Its no surprise that the past year has seen increased attention in network security. The pandemic-driven growth in telework has brought with it growing security threats, and the continuing rise of ransomware attacks has agencies taking a hard look at their security protocols. Add in the recent Executive Order on Improving the Nations Cybersecurity, which calls for implementation of zero-trust initiatives (among other things), and the environment seems right for greater adoption of multifactor authentication and cloud-based access.
However, despite the clear advantages of MFA in securing access to important data, adoption lags considerably in the federal market compared with the private sector. The need for government to catch up in that technology will only increase, as the cloud continues to change even the most basic ways that agencies connect with users and stakeholders.
This position, and others, has been echoed in a recent threat survey report titled Accelerated Cloud Transformation and Remote Work. (Note: This report was commissioned by Thales.)
How COVID caught federal IT security off-guard
COVID-19 has driven permanent changes to the government workforce and has accelerated the adoption of the cloud as the requirements of pandemic isolation prompted both remote working and a re-examination of how branch offices are composed.
Unfortunately, a considerable number of federal agencies were caught without a plan when COVID-19 forced the work-from-home change. According to survey findings, over three-fourths of respondents said they were unprepared to some degree, and only 15% responded as having been very prepared.
Consequently, cybersecurity dangers are top of mind as these agencies navigate the hazards of working from home. Nearly half of respondents said they are somewhat concerned about the security implications in remote work, with 46% also saying that privacy and security were the most important investments during the pandemic. That was considerably more than those who prioritized investment in infrastructure/cloud (30%) and investment in distributed (hybrid) cloud (24%).
These responses suggest the federal government should work harder to deploy basic security solutions like MFA. The reality, however, is that even though zero trust and similar initiatives are being pushed by the current administration, MFA adoption is still lagging behind other security tools such as network and endpoint security in the enterprise.
MFA, encryption, key management and tokens: The tools of the security trade
In this years survey, 52% of federal respondents claim to have adopted MFA, versus 62% in the U.S. overall. The government would do well to benchmark against other industries where MFA and other identity-related security measures are becoming more common, such as retail and financial services.
Perhaps because of the sluggish adoption of MFA, less than half of respondents were somewhat confident of their current remote access security product to secure their networks from the risk of employees working from home. Most organizations still use VPN and VDI to access applications, with 40% using conditional access. Conditional access was followed closely by 37% using zero trust network access/software-defined perimeter or cloud-based access management.
As for the most-used choices to protect data in the cloud, encryption, key management and tokenization top the list. Just over one-quarter of respondents store more than half of their data in the cloud. More than half of respondents indicated up to half of the data that is stored in an external cloud is sensitive. Whats alarming about this is that 39% of respondents have experienced a data breach involving data and applications in the cloud. An even higher number (45%) experience a breach or failed an audit involving data and applications stored in the cloud in the past year alone.
Encryption in the cloud might be a more widely adopted means of securing data across networks, but for the fact that most organizations are using multiple cloud services. The most varied cloud usage is in software as a service, with 39% of respondents using more than 50 SaaS applications and one-third using 26-50 SaaS apps. That pattern of cloud usage could pose challenges for managing encryption keys across multiple providers.
Change is coming in the form of increased adoption of zero trust, both because of the work-from-home phenomenon and the recent White House executive order. Nearly one-third of respondents said they have a formal strategy embracing a zero trust policy, outpacing the U.S. with 25%. According to survey responses, organizations with a formal zero-trust strategy are less likely to have been breached.
What have we learned from all this? First, security strategies must be agile to respond the growing sophistication of hackers bent on breaching government IT systems. Nonetheless, as work from home and the cloud take root in the security landscape, these solutions must still be flexible enough to deal with the hybrid ecosystem of infrastructure, applications, data and users.
Cloud computing and hybrid environments add considerable complexity to good security strategies. Looking ahead, both security controls and security management will need to extend to cloud in ways prevent each cloud environment from becoming its own isolated realm.
About the Author
Lloyd Mitchell is president of Thales Trusted Cyber Technologies.
