TechOnPurpose Logo

Episode 11: Data Encryption

by | Feb 1, 2022

Who's In Your Cloud?
Who's In Your Cloud?
Episode 11: Data Encryption
Loading
/
Welcome back to “Who’s In Your Cloud?” 21 Steps to Secure, Reliable, Trusted Technology. I’m Lauren Lev, Marketing Manager for TechOnPurpose, and this is Episode 11: Data Encryption.

In last week’s episode, we discussed the importance of Cloud SaaS Backup and how this solution helps guard your SaaS applications’ data from threats such as accidental deletion or ransomware. We were joined, as always, by an all-star cast of cyber experts who taught us about their available solutions to ensure protection, regulate compliance and improve data visibility for your cloud application data.

In today’s episode, as we take a deeper dive into TOPcyber21 best security practice number 11, we’ll discuss how data encryption helps deter malicious actors from accessing and using your sensitive data. Learn why encryption may mitigate the risk from bad actors when the other lines of your cybersecurity defense fall short- Before your data is compromised! We’re thankful to our cyber expert cast joining us today from AppRiver, ConnectWise, Cyber Trust Alliance, and GlobalSign, as they help us educate our clients and prospects on the road to #secure, reliable, trusted technology!

As a reminder, we began releasing a new episode every Tuesday, starting 10/20/21, and will continue to do so through late spring of 2022, with brief time off for holidays with family and friends. We’ll also follow each Tuesday episode release with subsequent Wednesday, Thursday, and Friday posts highlighting our (3) contributing solution partners from that week’s episode. We hope you’ll find this an immersive, hopefully simple, educational and enjoyable experience. So how do you tune in?

To easily follow the journey ahead, we’ve diversified your access options to all (23) of our coming episodes. You can follow along here on our blog or by any of the following methods:

  • Email Newsletter: sign up at techonpurpose.net/blog and have each episode delivered directly to your inbox when released.
  • LinkedIn: follow here
  • YouTube: follow here
  • Facebook: follow here
  • Podcast: follow here

Buckle up – it’s time to hit the road to #secure, reliable, trusted technology!

Read Transcript
Lauren Lev
Welcome back to “Who’s In Your Cloud?” 21 steps to Secure, Reliable, Trusted Technology. I’m Lauren Lev, Marketing Manager for TechOnPurpose and the host of your show, and this is Episode 11: Data Encryption. Before we get into it, catch up on all of our episodes of our #TOPcyber21 security practices on LinkedIn, Facebook, YouTube, or Spotify. And visit TechOnPurpose.net/blog to sign up to get episodes delivered straight to your inbox. In today’s global economy, the need for data encryption should be obvious by now. But how does that happen, where does it happen and whose job is it anyway to encrypt? Today, we’ll be discussing how you can use data encryption to deter malicious actors from accessing and using sensitive data as we take a closer look at TOPcyber21 best practice number 11. As you may have noticed by now we’re missing someone today, “Who’s In Your Cloud?” creator, Matt Tankersley isn’t able to join us but that’s okay because the star of the show, yours truly, is here today. And the show must go on. So with that, we also have an all star cast on deck to talk all things data encryption, so let’s meet our gang. Since I’m flying solo, I am very happy to welcome back two vlog veterans, our VIP cast member Jay Ryerse from ConnectWise and Jeremy Sadler from Cyber Trust Alliance. Since I’m carrying the team here, I’m so thankful for both of you coming back.

Jay Ryerse
And we’re excited to be here. So Lauren, thanks and to the rest of the gang, welcome.

Lauren Lev
All right and new to the vlog and I’m finally happy to have a girl- I think we’ve only had two girls on the vlog so far and we’re already halfway through, but we have Dena Bauckman from AppRiver. And then another new member we have is Patrik Nohe from GlobalSign. We are excited to introduce both of you guys to the blog.

Dena Bauckman
Yeah, very welcome to be here. Looking forward to it.

Lauren Lev
Yeah, of course.

Patrik Nohe
Thanks for having me.

Lauren Lev
Hopefully, you guys have enough fun and come back next time like Jay and Jeremy. Security experts projected that 2014 was going to be the year of encryption. But here we are almost a decade later, in fact, it’s eight years later, and it’s reported that no more than 4% of breach data is protected by encryption. So the primary problem seems to be a lack of overall understanding. So one of the biggest misconceptions is that people tend to think, including myself, that data encryption is only for the government or military or unless it’s legally required in their industry. But I’ve learned as a rule of thumb, if you have sensitive data, which could be anything about your products, operations, customers or employees, then you should always encrypt. Today, we’ll be learning that numerous factors go into it, including things like, what should be encrypted? Is my data at rest or in transit? And what does that even mean? Our goal today is that our viewers will know more and have the knowledge, tools and partners necessary to ensure all of their data is encrypted all of the time. So we are fortunate to have a comprehensive team of cyber experts, because my knowledge- that’s where it ends, right about here. So let’s meet our cast. Jay, we’ll start with you. Tell us about yourself and your role at ConnectWise.

