Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Thursday, 4 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Adopting a security policy around data is more efficient than the perimeter

by The Gurus
September 8, 2020
in Editor's News
Share on FacebookShare on Twitter

Having a “data-centric” policy may sound like a sensible option, but according to one chief security officer most businesses have no clue.

Speaking to IT Security Guru, Sol Cates, CSO at Vormetric said that while the concept of encryption and encrypting data is great, all it does is stop the person running an infrastructure from seeing the information. “Our research found that 73 per cent of respondents said that they had no way of protecting sensitive data; the driver has got to be proactive,” he said.
“There is no proactive control to prevent data loss from happening, nothing can make data protect itself but you can protect environments yet 53 per cent of spend is going on network perimeter defence as people don’t know any better and it has always been an access control problem, but this doesn’t get rid of the risk to data.
“Attacks are still the same, the operating system still tells you what to do and it is the system administrator with physical access to do this. After the details about Prism were revealed this summer, the NSA cut their number of systems administrators by 90 per cent. Yet if your systems administrator is blind to the data, it will constantly improve your risk experience as they will be able to manage data but not see it.”
Cates said that with a data-centric policy, a company can own the data, but have centralised management of it.
He said: “We have never got rid of the inherent problem: you should be able to do systems management without risk and exposure to data. Our argument is that only privileged users should be able to see the information and by putting in better controls, you consolidate it and end up hiding silos within the data centre.”
Cates said that with a data-centric policy, this will help on Big Data being restructured, as at the moment the problem is that there is too much unstructured data to make a decision and do decent analytics.
He concluded by saying that efficient privileged user management and the company knowing what is important to the company will allow for better security. “Definition, discovery and defence, what is core to the business and what do you share.”
IT Security Guru’s Dan Raywood talks to Sol Cates on this subject in our video here
ShareTweet
Previous Post

PHP.net in recovery after servers were infected

Next Post

DDoS awareness day aims to address the threat issues

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol