP solution that is easy to administer and maintain, at a price point that is within reach of even small and medium businesses that typically consider it too complex and expensive. For less than one percent of the costs incurred from an average data breach , your data can be automatically and completely protected.

Zgate is more than just a DLP product–it is cost-effective peace of mind enabling you to sleep soundly knowing that your sensitive data is safe.

Keep Your Sensitive Data Off Social Networks

Thursday, October 7th, 2010

With The Social Network being the number one movie last weekend, and recent survey results showing Facebook has surpassed Google as the online destination that users spend the majority of their time on, it seems like a good time to take a look at the impact of social networks on information security.

This white paper covers the risks and concerns of information leakage via social networking that IT administrators need to be aware of. It also discusses the need to guard sensitive information from being leaked via social networks or email–whether intentional or inadvertent–and simple, cost-effective solutions to prevent it from happening.

Click here to read the white paper: Don’t Let Your Sensitive Information Leak onto Social Networks

Zserver Protects Data in the Cloud

Friday, June 18th, 2010

A ComputerWorld article title Cloud Security in the Real World: 4 Examples cites Zecurion’s Zserver as a cloud-based storage encryption solution. 

Examining the issue of data encryption in the cloud, the article states “Several providers of cloud-based backup storage install appliances at the customer site to accommodate encryption, but Flushing was not interested in that setup.”

It also explains “At Flushing Bank in New York, CIO Allen Brewer turned to the cloud for data backup after getting fed up with on-site tape backup. Using Zserver from Zecurion, Flushing is now sending files over the Internet to be stored for backup.”

 Read the white paper Protecting Data in the Cloud to learn more about encrypting and protecting data in the cloud with Zecurion’s Zserver.