Jay Ryerse
Sure, thanks again, Lauren. So I’m Jay Ryerse, I’m VP of Global Security Sales. I bring a unique perspective to the conversation because while I own a sales team, I’m a CISSP. I ran a managed service business very similar to TechOnPurpose, where we supported, you know, hundreds of businesses around the world ultimately, but we had clients in 35 states. And so, encryption is a fantastic topic. It’s one that starts sadly on the wrong side of the tracks. Right. You know, I think back in 2015, the only people that got the message about the value of encryption were the bad guys, and we’ve been suffering through ransomware ever since, right? Now, it started before then, but that’s when we really started to see it take hold in the small-medium business space. At meaningful levels obviously, over the last five to six years, it’s become a major concern, right. But now let’s reverse this conversation right and jump to the right side of the tracks or on the good guys side. So you mentioned that the need to think about encryption includes data at rest and data in motion. Right? There’s also data in processing, which is actually one more layer that we have to think about. But it’s probably that we spend all day on just that topic, right? You know, how do you do it? What’s the right way? How does it work? What are certificates that fit in and those kinds of things? So one of the topics that I hope we cover today, and I’m pretty sure that Patrik might be our expert on it, though, who knows Jeremy and Dena might surprise me, is managing encryption keys. It’s worse than losing your car keys. And we need to make sure that we understand that and that we’re covering that today for everybody to clearly understand the impact of encryption. So with that, back to you.

Lauren Lev
Awesome, thank you. So Dena, you’re up first as my lady on the cast. So introduce yourself and AppRiver.

Dena Bauckman
Okay so, I’m Dena Bauckman. I’m VP of Product Management for Zix F River. And our, you know, focus is around email. So one of our products is email encryption. And so, it is very much something that we see is, as you said earlier Lauren, people don’t really understand why they need it. And we see that every day. And it’s interesting, because especially in the world of email, people don’t realize a standard email when sent is really like a postcard. There is nothing by default that protects the data in that email. And so, you know, if you’re not doing something to put encryption around that email communication, you know, you might as well just put all your information out on the internet, because every email goes over the internet. And if it’s not protected, it’s just, it’s out there. That’s very easy for hackers to get to.

Lauren Lev
Oh, yeah, absolutely. And how often do we just send an email and rattle off something super important and not think of encryption? I mean, I know until you just said that, I wouldn’t have even thought about that.

Dena Bauckman
Yeah. And the industry has tried to really, you know, up its game with standards that try and encrypt as much of the email traffic as possible. But we constantly see that, you know, people when they patch their systems, or change their configuration and servers, they mess it up. And so, one of the great things you can even look at is Google has what they call their transparency report, they actually track- Google tries very hard to always use encryption. And they track how often they can’t get encryption. And they do pretty good. Google, you know, tries to be very secure. But it’s about between 84 and 86% of the time, they can get encryption, which again, is pretty good. But if you’re dealing with really sensitive information, it’s not good enough.

Lauren Lev
Right, exactly. Okay. So we’re happy to learn more from you about that in round table topic number one. So yeah, I’ll be back to you. Awesome. Okay, perfect. Let’s see, Patrik, tell us more about your background and introduce GlobalSign. You guys are here for the first time.

Patrik Nohe
Yes, thanks for having us. GlobalSign is a globally trusted certificate authority and trust services provider. We deal a lot with certificates that handle authentication. More of the encryption that we’re dealing with is data in transit. But at the same time, you know, we’ve got some other offshoots that handle other other areas of encryption as well. You know, kind of to Jay’s point, I completely agree. I think key management has been one of the biggest obstacles that a lot of organizations are facing, especially as things scale, and they’re seeing more and more certificates and keys be used. And, you know, I think that’s a great topic to get into. Because if you don’t have adequate protections in place, and an employee moves on, or some emergency occurs, where you lose key material, you know, where you lose those keys, excuse me, you’re out all of that information. Anything that is encrypted is now very, very difficult for you to recover without going through some extraordinary means. So I think that’s a really important topic for us to lean on. But just in general, the management of certificates and keys, you know, over the course of the last couple of years as there’s been a rush to work in more remote situations because of the pandemic and everything going on and we’re seeing you know, people access networks from outside of the office more frequently. We’re seeing a lot of mixed environments. Now, that’s really opening a lot of organizations up to, you know, potential vulnerability as well. And I think that’s something that needs to be addressed and rectified very quickly here. Because you know, I’m not sure we’re going to be getting back to the office anytime soon. And as you’re working on closing those attack vectors, you’re leaving yourself open to, you know, something potentially happening.