- WhatsApp boosts end-to-end encryption - BusinessTech - September 17th, 2021
- WhatsApp to offer encryption on cloud backups: Heres all you need to know - India Today - September 17th, 2021
- London's Top Cop Says 'Big Tech,' Encryption Are Letting The Terrorists Win - Techdirt - September 17th, 2021
- Zoom unveils new security features including end-to-end encryption for Zoom Phone, verified identities and... - ZDNet - September 15th, 2021
- Insights on the Hardware Encryption Global Market to 2026 - by Algorithm & Standard, Architecture, Product, Application and Region - PRNewswire - September 15th, 2021
- Light Start: WhatsApp rolls out backup encryption, LG is more attractive, Google goes dark and iPhones only laak gud vaabs Stuff - Stuff Magazines - September 15th, 2021
- Revenant REvil. WhatsApp offers encryption. Hortum spyware in Turkey. Update on the UN data breach. Healthcare breaches disclosed. - The CyberWire - September 15th, 2021
- How a glitch in the Matrix led to apps potentially exposing encrypted chats - The Register - September 15th, 2021
- Secure cloud storage: which are the most secure providers? - ITProPortal - September 15th, 2021
- WhatsApp is finally allowing users to encrypt chat backups uploaded to iCloud and Google Drive - Buzz.ie - September 15th, 2021
- WhatsApp is adding encrypted backups - The Verge - September 11th, 2021
- What Is Fully Homomorphic Encryption (FHE)? - CIO Insight - September 11th, 2021
- WhatsApp end-to-end encrypted messages arent that private after all - Ars Technica - September 11th, 2021
- UK government backs Apple, and wants to scan encrypted messages for CSAM - 9to5Mac - September 11th, 2021
- VPN and Email Encryption Provider, WiTopia, Inc., Is Now Raising Capital Via StartEngine - PRNewswire - September 11th, 2021
- Future in the cloud for encryption - Capacity Media - September 8th, 2021
- WhatsApps Claims Of End-To-End Encryption Might Be Entirely True - Ubergizmo - September 8th, 2021
- Debunking Wi-Fi Security Myths: Wi-Fi Encryption Is Weak - TechSpective - September 8th, 2021
- WhatsApp Flaw Casts Doubt on End-to-End Encryption - Security Boulevard - September 8th, 2021
- Bluefin Receives U.S. Patent on Systems for Vaultless Tokenization and Encryption - WFMZ Allentown - September 8th, 2021
- Priti Patel backs ad campaign that criticises Facebook's stance on end-to-end encryption - Graham Cluley Security News - September 8th, 2021
- EXCLUSIVE: What's in the new zero-trust strategy - Politico - September 8th, 2021
- 3 ways to protect yourself from cyberattacks in the midst of an IT security skill shortage - Help Net Security - September 8th, 2021
- Apple Has Betrayed Its Privacy Legacy and Will Undermine End-to-end Encryption Everywhere - Privacy News Online - September 8th, 2021
- IBM's first 7nm Power10 chip arrives in E1080 server system with a wealth of shiny features - The Register - September 8th, 2021
- The adoption of multi-cloud drives the need for better data protection and management of encryption keys an... - Security Boulevard - August 26th, 2021
- Cryptomator Vs. BoxCryptor: Which One Is The Best Encryption Software? - Analytics Insight - August 26th, 2021
- Why you should encrypt your data on your computer and how to do it - The Star Online - August 26th, 2021
- Video end-to-end encryption on Ring to be available worldwide - ITP.net - August 26th, 2021
- What is a Vocoder? How an audio encryption device used in WW2 became the sound of electro and modern pop - Mixdown - August 26th, 2021
- Privacera partners with StreamSets to strengthen data security for ETL processing in the cloud - Help Net Security - August 26th, 2021
- R400m cocaine-in-a-boat accused used encryption app to communicate - TimesLIVE - August 26th, 2021
- Evervaults encryption as a service is now open access - TechCrunch - August 24th, 2021
- How to Encrypt Your Own Windows and Mac Devices (and Why You Need To) - Lifehacker - August 24th, 2021
- Why encryption is the key to digital fitness, according to Thales - iTnews - August 24th, 2021
- How to check each of your WhatsApp chats are ACTUALLY private right now and not being intercepted by h... - The Sun - August 24th, 2021
- WebCam: How Australia paved the way for Apple's encryption backflip - Crikey - August 24th, 2021
- Staggering 400% rise in child sexual abuse images detected by Facebook as fears over encryption plans g... - The Sun - August 24th, 2021
- Hardware-based Full Disk Encryption Market 2021 and Analysis to 2027 Micron Technology Inc, Seagate Technology PLC, Toshiba, Intel - The Market... - August 24th, 2021
- WhatsApp could soon have an iPad app for the first time - Engadget - August 24th, 2021
- Facebook is bringing end-to-end encryption to Messenger calls and Instagram DMs - TechCrunch - August 14th, 2021
- Apple opens the encryption Pandora's box - Axios - August 14th, 2021
