« Information security is easy | Main | Does the PCI DSS reduce crime? »

Tuesday, 31 March 2009

The best place to encrypt data

The best source of information about data breaches is probably the database maintained by the Open Security Foundation. This information shows that there are three sources of data breaches that are much more common than all the others. Based on the fraction of breaches that are due to each source, here are the big three:

Source

Fraction of breaches

Stolen laptop

21%

Hack

17%

Web

14%

Based on this information you might think that encrypting your laptops is the most important thing to do. On the other hand, looking at the number of records compromised gives a much different picture.

Here's how the big three compare based on that metric:

Source

Fraction of records lost

Stolen laptop

3%

Hack

45%

Web

1%

That looks much different, doesn't it?

From that point of view, laptops aren't your biggest concern. Instead, getting hacked is. If you encrypt your laptops, you'll be protecting against a loss of less that 3 percent of all the records that data breaches compromise. Protecting your data so that it's not useful to a hacker is probably a better use of your limited security budget, and you can do that by encrypting the data in a persistent way so that the encryption stays with the data. That may not protect against the biggest number of data breaches, but it looks like it will protect against the worst losses.

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/services/trackback/6a00e55375ef1c883301156fa8f227970b

Listed below are links to weblogs that reference The best place to encrypt data:

Comments

Luther Martin

That probably depends on exactly how you plan to use this product. It's almost never the actual encryption that you need to worry about with encryption products.

If it's just you, then you might want to think about how to recover your data if you forget your password or if there's a fatal interaction between the encryption software and some other application. It seems like every disk encryption vendor's sales pitch now includes a horror story about how a competitor's product managed to turn lots of expensive laptops into useless chunks of silicon and plastic, so this seems to happen often enough to worry about it.

If you're thinking about using this product enterprise-wide in a large business, then might want to worry about the cost of supporting and maintaining it.

Tooth

I´m using this Discryptor (discryptor.net). Do you think it is ok for this?

Post a comment

If you have a TypeKey or TypePad account, please Sign In.

Voltage Data Breach Index

  • Grab the Voltage Data Breach Index

February 2012

Sun Mon Tue Wed Thu Fri Sat
      1 2 3 4
5 6 7 8 9 10 11
12 13 14 15 16 17 18
19 20 21 22 23 24 25
26 27 28 29