Lauren Lev
Okay, so if I’m hearing you correctly, I shouldn’t have an encryption key printed in on my desk, right?

Patrik Nohe
Kind of prohibitive to print a good encryption key, but yes, ideally, that would not be a good way for you to store it.

Lauren Lev
Matt would be very upset with me for sure. All right, Jeremy, round us out.

Jeremy Sadler
My name is Jeremy Sadler. I am the Information Security Officer at Cyber Trust Alliance. My primary role and day-to-day activity is providing compliance guidance through primarily, risk assessment services and risk analysis for both regulated and unregulated industries. You know, everything from NIST and SANS related unregulated audits to HIPAA or PCI related audits and assessments. I love the topic of encryption, because it helps me to explain tangibly to a business owner or organization where their sensitive data is and how they should be encrypting and protecting that information, you know, to rehash some of the topics we’ve already introduced, right, both in transit and at rest. I love that Dena mentioned email encryption, that’s a big topic that a lot of people overlook. And then, related to that, also looking at the way encryption can not only protect our information from being exposed electronically and transit as we would an email message, or even our SSL web traffic over the web, but also how encryption can provide non-repudiation, right? Proof or evidence through digital signatures and signage of either emails or other things, to validate that a message did in fact, come from the person or entity you believe it did, right? So a lot of great uses of encryption, and how we leverage it to protect our data and prove the authenticity of our data or our information and where it’s coming from or where it’s going to. So, I’m super excited to be here today to discuss those and other topics.

Lauren Lev
Yeah, we’re excited for you to join us. All right, Mr. Ryerse, as our VIP cast member, I want you to start us off. So for our first round table topic, how do we categorize the types of data that needs to be encrypted? And then explain further on why it’s important and why someone like me should care. And of course, any scary facts, statistics, or stories that you have.

Jay Ryerse
I would never do that. Yeah, if you’ve heard before, I have a tendency to sometimes go too dark, too fast. So I apologize. But I won’t be as much here today, because I think I’ve already gotten there with the ransomware side of encryption. So our team spent a lot of time working with partners on encryption at the endpoint level, right. So think about the devices that are relevant, and what that’s gonna look like for you. And we don’t necessarily do encryption, we don’t have a product for encryption. But we work with our partners to think about, okay, what’s built into native Microsoft Windows operating system, what comes with a Mac, you know, you can start with some very basic disk encryption there, which is going to protect your data at rest in most cases. If you’re in healthcare, if you’re in a heavily regulated industry, you know, you’re going to have to have encryption turned on, on these devices. In that scenario, it’s easy to do, as long as you’ve got a good key management system, like you have a process you’re going to use to manage those keys. And today, it’s much, much easier than it was even two or three years ago. So working with TechOnPurpose and with other companies, you can quickly determine how you’re going to manage that. But think about it as, hey, if I want to identify the data in my network that’s most important to me- It’s your financial records, its business plans, it’s stock information, stockholder information, it’s client information. And like encrypting that’s going to be far more important to me, than you know, encrypting, you know, a five year old sales quote that was rejected and never used. I mean, it probably has value on there and things you’re trying to protect, like, you know, personally identifiable information or your client information might be there. But it’s gonna be a little less important than your most important data. Right. The other thing that we think about and talk about with partners on a regular basis is, you know, it used to be where all the data was on a server in a closet in the back. Well, now we know it’s everywhere. I mean, data truly is in the cloud. And you’ve got to understand what the encryption policies and guidelines are for all of your data storage locations. So a great question to ask this group because I don’t even know what I know the answer today is, you know, how does Microsoft encrypt our data? What does it require to do that there? What is Google doing for us? What is QuickBooks doing for us? What is Peachtree software or whoever you’re using today- Your electronic medical records company, all these places where we’re putting data and we trust that they’re backing it up, and that’s encrypted, right? We’ve had that conversation of backups before. And making sure that it’s meeting the requirements that you have for your regulations that you’re trying to meet, what your legal responsibilities are, and then understanding what type of encryption they’re doing. Because we haven’t even got into the different types of encryption. And again, I’m going to let Jeremy own that if he wants to. Because we can spend all day just covering, you know, how you encrypt and what that looks like. So I’m thinking about the easiest stop for most business owners that are listening in today and business leaders, encrypt that data that’s at rest, the stuff that you have control over so that you can reach out and get to it quickly. So on your servers in your office, in your workstations, on your mobile devices, make sure that your users have encryption turned on. And it’s not difficult, and it’s typically not expensive. But it does require a strategy and a plan to implement, and probably company policy that you’re going to follow and make sure that the colleagues, you know, are aligned to and understand the importance of it.

Lauren Lev
Right, exactly. So Jay’s coming for my job, Jeremy, he set you up perfectly. What does our audience need to know about data encryption from you? And can you touch base a little bit on compliance?