- How to encrypt your computer (and why you should) - Mashable - August 14th, 2021
- Protects User Privacy With Encryption and Authentication - Security Magazine - August 14th, 2021
- An Overview of Blockchain in Supply Chain: Whats the Link? - JD Supra - August 14th, 2021
- Facebook introduces end-to-end encryption for its voice & video call features - Techstory - August 14th, 2021
- Hardware Encryption Devices Market Research Report 2021 Elaborate Analysis With Growth Forecast To 2027 Intel, Toshiba, Micron Technology Inc,... - August 14th, 2021
- If You Build It, They Will Come: Apple Has Opened the Backdoor to Increased Surveillance and Censorship Around the World - EFF - August 14th, 2021
- Encryption Software Market Report 2021-26: Size, Growth, Size, Share and Forecast IMARC Group - The Market Writeuo - The Market Writeuo - August 14th, 2021
- AES Encryption Software Market Growth in the Forecast Period of 2021 to 2026 With Top Companies: , Dell, Eset, Gemalto, IBM, Mcafee - The Market... - August 14th, 2021
- Regulated encryption isnt possible heres what is - POLITICO Europe - August 3rd, 2021
- Atakama and Spirion to announce their strategic partnership at Black Hat 2021 - PRNewswire - August 3rd, 2021
- Spirion and Atakama Join Forces at Black Hat 2021 Conference - MarTech Series - August 3rd, 2021
- Looking for ways to password protect a file or folder on Windows 11? Here's how you can do it - India Today - August 3rd, 2021
- XSOC CORP's SOCKET Receives UL- 2900 Certification for Securing Encrypted Workflows of Today's Enterprise and Industrial Connected Devices - Business... - August 3rd, 2021
- Apple @ Work: FileVault 2 is so good, theres no reason for IT departments not to use it - 9to5Mac - August 3rd, 2021
- The Future of Industrial Security - Security Today - August 3rd, 2021
- Global Encryption Software System Market Size And Forecast to 2021 2027 analysis with key players : IBM, Microsoft, Sophos ltd, Gemalto, Net App Inc,... - August 3rd, 2021
- Cloud Encryption Software Market Size 2021 Industry Demand, Share, Global Trend, Industry News, Business Growth, Top Key Players Update, Business... - August 3rd, 2021
- Global E-mail Encryption Market Dynamics Analysis, Production, Supply and Demand, Covered in the Latest Research 2021-2026 - Digital Journal - August 3rd, 2021
- Insights on the Optical Encryption Global Market to 2027 - Featuring Arista Networks, Broadcom and CenturyLink Among Others - ResearchAndMarkets.com -... - July 8th, 2021
- Jupiter Project Presents 'Metis Messenger', the Decentralized Chat Application That Syncs Across All Platforms - GlobeNewswire - July 8th, 2021
- If full encryption of police radios necessary? Berkeley may allow public to hear one of their channels - The Daily Post - July 2nd, 2021
- Leveraging Encryption Keys to Better Secure the Federal Cloud - Nextgov - July 2nd, 2021
- Benefits of Adopting Data Encryption in Businesses - CIOReview - July 2nd, 2021
- Encryption can be lucrative, but with environmental costs - Floridanewstimes.com - July 2nd, 2021
- UK Government has suggested messaging apps to avoid using end-to-end encryption on the accounts of children because that can be harmful to them -... - July 2nd, 2021
- Diavol ransomware linked to Trickbot botnet - IT PRO - July 2nd, 2021
- Got data? The biggest-ever portable encrypted SSD just came out - Cult of Mac - July 2nd, 2021
- Application-Level Encryption Market is expected to expand at a CAGR of 25% from 2020 to 2030 KSU | The Sentinel Newspaper - KSU | The Sentinel... - July 2nd, 2021
- Encryption Key Management Market to Eyewitness Massive Growth by 2028: Ciphercloud, Gemalto, Google The Manomet Current - The Manomet Current - July 2nd, 2021
- Data storage: the importance of protecting the device and not just the network - IT-Online - July 2nd, 2021
- Global E-mail Encryption Market 2021 Demands To Sustain in Future Industry Size, Growth, Revenue, Global Statistics and Forecast to 2030 The Manomet... - July 2nd, 2021
- Hardware Encryption Market 2021 Industry Analysis by Manufacturers, End-User, Type, Application, Regions and Forecast to 2027 The Manomet Current -... - July 2nd, 2021
- Former Anonymous and Lulzsec hacker discusses his criminal past and gives his top tips for avoiding ransomware - Texasnewstoday.com - July 2nd, 2021
- Why Inspecting Encrypted Traffic Is A Must - Security Boulevard - June 25th, 2021
- Researchers: 2G Connection Encryption Deliberately Weakened To Comply With Cryptowar Export Restrictions - Techdirt - June 25th, 2021
- The Ultimate Guide to Key Management Systems - Hashed Out by The SSL Store - Hashed Out by The SSL Store - June 25th, 2021
- Will regulation adapt to encryption, or will encryption adapt to regulation?Expert answers - QNT - June 25th, 2021
- China 'all in' on its own encryption brand - BollyInside - June 25th, 2021