how to secure your emails for sensitive docs

27
Why You Shouldn’t Email Your Sensitive Documents David Strom [email protected] TechNet Mid America July 2012

Upload: david-strom

Post on 18-Nov-2014

789 views

Category:

Travel


0 download

DESCRIPTION

This was a presentation that I gave at Technet MidAmerica conference in St. Louis in July 2012

TRANSCRIPT

Page 1: How to secure your emails for sensitive docs

Why You Shouldn’t Email Your Sensitive Documents

David [email protected]

TechNet Mid America July 2012

Page 2: How to secure your emails for sensitive docs

Email docs to yourself

Page 3: How to secure your emails for sensitive docs

Email is inherently insecure…

Page 4: How to secure your emails for sensitive docs

4

Obstacles to Email Encryption Adoption Today

• Unencrypted emails are too easy to send• IT admins think encryption is too expensive or

cumbersome or complex• Compliance regs should drive more email

encryption usage (but don’t…)• The mobile encryption experience hasn’t been

so wonderful

Page 5: How to secure your emails for sensitive docs

Investors’ Email Compromises Have Consequences!

5

Page 6: How to secure your emails for sensitive docs
Page 7: How to secure your emails for sensitive docs
Page 8: How to secure your emails for sensitive docs

Secure email alternatives

• Cloud-based storage• Secure document delivery services • Data loss prevention products• Full encryption choices

Page 9: How to secure your emails for sensitive docs

File sending services

Page 10: How to secure your emails for sensitive docs
Page 11: How to secure your emails for sensitive docs
Page 12: How to secure your emails for sensitive docs
Page 13: How to secure your emails for sensitive docs
Page 14: How to secure your emails for sensitive docs

YouSendIt Privacy Policy

Certain information may become accessible, such as the text and subject of messages you have sent, the name and content of the User Files you have sent, the date and time messages were sent, and the email addresses of the recipients.

Page 15: How to secure your emails for sensitive docs

Responses to MegaUpload shutdown

Page 16: How to secure your emails for sensitive docs

Secure document services

Page 17: How to secure your emails for sensitive docs
Page 18: How to secure your emails for sensitive docs

Secure document issues

• Do you need secure intra- or inter-enterprise collaboration?

• Can you recall sent messages? • What happens when someone leaves your

company? • How does the service affect users’ existing

email experience? • Can you authenticate recipients and thwart

malware such as key-loggers?

Page 19: How to secure your emails for sensitive docs

Data loss prevention

• Global Velocity's GV-2010 security appliance • BlueCoat Networks DLP appliance• Sendmail's Sentrion email server• McAfee Host DLP• Symantec/Vontu DLP v10• Safend Protector• Trend Micro DLP

Page 20: How to secure your emails for sensitive docs
Page 21: How to secure your emails for sensitive docs

DLP Drawbacks

• You are tracking rather than encrypting messages

• Once a message leaves your premises, you can’t do anything about it

• Can be expensive

Page 22: How to secure your emails for sensitive docs

Full encryption choices

• Voltage SecureMail• PGP Universal Server• Sophos Email Appliance• Cisco IronPort• Proofpoint Protection Server• Mimecast's Unified Email Messaging• Echoworx Encrypted Mail

Page 23: How to secure your emails for sensitive docs

Common product features

• Crypto key management• Auto encrypt sensitive info as part of their

policies• Lots more rules processing• Outlook plug-ins

Page 24: How to secure your emails for sensitive docs
Page 25: How to secure your emails for sensitive docs

Encryption LandscapeVendor Approach Key/Certificate Management Mobile capability

Cisco IronPort Symmetric key per message

CRES (cloud)Or on premise

Web-based

Proofpoint Symmetric key per message

PP Key service or on premise Web-based; read only

Symantec/PGP PKI PGP Directory or on premise Web-based; read only

Entrust PKI Entrust PKI or on premise Web-based

Zix PKI Zix Directory Web-based

Voltage Identity-based encryption

Cloud-based Native app

Echoworx PKI Echoworx PKI Native app

Page 26: How to secure your emails for sensitive docs

Voltage’s Secure email mobile client

Page 27: How to secure your emails for sensitive docs

Questions?

David [email protected]

314 277 7832@dstrom (Twitter)

http://strominator.com