Jeremy Sadler
Absolutely. So, you know, one of the things I think I want to start- I want to lead off with along the compliance side of things is for business owners to understand that whether they have a regulatory obligation to encrypt a particular type of data, like health data, or whether they have just sensitive business data, whether it be competitor data, intellectual property data, or sensitive financial data, to each individual business, that information can be equally valuable as a different data type is to a different entity. The importance is to protect that data, right? That’s what encryption does. You think about, I actually want to cue off of something else Jay mentioned as he started off, he mentioned getting dark in the ransomware segment, you think about what ransomware does to our data. What does it do? It encrypts it, right? That’s how it leverages the ransom against us by encrypting and making our data unavailable to us. If we can leverage that same tool of encryption, to make it unreadable by the threat actors and unrecoverable by unauthorized people, we then turn the whole thing on its head, right, and take advantage of the same technology they’re using against us. Right. That’s the intent. So great example, as Jay mentioned, you know, laptops or even servers for that matter, right, and encryption at rest. You look at something like breach of protected health information. I don’t care if you lose a laptop or a server that has a million patient records on it, if you can prove, effectively, that device was encrypted at rest, it does not constitute a material breach of that information. Right. So that’s where, of course, effective key management comes into play. Because the intention of proving that encryption is in place is that you can prove beyond reasonable doubt that that data could not be recovered by unauthorized individuals. The only way that’s going to be true is that it was encrypted. And then you’ve got good secure key management. Right. In other words, not only is it encrypted, but the recovery key for that encryption isn’t, you know, tattooed on the backside of the device or whatever the case might be. Right. So that’s exactly where we come in with encryption under a compliance perspective, right, if we look at the ways to protect our data and our regulatory obligation to protect that data, even if it gets breached, how can we prevent it from being recovered or read by or observed by unauthorized individuals.

Lauren Lev
All right, thanks, Jeremy. Dena, we’re gonna turn it over to you, the floor is all of yours. Talk about data encryption in general, and can you speak more to the specifics on email encryption? I know we touched on it before, but go more in depth.

Dena Bauckman
Yeah. So, email encryption- I think we’ve kind of hit on this a number of times. It is very important. It is really important if you’re an organization that is under certain regulations like HIPAA, or Gramm-Leach-Bliley, or even if you’re not under regulations, but you’re worried about your reputation as a company if you’re handling sensitive data for your customers. Now, specifically in the area of of email, one of the issues with email communication, if you think of your day-to-day work life, you probably use email a lot and when you jump into an email, you’re not stopping to think about, oh, let me think about each piece of information I’m putting in here. You’re trying to get your job done, okay, you’re trying to send some information to somebody else so they can do their job. And so, what we find a lot with email is that because it’s that quick, you know, I’m just going to send this real quick, I’m going to get it done. People don’t stop and think about what they’re sending. And as I talked about before, in fact, somebody asked about Google and Microsoft, I think Jay, that was you, Google and Microsoft do a really good job. When the data- when the emails are in their system, they do a good job of encrypting that data and protecting it. But every email you send is going to go over the internet. And it’s over that internet, where it’s very easy for hackers to kind of look at the traffic and you know, see what’s being sent. And so, that’s where we really see the biggest need for encryption. And we also kind of touched on the certificate management, that’s always what’s made email encryption the hardest, is how do you manage keys and manage the certificates with all the people you want to send emails to? And so, you know, for years and years, that’s what kind of helped people up from even doing anything about encrypting that data. So yeah, it’s a huge area, one that’s incredibly important to think about. And obviously, if you’re in a regulated industry, you definitely need to think about it.

Lauren Lev
All right, thank you, Dena. Patrik, over to you. Why should our audience care about data encryption? And what more do we need to know about digital certificates?

Patrik Nohe
Well, to touch on something that Dena just said, regarding S/MIME certificates, which are email security certificates, and the difficulty in historically being able to, you know, get them out across your organization to all the endpoints that would need them. That’s really something that over the past few years through various automation tools and management tools we’ve been able to overcome. So that’s no longer an obstacle. And frankly, I think it’s important that most organizations understand that that barrier no longer exists, and that they should be using email security certificates. But that sort of speaks to a larger trend we’re seeing, which is that the volume of certificates being used, and it might help for me to really quickly explain what a certificate is used for, you know, the types of certificates that serve various types of functions, whether that’s creating digitally secure cryptographic signatures, whether that’s securing emails through signatures and encryption, whether that’s securing web traffic with SSL, there’s a number of different use cases for different types of certificates. And organizations, especially enterprises are using more and more now than ever before. So really, as you’re starting to use more certificates, that means you’re managing more certificates. And not only just having the proper tools to manage all the certificates and keys becomes so important, but so does automating a lot of those more tedious functions so that you can continue to turn over certificates and renew them when they need to be renewed or revoke them when they need to be revoked. If you don’t have the capability of doing that at scale, you’re really going to be putting your IT and security teams in kind of a hole because they’re going to be doing so much work just to maintain your own PKI, which is public key infrastructure, which is a huge mechanism of encryption, that they’re gonna have a hard time focusing on really anything else. So as you are looking at encrypting, understand, that’s going to require the usage of a large number of certificates. And that’s going to require mechanisms to both manage those certificates, and also handle some of the more tedious functions through automation.

Lauren Lev
We are going to move into our second round table topic today. And ladies first, we’re going to have Dena chime in. So let’s hear about your company’s specific solution to data encryption.

Dena Bauckman
Sure. So obviously, because I’ve been talking about email encryption throughout this, that is what we provide. We provide a hosted email encryption service. It basically will work with any email system. A lot of our customers today have gone to either Office365 or Google. And so, those are primarily what we support. But what we do is customers basically route their email traffic through us. And we don’t actually just do email encryption. We also do email DLP, so we will scan the email, determine if there’s sensitive data in it, and then if there is then we encrypt the email. And yeah, Patrik hit on the fact S/MIME has gotten a lot easier. S/MIME is predominantly what we use. And we actually do all of that key management for our customer so they don’t have to deal with that. A lot of our customers are small businesses that, you know, terms like PKI, or just like, you know, blow their mind. So, we do all the key management for our customers. And we automatically encrypt all of the emails between our customers, because we have their keys. And our kind of focus in email encryption, because it’s always been kind of one of these things that’s difficult is we do everything we can to make it easy. And so yeah, and so even if you’re not a customer, if you received an encrypted email from us, what we do is put it into a secure email portal that looks like your standard web based email, right? So somebody getting that is going to go, oh, this is kind of like Gmail, let me just kind of, you know, do my thing here. And that’s hugely important when you’re trying to get users to, you know, make sure they’re securing that email communication is that you make it as easy as possible, but yeah, that’s what we do and have done that for- Gosh, let me see, since 1999. So we’ve been doing it for a long time.

Lauren Lev
I know that as a user outside of TechOnPurpose and being an MSP, that I’ve noticed some emails coming through as, like data encrypted, but I haven’t had to do anything. Nothing has been different for me. So that’s really important, because I need it easy. I need it simple and it’s broken down for me.

Dena Bauckman
Yeah, we actually call it, which kind of sounds like a bad term, we call that transparent email encryption because we actually encrypt it after the users hit send and then we decrypt it before it lands in the recipients inbox. So it’s encrypted over the internet, but sender and recipient are like, I don’t have to do anything.

Lauren Lev
Right. And that’s important, right? Because some of these cybersecurity topics are so complex, and the everyday person or someone like me, that knows very little, it’s important that it’s super simple. It’s automated and we don’t need to do anything, but it is still cybersecurity and is still safe. Yeah, I think that’s like, what are the most important approaches to cybersecurity? Thanks, Tina, Patrik, over to you what is GlobalSign’s approach?

Patrik Nohe
GlobalSign is a certificate authority. So we are one of the trusted entities that the web has given the permissions to issue trusted certificates for a range of different use cases, like we discussed before, whether that’s email certificates, SSL certificates for securing web traffic, you know, we issue client certificates, we issue IoT certificates, a whole range of different trusted certificate types that you can use to secure various endpoints. You know, one of the things that we are most focused on, you know, that we’re most known for, I guess, would be SSL TLS certificates. And, you know, that’s because that’s probably been one of the most public types of digital certificates owing largely to Google’s push to encrypt the entire web and require every website to have an SSL certificate. And I think that maybe it would be good to kind of, maybe you’ve done this in an earlier episode, sort of zoom out on why that’s so important. And it’s not just for web connections, it’s for anything on the internet. It’s not an A to B connection, when you’re sending something online, it doesn’t just go from your endpoint to their endpoint. It bounces and goes through a whole bunch of different endpoints on its way to its destination, and you can’t possibly trust that each one of those endpoints is secure and that nobody’s eavesdropping on it, nobody’s capable of looking at what you’re doing. So when you encrypt data along that, that route, it helps to ensure not only that the data stays secure and isn’t stolen, but as was mentioned earlier, that it stays authentic, that you know, that it’s what was intended to be sent, that it can’t be manipulated or tampered with or anything like that. And that’s important across so many different touch points on the internet, not just web connections. So it’s really important that you understand what it is you’re doing to secure that. And, you know, with certificates, you can do so much of that at least securing the data in transit, not so much the data at rest. So that’s really what GlobalSign does is as a certificate authority, we help organizations large and small to secure their endpoints, and then to manage it all and automate the portions that they want to so that it doesn’t become a burden for them. And so, that it is easy and that’s, you know, one of the first things about PKI is it’s not naturally easy. It’s something that you know, you need a trusted partner to really help you know, guide you through this because as Dena said, you know, PKI makes a lot of people’s minds blow up. That’s not a term that’s widely known. So, you know, when you have a trusted partner that can help you with those decisions and, you know, to a larger extent, even with a crypto agility with the incoming threat of quantum computing and understanding what crypto systems and algorithms you should be using, and you know how to best position yourself for that there’s a lot of different things that you need to focus on with regard to what we do. And you know, being a trusted partner is really the biggest part of our strategy is you need somebody like that in your corner.

Lauren Lev
Yeah, absolutely. And approach that I like to take to this topic, or actually, any of our cybersecurity topics is the KISS approach, which is keep it simple, stupid, right? It’s obvious there like are- Well, besides you guys, most people out there, like don’t know what we’re talking about, right? And so, it’s really important to keep it super simple, keep it automated, keep it easy for everyone to understand and implement, you know, because then they’re going to do it. Right. If there’s too much to learn, they’re gonna fall by the wayside. I couldn’t agree more. So Jeremy, what solutions does Cyber Trust have for data encryption?

Jeremy Sadler
Good question. So we are basically a GCR organization: products and services centered around governance, compliance and risk, right. So while we don’t have encryption solutions, per se, we offer services that help an organization focus on where they require those governance or compliance or risk assessment situations. And one of the ways we find that organizations repeatedly fall short and need some help or some guidance is identifying the valuable data in their organization or the sensitive data in their organization. Some of them might have an idea, oh, yeah, I know I have an EMR, a full patient health information. Well, that’s great, but where else are you sending that patient health information? Are you using your scanners to email content from paper into your EMR? And if you are, you need to be concerned about the encryption from that scanner and that email functionality. Right. So we focus not only on the risk assessment and compliance and governance facet of it, but also the discovery process of helping organizations to become aware of where their data lies and where it needs to be protected. One of the areas that I’ve been emphasizing most recently that a lot of organizations have forgotten about protecting are their backups, right? So you look at a world where as an industry, we’ve moved away from the old tape backups, but tape backups were awesome for one very specific reason. We had an offline copy of our backups that couldn’t be destroyed by attackers that couldn’t be erased by ransomware, that we could restore to reliably within reason. Of course tapes had their issues, magnetic media has its shortcomings and its own reliability challenges. But in a world where online replication has become the cost effective solution for our backups, I’ve been educating organizations on utilizing either encryption or other solutions to protect their backups to help to deflate some of the power that the ransomware threat actors have over our organizations by protecting their backups the same way they protect their critical data. You see that in a lot of different solutions that are out there. Some immutable S3 Buckets are a great example. Of course, the old “write once, read many” solutions of tape backups or just plain old fashioned encrypted digit physical storage that you air gapped or unplug to protect it.

Lauren Lev
Before I close out today, Jay, what are your final thoughts on this topic?

Jay Ryerse
Actually, it doesn’t feel like we’ve made this easy yet. Because we can’t forget that it’s not easy. Patrik, I’m going to call on you to kinda help guide this next section, because I’ve got a question for you that I think would provide value for everybody else that might help make it easy. You know, Jeremy talked earlier about nonrepudiation authentication of one side and the other in the conversation. When a certificate is issued, like when a company comes to us, it is handy to put a SSL certificate on my website, right, that you got to authenticate who that company is. What are some of the things that you guys look for to verify that they really are that company, that they’re really Coca-Cola, or Pepsi or whoever and they’re not some hacker trying to get a certificate so they can impersonate? So what does that look like? Because I think that’s interesting stuff that the audience might like.

Patrik Nohe
That is a really good question and that kind of goes to a larger conversation that we’ve been having kind of as an industry about the level of validation that should be required for a web server certificate. Because at the bottom, the basic most, you know, low level of validation is just simple domain validation, you know, where you’re just ensuring that the hostname matches what they’re trying to request and then you can get a certificate. You can get a free SSL certificate with very little validation. If you want to actually prove that you’re an organization, there are two higher levels of validation: organization validation and extended validation. Extended validation used to have its own little perk, it would put the validated/authenticated name of the organization in the address bar of a web browser. I think that largely people use their phones now more than computers for a lot of browsing. And there was difficulty in displaying it that way and I think there were some other actors that questioned the value of that level of validation anyway, and just wanted to get a certificate on every server, regardless of you know, trying to make as few hoops as possible to jump through. But with organization validation and extended validation, we do actually have to look for proof that that business has a legal registration in the area that it’s it’s claiming to be in, that it has business phones, that it has, you know, certain proof that it is actually a business, that it does operate in that area. There’s a number of actual checks that are prescribed through the CAB Forums, baseline requirements that our vetting process or vetting department has to go through in order to understand who the organization is. And once they have satisfied all of those checks. And you know, those are constantly being tweaked by the CAB Forum, which is kind of the governing body for SSL and publicly trusted digital certificates. Once those are satisfied, then that certificate can be issued. And when you review the certificate, and this is another problem is that a lot of consumers and web users don’t understand how to look at a website certificate, it will show that verified information about the company that’s operating the website if it uses a higher level of validation with its web certificate. But right now with domain validated certificates, you can really get a certificate from anywhere. And I mean, not to speak ill because it’s a great service, but one of the things that they say is that, well the criminals use Let’s Encrypt because you can just get a certificate with a web name.

Jay Ryerse
It’s clear as mud right?

Patrik Nohe
Yeah, I don’t think that that did much to clarify, I apologize. But it is-

Jay Ryerse
But Patrik, it does, because it starts to help people understand that what’s really happening is that you’re, you’re standing behind who you’re issuing a certificate to at different levels, I get it. But so, that there’s confidence that if I see a certificate assigned to a business, there’s a high probability that that’s correct. It doesn’t mean there’s not malicious actors out there that are going to find ways around it and use other techniques to bypass encryption keys and that certificate management. But it makes it much more difficult when a user can point and click and see who authenticated it, when, and is this a trusted company that issues certificates, you know, and it is authenticated as such, right. So it never stops the authentication process. So it’s good to know that behind the scenes, there’s a lot of really, really smart people making this possible. Our team here at ConnectWise, you know, works with partners that they learn how to implement security and how to think about it. Encryption is one of the areas that we teach, but we don’t deliver a product. So I’m not here to say, hey, use us as much as you know- start talking to your TechOnPurpose, talk to your IT professionals about where security fits in their business and where encryption fits because Jeremy hinted earlier those safe harbor laws, those rules that say, Hey, if you can prove the laptop that was stolen out of your car was encrypted, I don’t have to report that breach. And that’s a really big deal. And that’s just a small sample of how many different types of ways it happens. So, again, encrypt, encrypt, encrypt, and make sure you’re talking to your teams about data in rest, data in motion and data in processing, which is like when firewalls open up, you have to look at look and see if anything malicious inside of them and put them back together again. So a lot of areas where you can focus as a business owner, to get your team’s giving you the right answers.

Lauren Lev
Right. Like I said in the intro, encrypt all data all the time. Right. So Dena and Jeremy, before I close this out, do you guys have any final comments on data encryption?

Dena Bauckman
Well, one thing just real quick that I hope people also picked up on is to find a good partner, somebody that already knows more about this than you do? It’s not, you know, companies or people in IT can’t be experts on everything. So it’s really important you find those organizations that you can partner with that really can help you figure out what you need to do. And there’s a lot of good companies out there to talk to.

Lauren Lev
Jeremy, any final words?

Jeremy Sadler
You know, Dena hit the nail on the head and took words right out of my mouth, right. In summarizing what Jay was trying to drive home, and how do we simplify this for organizations to understand it really comes down to, there are plenty of pitfalls in encryption, plenty of details, plenty of pure topics and categories, right? When you look at our panelists here today, whether it’s endpoint email, SSL certificates or authentication certificates or other forms of certificates, there’s so many different individual specialties within the encryption domain. That an organization really should pursue the assistance of a trusted vendor, trusted partner like TechOnPurpose, or otherwise, to help bring the right solutions for that business’s needs.

Lauren Lev
An important takeaway from today is that when the other lines of your cybersecurity defenses fall short, and your data is compromised, encryption can help to mitigate the risk from bad actors who lack the tools or even encryption keys, right and hopefully, needed to unleash the habit that they intend. But join us next week as we dive into mobile device management. Working remotely has become more essential and is likely here to stay. Mobile devices have become an integral part of most organizations. It’s a vital tool for productivity and efficiency, but how can you safeguard them from attack? Catch up on all episodes on LinkedIn, Facebook, YouTube, or Spotify and get delivery straight to your inbox by signing up TechOnPurpose.net/blog. And if you would like to start a free trial from our solution partners today, send us an email at . And while you’re over there, sign up for our free cybersecurity risk assessment at WhosInYour.Cloud. Well, that is all from us today. I appreciate all of you joining us and we will see you next week. Bye everybody.

Ready for your free cybersecurity survey? Discover potential vulnerabilities for your business and get a copy of our #TOPcyber21 Best Security Practices to help get you started on the road to #secure, reliable, trusted technology! Subscribe to our blog to get episodes of “Who’s In Your Cloud?” delivered direct to your inbox weekly.
Claim Your Free Cybersecurity Sruvey
Protecting your Blindside. Your Team is Your 1st Line of Defense

Protecting your Blindside. Your Team is Your 1st Line of Defense

Cyberattacks are on the rise, with phishing, ransomware, and social engineering attacks becoming more prevalent and harder to detect. A recent report from the Anti-Phishing Working Group (APWG) shows a significant increase in phishing attacks, with attackers becoming more sophisticated in their tactics.

View Next

Diagram showing how Texas cybersecurity law applies to every business, with two outcome paths — documented before a breach leads to safe harbor, documented after leads to full legal exposure

Texas Cybersecurity Law: What Every Business Must Know

⏱ 6 min readKey Takeaways Texas cybersecurity law already requires every business, regardless of size, to protect sensitive personal information and report breaches within 60 days of discovery. SB 2610 offers a safe harbor from punitive damages — but only if you can...
CVE dashboard showing NIST's "Not Scheduled" status replacing CVSS scores — patch prioritization without a score

NIST Just Derailed Patch Prioritization — Here’s Your Fix

⏱ 3 min readKey Takeaways NIST stopped automatic CVSS scoring for most CVEs on April 15 — the patch prioritization signal most organizations relied on just changed permanently. Only CVEs on CISA's KEV list, federal software, and EO 14028 critical software receive...
AI-Enabled Device Code Phishing — TechOnPurpose Identity & Access Management MFA Bypass Prevention

AI-Enabled Device Code Phishing Is Bypassing MFA — What Your Microsoft 365 Users Are Up Against

⏱ 4 min readKey Takeaways Device code phishing abuses a legitimate Microsoft OAuth flow — no passwords stolen, no MFA prompt triggered, full M365 access granted. AI-generated lures are now role-specific and hyper-personalized — standard phishing training won't catch...
Chrome Zero-Day Patch — TechOnPurpose TC21-05 Endpoint Patch Management Urgency

Chrome Zero Day Patch: Update Now

⏱ 4 min readKey Takeaways This chrome zero day patch isn’t routine maintenance — it covers two vulnerabilities already being weaponized. CVE-2026-5289 scored a 9.6 CVSS — a full sandbox escape. If exploited, an attacker owns the endpoint. CISA added CVE-2026-5281 to...
Russian CTRL Toolkit remote desktop hijacking — TechOnPurpose TC21-15 secure remote access defense

Russian Malware CTRL: Remote Desktop Hijacking Undetected

⏱ 4 min readKey Takeaways Newly disclosed Russian remote access toolkit called CTRL is enabling remote desktop hijacking attacks that bypass all known threat intelligence platforms — including VirusTotal CTRL is a newly disclosed Russian-origin remote access toolkit...
Old vulnerabilities cyber risk — TechOnPurpose patch management defense-in-depth

#CYBERinsanity: The Vulnerabilities Attacking You Today Were Published a Decade Ago

⏱ 5 min readKey Takeaways 32% of the most active exploits are old vulnerabilities, more than ten years old — patches exist, they're just not being applied. Attackers start with the low-hanging fruit: automated scans for known, unpatched flaws before deploying anything...
Defense in depth strategy — TechOnPurpose TOPCYBER21 cybersecurity framework protects your organization from vulnerability exploits

Why Patching Alone Won’t Stop 40% of Cyberattacks

⏱ 4 min readKey Takeaways A defense in depth strategy is no longer optional — it's the only architecture that holds when patching alone fails. Nearly 40% of all intrusions in Q4 2025 were caused by exploited vulnerabilities — not phishing, not credential theft. Some...
2026 National Cyber Strategy Blog Post image

2026 National Cybersecurity Strategy: What It Means for You

⏱ 5 min readKey Takeaways The White House's 2026 national cybersecurity strategy introduces six strategic pillars — the clearest federal signal yet that passive cyber defense is no longer acceptable. All six pillars align directly to the TOPCYBER21™ framework — if...
TechOnPurpose achieves MSSP Alert's prestigious 2025 Top 250 Managed Security Service Providers (MSSPs) list, ranking #159 globally—a significant jump of 32 positions from last year's #191.

TechOnPurpose Named to MSSP Alert’s 2025 List of Top 250 MSSPs – Climbs 32 Spots Year-Over-Year

TechOnPurpose is proud to announce its inclusion in MSSP Alert's prestigious 2025 Top 250 Managed Security Service Providers (MSSPs) list, ranking #159 globally - a significant jump of 32 positions from last year's #191. This marks the second consecutive year...
#STOPtheCYBERinsanity image - Is Pen Testing a Dollars-Before-Defense Mistake

#CYBERinsanity: When Pen Testing Becomes a Dollars-Before-Defense Mistake

The Fallacy of Pen Testing as a Priority in Cybersecurity If you’ve been following our STOP the #CYBERinsanity series, you already know this uncomfortable truth: Most cybersecurity failures aren’t caused by brilliant hackers or exotic zero-day exploits. They’re caused...
en_US